Article 54
Rules on the establishment of the supervisory authority

Official
Texts
Guidelines Caselaw Review of
EU Regulation
Review of
Nat. Regulation
Show the recitals of the Regulation related to article 54 keyboard_arrow_down Hide the recitals of the Regulation related to article 54 keyboard_arrow_up

(121) The general conditions for the member or members of the supervisory authority should be laid down by law in each Member State and should in particular provide that those members are to be appointed, by means of a transparent procedure, either by the parliament, government or the head of State of the Member State on the basis of a proposal from the government, a member of the government, the parliament or a chamber of the parliament, or by an independent body entrusted under Member State law. In order to ensure the independence of the supervisory authority, the member or members should act with integrity, refrain from any action that is incompatible with their duties and should not, during their term of office, engage in any incompatible occupation, whether gainful or not. The supervisory authority should have its own staff, chosen by the supervisory authority or an independent body established by Member State law, which should be subject to the exclusive direction of the member or members of the supervisory authority.

Show the recitals of the Directive related to article 54 keyboard_arrow_down Hide the recitals of the Directive related to article 54 keyboard_arrow_up

(62) Whereas the establishment in Member States of supervisory authorities, exercising their functions with complete independence, is an essential component of the protection of individuals with regard to the processing of personal data;

The GDPR

Article 54 requires that Member States provide by law the conditions of establishment of the supervisory authorities. Each Member State sets the terms of appointment of the members both in regards to the appointment procedure and to the skills required, the term of office, and the prohibitions of employment or activities.

Thus, each Member State must provide by law (Art. 54 (1)):

- the establishment of each supervisory authority (a);

- the qualifications and eligibility conditions required to be appointed as member of each supervisory authority (b);

- the rules and procedures for the appointment of the member or members of each supervisory authority (c);

- the duration of the term of the member or members of each supervisory authority (that cannot be less than four years) and whether and, if so, for how many terms the member or members of each supervisory authority is eligible for reappointment (e); The duration of the first appointment after the entry of the Regulation in force may be less than 4 years where that is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure (d);

- the conditions governing the obligations of the member or members and staff of each supervisory authority, prohibitions on actions, occupations and benefits incompatible therewith during and after the term of office and rules governing the cessation of employment (f).

Finally, the last paragraph of Article 54 imposes that the member or members and the staff of each supervisory authority shall be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks or exercise of their powers as already provided by the Directive in its Article 28 (7).  This duty of professional secrecy is applied in particular with respect to reporting by natural persons of infringements of this Regulation (paragraph 2).

The Directive

As already indicated, the Directive says very little about the terms of appointment and the status applicable to the members of the supervisory authority as well as the modes for establishment of the supervisory authorities; at most, Article 28 (7) of the Directive imposed an obligation on the Member States to ensure that the members and staff of the supervisory authority, even after their employment has ended, are to be subject to a duty of professional secrecy with regard to confidential information to which they have access.

Potential issues

We do not see a priori any specific implementation difficulties.

Summary

European Union

European Union

Retour au sommaire

Article 29 Working Party

Guidelines on the Lead Supervisory Authority - wp244rev.01 (5 April 2017)

(Endorsed by the EDPB)

Identifying a lead supervisory authority is only relevant where a controller or processor is carrying out the cross-border processing of personal data. Article 4(23) of the General Data Protection Regulation (GDPR) defines ‘cross-border processing’ as either the:

- processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or the

- processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.

This means that where an organisation has establishments in France and Romania, for example, and the processing of personal data takes place in the context of their activities, then this will constitute cross-border processing.

Alternatively, the organisation may only carry out processing activity in the context of its establishment in France. However, if the activity substantially affects – or is likely to substantially affect - data subjects in France and Romania then this will also constitute crossborder processing.

Link

Retour au sommaire

Summary

European Union

European Union

CJEU caselaw

C-518/07 (9 March 2010) - Commission v Germany

1.      Declares that, by making the authorities responsible for monitoring the processing of personal data by non-public bodies and undertakings governed by public law which compete on the market (öffentlich-rechtliche Wettbewerbsunternehmen) in the different Länder subject to State scrutiny, and by thus incorrectly transposing the requirement that those authorities perform their functions ‘with complete independence’, the Federal Republic of Germany failed to fulfil its obligations under the second subparagraph of Article 28(1) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data;

2.      Orders the Federal Republic of Germany to pay the costs of the Commission;

3.      Orders the European Data Protection Supervisor (EDPS) to bear his own costs.

Opinion of Advocate general 

Judgment of the Court

C-614/10 (16 October 2012) -  Commission v Austria

1.      Declares that, by failing to take all of the measures necessary to ensure that the legislation in force in Austria meets the requirement of independence with regard to the Datenschutzkommission (Data Protection Commission), more specifically by laying down a regulatory framework under which

–        the managing member of the Datenschutzkommission is a federal official subject to supervision,

–        the office of the Datenschutzkommission is integrated with the departments of the Federal Chancellery, and

–        the Federal Chancellor has an unconditional right to information covering all aspects of the work of the Datenschutzkommission,

the Republic of Austria has failed to fulfil its obligations under the second subparagraph of Article 28(1) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data;

2.      Orders the Republic of Austria to pay the costs incurred by the European Commission;

3.      Orders the Federal Republic of Germany and the European Data Protection Supervisor to bear their own respective costs.

Opinion of Advocate general 

Judgment of the Court

C-230/14 (1 October 2015) - Weltimmo

1.      Article 4(1)(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data must be interpreted as permitting the application of the law on the protection of personal data of a Member State other than the Member State in which the controller with respect to the processing of those data is registered, in so far as that controller exercises, through stable arrangements in the territory of that Member State, a real and effective activity — even a minimal one — in the context of which that processing is carried out.

In order to ascertain, in circumstances such as those at issue in the main proceedings, whether that is the case, the referring court may, in particular, take account of the fact (i) that the activity of the controller in respect of that processing, in the context of which that processing takes place, consists of the running of property dealing websites concerning properties situated in the territory of that Member State and written in that Member State’s language and that it is, as a consequence, mainly or entirely directed at that Member State, and (ii) that that controller has a representative in that Member State, who is responsible for recovering the debts resulting from that activity and for representing the controller in the administrative and judicial proceedings relating to the processing of the data concerned.

By contrast, the issue of the nationality of the persons concerned by such data processing is irrelevant.

2.      Where the supervisory authority of a Member State, to which complaints have been submitted in accordance with Article 28(4) of Directive 95/46, reaches the conclusion that the law applicable to the processing of the personal data concerned is not the law of that Member State, but the law of another Member State, Article 28(1), (3) and (6) of that directive must be interpreted as meaning that that supervisory authority will be able to exercise the effective powers of intervention conferred on it in accordance with Article 28(3) of that directive only within the territory of its own Member State. Accordingly, it cannot impose penalties on the basis of the law of that Member State on the controller with respect to the processing of those data who is not established in that territory, but should, in accordance with Article 28(6) of that directive, request the supervisory authority within the Member State whose law is applicable to act.

3.      Directive 95/46 must be interpreted as meaning that the term ‘adatfeldolgozás’ (technical manipulation of data), used in the Hungarian version of that directive, in particular in Articles 4(1)(a) and 28(6) thereof, must be understood as having the same meaning as that of the term ‘adatkezelés’ (data processing).

Opinion of Advocate general 

Judgment of the Court

Retour au sommaire Retour au sommaire
Regulation
1e 2e

Art. 54

1.   Each Member State shall provide by law for all of the following:

a) the establishment of each supervisory authority;

b) the qualifications and eligibility conditions required to be appointed as member of each supervisory authority;

c) the rules and procedures for the appointment of the member or members of each supervisory authority;

d) the duration of the term of the member or members of each supervisory authority of no less than four years, except for the first appointment after 24 May 2016, part of which may take place for a shorter period where that is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure;

e) whether and, if so, for how many terms the member or members of each supervisory authority is eligible for reappointment;

f) the conditions governing the obligations of the member or members and staff of each supervisory authority, prohibitions on actions, occupations and benefits incompatible therewith during and after the term of office and rules governing the cessation of employment.

2.   The member or members and the staff of each supervisory authority shall, in accordance with Union or Member State law, be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks or exercise of their powers. During their term of office, that duty of professional secrecy shall in particular apply to reporting by natural persons of infringements of this Regulation.

1st proposal close

Art. 49

Each Member State shall provide by law within the limits of this Regulation:

(a)     the establishment and status of the supervisory authority;

(b)     the qualifications, experience and skills required to perform the duties of the members of the supervisory authority;

(c)     the rules and procedures for the appointment of the members of the supervisory authority, as well the rules on actions or occupations incompatible with the duties of the office;

(d)     the duration of the term of the members of the supervisory authority which shall be no less than four years, except for the first appointment after entry into force of this Regulation, part of which may take place for a shorter period where this is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure;

(e)     whether the members of the supervisory authority shall be eligible for reappointment;

(f)      the regulations and common conditions governing the duties of the members and staff of the supervisory authority;

(g)     the rules and procedures on the termination of the duties of the members of the supervisory authority, including in case that they no longer fulfil the conditions required for the performance of their duties or if they are guilty of serious misconduct.

2nd proposal close

1. Chaque État membre prévoit, par voie législative:

a) la création (…) de chaque autorité de contrôle;

b) les qualifications (...) requises pour exercer les fonctions de membre de l'autorité de contrôle;

c) les règles et les procédures pour la nomination du membre ou des membres de chaque autorité de contrôle (…);

d) la durée du mandat du membre ou des membres de chaque autorité de contrôle, qui ne doit pas être (…) inférieure à quatre ans, sauf pour le premier mandat suivant l'entrée en vigueur du présent règlement, qui peut être d'une durée plus courte lorsque cela est nécessaire pour protéger l'indépendance de l'autorité de contrôle au moyen d'une procédure de nominations échelonnées;

e) le caractère renouvelable ou non renouvelable du mandat du membre ou des membres de chaque autorité de contrôle et, dans l'affirmative, pour combien de mandats;

f) (...) les conditions régissant les obligations du membre ou des membres et des agents de chaque autorité de contrôle, les interdictions d'activités ou d'emplois incompatibles avec celles-ci, y compris après la cessation de leurs activités, et les règles régissant la cessation de l'emploi;

g) (…).

2. Le membre ou les membres et les agents de chaque autorité de contrôle sont soumis, conformément au droit de l'Union ou à la législation nationale, au secret professionnel concernant toute information confidentielle dont ils ont eu connaissance dans l'exercice de leurs fonctions (…) ou de leurs pouvoirs, y compris après la cessation de leurs activités.

Directive close

Art. 28

1. Each Member State shall provide that one or more public authorities are responsible for monitoring the application within its territory of the provisions adopted by the Member States pursuant to this Directive.

These authorities shall act with complete independence in exercising the functions entrusted to them.

2. Each Member State shall provide that the supervisory authorities are consulted when drawing up administrative measures or regulations relating to the protection of individuals' rights and freedoms with regard to the processing of personal data.

3. Each authority shall in particular be endowed with:

- investigative powers, such as powers of access to data forming the subject-matter of processing operations and powers to collect all the information necessary for the performance of its supervisory duties,

- effective powers of intervention, such as, for example, that of delivering opinions before processing operations are carried out, in accordance with Article 20, and ensuring appropriate publication of such opinions, of ordering the blocking, erasure or destruction of data, of imposing a temporary or definitive ban on processing, of warning or admonishing the controller, or that of referring the matter to national parliaments or other political institutions,

- the power to engage in legal proceedings where the national provisions adopted pursuant to this Directive have been violated or to bring these violations to the attention of the judicial authorities.

Decisions by the supervisory authority which give rise to complaints may be appealed against through the courts.

4. Each supervisory authority shall hear claims lodged by any person, or by an association representing that person, concerning the protection of his rights and freedoms in regard to the processing of personal data. The person concerned shall be informed of the outcome of the claim.

Each supervisory authority shall, in particular, hear claims for checks on the lawfulness of data processing lodged by any person when the national provisions adopted pursuant to Article 13 of this Directive apply. The person shall at any rate be informed that a check has taken place.

5. Each supervisory authority shall draw up a report on its activities at regular intervals. The report shall be made public.

6. Each supervisory authority is competent, whatever the national law applicable to the processing in question, to exercise, on the territory of its own Member State, the powers conferred on it in accordance with paragraph 3. Each authority may be requested to exercise its powers by an authority of another Member State.

The supervisory authorities shall cooperate with one another to the extent necessary for the performance of their duties, in particular by exchanging all useful information.

7. Member States shall provide that the members and staff of the supervisory authority, even after their employment has ended, are to be subject to a duty of professional secrecy with regard to confidential information to which they have access.

Artículo 48. La Presidencia de la Agencia Española de Protección de Datos.

1. La Presidencia de la Agencia Española de Protección de Datos la dirige, ostenta su representación y dicta sus resoluciones, circulares y directrices.

2. La Presidencia de la Agencia Española de Protección de Datos estará auxiliada por un Adjunto en el que podrá delegar sus funciones, a excepción de las relacionadas con los procedimientos regulados por el título VIII de esta ley orgánica, y que la sustituirá en el ejercicio de las mismas en los términos previstos en el Estatuto Orgánico de la Agencia Española de Protección de Datos.

Ambos ejercerán sus funciones con plena independencia y objetividad y no estarán sujetos a instrucción alguna en su desempeño. Les será aplicable la legislación reguladora del ejercicio del alto cargo de la Administración General del Estado.

En los supuestos de ausencia, vacante o enfermedad de la persona titular de la Presidencia o cuando concurran en ella alguno de los motivos de abstención o recusación previstos en el artículo 23 de la Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público, el ejercicio de las competencias relacionadas con los procedimientos regulados por el título VIII de esta ley orgánica serán asumidas por la persona titular del órgano directivo que desarrolle las funciones de inspección. En el supuesto de que cualquiera de las circunstancias mencionadas concurriera igualmente en dicha persona, el ejercicio de las competencias afectadas será asumido por las personas titulares de los órganos directivos con nivel de subdirección general, por el orden establecido en el Estatuto.

El ejercicio del resto de competencias será asumido por el Adjunto en los términos previstos en el Estatuto Orgánico de la Agencia Española de Protección de Datos y, en su defecto, por las personas titulares de los órganos directivos con nivel de subdirección general, por el orden establecido en el Estatuto.

3. La Presidencia de la Agencia Española de Protección de Datos y su Adjunto serán nombrados por el Gobierno, a propuesta del Ministerio de Justicia, entre personas de reconocida competencia profesional, en particular en materia de protección de datos. Dos meses antes de producirse la expiración del mandato o, en el resto de las causas de cese, cuando se haya producido éste, el Ministerio de Justicia ordenará la publicación en el Boletín Oficial del Estado de la convocatoria pública de candidatos.

Previa evaluación del mérito, capacidad, competencia e idoneidad de los candidatos, el Gobierno remitirá al Congreso de los Diputados una propuesta de Presidencia y Adjunto acompañada de un informe justificativo que, tras la celebración de la preceptiva audiencia de los candidatos, deberá ser ratificada por la Comisión de Justicia en votación pública por mayoría de tres quintos de sus miembros en primera votación o, de no alcanzarse ésta, por mayoría absoluta en segunda votación, que se realizará inmediatamente después de la primera. En este último supuesto, los votos favorables deberán proceder de Diputados pertenecientes, al menos, a dos grupos parlamentarios diferentes.

4. La Presidencia y el Adjunto de la Agencia Española de Protección de Datos serán nombrados por el Consejo de Ministros mediante real decreto.

5. El mandato de la Presidencia y del Adjunto de la Agencia Española de Protección de Datos tiene una duración de cinco años y puede ser renovado para otro período de igual duración.

La Presidencia y el Adjunto solo cesarán antes de la expiración de su mandato, a petición propia o por separación acordada por el Consejo de Ministros, por:

a) Incumplimiento grave de sus obligaciones,

b) incapacidad sobrevenida para el ejercicio de su función,

c) incompatibilidad, o

d) condena firme por delito doloso.

En los supuestos previstos en las letras a), b) y c) será necesaria la ratificación de la separación por las mayorías parlamentarias previstas en el apartado 3 de este artículo.

6. Los actos y disposiciones dictados por la Presidencia de la Agencia Española de Protección de Datos ponen fin a la vía administrativa, siendo recurribles, directamente, ante la Sala de lo Contencioso-administrativo de la Audiencia Nacional.

 

Artículo 49. Consejo Consultivo de la Agencia Española de Protección de Datos.

1. La Presidencia de la Agencia Española de Protección de Datos estará asesorada por un Consejo Consultivo compuesto por los siguientes miembros:

a) Un Diputado, propuesto por el Congreso de los Diputados.

b) Un Senador, propuesto por el Senado.

c) Un representante designado por el Consejo General del Poder Judicial.

d) Un representante de la Administración General del Estado con experiencia en la materia, propuesto por el Ministro de Justicia.

e) Un representante de cada Comunidad Autónoma que haya creado una Autoridad de protección de datos en su ámbito territorial, propuesto de acuerdo con lo que establezca la respectiva Comunidad Autónoma.

f) Un experto propuesto por la Federación Española de Municipios y Provincias.

g) Un experto propuesto por el Consejo de Consumidores y Usuarios.

h) Dos expertos propuestos por las Organizaciones Empresariales.

i) Un representante de los profesionales de la protección de datos y de la privacidad, propuesto por la asociación de ámbito estatal con mayor número de asociados.

j) Un representante de los organismos o entidades de supervisión y resolución extrajudicial de conflictos previstos en el Capítulo IV del Título V, propuesto por el Ministro de Justicia.

k) Un experto, propuesto por la Conferencia de Rectores de las Universidades Españolas.

l) Un representante de las organizaciones que agrupan a los Consejos Generales, Superiores y Colegios Profesionales de ámbito estatal de las diferentes profesiones colegiadas, propuesto por el Ministro de Justicia.

m) Un representante de los profesionales de la seguridad de la información, propuesto por la asociación de ámbito estatal con mayor número de asociados.

n) Un experto en transparencia y acceso a la información pública propuesto por el Consejo de Transparencia y Buen Gobierno.

ñ) Dos expertos propuestos por las organizaciones sindicales más representativas.

2. A los efectos del apartado anterior, la condición de experto requerirá acreditar conocimientos especializados en el Derecho y la práctica en materia de protección de datos mediante el ejercicio profesional o académico.

3. Los miembros del Consejo Consultivo serán nombrados por orden del Ministro de Justicia, publicada en el Boletín Oficial del Estado.

4. El Consejo Consultivo se reunirá cuando así lo disponga la Presidencia de la Agencia Española de Protección de Datos y, en todo caso, una vez al semestre.

5. Las decisiones tomadas por el Consejo Consultivo no tendrán en ningún caso carácter vinculante.

6. En todo lo no previsto por esta ley orgánica, el régimen, competencias y funcionamiento del Consejo Consultivo serán los establecidos en el Estatuto Orgánico de la Agencia Española de Protección de Datos.

---

Article 48. The Presidency of the Spanish Data Protection Agency.

1. The Presidency of the Spanish Data Protection Agency directs it, represents it and issues its resolutions, circulars and guidelines.

2. The Presidency of the Spanish Data Protection Agency shall be assisted by a Deputy to whom it may delegate its functions, with the exception of those related to the procedures regulated by Title VIII of this Organic Law, and who shall substitute it in the exercise of the same under the terms provided in the Organic Statute of the Spanish Data Protection Agency.

Both shall exercise their functions with full independence and objectivity and shall not be subject to any instruction in their performance. The legislation regulating the exercise of senior positions in the General State Administration shall be applicable to them.

3. The Presidency of the Spanish Data Protection Agency and its Deputy shall be appointed by the Government, at the proposal of the Ministry of Justice, from among persons of recognized professional competence, particularly in the field of data protection.

Two months prior to the expiration of the term of office or, in the case of other causes for dismissal, when the latter has occurred, the Ministry of Justice shall order the publication in the Official State Gazette of the public call for candidates.

After evaluating the merit, capacity, competence and suitability of the candidates, the Government shall submit to the Congress of Deputies a proposal for the Presidency and Deputy, accompanied by a report justifying it, which, after holding the mandatory hearing of the candidates, shall be ratified by the Justice Committee in a public vote by a majority of three-fifths of its members in the first vote or, if this is not reached, by an absolute majority in the second vote, which shall be held immediately after the first vote. In the latter case, the votes in favor must come from Members belonging to at least two different parliamentary groups.

4. The Presidency and the Deputy of the Spanish Data Protection Agency will be appointed by the Council of Ministers by Royal Decree.

5. The term of office of the Presidency and the Deputy of the Spanish Data Protection Agency is five years and may be renewed for another term of the same duration.

 

The Presidency and the Deputy shall only cease before the expiration of their term of office, at their own request or by separation agreed by the Council of Ministers, by:

a) Serious non-compliance with its obligations,

b) supervening incapacity to perform his or her duties,

c) incompatibility, or

d) conviction for an intentional crime.

 

In the cases provided for in letters a), b) and c), the ratification of the separation by the parliamentary majorities provided for in paragraph 3 of this article shall be necessary.

6. The acts and provisions issued by the Presidency of the Spanish Data Protection Agency put an end to administrative proceedings, and may be appealed directly before the Contentious-Administrative Chamber of the National High Court.

 

Article 49. Advisory Council of the Spanish Data Protection Agency.

1. The Presidency of the Spanish Data Protection Agency will be advised by an Advisory Council composed of the following members:

a) One Deputy, proposed by the Congress of Deputies.

b) One Senator, nominated by the Senate.

c) A representative appointed by the General Council of the Judiciary.

d) A representative of the General State Administration with experience in the field, proposed by the Minister of Justice.

e) A representative of each Autonomous Community that has created a Data Protection Authority in its territorial area, proposed in accordance with the provisions of the respective Autonomous Community.

f) An expert proposed by the Spanish Federation of Municipalities and Provinces.

g) An expert proposed by the Consumers and Users Council.

h) Two experts proposed by the Business Organizations.

i) A representative of data protection and privacy professionals, proposed by the statewide association with the largest number of members.

j) A representative of the bodies or entities for the supervision and extrajudicial resolution of conflicts provided for in Chapter IV of Title V, proposed by the Minister of Justice.

k) An expert, proposed by the Conference of Rectors of Spanish Universities.

I) A representative of the organizations that bring together the General Councils, Higher Councils and Professional Associations at the state level of the different collegiate professions, proposed by the Minister of Justice.

m) A representative of the information security professionals, proposed by the statewide association with the largest number of members.

n) An expert in transparency and access to public information proposed by the Council for Transparency and Good Governance.

ñ) Two experts proposed by the most representative trade union organizations.

2. For the purposes of the preceding paragraph, the status of expert shall require accreditation of specialized knowledge in data protection law and practice through professional or academic practice.

3. The members of the Advisory Council shall be appointed by order of the Minister of Justice, published in the Official State Gazette.

4. The Advisory Council shall meet when so ordered by the Presidency of the Spanish Data Protection Agency and, in any case, once every six months.

5. The decisions taken by the Advisory Council shall in no case be binding.

6. In all matters not provided for in this Organic Law, the regime, competences and operation of the Advisory Council shall be those established in the Organic Statute of the Spanish Data Protection Agency.

Old law close

Organic Law 15/1999 on Personal Data Protection regulated. This law has been repealed by Organic Law 3/2018.

 

close