Article 58
Powers
(63) Whereas such authorities must have the necessary means to perform their duties, including powers of investigation and intervention, particularly in cases of complaints from individuals, and powers to engage in legal proceedings; whereas such authorities must help to ensure transparency of processing in the Member States within whose jurisdiction they fall;
|
Regulation
Art. 58 1. Each supervisory authority shall have all of the following investigative powers: (a) to order the controller and the processor, and, where applicable, the controller's or the processor's representative to provide any information it requires for the performance of its tasks; (b) to carry out investigations in the form of data protection audits; (c) to carry out a review on certifications issued pursuant to Article 42(7); (d) to notify the controller or the processor of an alleged infringement of this Regulation; (e) to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks; (f) to obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with Union or Member State procedural law. 2. Each supervisory authority shall have all of the following corrective powers: (a) to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of this Regulation; (b) to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation; (c) to order the controller or the processor to comply with the data subject's requests to exercise his or her rights pursuant to this Regulation; (d) to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period; (e) to order the controller to communicate a personal data breach to the data subject; (f) to impose a temporary or definitive limitation including a ban on processing; (g) to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19; (h) to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met; (i) to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case; (j) to order the suspension of data flows to a recipient in a third country or to an international organisation. 3. Each supervisory authority shall have all of the following authorisation and advisory powers: (a) to advise the controller in accordance with the prior consultation procedure referred to in Article 36; (b) to issue, on its own initiative or on request, opinions to the national parliament, the Member State government or, in accordance with Member State law, to other institutions and bodies as well as to the public on any issue related to the protection of personal data; (c) to authorise processing referred to in Article 36(5), if the law of the Member State requires such prior authorisation; (d) to issue an opinion and approve draft codes of conduct pursuant to Article 40(5); (e) to accredit certification bodies pursuant to Article 43; (f) to issue certifications and approve criteria of certification in accordance with Article 42(5); (g) to adopt standard data protection clauses referred to in Article 28(8) and in point (d) of Article 46(2); (h) to authorise contractual clauses referred to in point (a) of Article 46(3); (i) to authorise administrative arrangements referred to in point (b) of Article 46(3); (j) to approve binding corporate rules pursuant to Article 47. 4. The exercise of the powers conferred on the supervisory authority pursuant to this Article shall be subject to appropriate safeguards, including effective judicial remedy and due process, set out in Union and Member State law in accordance with the Charter. 5. Each Member State shall provide by law that its supervisory authority shall have the power to bring infringements of this Regulation to the attention of the judicial authorities and where appropriate, to commence or engage otherwise in legal proceedings, in order to enforce the provisions of this Regulation. 6. Each Member State may provide by law that its supervisory authority shall have additional powers to those referred to in paragraphs 1, 2 and 3. The exercise of those powers shall not impair the effective operation of Chapter VII. |
Directive
Art. 28 1. Each Member State shall provide that one or more public authorities are responsible for monitoring the application within its territory of the provisions adopted by the Member States pursuant to this Directive. These authorities shall act with complete independence in exercising the functions entrusted to them. 2. Each Member State shall provide that the supervisory authorities are consulted when drawing up administrative measures or regulations relating to the protection of individuals' rights and freedoms with regard to the processing of personal data. 3. Each authority shall in particular be endowed with: - investigative powers, such as powers of access to data forming the subject-matter of processing operations and powers to collect all the information necessary for the performance of its supervisory duties, - effective powers of intervention, such as, for example, that of delivering opinions before processing operations are carried out, in accordance with Article 20, and ensuring appropriate publication of such opinions, of ordering the blocking, erasure or destruction of data, of imposing a temporary or definitive ban on processing, of warning or admonishing the controller, or that of referring the matter to national parliaments or other political institutions, - the power to engage in legal proceedings where the national provisions adopted pursuant to this Directive have been violated or to bring these violations to the attention of the judicial authorities. Decisions by the supervisory authority which give rise to complaints may be appealed against through the courts. 4. Each supervisory authority shall hear claims lodged by any person, or by an association representing that person, concerning the protection of his rights and freedoms in regard to the processing of personal data. The person concerned shall be informed of the outcome of the claim. Each supervisory authority shall, in particular, hear claims for checks on the lawfulness of data processing lodged by any person when the national provisions adopted pursuant to Article 13 of this Directive apply. The person shall at any rate be informed that a check has taken place. 5. Each supervisory authority shall draw up a report on its activities at regular intervals. The report shall be made public. 6. Each supervisory authority is competent, whatever the national law applicable to the processing in question, to exercise, on the territory of its own Member State, the powers conferred on it in accordance with paragraph 3. Each authority may be requested to exercise its powers by an authority of another Member State. The supervisory authorities shall cooperate with one another to the extent necessary for the performance of their duties, in particular by exchanging all useful information. 7. Member States shall provide that the members and staff of the supervisory authority, even after their employment has ended, are to be subject to a duty of professional secrecy with regard to confidential information to which they have access. |
Spain
Artículo 51. Ámbito y personal competente. 1. La Agencia Española de Protección de Datos desarrollará su actividad de investigación a través de las actuaciones previstas en el Título VIII y de los planes de auditoría preventivas.
2. La actividad de investigación se llevará a cabo por los funcionarios de la Agencia Española de Protección de Datos o por funcionarios ajenos a ella habilitados expresamente por su Presidencia.
3. En los casos de actuaciones conjuntas de investigación conforme a lo dispuesto en el artículo 62 del Reglamento (UE) 2016/679, el personal de las autoridades de control de otros Estados Miembros de Unión Europea que colabore con la Agencia Española de Protección de Datos ejercerá sus facultades con arreglo a lo previsto en la presente ley orgánica y bajo la orientación y en presencia del personal de esta.
4. Los funcionarios que desarrollen actividades de investigación tendrán la consideración de agentes de la autoridad en el ejercicio de sus funciones, y estarán obligados a guardar secreto sobre las informaciones que conozcan con ocasión de dicho ejercicio, incluso después de haber cesado en él.
Artículo 52. Deber de colaboración. 1. Las Administraciones Públicas, incluidas las tributarias y de la Seguridad Social, y los particulares estarán obligados a proporcionar a la Agencia Española de Protección de Datos los datos, informes, antecedentes y justificantes necesarios para llevar a cabo su actividad de investigación.
Cuando la información contenga datos personales la comunicación de dichos datos estará amparada por lo dispuesto en el artículo 6.1 c) del Reglamento (UE) 2016/679.
2. En el marco de las actuaciones previas de investigación, cuando no haya podido realizar la identificación por otros medios, la Agencia Española de Protección de Datos podrá recabar de las Administraciones Públicas, incluidas las tributarias y de la Seguridad Social, las informaciones y datos que resulten imprescindibles con la exclusiva finalidad de lograr la identificación de los responsables de las conductas que pudieran ser constitutivas de infracción del Reglamento (UE) 2016/679 y de la presente ley orgánica.
En el supuesto de las Administraciones tributarias y de la Seguridad Social, la información se limitará a la que resulte necesaria para poder identificar inequívocamente contra quién debe dirigirse la actuación de la Agencia Española de Protección de Datos en los supuestos de creación de entramados societarios que dificultasen el conocimiento directo del presunto responsable de la conducta contraria al Reglamento (UE) 2016/679 y a la presente ley orgánica.
3. Cuando no haya podido realizar la identificación por otros medios, la Agencia Española de Protección de Datos podrá recabar de los operadores que presten servicios de comunicaciones electrónicas disponibles al público y de los prestadores de servicios de la sociedad de la información los datos que obren en su poder y que resulten imprescindibles para la identificación del presunto responsable de la conducta contraria al Reglamento (UE) 2016/679 y a la presente ley orgánica cuando se hubiere llevado a cabo mediante la utilización de un servicio de la sociedad de la información o la realización de una comunicación electrónica. A tales efectos, los datos que la Agencia Española de Protección de Datos podrá recabar al amparo de este apartado son los siguientes:
a) Cuando la conducta se hubiera realizado mediante la utilización de un servicio de telefonía fija o móvil:
1.º El número de teléfono de origen de la llamada en caso de que el mismo se hubiese ocultado.
2.º El nombre, número de documento identificativo y dirección del abonado o usuario registrado al que corresponda ese número de teléfono.
3.º La mera confirmación de que se ha realizado una llamada específica entre dos números en una determinada fecha y hora.
b) Cuando la conducta se hubiera realizado mediante la utilización de un servicio de la sociedad de la información:
1.º La identificación de la dirección de protocolo de Internet desde la que se hubiera llevado a cabo la conducta y la fecha y hora de su realización.
2.º Si la conducta se hubiese llevado a cabo mediante correo electrónico, la identificación de la dirección de protocolo de Internet desde la que se creó la cuenta de correo y la fecha y hora en que la misma fue creada.
3.º El nombre, número de documento identificativo y dirección del abonado o del usuario registrado al que se le hubiera asignado la dirección de Protocolo de Internet a la que se refieren los dos párrafos anteriores.
Estos datos deberán ser cedidos, previo requerimiento motivado de la Agencia Española de Protección de Datos, exclusivamente en el marco de actuaciones de investigación iniciadas como consecuencia de una denuncia presentada por un afectado respecto de una conducta de una persona jurídica o respecto a la utilización de sistemas que permitan la divulgación sin restricciones de datos personales. En el resto de los supuestos la cesión de estos datos requerirá la previa obtención de autorización judicial otorgada conforme a las normas procesales cuando resultara exigible.
Quedan excluidos de lo previsto en este apartado los datos de tráfico que los operadores estuviesen tratando con la exclusiva finalidad de dar cumplimiento a las obligaciones previstas en la Ley 25/2007, de 18 de octubre, de conservación de datos relativos a las comunicaciones electrónicas y a las redes públicas de comunicaciones, cuya cesión solamente podrá tener lugar de acuerdo con lo dispuesto en ella, previa autorización judicial solicitada por alguno de los agentes facultados a los que se refiere el artículo 6 de dicha ley.
Artículo 53. Alcance de la actividad de investigación. 1. Quienes desarrollen la actividad de investigación podrán recabar las informaciones precisas para el cumplimiento de sus funciones, realizar inspecciones, requerir la exhibición o el envío de los documentos y datos necesarios, examinarlos en el lugar en que se encuentren depositados o en donde se lleven a cabo los tratamientos, obtener copia de ellos, inspeccionar los equipos físicos y lógicos y requerir la ejecución de tratamientos y programas o procedimientos de gestión y soporte del tratamiento sujetos a investigación.
2. Cuando fuese necesario el acceso por el personal que desarrolla la actividad de investigación al domicilio constitucionalmente protegido del inspeccionado, será preciso contar con su consentimiento o haber obtenido la correspondiente autorización judicial.
3. Cuando se trate de órganos judiciales u oficinas judiciales el ejercicio de las facultades de inspección se efectuará a través y por mediación del Consejo General del Poder Judicial.
Artículo 53 bis. Actuaciones de investigación a través de sistemas digitales. Las actuaciones de investigación podrán realizarse a través de sistemas digitales que, mediante la videoconferencia u otro sistema similar, permitan la comunicación bidireccional y simultánea de imagen y sonido, la interacción visual, auditiva y verbal entre la Agencia Española de Protección de Datos y el inspeccionado. Además, deben garantizar la transmisión y recepción seguras de los documentos e información que se intercambien, y, en su caso, recoger las evidencias necesarias y el resultado de las actuaciones realizadas asegurando su autoría, autenticidad e integridad. La utilización de estos sistemas se producirá cuando lo determine la Agencia y requerirá la conformidad del inspeccionado en relación con su uso y con la fecha y hora de su desarrollo.
Artículo 54. Planes de auditoría. 1. La Presidencia de la Agencia Española de Protección de Datos podrá acordar la realización de planes de auditoría preventiva, referidos a los tratamientos de un sector concreto de actividad. Tendrán por objeto el análisis del cumplimiento de las disposiciones del Reglamento (UE) 2016/679 y de la presente ley orgánica, a partir de la realización de actividades de investigación sobre entidades pertenecientes al sector inspeccionado o sobre los responsables objeto de la auditoría. 2. A resultas de los planes de auditoría, la Presidencia de la Agencia Española de Protección de Datos podrá dictar las directrices generales o específicas para un concreto responsable o encargado de los tratamientos precisas para asegurar la plena adaptación del sector o responsable al Reglamento (UE) 2016/679 y a la presente ley orgánica. En la elaboración de dichas directrices la Presidencia de la Agencia Española de Protección de Datos podrá solicitar la colaboración de los organismos de supervisión de los códigos de conducta y de resolución extrajudicial de conflictos, si los hubiere. 3. Las directrices serán de obligado cumplimiento para el sector o responsable al que se refiera el plan de auditoría.
Artículo 55. Potestades de regulación. Circulares de la Agencia Española de Protección de Datos. 1. La Presidencia de la Agencia Española de Protección de Datos podrá dictar disposiciones que fijen los criterios a que responderá la actuación de esta autoridad en la aplicación de lo dispuesto en el Reglamento (UE) 2016/679 y en la presente ley orgánica, que se denominarán «Circulares de la Agencia Española de Protección de Datos». 2. Su elaboración se sujetará al procedimiento establecido en el Estatuto de la Agencia Española de Protección de Datos, que deberá prever los informes técnicos y jurídicos que fueran necesarios y la audiencia a los interesados. 3. Las circulares serán obligatorias una vez publicadas en el Boletín Oficial del Estado. --- Article 51. Scope and competent personnel. 1. The Spanish Data Protection Agency will develop its investigation activity through the actions provided for in Title VIII and the preventive audit plans. 2. The investigation activity will be carried out by officials of the Spanish Data Protection Agency or by officials from outside the Agency expressly authorized by its Presidency. 3. In cases of joint investigative actions in accordance with the provisions of Article 62 of Regulation (EU) 2016/679, the staff of the supervisory authorities of other Member States of the European Union who collaborate with the Spanish Data Protection Agency shall exercise their powers in accordance with the provisions of this Organic Law and under the guidance and in the presence of the staff of the Spanish Data Protection Agency. 4. Officials carrying out investigative activities shall be considered agents of the authority in the performance of their duties, and shall be bound to keep secret any information they may learn in the course of their duties, even after they have ceased to perform them.
Article 52. Duty of collaboration. 1. The Public Administrations, including the tax and Social Security Administrations, and individuals shall be obliged to provide the Spanish Data Protection Agency with the data, reports, background information and supporting documents necessary to carry out its investigation activities.
Where the information contains personal data the communication of such data shall be covered by the provisions of Article 6(1)(c) of Regulation (EU) 2016/679. 2. Within the framework of preliminary investigation actions, when the Spanish Data Protection Agency has not been able to carry out the identification by other means, it may request the following from the Public Administrations, including tax and Social Security authorities Social, information and data that are essential for the sole purpose of identifying those responsible for conduct that could constitute an infringement of Regulation (EU) 2016/679 and this Organic Law. In the case of the Tax and Social Security Administrations, the information will be limited to that which is necessary to be able to unequivocally identify against whom the Spanish Data Protection Agency must take action in cases of creation of corporate networks that would make it difficult to obtain direct knowledge of the alleged perpetrator of the conduct contrary to Regulation (EU) 2016/679 and to this Organic Law. 3. When it has not been able to carry out the identification by other means, the Spanish Data Protection Agency may request from the operators that provide publicly available electronic communications services and from the providers of information society services the data in its possession that are essential for the identification of the alleged perpetrator of the conduct contrary to Regulation (EU) 2016/679 and to this Organic Law when it has been carried out through the use of an information society service or the making of an electronic communication. For such purposes, the data that the Spanish Data Protection Agency may collect under this section are the following: a) When the conduct has been carried out through the use of a fixed or mobile telephone service: 1. ° The telephone number of origin of the call in case it has been hidden. 2. ° The name, identification document number and address of the subscriber or registered user to whom the telephone number corresponds. 3. ° The mere confirmation that a specific call has been made between two numbers at a specific date and time. b) When the conduct has been carried out through the use of an information society service: 1. The identification of the Internet protocol address from which the conduct was carried out and the date and time of the conduct. 2. ° If the conduct was carried out by e-mail, the identification of the Internet protocol address from which the e-mail account was created and the date and time at which it was created. 3. ° The name, identification document number and address of the subscriber or registered user to whom the Internet Protocol address referred to in the two preceding paragraphs has been assigned. These data must be transferred, upon a reasoned request from the Spanish Data Protection Agency, exclusively within the framework of investigation actions initiated as a result of a complaint filed by an affected party regarding a conduct of a legal person or regarding the use of systems that allow the unrestricted disclosure of personal data. In all other cases, the transfer of this data will require prior judicial authorization granted in accordance with the procedural rules when required. Excluded from the provisions of this section are traffic data that operators are processing for the sole purpose of complying with the obligations set forth in Law 25/2007, of October 18, 2007, on the conservation of data relating to electronic communications and public communications networks, the transfer of which may only take place in accordance with the provisions thereof, upon prior judicial authorization requested by any of the authorized agents referred to in Article 6 of said Law.
Article 53. Scope of the research activity. 1. Those carrying out the investigation activity may collect the information necessary for the fulfillment of their functions, carry out inspections, require the exhibition or sending of the necessary documents and data, examine them at the place where they are stored or where the processing is carried out, obtain copies of them, inspect the physical and logical equipment and require the execution of processing and management programs or procedures and support of the processing subject to investigation. 2. When it is necessary for the personnel carrying out the investigative activity to access the constitutionally protected domicile of the inspected person, it will be necessary to have his or her consent or to have obtained the corresponding judicial authorization. 3. In the case of judicial bodies or judicial offices, the exercise of the powers of inspection shall be carried out through and by means of the General Council of the Judiciary.
Article 53 bis. Investigation activities through digital systems. Investigation activities may be carried out through digital systems which, by means of videoconferencing or other similar systems, allow the bidirectional and simultaneous communication of image and sound, as well as visual, auditory and verbal interaction between the Spanish Data Protection Agency and the inspected party. In addition, such systems must ensure the secure transmission and receipt of the documents and information exchanged and, where appropriate, enable the collection of the necessary evidence and the outcome of the actions carried out guaranteeing their authorship, authenticity and integrity. The use of such systems shall take place when determined by the Spanish Data Protection Agency and shall require the consent of the inspected party regarding their use and the date and time of their conduct.
Article 54. Audit plans. 1. The Presidency of the Spanish Data Protection Agency may agree to carry out preventive audit plans, referring to the processing of a specific sector of activity. They will be aimed at analyzing compliance with the provisions of Regulation (EU) 2016/679 and of this Organic Law, based on the performance of research activities on entities belonging to the inspected sector or on the controllers subject to the audit. 2. As a result of the audit plans, the Presidency of the Spanish Data Protection Agency may issue the general or specific guidelines for a specific controller or processor required to ensure the full adaptation of the sector or controller to Regulation (EU) 2016/679 and to this Organic Law. In the preparation of such guidelines, the Presidency of the Spanish Data Protection Agency may request the collaboration of the supervisory bodies of the codes of conduct and extrajudicial resolution of conflicts, if any. 3. The guidelines shall be mandatory for the sector or manager to which the audit plan refers.
Article 55. Regulatory powers. Circulars of the Spanish Data Protection Agency. 1. The Presidency of the Spanish Data Protection Agency may issue provisions establishing the criteria to be followed by this authority in the application of the provisions of Regulation (EU) 2016/679 and this Organic Law, which shall be called "Circulars of the Spanish Data Protection Agency". 2. Its preparation shall be subject to the procedure established in the Statute of the Spanish Data Protection Agency, which shall provide for the necessary technical and legal reports and the hearing of the interested parties. 3. The circulars will be binding once published in the Official State Gazette. |
Serbia
|
