Article 55
Competence
(62) Whereas the establishment in Member States of supervisory authorities, exercising their functions with complete independence, is an essential component of the protection of individuals with regard to the processing of personal data;
|
Regulation
Art. 55 1. Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State. 2. Where processing is carried out by public authorities or private bodies acting on the basis of point (c) or (e) of Article 6(1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply. 3. Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity. |
Directive
Art. 28 (…). 6. Each supervisory authority is competent, whatever the national law applicable to the processing in question, to exercise, on the territory of its own Member State, the powers conferred on it in accordance with paragraph 3. Each authority may be requested to exercise its powers by an authority of another Member State. (…). |
United Kingdom
51. General duties of Commissioner (1) It shall be the duty of the Commissioner to promote the following of good practice by data controllers and, in particular, so to perform his functions under this Act as to promote the observance of the requirements of this Act by data controllers. (2) The Commissioner shall arrange for the dissemination in such form and manner as he considers appropriate of such information as it may appear to him expedient to give to the public about the operation of this Act, about good practice, and about other matters within the scope of his functions under this Act, and may give advice to any person as to any of those matters. (3) Where— (a) the [F1 Secretary of State] so directs by order, or (b) the Commissioner considers it appropriate to do so, the Commissioner shall, after such consultation with trade associations, data subjects or persons representing data subjects as appears to him to be appropriate, prepare and disseminate to such persons as he considers appropriate codes of practice for guidance as to good practice. (4) The Commissioner shall also— (a) where he considers it appropriate to do so, encourage trade associations to prepare, and to disseminate to their members, such codes of practice, and (b) where any trade association submits a code of practice to him for his consideration, consider the code and, after such consultation with data subjects or persons representing data subjects as appears to him to be appropriate, notify the trade association whether in his opinion the code promotes the following of good practice. (5) An order under subsection (3) shall describe the personal data or processing to which the code of practice is to relate, and may also describe the persons or classes of persons to whom it is to relate. [F2(5A)In determining the action required to discharge the duties imposed by subsections (1) to (4), the Commissioner may take account of any action taken to discharge the duty imposed by section 52A (data-sharing code) [F3or section 52AA (direct marketing code)].] (6) The Commissioner shall arrange for the dissemination in such form and manner as he considers appropriate of— (a) any Community finding as defined by paragraph 15(2) of Part II of Schedule 1, (b) any decision of the European Commission, under the procedure provided for in Article 31(2) of the Data Protection Directive, which is made for the purposes of Article 26(3) or (4) of the Directive, and (c) such other information as it may appear to him to be expedient to give to data controllers in relation to any personal data about the protection of the rights and freedoms of data subjects in relation to the processing of personal data in countries and territories outside the European Economic Area. (7) The Commissioner may, with the consent of the data controller, assess any processing of personal data for the following of good practice and shall inform the data controller of the results of the assessment. (8) The Commissioner may charge such sums as he may F4... determine for any [F5 relevant] services provided by the Commissioner by virtue of this Part. [F6(8A) In subsection (8) “relevant services” means— (a) the provision to the same person of more than one copy of any published material where each of the copies of the material is either provided on paper, a portable disk which stores the material electronically or a similar medium, (b) the provision of training, or (c) the provision of conferences. (8B)The Secretary of State may by order amend subsection (8A).] (9) In this section— “good practice” means such practice in the processing of personal data as appears to the Commissioner to be desirable having regard to the interests of data subjects and others, and includes (but is not limited to) compliance with the requirements of this Act; “trade association” includes any body representing data controllers. 52. Reports and codes of practice to be laid before Parliament (1) The Commissioner shall lay annually before each House of Parliament a general report on the exercise of his functions under this Act. (2) The Commissioner may from time to time lay before each House of Parliament such other reports with respect to those functions as he thinks fit. (3) The Commissioner shall lay before each House of Parliament any code of practice prepared under section 51(3) for complying with a direction of the [F1 Secretary of State] , unless the code is included in any report laid under subsection (1) or (2). Schedule 5 - The Data Protection Commissioner 1 (1) The corporation sole by the name of the Data Protection Registrar established by the M1Data Protection Act 1984 shall continue in existence by the name of the [F2Information Commissioner]. (2) The Commissioner and his officers and staff are not to be regarded as servants or agents of the Crown. 2 (1) Subject to the provisions of this paragraph, the Commissioner shall hold office for such term not exceeding [F4seven years] as may be determined at the time of his appointment. (2) The Commissioner may be relieved of his office by Her Majesty at his own request. (3) The Commissioner may be removed from office by Her Majesty in pursuance of an Address from both Houses of Parliament. |
Poland
In force until May 25, 2018: The Act on Personal Data Protection
Article 12 The duties entrusted to the Inspector General comprise, in particular: 1) supervision over ensuring the compliance of data processing with the provisions on the protection of personal data, 2) issuing administrative decisions and considering complaints with respect to the enforcement of the provisions on the protection of personal data, 3) ensuring the obligors’ fulfillment of non-pecuniary obligations arising under the decisions referred to in point 2 by the means of enforcement measures foreseen in the Act of 17 June 1966 on enforcement proceedings in administration (Journal of Laws of 2005, no. 229, item 1954 with amendments), 4) keeping the register of data filing systems and the register of administrators of information security, as well as providing information on the registered data files and the registered administrators of information security, 5) issuing opinions on bills and regulations with respect to the protection of personal data, 6) initiating and undertaking activities to improve the protection of personal data, 7) participating in the work of international organizations and institutions involved in personal data.
Article 14 In order to carry out the tasks referred to in Article 12 point 1 and 2, the Inspector General, the Deputy Inspector General or employees of the Bureau, hereinafter referred to as “the inspectors”, authorized by him/her shall be empowered, in particular to: 1) enter, from 6 a.m. to 10 p.m., upon presentation of a document of personal authorization and service identity card, any premises where the data filing systems are being kept and premises where data are processed outside from the data filing system, and to perform necessary examination or other inspection activities to assess the compliance of the data processing activities with the Act, 2) demand written or oral explanations, and to summon and question any person within the scope necessary to determine the facts of the case, 3) consult any documents and data directly related to the subject of the inspection, and to make a copy of these documents, 4) perform inspection of any devices, data carriers, and computer systems used for data processing, 5) commission expertise and opinions to be prepared.
Article 19 Should the inspection reveal that the action or failure in duties of the head of an organizational unit, its employee or any other natural person acting as the controller bears attributes of an offence within the meaning of the Act, the Inspector General shall inform about it a proper prosecuting body, enclosing the evidence confirming his/her suspicions.
Article 19a 1. In order to perform the tasks referred to in Article 12 point 6, the Inspector General may address state authorities, territorial self-government authorities, as well as To state and municipal organizational units, private entities performing public tasks, natural and legal persons, organizational units without legal personality and other entities in order to ensure efficient protection of personal data. 2. The Inspector General may also request competent authorities to undertake legislative initiatives and to issue or to amend legal acts in cases relative to personal data protection. 3. The entity receiving the address or request referred in paragraphs 1 and 2 shall give an answer in writing to such address or request within 30 days of its receipt.
Article 19b 1. The Inspector General can request an administrator of information security entered into the register referred to in Art. 46c to carry out a check referred to in Art. 36a para. 2 point 1 letter a) at the controller’s, who appointed the administrator of information security, indicating the scope and date of the check. 2. After carrying out the check referred in Art. 36a para. 2 point 1 letter a), the administrator of information security, through the agency of the controller, shall submit to the Inspector General a report referred to in Art. 36a para. 2 point 1 letter a). 3. The fact that the administrator of information security has carried out a check in the case referred to in para. 1 does not exclude the Inspector General’s right to carry out a supervision referred to in Art. 12 point 1. |
