Portuguese National Statistical Institute

€4,300,000

Non-compliance with general data processing principles

Ημερομηνία απόφασης

2 Νοεμβρίου 2022

Αρχή

Portuguese Data Protection Authority (CNPD)

PT

Τομέας

Public Sector and Education

Χώρα

PT

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in Portugal. The DPA first found that the controller had failed to inform the data subjects that the provision of religious and health data was purely voluntary. The DPA considered this to be an interference with the data subjects' ability to freely express their will regarding data processing. In addition, the DPA found that the controller failed to exercise due diligence in selecting its processor, contrary to its obligation under Art. 28 GDPR. In addition, the order processing contract permitted the transfer of personal data outside the EEA without providing for additional security measures besides the SCCS approved by the European Commission, as required under the Schrems II ruling. The DPA considered this to be a breach of Art. 44 GDPR and Art. 46 (2) GDPR. Finally, the DPA found that the controller failed to conduct a data protection impact assessment regarding the census.

Νομικές παραπομπές

Art. 5 (1)Art. 9 (1)Art. 12Art. 13Art. 28 (1)Art. 35 (1)Art. 44Art. 46 (2)

Θέματα & Παραβάσεις

Non-compliance with general data processing principles

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.