{"id":16803,"date":"2020-07-14T17:58:36","date_gmt":"2020-07-14T17:58:36","guid":{"rendered":"https:\/\/businessadapter.es\/municipality-sanctioned-for-not-having-a-dpd\/"},"modified":"2024-12-11T10:49:21","modified_gmt":"2024-12-11T10:49:21","slug":"municipality-sanctioned-for-not-having-a-dpd","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/municipality-sanctioned-for-not-having-a-dpd\/","title":{"rendered":"Municipality sanctioned for not having a DPD"},"content":{"rendered":"\n<h2><strong>First sanction to a City Council for failure to appoint a DPD<\/strong><\/h2>\n<p style=\"text-align: justify;\">To have a <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><strong>Data Protection Officer<\/strong> <\/a>(hereinafter <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><strong>DPD<\/strong><\/a>) may be<a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><img decoding=\"async\" class=\" wp-image-5020 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/07\/DPD-300x200.jpg\" alt=\"\" width=\"540\" height=\"360\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/07\/DPD-300x200.jpg 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/07\/DPD-1024x683.jpg 1024w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/07\/DPD-768x512.jpg 768w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/07\/DPD-1536x1024.jpg 1536w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/07\/DPD.jpg 1920w\" sizes=\"(max-width: 540px) 100vw, 540px\" \/><\/a> be mandatory or voluntary, depending on the entity we are talking about, and in accordance with the provisions of articles 37 of the <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\"><strong>RGPD<\/strong> <\/a>and 34 of the<a href=\"https:\/\/www.boe.es\/boe\/dias\/2018\/12\/06\/pdfs\/BOE-A-2018-16673.pdf\" target=\"_blank\" rel=\"noopener\"><strong> LOPDGDD<\/strong><\/a>.<\/p>\n<p style=\"text-align: justify;\">As is well known, the <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><strong>DPD<\/strong> <\/a>is a natural or legal person, appointed by the data controller and the data processor, who must have specialized knowledge in law and practice in the field of data protection; will act as interlocutor between the data controller and the <a href=\"https:\/\/www.aepd.es\/es\/informes-y-resoluciones\/resoluciones\" target=\"_blank\" rel=\"noopener\">AEPD<\/a>; will have inspection and recommendation functions, not being subject to the sanctioning regime, according to article 35 and 36. 1 LOPDGDDD. <\/p>\n<h3>Inquiries<\/h3>\n<p style=\"text-align: justify;\">At our <strong>Valencia<\/strong> headquarters we have received several queries related to the obligation to appoint a <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><strong>DPD<\/strong><\/a>as well as the candidate&#8217;s profile and functions.<\/p>\n<p style=\"text-align: justify;\">In the face of such doubts in this aspect, it is important to point out that last June, the <strong>Spanish Data Protection Agency<\/strong> has recently imposed (Sanctioning Procedure Resolution No. PS\/00001\/2020) a sanction to a City Council in the Autonomous Community of Andalusia, as a result of a complaint filed by a citizen who alleged that the municipal council did not have the figure of the DPD, despite being obliged by the <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/proteccion-datos-valencia\"><strong>data protection<\/strong><\/a> regulations.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Mandatory appointment of a DPD<\/strong><\/h3>\n<p style=\"text-align: justify;\">Article 37 of the GDPR determines as mandatory for the controller and processor, the appointment of the <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\">DPD<\/a> in the following cases:<\/p>\n<p>a) the processing is carried out by a public authority or body, except for courts acting in their judicial function;<\/p>\n<p>(b) the main activities of the controller or processor consist of processing operations which, by virtue of their nature, scope and\/or purposes, require regular and systematic observation of data subjects on a large scale; or<\/p>\n<p>(c) the main activities of the controller or processor consist of large-scale processing of special categories of personal data pursuant to Article 9 and of data relating to criminal convictions and offences referred to in Article 10.<\/p>\n<p style=\"text-align: justify;\">The LOPDGDD is much more specific on this point, and Article 34.1 states that the following cases are mandatory:<\/p>\n<p>a) Professional associations and their general councils.<\/p>\n<p>b) Educational centers offering education at any of the levels established in the legislation regulating the right to education, as well as public and private universities.<\/p>\n<p>c) Entities operating electronic communications networks and providing electronic communications services in accordance with the provisions of their specific legislation, when they routinely and systematically process personal data on a large scale.<\/p>\n<p>d) Information society service providers when they prepare large-scale profiles of service users.<\/p>\n<p>e) The entities included in Article 1 of Law 10\/2014, of June 26, on the regulation, supervision and solvency of credit institutions.<\/p>\n<p>f) Financial credit institutions.<\/p>\n<p>g) Insurance and reinsurance companies.<\/p>\n<p>h) Investment services companies, regulated by the Securities Market legislation.<\/p>\n<p>i) Distributors and marketers of electric energy and distributors and marketers of natural gas.<\/p>\n<p>j) The entities responsible for common files for the evaluation of solvency and creditworthiness or common files for the management and prevention of fraud, including those responsible for the files regulated by the legislation for the prevention of money laundering and the financing of terrorism.<\/p>\n<p>k) Entities that carry out advertising and commercial prospecting activities, including commercial and market research, when they carry out processing based on the preferences of data subjects or perform activities that involve profiling them.<\/p>\n<p>l) Health centers legally obliged to keep patients&#8217; medical records.<\/p>\n<p style=\"text-align: justify;\">Exceptions are health professionals who, although legally obliged to keep patients&#8217; medical records, carry out their activity on an individual basis.<\/p>\n<p>m) Entities that have as one of their objects the issuance of commercial reports that may refer to natural persons.<\/p>\n<p>n) Operators that develop the gaming activity through electronic, computerized, telematic and interactive channels, in accordance with the gaming regulation regulations.<\/p>\n<p style=\"text-align: justify;\">\u00f1) Private security companies.<\/p>\n<p>o) Sports federations when processing data of minors.<\/p>\n<p style=\"text-align: justify;\">Apart from these legal cases in which it is mandatory to appoint a DPD <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><strong>DPD<\/strong><\/a>The LOPDGDD also provides for voluntary appointment in Article 34, paragraph 2.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Notification to the AEPD of the appointment of the DPD<\/strong><\/h3>\n<p style=\"text-align: justify;\">In all cases, both mandatory and voluntary, in which there is a designation and appointment of a <strong>DPD<\/strong>, the AEPD must be notified within a maximum period of 10 days.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Serious infringement and sanctioning procedure  <\/strong><\/h3>\n<p style=\"text-align: justify;\">Failure to comply with the obligation to designate a <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/dpd-dpo-valencia\"><strong>DPD<\/strong> <\/a>when this is required by law, is considered a serious infringement under Article 73 v) of the LOPDGDD.<\/p>\n<p style=\"text-align: justify;\">Article 77.1 d) of the LOPDGDD establishes the penalty regime when those responsible for or in charge of the processing are the General State Administration, the Administrations of the Autonomous Communities and the entities comprising the Local Administration.<\/p>\n<p style=\"text-align: justify;\">The penalties linked to serious breaches are set out in Article 83.4 a) of the GDPR, where the administrative fine may be up to EUR 10 000 00, if they are related to breaches of the obligations of the controller and the person in charge set out in Articles 8, 11, 25 to 39, 42 and 43.<\/p>\n<h3 style=\"text-align: justify;\"><strong>The case of the Hu\u00e9rcal City Council (Almer\u00eda)<\/strong><\/h3>\n<p style=\"text-align: justify;\">For the first time, the AEPD has sanctioned a City Council for not having a DPD.<\/p>\n<p style=\"text-align: justify;\">The supervisory authority received a complaint from a citizen in which it was made clear that the City Council did not have the figure of the <strong>DPD<\/strong>, being an entity obliged by law, as it is a public authority\/agency, which treats personal data of citizens, among which were data related to users of social services and groups in a state of vulnerability or at risk of exclusion.<\/p>\n<p style=\"text-align: justify;\">The Agency initiated the corresponding investigations, reaching the conclusion that, at the date on which the facts occurred and the complaint was filed, the GDPR was already in force and therefore, it was susceptible to demand its compliance; therefore, the City Council was obliged to appoint a <strong>DPD<\/strong> and notify such appointment to the supervisory authority within 10 days, which had not been done so far.<\/p>\n<p style=\"text-align: justify;\">Under these circumstances, in June of this year, the Agency decided to sanction the municipal council with a warning, applying Article 83.4 a) of the RGPD, requiring the appointment of the <strong>DPD<\/strong>, who must be informed within one month from the notification of the resolution.<\/p>\n<h4 style=\"text-align: center;\">If you have any doubts about whether or not it is mandatory to have a DPD in your organization or to know the benefits of having a DPD, with Business Adapter <strong><a href=\"https:\/\/businessadapter.es\/en\/contact\/\">here<\/a><\/strong><\/h4>\n<p style=\"text-align: right;\">Business Adapter Legal Department<\/p>\n","protected":false},"excerpt":{"rendered":"<p>First sanction to a City Council for failure to appoint a DPD To have a Data Protection Officer (hereinafter DPD) [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[],"class_list":["post-16803","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16803"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16803\/revisions"}],"predecessor-version":[{"id":16805,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16803\/revisions\/16805"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}