You are on page 1of 15

EUROPEAN

DATA
PROTECTION
SUPERVISOR
The EU’s independent data
protection authority

Thomas ZERDICK, LL.M.


Head of Unit of S&E

thomas.zerdick@edps.europa.eu
The EDPS Supervision and
Enforcement Unit (S&E)

19 September 2023
What the EDPS does

2
Regulation (EU) 2018/1725 [EDPR]
Chapter I General Provisions Regulation (EU) 2016/679 [GDPR]
Chapter II General Principles Regulation (EU) 2016/679 [GDPR]
Chapter III Rights of the Data Subject Regulation (EU) 2016/679 [GDPR]
Chapter IV Controller and Processor Regulation (EU) 2016/679 [GDPR]
Section 2 Security of personal data (Art. 33-35) Section 2 Security of personal data (Art. 32-34)
Section 3 Confidentiality of electronic communications Directive 2002/58/EC [e-Privacy]*
Chapter V Transfers of personal data to third countries or Regulation (EU) 2016/679 [GDPR]
international organisations
Chapter VI European Data Protection Supervisor Regulation (EU) 2016/679 [GDPR]
Chapter VII Cooperation and Consistency Regulation (EU) 2016/679 [GDPR]
Chapter VIII Remedies, Liability And Penalties Regulation (EU) 2016/679 [GDPR]
Chapter IX Processing of operational personal data by Union Data Protection Directive (EU) 2016/680
bodies, offices and agencies when carrying out activities for Police and Law enforcement [LED]
which fall within the scope of Chapter 4 or Chapter 5 of
Title V of Part Three TFEU
Personal data breaches (Art. 92+93)
Chapter X Implementing Acts Regulation (EU) 2016/679 [GDPR]

Chapter XI Review Regulation (EU) 2016/679 [GDPR]


Chapter XII Final provisions Regulation (EU) 2016/679 [GDPR]
4
S&E

Supervision Enforcement

Data Protection
culture

5
What the S&E does

ADVISE INVESTIGATE CORRECT REFER COOPERATE

advise data investigations, issue warnings, matters to the with national


subjects, audits, obtain reprimands, refer Court of Justice of supervisory
controllers, access to matter to the the EU and authorities.
consultations on premises, order European INTERVENE;
administrative controller to give Parliament, order
measures and information; rectification or
internal rules, erasure; impose
issue own administrative
initiative opinions, fines;
awareness raising;

6
Our tools
Investigative Corrective Authorisation &
powers powers advisory powers
Check compliance Sanction Advise

• complaints • warning • consultations


• investigations • reprimand • visits
• audits • referral to • trainings
• inspections controller • guidelines
• ban on
processing
• administrative
fine 7
Consultations and audits sector
consultations on
administrative DPIA
matters

54 consultations in
Audits/visits
2021

Thematic guidelines 8 FTE

8
Complaints and investigations sector
Investigation into
Schrems II strategy ‘Cloud II’ infrastructure
contracts

Investigation into
more than 300
Commission’s use of
complaints in 2021
Microsoft 365

Court proceedings
(interventions in staff 7 FTE
cases)

10
C&I

complaints received 2018-2023


350
302
300
270

240
250 227
203
200
151
150

100
59 65
48 43 50 44
50

0
1 2 3 4 5 6

Series1 Series2

11
AFSJ sector
EDPS - Europol statistics 2021

• Europol,
• Eurojust
• European Border and
Coast Guard Agency
(Frontex)
• European Public
Prosecutor Office (EPPO)

13
EDPS resources
Supervision & enforcement Complaints:
overview: https://edps.europa.eu/data-
• https://edps.europa.eu/data- protection/our-role-
protection/our-role- supervisor/complaints_en
supervisor_en Guidance:
EDPS Investigation Policy: • https://edps.europa.eu/data-
• https://edps.europa.eu/data- protection/our-work/our-work-
protection/our-work/our-work- by-type/guidelines_en
by-type/investigations_en

You might also like