Short Reads

Walking the tightrope between data protection and EU investigations

Walking the tightrope between data protection and EU investigations

Walking the tightrope between data protection and EU investigations

04.01.2019 NL law

Two recent publications confirm that it is possible for companies to cooperate with a European Commission investigation and still comply with the data protection rules. It is also possible for the Commission to deviate from certain data protection obligations in the interest of a competition law investigation. The tightrope between data protection and Commission investigations may not be as rigid as initially feared.

However, companies should still remain vigilant when dealing with information requests during investigations.

Several EU institutions, including the European Commission's Directorate-General for Competition, voiced concerns to the European Data Protection Supervisor (EDPS) about companies claiming the General Data Protection Regulation (GDPR) prevents them from cooperating with EU investigations. In response to these concerns, the EDPS clarified that the GDPR does not prevent companies from submitting information containing personal data to EU institutions, either voluntarily or in response to a legal obligation, as long as the EU institutions act within their powers. In addition, the EDPS stated that companies do not have a legal obligation to inform people about the disclosure of their personal data to EU institutions if this data is submitted with a view to carrying out a particular inquiry within the powers of the EU institutions. In the context of EU antitrust investigations, companies can therefore still be GDPR compliant while submitting information - either voluntarily or under a legal obligation - to the European Commission that may include personal data, as long as they double-check whether:

  • the request for information falls with the scope of the Commission's investigative powers;
  • the disclosure of the information is necessary to comply with the legal obligation;
  • the requested information is provided within the framework of a particular inquiry, or
  • the information is provided in order for the Commission to carry out a particular inquiry.

Similar to the GDPR not preventing companies from cooperating with EU investigations, Regulation 2018/1725 - the EU institutions' version of the GDPR – does not prevent EU institutions from conducting investigations under certain specified conditions. In regard of antitrust investigations, this is further explained in a recent Decision which states that the Commission may restrict certain rights of data subjects if the full application of these rights would jeopardise the purpose of its investigation. For the same reason, the Commission may also restrict data subjects' rights in relation to personal data obtained from other EU institutions, Member State authorities, third countries or international organisations. When doing so, the Commission will have to record and register its reasons for restricting the data subjects' rights. The Commission will also need to assess whether these restrictions are indeed proportionate and necessary for the purpose of the Commission's investigation. The Data Protection Officer will have to be informed whenever data subjects' rights are restricted and can carry out an independent review of the application of the restrictions to check whether they are in line with the Decision.

Team

Related news

28.07.2022 NL law
Purely commercial interest also a legitimate interest? Council of State leaves the question unanswered.

Short Reads - On 27 July 2022, the Council of State confirmed that the Dutch Data Protection Authority wrongly imposed a €575,000 fine on VoetbalTV. But the Council did not answer the question whether the AP rightly or wrongly believes that a purely commercial interest cannot be a legitimate interest within the meaning of the General Data Protection Regulation.

Read more

20.09.2022 EU law
Launch of Metaverse blog series

Articles - Stibbe launches a new blog series focusing on the legal challenges of the Metaverse. In our upcoming blog posts, we will discuss the legal challenges of NFTs, crypto-assets, Metaverse platforms, crypto exchanges, DAO, and many more.

Read more

28.07.2022 NL law
Zuiver commercieel belang ook gerechtvaardigd belang: Raad van State laat zich er niet over uit

Short Reads - Op 27 juli 2022 heeft de Raad van State bevestigd dat de Autoriteit Persoonsgegevens onterecht een boete van € 575.000 aan VoetbalTV heeft opgelegd. De hoop bestond dat de Afdeling antwoord zou geven op de vraag of de AP terecht of onterecht meent dat een zuiver commercieel belang géén gerechtvaardigd belang kan zijn in de zin van de Algemene Verordening Gegevensbescherming. Het antwoord op deze vraag blijft echter uit.  

Read more

03.08.2022 EU law
Gotta catch ‘em all? Upward referral of ‘killer acquisitions’ upheld

Short Reads - Companies involved in intended or completed M&A transactions falling below EU and national merger notification thresholds should beware that their deals may still catch the European Commission’s eye. The General Court has upheld the Commission’s decision to accept a national referral request regarding Illumina’s acquisition of Grail: a transaction not triggering any of the notification thresholds within the EEA.

Read more