Articles

Part two - GDPR and Public Law: Data protection in public procurement

Part two - GDPR and Public Law: Data protection in public procurement

Part two - GDPR and Public Law: Data protection in public procurement

05.06.2019 BE law

Since the General Data Protection Regulation (“GDPR”) became applicable almost one year ago, multiple questions have arisen about its interaction with other fields of law. In this three-part blog series of “GDPR and public law”, we discuss three capita selecta of the interaction of GDPR with public law and government. In this blog we discuss some GDPR-related aspects of public procurement.

CVs and references

Public authorities may require contenders to demonstrate their technical and professional capacity and experience during the selection phase, by requesting references and CVs. References and CVs often contain personal data of the contenders’ employees and of contact persons of (previous) customers. Therefore the obligations of the GDPR need to be complied with.

Firstly, such personal data should be limited to what is strictly necessary for the tender in question (e.g. no information on hobbies, family situation, etc.).

Secondly, information on how these personal data will be processed must be provided to the data subjects. The contracting authority can provide this information in the tendering specifications. The contenders in turn need to provide the relevant information to their employees and to the contact persons of their (previous) customers.

Thirdly, the processing requires a lawful basis. The contracting authority can justify its processing through its task in the public interest or the exercise of official authority. For the contenders, it is recommended to collect consent from their employees or to include in the employment agreement the necessity of sharing CVs with customers and prospects, amongst which public authorities. Importantly, in employment relations consent is generally not considered as being “freely given” due to the imbalance in the relationship, and therefore cannot constitute a valid basis. Vis-à-vis contact persons of (previous) customers, consent may be collected upon signature of the agreement or upon signature of the certificate of good performance (“attest van goede uitvoering / attestation de bonne exécution”) via a specific tick box. Alternatively, consent may also be collected on an ad hoc basis, though this may pose a larger administrative burden. The contenders could justify the processing on their legitimate interests. As this lawful basis requires a balance of interests, the provision of information towards data subjects in order to manage their reasonable privacy expectations becomes even more important.

Data Processing Agreements

Not every contender will qualify as a data processor. The key question is whether the future service provider will be processing personal data on behalf of and following the instructions of the contracting authority. Simply transferring or receiving personal data is not sufficient. Typical examples of data processors include issuers of service vouchers and hosting providers, although this depends on the specific circumstances.

If a data processing agreement is required, when and how does this need to be managed in a tendering process? The qualifications of data processor and data controller should be allocated as soon as possible in order to avoid discussions at a later stage. The determination of the exact content and modalities of the data processing agreement depends on the type of the tendering procedure. In a procedure with negotiations, the input of suppliers may be taken into account, whereas in a classic – more strict – attribution procedure without negotiations, the provisions will be stipulated unilaterally. In any event the content should be determined during the competition and at the latest in the request for proposal document, as changes after the competition are restricted. Strict provisions that the contenders can possibly not comply with (e.g. Supplier may not transfer personal data outside the EU) should be avoided, as this may possibly render the tendering process invalid.

Conclusion

Recital 78 GDPR emphasizes that the principles of data protection by design and by default should be taken into consideration in the context of public tenders. Attention must be paid to the capacity in which the public entity is acting (e.g. “public authority”, “data controller”, etc.) and to the data protection obligations throughout the whole tendering process. We strongly believe that it is of utmost importance for public authorities to properly set-up and organize the function of a Data Protection Officer, who should then be involved in all issues relating to data protection.

 

Carolien Michielsen & Niels Tack

Team

Related news

21.02.2020 NL law
Podcast: Data en financiële instellingen

Short Reads - In deze podcast praten Roderik Vrolijk en Frederiek Fernhout van Stibbe in Amsterdam en Joran Iedema van Stibbe StartsUP-deelnemer Dyme over Fintech, PSD2 en het gebruik van data door financiële instellingen. Aan de ene kant biedt nieuwe regelgeving zoals PSD2 nieuwe mogelijkheden, aan de andere kant neemt de regeldruk en het toezicht op bescherming van persoonsgegevens toe.

Read more

12.02.2020 NL law
Van inspraakverordening naar participatieverordening op decentraal niveau

Short Reads - De regering stelt voor om de reikwijdte van de decentrale inspraakverordeningen te vergroten naar de uitvoering en evaluatie van decentraal beleid. Dat staat in een conceptwetsvoorstel dat op 9 december 2019 ter internetconsultatie is voorgelegd. Het conceptwetsvoorstel beoogt een wijziging van onder meer de Gemeentewet, de Provinciewet en de Waterschapswet.

Read more

12.02.2020 NL law
Het oproepen en horen van getuigen in het bestuursrecht: hoe zit het ook al weer?

Short Reads - Het oproepen van getuigen en het horen daarvan ter zitting door de bestuursrechter heeft de Hoge Raad in zijn arrest van 15 november 2019 overzichtelijk in kaart gebracht. Dat arrest, dat door de belastingkamer in een bestuurlijke boetezaak is gewezen, is ook voor andere terreinen van het bestuursrecht van belang. Mede ook omdat het horen van getuigen buiten het fiscale bestuursrecht nog in de kinderschoenen staat. In dit bericht bespreken we daarom de mogelijkheden die er bestaan om getuigen te (laten) oproepen en hoe de bestuursrechter daarmee moet omgaan.

Read more

07.02.2020 BE law
Het finale Belgische ‘nationaal energie- en klimaatplan’ en de Belgische langetermijnstrategie: het geduld van de Commissie op de proef gesteld?

Articles - Op 31 december 2019 diende België, nog net op tijd, zijn definitieve nationaal energie- en klimaatplan (NEKP) in bij de Commissie. Het staat nu al vast dat het Belgische NEKP niet op applaus zal worden onthaald door de Commissie. Verder laat ook de Belgische langetermijnstrategie op zich wachten. Wat zijn de gevolgen?

Read more

12.02.2020 NL law
Omgevingsrecht en mobiliteit: hoe werkt het afwijken van parkeernormen in bestemmingsplannen?

Short Reads - Op grond van artikel 3.1.2, tweede lid, Bro kan een bestemmingsplan ten behoeve van een goede ruimtelijke ordening regels bevatten waarvan de uitleg bij de uitoefening van een daarbij aangegeven bevoegdheid afhankelijk wordt gesteld van beleidsregels. Van deze mogelijkheid maken gemeenteraden in hun bestemmingsplannen vaak gebruik als het gaat om parkeernormen

Read more

This website uses cookies. Some of these cookies are essential for the technical functioning of our website and you cannot disable these cookies if you want to read our website. We also use functional cookies to ensure the website functions properly and analytical cookies to personalise content and to analyse our traffic. You can either accept or refuse these functional and analytical cookies.

Privacy – en cookieverklaring