Day 02 - S+E-TZ-Western Balkans+EPR.pdf

Support for Improvement in Governance and Management  SIGMA
EUROPEAN
DATA
PROTECTION
SUPERVISOR
The EU’s independent data
protection authority
The EDPS Supervision and
Enforcement Unit (S&E)
Thomas ZERDICK, LL.M.
Head of Unit of S&E
thomas.zerdick@edps.europa.eu
19 September 2023
What the EDPS does
2
Regulation (EU) 2018/1725 [EDPR]
Chapter I General Provisions Regulation (EU) 2016/679 [GDPR]
Chapter II General Principles Regulation (EU) 2016/679 [GDPR]
Chapter III Rights of the Data Subject Regulation (EU) 2016/679 [GDPR]
Chapter IV Controller and Processor
Section 2 Security of personal data (Art. 33-35)
Section 3 Confidentiality of electronic communications
Regulation (EU) 2016/679 [GDPR]
Section 2 Security of personal data (Art. 32-34)
Directive 2002/58/EC [e-Privacy]*
Chapter V Transfers of personal data to third countries or
international organisations
Regulation (EU) 2016/679 [GDPR]
Chapter VI European Data Protection Supervisor Regulation (EU) 2016/679 [GDPR]
Chapter VII Cooperation and Consistency Regulation (EU) 2016/679 [GDPR]
Chapter VIII Remedies, Liability And Penalties Regulation (EU) 2016/679 [GDPR]
Chapter IX Processing of operational personal data by Union
bodies, offices and agencies when carrying out activities
which fall within the scope of Chapter 4 or Chapter 5 of
Title V of Part Three TFEU
Personal data breaches (Art. 92+93)
Data Protection Directive (EU) 2016/680
for Police and Law enforcement [LED]
Chapter X Implementing Acts Regulation (EU) 2016/679 [GDPR]
Chapter XI Review Regulation (EU) 2016/679 [GDPR]
Chapter XII Final provisions Regulation (EU) 2016/679 [GDPR]
4
5
S&E
Enforcement
Data Protection
culture
Supervision
What the S&E does
6
ADVISE
advise data
subjects,
controllers,
consultations on
administrative
measures and
internal rules,
issue own
initiative opinions,
awareness raising;
INVESTIGATE
investigations,
audits, obtain
access to
premises, order
controller to give
information;
CORRECT
issue warnings,
reprimands, refer
matter to the
European
Parliament, order
rectification or
erasure; impose
administrative
fines;
REFER
matters to the
Court of Justice of
the EU and
INTERVENE;
COOPERATE
with national
supervisory
authorities.
7
Investigative
powers
Corrective
powers
Authorisation &
advisory powers
Check compliance
• complaints
• investigations
• audits
• inspections
Sanction
• warning
• reprimand
• referral to
controller
• ban on
processing
• administrative
fine
Advise
• consultations
• visits
• trainings
• guidelines
Our tools
Consultations and audits sector
8
consultations on
administrative
matters
DPIA
Audits/visits
54 consultations in
2021
Thematic guidelines 8 FTE
Day 02 -  S+E-TZ-Western Balkans+EPR.pdf
Complaints and investigations sector
10
Schrems II strategy
Investigation into
‘Cloud II’ infrastructure
contracts
Investigation into
Commission’s use of
Microsoft 365
more than 300
complaints in 2021
Court proceedings
(interventions in staff
cases)
7 FTE
C&I
11
240
151
203
270
302
227
48
59
43 50
65
44
0
50
100
150
200
250
300
350
1 2 3 4 5 6
complaints received 2018-2023
Series1 Series2
Day 02 -  S+E-TZ-Western Balkans+EPR.pdf
• Europol,
• Eurojust
• European Border and
Coast Guard Agency
(Frontex)
• European Public
Prosecutor Office (EPPO)
AFSJ sector
13
EDPS - Europol statistics 2021
Day 02 -  S+E-TZ-Western Balkans+EPR.pdf
EDPS resources
Supervision & enforcement
overview:
• https://edps.europa.eu/data-
protection/our-role-
supervisor_en
EDPS Investigation Policy:
• https://edps.europa.eu/data-
protection/our-work/our-work-
by-type/investigations_en
Complaints:
https://edps.europa.eu/data-
protection/our-role-
supervisor/complaints_en
Guidance:
• https://edps.europa.eu/data-
protection/our-work/our-work-
by-type/guidelines_en
1 de 15

Recomendados

GDPR Day 2018 - GDPR Pain Points por
GDPR Day 2018 - GDPR Pain PointsGDPR Day 2018 - GDPR Pain Points
GDPR Day 2018 - GDPR Pain PointsGDPR Day
329 vistas17 diapositivas
The Privacy Advantage 2016 - Wojciech Wiewiorowski por
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
312 vistas20 diapositivas
Why GDPR Must Be an Integral Part of Your GRC Framework por
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
1K vistas41 diapositivas
Data Protection - GDPR - Lantern fundforum 2017 Leonardi Andrea - Michelotti ... por
Data Protection - GDPR - Lantern fundforum 2017 Leonardi Andrea - Michelotti ...Data Protection - GDPR - Lantern fundforum 2017 Leonardi Andrea - Michelotti ...
Data Protection - GDPR - Lantern fundforum 2017 Leonardi Andrea - Michelotti ...Andrea Leonardi
106 vistas30 diapositivas
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal por
"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal"Legal tips and compliance requirements" - Anastasia Botsi, ICT Legal
"Legal tips and compliance requirements" - Anastasia Botsi, ICT LegalCyber Watching
127 vistas19 diapositivas
EU Data Protection, Legislation and Certification por
EU Data Protection, Legislation and Certification EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification CRISP Project
159 vistas12 diapositivas

Más contenido relacionado

Similar a Day 02 - S+E-TZ-Western Balkans+EPR.pdf

Introduction to GDPR por
Introduction to GDPRIntroduction to GDPR
Introduction to GDPRMartyn Ripley
21 vistas8 diapositivas
Data Flow Mapping and the EU GDPR por
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
8.4K vistas34 diapositivas
20150610 febelmar privacy matters eu regulation por
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulationFebelmar
285 vistas26 diapositivas
Revising policies and procedures under the new EU GDPR por
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
4.9K vistas32 diapositivas
EU GDPR(general data protection regulation) por
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
334 vistas10 diapositivas
Gdpr presentation-february-24t por
Gdpr presentation-february-24tGdpr presentation-february-24t
Gdpr presentation-february-24tMark Drinkwater
26 vistas15 diapositivas

Similar a Day 02 - S+E-TZ-Western Balkans+EPR.pdf(20)

20150610 febelmar privacy matters eu regulation por Febelmar
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation
Febelmar285 vistas
Revising policies and procedures under the new EU GDPR por IT Governance Ltd
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
IT Governance Ltd4.9K vistas
EU GDPR(general data protection regulation) por RAKESH S
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
RAKESH S334 vistas
EU GDPR and you: requirements for marketing por IT Governance Ltd
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
IT Governance Ltd1.7K vistas
CyNation: 7 Things You Should Know about EU GDPR por Iryna Chekanava
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
Iryna Chekanava747 vistas
CyNation - 7 things you should know about EU-GDPR por Shadi A. Razak
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPR
Shadi A. Razak298 vistas
GDPR - New European Union Legislation por Tekwill
GDPR - New European Union LegislationGDPR - New European Union Legislation
GDPR - New European Union Legislation
Tekwill54 vistas
General Data Protection Regulations (GDPR) Summary por Compliance3
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary
Compliance3 531 vistas
Regulation (EU) 2016_679_GDPR_Overview_June 2016 por John Greenwood
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
John Greenwood216 vistas
Data Protection and Privacy, Ireland 2018 por Matheson Law Firm
Data Protection and Privacy, Ireland 2018Data Protection and Privacy, Ireland 2018
Data Protection and Privacy, Ireland 2018
Matheson Law Firm965 vistas
Getting the Deal Through: Data Protection and Privacy, Ireland 2018 por Hazel Murray
Getting the Deal Through: Data Protection and Privacy, Ireland 2018 Getting the Deal Through: Data Protection and Privacy, Ireland 2018
Getting the Deal Through: Data Protection and Privacy, Ireland 2018
Hazel Murray120 vistas
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP... por Emma Mirrington
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
Emma Mirrington306 vistas
Internet user's rights and fundamental freedoms day por moldovaictsummit2016
Internet user's rights and fundamental freedoms dayInternet user's rights and fundamental freedoms day
Internet user's rights and fundamental freedoms day

Más de Support for Improvement in Governance and Management SIGMA

Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig... por
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...Support for Improvement in Governance and Management SIGMA
6 vistas61 diapositivas
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv... por
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...Support for Improvement in Governance and Management SIGMA
3 vistas17 diapositivas
E-Gov, by Emir Ramadanovic (bih) - SIGMA Webinars on service design and deliv... por
E-Gov, by Emir Ramadanovic (bih) - SIGMA Webinars on service design and deliv...E-Gov, by Emir Ramadanovic (bih) - SIGMA Webinars on service design and deliv...
E-Gov, by Emir Ramadanovic (bih) - SIGMA Webinars on service design and deliv...Support for Improvement in Governance and Management SIGMA
5 vistas11 diapositivas
PPT - SIGMA-GIZ Academies - Topic 4 - 1.1 - Germany Life Events Survey - EXT.pdf por
PPT - SIGMA-GIZ Academies - Topic 4 - 1.1 - Germany Life Events Survey - EXT.pdfPPT - SIGMA-GIZ Academies - Topic 4 - 1.1 - Germany Life Events Survey - EXT.pdf
PPT - SIGMA-GIZ Academies - Topic 4 - 1.1 - Germany Life Events Survey - EXT.pdfSupport for Improvement in Governance and Management SIGMA
6 vistas24 diapositivas
PPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdf por
PPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdfPPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdf
PPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdfSupport for Improvement in Governance and Management SIGMA
51 vistas8 diapositivas
PPT - SIGMA-GIZ Academies - Topic 4 - Azerbaijan - Public Service Design.pdf por
PPT - SIGMA-GIZ Academies - Topic 4 - Azerbaijan - Public Service Design.pdfPPT - SIGMA-GIZ Academies - Topic 4 - Azerbaijan - Public Service Design.pdf
PPT - SIGMA-GIZ Academies - Topic 4 - Azerbaijan - Public Service Design.pdfSupport for Improvement in Governance and Management SIGMA
52 vistas37 diapositivas

Más de Support for Improvement in Governance and Management SIGMA (20)

Último

Ending Stagnation: A New Economic Strategy for Britain por
Ending Stagnation: A New Economic Strategy for BritainEnding Stagnation: A New Economic Strategy for Britain
Ending Stagnation: A New Economic Strategy for BritainResolutionFoundation
1.6K vistas78 diapositivas
COP28 President Launches Global Decarbonization Accelerator por
COP28 President Launches Global Decarbonization AcceleratorCOP28 President Launches Global Decarbonization Accelerator
COP28 President Launches Global Decarbonization AcceleratorEnergy for One World
40 vistas3 diapositivas
MMF Newsletter Februar 2022.pdf por
MMF Newsletter Februar 2022.pdfMMF Newsletter Februar 2022.pdf
MMF Newsletter Februar 2022.pdfmmpcofficial
7 vistas12 diapositivas
Monitoring and Evaluation Plan (Theory of change, results framework, Logframe... por
Monitoring and Evaluation Plan (Theory of change, results framework, Logframe...Monitoring and Evaluation Plan (Theory of change, results framework, Logframe...
Monitoring and Evaluation Plan (Theory of change, results framework, Logframe...Scoffy Wangang
6 vistas58 diapositivas
World Soil Day 2023 Key messages. por
 World Soil Day 2023 Key messages. World Soil Day 2023 Key messages.
World Soil Day 2023 Key messages.Christina Parmionova
8 vistas2 diapositivas
Job Posting - Fire Inspector, PT.pdf por
Job Posting - Fire Inspector, PT.pdfJob Posting - Fire Inspector, PT.pdf
Job Posting - Fire Inspector, PT.pdfNorthwestBOCA
28 vistas1 diapositiva

Último(20)

Ending Stagnation: A New Economic Strategy for Britain por ResolutionFoundation
Ending Stagnation: A New Economic Strategy for BritainEnding Stagnation: A New Economic Strategy for Britain
Ending Stagnation: A New Economic Strategy for Britain
ResolutionFoundation1.6K vistas
COP28 President Launches Global Decarbonization Accelerator por Energy for One World
COP28 President Launches Global Decarbonization AcceleratorCOP28 President Launches Global Decarbonization Accelerator
COP28 President Launches Global Decarbonization Accelerator
MMF Newsletter Februar 2022.pdf por mmpcofficial
MMF Newsletter Februar 2022.pdfMMF Newsletter Februar 2022.pdf
MMF Newsletter Februar 2022.pdf
mmpcofficial7 vistas
Monitoring and Evaluation Plan (Theory of change, results framework, Logframe... por Scoffy Wangang
Monitoring and Evaluation Plan (Theory of change, results framework, Logframe...Monitoring and Evaluation Plan (Theory of change, results framework, Logframe...
Monitoring and Evaluation Plan (Theory of change, results framework, Logframe...
Scoffy Wangang6 vistas
Job Posting - Fire Inspector, PT.pdf por NorthwestBOCA
Job Posting - Fire Inspector, PT.pdfJob Posting - Fire Inspector, PT.pdf
Job Posting - Fire Inspector, PT.pdf
NorthwestBOCA28 vistas
Arunima Himawan - Future of Ageing 2023 por ILCUK
Arunima Himawan - Future of Ageing 2023Arunima Himawan - Future of Ageing 2023
Arunima Himawan - Future of Ageing 2023
ILCUK6 vistas
WCAG 2.2 - An Overview of the New Accessibility Guidelines.pptx por AbilityNet
WCAG 2.2 - An Overview of the New Accessibility Guidelines.pptxWCAG 2.2 - An Overview of the New Accessibility Guidelines.pptx
WCAG 2.2 - An Overview of the New Accessibility Guidelines.pptx
AbilityNet89 vistas
The National Security Framework of Spain por Miguel A. Amutio
The National Security Framework of SpainThe National Security Framework of Spain
The National Security Framework of Spain
Miguel A. Amutio38 vistas
Support Girl students with Education por SERUDS INDIA
Support Girl students with EducationSupport Girl students with Education
Support Girl students with Education
SERUDS INDIA7 vistas
MMF Newsletter March 2022.pdf por mmpcofficial
MMF Newsletter March 2022.pdfMMF Newsletter March 2022.pdf
MMF Newsletter March 2022.pdf
mmpcofficial22 vistas
Food for Elderly homeless por SERUDS INDIA
Food for Elderly homelessFood for Elderly homeless
Food for Elderly homeless
SERUDS INDIA10 vistas
Arunima Himawan (Prevention Index) - Future of Ageing 2023 por ILCUK
Arunima Himawan (Prevention Index) - Future of Ageing 2023Arunima Himawan (Prevention Index) - Future of Ageing 2023
Arunima Himawan (Prevention Index) - Future of Ageing 2023
ILCUK36 vistas
COP28: Example of Formation of Negotiated Texts: Global StockTake por Energy for One World
COP28: Example of  Formation of Negotiated Texts: Global StockTakeCOP28: Example of  Formation of Negotiated Texts: Global StockTake
COP28: Example of Formation of Negotiated Texts: Global StockTake
Advancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp por OECD CFE
Advancing and democratizing business data in Canada- Patrick Gill & Stephen TappAdvancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp
Advancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp
OECD CFE7 vistas
Andreas Schleicher Global Launch of PISA - Presentation - 5 December 2023 por EduSkills OECD
Andreas Schleicher Global Launch of PISA - Presentation - 5 December 2023Andreas Schleicher Global Launch of PISA - Presentation - 5 December 2023
Andreas Schleicher Global Launch of PISA - Presentation - 5 December 2023
EduSkills OECD90 vistas

Day 02 - S+E-TZ-Western Balkans+EPR.pdf

  • 1. EUROPEAN DATA PROTECTION SUPERVISOR The EU’s independent data protection authority The EDPS Supervision and Enforcement Unit (S&E) Thomas ZERDICK, LL.M. Head of Unit of S&E thomas.zerdick@edps.europa.eu 19 September 2023
  • 2. What the EDPS does 2
  • 3. Regulation (EU) 2018/1725 [EDPR] Chapter I General Provisions Regulation (EU) 2016/679 [GDPR] Chapter II General Principles Regulation (EU) 2016/679 [GDPR] Chapter III Rights of the Data Subject Regulation (EU) 2016/679 [GDPR] Chapter IV Controller and Processor Section 2 Security of personal data (Art. 33-35) Section 3 Confidentiality of electronic communications Regulation (EU) 2016/679 [GDPR] Section 2 Security of personal data (Art. 32-34) Directive 2002/58/EC [e-Privacy]* Chapter V Transfers of personal data to third countries or international organisations Regulation (EU) 2016/679 [GDPR] Chapter VI European Data Protection Supervisor Regulation (EU) 2016/679 [GDPR] Chapter VII Cooperation and Consistency Regulation (EU) 2016/679 [GDPR] Chapter VIII Remedies, Liability And Penalties Regulation (EU) 2016/679 [GDPR] Chapter IX Processing of operational personal data by Union bodies, offices and agencies when carrying out activities which fall within the scope of Chapter 4 or Chapter 5 of Title V of Part Three TFEU Personal data breaches (Art. 92+93) Data Protection Directive (EU) 2016/680 for Police and Law enforcement [LED] Chapter X Implementing Acts Regulation (EU) 2016/679 [GDPR] Chapter XI Review Regulation (EU) 2016/679 [GDPR] Chapter XII Final provisions Regulation (EU) 2016/679 [GDPR]
  • 4. 4
  • 6. What the S&E does 6 ADVISE advise data subjects, controllers, consultations on administrative measures and internal rules, issue own initiative opinions, awareness raising; INVESTIGATE investigations, audits, obtain access to premises, order controller to give information; CORRECT issue warnings, reprimands, refer matter to the European Parliament, order rectification or erasure; impose administrative fines; REFER matters to the Court of Justice of the EU and INTERVENE; COOPERATE with national supervisory authorities.
  • 7. 7 Investigative powers Corrective powers Authorisation & advisory powers Check compliance • complaints • investigations • audits • inspections Sanction • warning • reprimand • referral to controller • ban on processing • administrative fine Advise • consultations • visits • trainings • guidelines Our tools
  • 8. Consultations and audits sector 8 consultations on administrative matters DPIA Audits/visits 54 consultations in 2021 Thematic guidelines 8 FTE
  • 10. Complaints and investigations sector 10 Schrems II strategy Investigation into ‘Cloud II’ infrastructure contracts Investigation into Commission’s use of Microsoft 365 more than 300 complaints in 2021 Court proceedings (interventions in staff cases) 7 FTE
  • 11. C&I 11 240 151 203 270 302 227 48 59 43 50 65 44 0 50 100 150 200 250 300 350 1 2 3 4 5 6 complaints received 2018-2023 Series1 Series2
  • 13. • Europol, • Eurojust • European Border and Coast Guard Agency (Frontex) • European Public Prosecutor Office (EPPO) AFSJ sector 13 EDPS - Europol statistics 2021
  • 15. EDPS resources Supervision & enforcement overview: • https://edps.europa.eu/data- protection/our-role- supervisor_en EDPS Investigation Policy: • https://edps.europa.eu/data- protection/our-work/our-work- by-type/investigations_en Complaints: https://edps.europa.eu/data- protection/our-role- supervisor/complaints_en Guidance: • https://edps.europa.eu/data- protection/our-work/our-work- by-type/guidelines_en