Data Privacy Compliance in the Cloud
Made Easy

Understand Cloud and Data Protection Law in only 4 easy steps. Plus highly relevant legal information for 33 countries. Provided by EuroCloud and 53 European lawyers.

The discussions around the national law on personal data processing

29.05.2018

The Latvian legislator is facing delays with the adaptation of the national Law on Personal Data Processing (the Draft Law). On April 12, the Latvian Parliament, the Saeima, has conceptually supported the Draft Law in the first sitting. The date of the second sitting is unknown yet, however, the table of proposals submitted until April 20 (the final deadline) is pretty long, and the most of proposals relate to the duties and functions of the Data State Inspectorate along with the certification of the data protection officer appointed by the data controller (i.e. should it be a person included in an official list of a Data State Inspectorate, or the data controller may choose any person in accordance with the requirements of GDPR).

Many discussions and concerns were also caused by the Article 26 of the Draft Law allowing the authorities of national Data State Inspectorate, without any warning and upon receipt of the decision of the court judge, to enter, in the presence of police, the non-residential premises, apartments, buildings or other objects of immovable property which are in ownership, possession or in use of a data controller or processor, and to perform coercive screening or inspection, to receive any and all documents (including the information on electronic devices) and even the rights to seal such premises for 72 hours to ensure the preservation of evidence.

Currently the Criminal Law already stipulates criminal liability for the illegal activities involving personal data of natural persons, if such activities have caused substantial harm, they have been performed by a personal data processing administrator or operator for the purpose of vengeance, acquisition of property or blackmail, or for influencing a personal data processing administrator or operator, or the data subject, using violence or threats, or using trust in bad faith, or using deceit in order to perform illegal activities involving personal data of a natural person. Thus, the search measures of Draft Law, as described above, could be performed under certain circumstances as a part of criminal proceedings by the corresponding authorities conducting the criminal proceedings, and the actions described in the Draft Law would therefore be recognized as unnecessary and disproportionate to the aims of GDPR.

The Article 30 of the National Personal Data Protection Law, which implemented the Directive 95/46/EC in year 2000, stipulates that the authorities of national Data State Inspectorate have the rights to freely enter any non-residential premises where processing of personal data is located, and in the presence of a representative of the administrator (i.e. the representative of the data controller), to carry out necessary inspections or other measures in order to determine the compliance of the procedure of processing of personal data with the law. Such limited rights of the Data State Inspectorate seemed much more appropriate and proportionate to the controller’s interests.

However, the limits of the applicable legislation are decisive: the GDPR increases the essential requirements for control so high, that the legislator wants to have as many options to protect the legal interests described in GDPR, as he can. However, taking into account the discussions and concerns mentioned above, the Ministry of Justice has promised to review this Article of Draft Law one more time.

 

Article provided by: Jana Panko (Lawyer, Njord Law Latvia)

 

References 

 

Discover more about the Cloud Privacy Check(CPC) / Data Privacy Compliance(DPC) project

Director CPC project: Dr. Tobias Höllwarthtobias.hoellwarth@eurocloud.org

VIEW PROJECT

WHAT IS THE DPC/CPC PROJECT?

53 lawyers from 33 countries are contributing to the project “Data Privacy Compliance (DPC)/Cloud Privacy Check (CPC)” in 26 different languages.

Understanding the complexity of current European data protection laws and regulations is already difficult enough for an IT engineer, buyer, or business user. In combination with the often small but nevertheless significant differences between various EU member states, however, it can become an almost insurmountable challenge without proper juristic accompaniment from the very start... Read More

 

CPC MISSION & VISION STATEMENT, 2018

The CPC is a trusted, not-for-profit international network of qualified professionals who deliver simplified and straight-forward guidance to help navigate the legal and regulatory environment relating to privacy and the cloud. This is done through collective know-how, research and market analysis gained from pan-European industry activity, collaboration and experience. Our mission is to provide authoritative views, information and practical solutions to two principal stakeholders: industry professionals and public authorities.