{"id":2550,"date":"2020-05-24T10:47:37","date_gmt":"2020-05-24T10:47:37","guid":{"rendered":"http:\/\/www.bizlegal.eu\/?page_id=2550"},"modified":"2020-05-24T14:47:35","modified_gmt":"2020-05-24T14:47:35","slug":"newsletter-may-2020-covid-19-update","status":"publish","type":"page","link":"https:\/\/www.bizlegal.eu\/?page_id=2550","title":{"rendered":"Newsletter May 2020 &#8211; Covid-19 Update"},"content":{"rendered":"\n<p>Business Legal specialises in three core areas and Legal Project Management.\u00a0<\/p>\n\n\n\n<p>1. Health and Safety&nbsp;<\/p>\n\n\n\n<p>2. HR and Employment&nbsp;&nbsp;<\/p>\n\n\n\n<p>3. Data Protection and Privacy&nbsp;<\/p>\n\n\n\n<p>4. Legal Project Management\/General Counsel services&nbsp;<\/p>\n\n\n\n<p><strong>Newsletter&nbsp;<\/strong><br><strong>NEWSFLASH!&nbsp;<\/strong><\/p>\n\n\n\n<p>Almost uniquely, this pandemic touches upon all of these three core areas areas, but in this newsflash edition we are\u00a0advising of some BIG data protection news.\u00a0<\/p>\n\n\n\n<p><strong>Data Protection Commission issues first&nbsp;&nbsp; GDPR administrative fine&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>Coming from a low base&nbsp;<\/strong><\/p>\n\n\n\n<p>Historically, the Data Protection Commission (\u201cDPC\u201d) has not had the power to issue administrative&nbsp; fines, or indeed any other penalties for breach of data protection law.&nbsp; This fact is not always&nbsp; appreciated by our more recent GDPR practitioners.&nbsp; The DPC did however find ways to enforce in some&nbsp; circumstances.&nbsp; It was always the case that data protection legislation in Ireland provided for voluntary&nbsp; arrangements to resolve data protection disputes.&nbsp; In such circumstances, the DPC would agree not to&nbsp; further investigate a particular issue, in return for an offer of amends from the controller to the data&nbsp; subject, often involving compensation.&nbsp; Apart from this, the DPC occasionally insisted on payments of&nbsp; its own costs, as a prerequisite for agreeing not to prosecute.&nbsp; It was a fairly limited enforcement system&nbsp; and could very much be said to be a light touch regulation.&nbsp;<\/p>\n\n\n\n<p>Separately to this, there was, and still remains an ability for the DPC to prosecute certain limited matters&nbsp; under data protection law.&nbsp; Essentially these are impeding the DPC or failing to follow their lawful&nbsp; directions, and some very limited offences relating to employment, micro-targeting of children,&nbsp;&nbsp; processing of information relating to convictions or alleged criminal offences, unauthorised disclosure&nbsp; by a processor or an agent or employee of a processor.&nbsp; Some of these offences carry penal terms of up&nbsp; to 5 years imprisonment.&nbsp; They are criminal offences, not mere breaches of GDPR.&nbsp;<\/p>\n\n\n\n<p>Notwithstanding the above, the history of data protection from 1988 to date has been one of zero&nbsp; criminal convictions, and very light fines.&nbsp; There was an expectation that GDPR would see a massive&nbsp; increase in fines, particularly as it was now possible for the DPC to issue administrative fines generally&nbsp; of up to \u20ac20 million or 4% of total worldwide annual turnover for a proceeding financial year, whichever&nbsp; was the greater.&nbsp; In short, the DPC now has the tools with which to heavily enforce the GDPR.&nbsp; The&nbsp; question was however, would they use these tools?&nbsp; <img loading=\"lazy\" src=\"\" width=\"793\" height=\"103\"><br><\/p>\n\n\n\n<p><strong>Administrative Fines&nbsp;<\/strong><\/p>\n\n\n\n<p>Administrative fines are issued by the DPC, but as only the Courts may issue fines in Ireland, a pro forma&nbsp; application is made to the Circuit Court in order to turn an administrative fine into a judicial fine.&nbsp; These&nbsp; fines can be resisted, but only on the basis of administrative impropriety.&nbsp; There is a similar regime for&nbsp; the enforcement of employment law determinations issued by employment body fora such as the&nbsp; Workplace Relations Commission.&nbsp; It is rare that these are contested, as one has to show a breach of&nbsp; administrative law in relation to the fines, rather than that the recipient of the fine disagrees with the&nbsp; basis of the decision, or the amount of the fine.&nbsp;<\/p>\n\n\n\n<p><strong>The Phoney War&nbsp;<\/strong><\/p>\n\n\n\n<p>Initially, the DPC announced in general terms that it would be giving approximately one year\u2019s grace&nbsp; post 25 May 2018 before enforcement activity began in earnest.&nbsp; This was despite the two years grace&nbsp; period contained in the legislation, which ran for the two years prior to 25 May 2018.&nbsp; In fact, the DPC&nbsp; has not concentrated on enforcement in the two further years since the GDPR became operational.&nbsp;<\/p>\n\n\n\n<p>Businesses have therefore had four years within which to become operationally ready for the GDPR\u2019s&nbsp; enforcement regime, but not unsurprisingly, the attitude of many businesses has been that if the DPC&nbsp; is not prepared to enforce, why should they spend money on what is after all a regulatory regime which&nbsp; in the absence of enforcement would have a more limited effect on their business.&nbsp;<\/p>\n\n\n\n<p><strong>Things just got interesting&nbsp;<\/strong><\/p>\n\n\n\n<p>Last Friday, the DPC filed a Circuit Court action against TUSLA to&nbsp; confirm an administrative fine of \u20ac75,000 in relation to 3 data&nbsp; breaches.&nbsp; TUSLA has not contested the administrative fine.&nbsp;<\/p>\n\n\n\n<p>In relation to timeframes, this was an investigation that started in October 2019, and has just been&nbsp; completed, taking a total of eight months.&nbsp; All investigations will be different, but it is indicative of the&nbsp; timescales involved.&nbsp; Considering the maximum amount of the administrative fine which could be&nbsp; imposed was \u20ac10 million in this case (there is a lower limit for certain types of breaches of the GDPR,&nbsp; including data breaches), a fine of \u20ac75,000 represents a fine of 0.75% of the maximum fine.&nbsp; This does&nbsp; suggest that fines for single incident data breaches may be relatively low.&nbsp;<\/p>\n\n\n\n<p>Notwithstanding this of course, the organisation involved has suffered severe reputational loss, been&nbsp; fined for a breach, and \u20ac75,000 is a far cry from the previous level of fines imposed for criminal offences&nbsp; under the old regime, which often amounted to fines of several hundred euro. &nbsp;As against that, the&nbsp; three breaches do appear to be serious.&nbsp; In one breach TUSLA accidentally disclosed the address of the&nbsp; foster home to the children\u2019s imprisoned father, who then wrote to them at that address, in another&nbsp; case TUSLA accidentally gave contact details of foster parents and the children\u2019s school to a&nbsp; grandparent, which allowed the grandparent to make contact, and in the third case TUSLA accidentally&nbsp; disclosed contact and location data of a mother and child to their alleged abuser.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>It is expected that over time that the consistency mechanism in the GDPR will result in an equalisation&nbsp; of administrative fines across the EU to some degree, with some countries such as Germany perhaps&nbsp; levelling down, whilst other countries such as Ireland, level up.&nbsp; <img loading=\"lazy\" src=\"\" width=\"793\" height=\"103\"><br><\/p>\n\n\n\n<p><strong>Commercial ramifications.&nbsp;<\/strong><\/p>\n\n\n\n<p>This is the first case of an administrative fine in Ireland.&nbsp; In general, across the EU, enforcement has&nbsp; been mostly quite restrained.&nbsp; Indeed, the largest privacy\/data protection fines have actually been in&nbsp; the United States.&nbsp; However, this recent fine and the recent announcement by the DPC that it is scouring&nbsp; websites for cookie consent in order to take action probably means that this is the start of a much more&nbsp; impactful enforcement campaign.&nbsp; There is no reason to believe that only state organisations such as&nbsp; TUSLA will be targeted.&nbsp; Indeed, were a private organisation to have its data breaches made public, and&nbsp; make headline news, as a result of fines of this order or greater, the commercial impact would be severe.&nbsp;&nbsp; Such impacts include loss of confidence by customers, by staff, by group companies, by affiliates et&nbsp; cetera.&nbsp;<\/p>\n\n\n\n<p><strong>There is no need to panic&nbsp;<\/strong><\/p>\n\n\n\n<p>There is no need to panic because one of the key determinants in your&nbsp; treatment by the DPC is whether you have put in place a proper&nbsp; system.&nbsp; The DPC understands that accidents will always happen, and&nbsp; has made it clear that where an organisation has made its best efforts,&nbsp; that it will either not be administratively fined, or it will be issued with&nbsp; a very low administrative fine, possibly even a fine of zero.&nbsp; As&nbsp; important therefore as not having any breaches (this is nearly&nbsp; impossible) is having a system in place that will assure the DPC that you&nbsp; have made a reasonable effort to put in place appropriate data&nbsp; protection systems.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><td><\/td><td><\/td><td><\/td><\/tr><tr><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"313\" height=\"123\"><\/td><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"353\" height=\"134\"><\/td><\/tr><tr><td><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"793\" height=\"103\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Business Legal specialises in three core areas and Legal Project Management.\u00a0 1. Health and Safety&nbsp; 2. HR and Employment&nbsp;&nbsp; 3. Data Protection and Privacy&nbsp; 4. Legal Project Management\/General Counsel services&nbsp; Newsletter&nbsp;NEWSFLASH!&nbsp; Almost uniquely, this pandemic touches upon all of these three core areas areas, but in this newsflash edition we are\u00a0advising of some BIG data &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.bizlegal.eu\/?page_id=2550\"> <span class=\"screen-reader-text\">Newsletter May 2020 &#8211; Covid-19 Update<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":""},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.bizlegal.eu\/?author=3","display_name":"Sharon McGauley"},"relative_dates":{"created":"Posted 6 years ago","modified":"Updated 6 years ago"},"absolute_dates":{"created":"Posted on 24\/05\/2020","modified":"Updated on 24\/05\/2020"},"absolute_dates_time":{"created":"Posted on 24\/05\/2020 10:47 am","modified":"Updated on 24\/05\/2020 2:47 pm"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2550"}],"collection":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2550"}],"version-history":[{"count":2,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2550\/revisions"}],"predecessor-version":[{"id":2578,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2550\/revisions\/2578"}],"wp:attachment":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}