On 13 February 2024, the European Data Protection Board (“EDPB”) issued its Opinion 04/ 2024 has been adopted. (“GDPR”) (“Opinions”).
This opinion was requested by the French Data Protection Authority (“CNIL”) and clarifies the concept of a data controller’s “principal establishment” in the EU within the meaning of Article 4(16)(a) of the GDPR. It is intended to. Article 4(16)(a) defines the concept of “principal establishment” as: “The central place of administration in the Union, unless decisions regarding the purposes and means of the processing of personal data are taken by other institutions. The Union controller and the establishment of the latter have the power to implement such decisions. , in which case the establishment making such a determination is considered the principal establishment.” The principal founding concept is that, where an EU data protection authority exists, it determines the lead supervisory authority for cross-border data protection cases. It is the basis for a one-stop shop for GDPR.
The key takeaways from this opinion are:
- A data controller’s “central place of control” in the EU is considered a principal establishment only if that establishment makes decisions about the purposes and means of data processing activities and has the authority to implement those decisions. .
- A one-stop shop can only be applied if there is evidence that one of the EU institutions has taken decisions about the purposes and means of the processing activities involved and has the authority to implement these decisions. This means that if decisions regarding the purposes and means of the relevant processing are taken outside the EU (e.g. in a parent company in a third country such as the United States), there is no key establishment within the meaning of Article 4. (16) Paragraph (a) of the GDPR and One Stop Shop do not apply.
- The burden of proof with respect to a “central place of control” ultimately rests with the data controller, who will have access to the records of processing activities maintained under Article 30 and the privacy policy, etc., to make such a determination. You can utilize various elements. Data controllers have an obligation to cooperate with supervisory authorities.
- Supervisors may challenge the data controller’s assessment by objectively reviewing the relevant facts and requesting further information if necessary. Throughout this process, supervisory authorities should work together and jointly agree on the level of detail that is appropriate for the particular case under consideration.
- Determining the location of central control is a first step to help supervisory authorities identify where decisions about the purposes and means of data processing are made and where the authority to implement such decisions lies. Not too much. Supervisors will need to assess whether significant processing decisions are taken at another facility of the controller who has the authority to make them. As part of the GDPR cooperation mechanism under Article 60(1) of the GDPR, the supervisory authority’s assessment of the presence of key facilities must be shared with all relevant supervisory authorities in order to reach an agreement on the subject matter.
In its opinion, the EDPB also recalled the general purpose of the one-stop shop mechanism. The aim is to reduce legal uncertainty and fragmentation in applying the GDPR across the EU and enable organizations to operate in multiple EU Member States. Engage in cross-border processing activities to benefit from a single point of contact, i.e. a lead supervisory authority.
Read EDPB press releases and opinions.
