COMECE Secretariat · Organisations representing churches and religious communities · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 35 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
Commission of the Bishops’ Conferences of the European Union COMECE | Square de Meeûs 19 – BE-1050 Brussels | Tel. +32 2 235 05 12 | Email [email protected] Website: www.comece.eu | Facebook & Twitter @ComeceEu Evaluation and review of the General Data Protection Regulation A contribution by the Secretariat of COMECE (Commission of the Episcopates of the European Union) 1. Introductory remarks The Catholic Church supports and values protection of personal data and has specific and well-developed internal rules on the matter. The Church’s understanding of the importance of protection of personal data and privacy is reflected in its internal provisions: for instance, according to Canon 220 of the Code of Canon Law “No one is permitted to harm illegitimately the good reputation which a person possesses nor to injure the right of any person to protect his or her own privacy".
…the good reputation which a person possesses nor to injure the right of any person to protect his or her own privacy". This principle is at the core of the work of COMECE on the data protection dossier. The Church appreciates the approach taken with the General Data Protection Regulation (GDPR) to strengthen data protection and citizens' rights. It supports the attempt to reinforce fundamental rights in the EU and is committed to guarantee a high level of data protection in its structures. With the help of its Secretariat, COMECE assisted its member Bishops' Conferences through the process launched with the General Data Protection Regulation and will continue to help them to address the specific challenges posed by the file to the Church in the EU Member States.
…will continue to help them to address the specific challenges posed by the file to the Church in the EU Member States. Concerning the GDPR, dialogue was maintained by COMECE with both the European Commission and the European Data Protection Board, with the assistance of its Legal Affairs Commission. Throughout this first phase, the Church at the national level has entertained close and constructive relations with the respective Data Protection Authorities (DPAs). In general, Member States have expressed satisfaction with the level of protection of personal data ensured by the Catholic Church. Bishops' Conferences and Dioceses have been actively setting up internal training tools and initiatives on specific data protection issues. The GDPR has undoubtedly contributed to strengthening data protection culture and awareness in the EU at all levels and areas of society.
…contributed to strengthening data protection culture and awareness in the EU at all levels and areas of society. The option for a more invasive legislative tool, like a Regulation, created some difficulties. In this contest, the fact that the Regulation allowed national law to specify a number of aspects proved important. In the context of the ongoing GDPR evaluation and review, we take the liberty of submitting some observations and elements, based on extensive internal reflections and on first evidence of the relevance of the GDPR with regard to Church activities in the Member States. We would highlight the particular importance of remarks concerning Article 91 GDPR (pages 4-5). Ref. Ares(2020)2288072 - 29/04/2020 COMECE | Square de Meeûs 19 – BE-1050 Brussels | Tel.
Article 91 GDPR (pages 4-5). Ref. Ares(2020)2288072 - 29/04/2020 COMECE | Square de Meeûs 19 – BE-1050 Brussels | Tel. +32 2 235 05 12 | Email [email protected] Website: www.comece.eu | Facebook & Twitter @ComeceEu 2 Taking into account the evident impact that the Covid-19 crisis is having on protection of personal data and privacy, we take this opportunity to underline - in the strongest possible terms - that any temporary erosion of relevant standards, linked with this exceptional situation, will have to be eliminated at the earliest possible stage; and that even in the current phase, the highest possible protection of personal data and privacy must be ensured.
…and that even in the current phase, the highest possible protection of personal data and privacy must be ensured. 2. The fundamental right to freedom of religion Recital 4 of the Regulation highlights the provisions of the Charter of Fundamental Rights of the EU (CFR) in the light of which - in particular - the text should be interpreted and applied. Among them, the articles concerning the fundamental right to freedom of religion (Article 10 CFR) and respect for cultural, religious and linguistic diversity (Article 22 CFR). This GDPR provision is important in interpreting Article 91 GDPR on "Existing data protection rules of churches and religious associations" (on which more at pages 4-5). In accordance with Article 52.3 CFR, Article 10 CFR covers the collective, as well as the institutional dimension of freedom of religion, as outlined in the protective jurisprudence of the European…
…alia, about its obligation to record sacraments, as well as defining and applying its internal data protection rules. 3. Lawfulness of processing A specific question with regard to legal basis' for processing concerns consent as a possible legal basis for processing when a child is involved: the GDPR provides limited indications at its Article 8, which are relevant only for information society services. The question of how to address the issue in areas that do not fall under the offer of information society services remains open to the national legislator. Consent by the holder of parental responsibility over the child should be referred to as a possible legal basis in such cases. This also affects the Church's approach and its mission in favour of children and youth, in particular catechesis. 4.
This also affects the Church's approach and its mission in favour of children and youth, in particular catechesis. 4. Right to erasure While Directive 95/46/EC already referred to a right to erasure at Article 12, point (b), the formulation adopted with the Regulation is decidedly more developed and pervasive. The cases in which the data subject has the right to request erasure of personal data concerning him/her are quite broadly worded and therefore create grounds for a multiplication of requests.
…data concerning him/her are quite broadly worded and therefore create grounds for a multiplication of requests. Concerning the explicit and close link established by Article 17.1, point (c) GDPR between the exercise of the right to object (Article 21.1 GDPR) and the right to erasure, it is to be recalled that § 78 of the Explanatory Report to the Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, underlines that: "The right to object operates in a distinct and separate manner from the right to obtain rectification or erasure". COMECE | Square de Meeûs 19 – BE-1050 Brussels | Tel. +32 2 235 05 12 | Email [email protected] Website: www.comece.eu | Facebook & Twitter @ComeceEu 3 In general, the clauses of Article 17.3 GDPR seem insufficient in the protection of the rights of data controllers.
…general, the clauses of Article 17.3 GDPR seem insufficient in the protection of the rights of data controllers. Concerning the exception related to the exercise of the fundamental right of freedom of expression and information - Article 17.3, point (a) GDPR - the same approach could have been adopted for the fundamental right to freedom of religion, considering that both freedoms are identified by the jurisprudence of the European Court of Human Rights among the foundations of a democratic society. The reference to "archiving purposes" - Article 17.3, point (d) GDPR - is somewhat restricted by its link with the "public interest" element, despite the useful integration provided by Recital 158.
…restricted by its link with the "public interest" element, despite the useful integration provided by Recital 158. Preservation of Church sacramental records from erasure of historical facts and events that have taken place within the Church community is indispensable to the Church for carrying out its institutional mission (e.g. celebrating sacraments such as baptisms, marriages etc.) and for protecting interests of relevant family members. As recalled above, the fundamental right to freedom of religion has a personal but also an institutional aspect. Bearing this in mind, as the recording of a sacrament (e.g. baptism) in a Church record also represents an important aspect of the function of an ecclesial body, erasure of the relevant records could lead to the violation of the fundamental right in question.
…of an ecclesial body, erasure of the relevant records could lead to the violation of the fundamental right in question. 5. Right to object The impact of the reversal of the burden of proof introduced with Article 21.1 GDPR should be carefully assessed, particularly considering that the broad and open formulation of the provision can cause an increase in litigation. The previous references to the need to balance the right to protection of personal data with the the right to freedom of religion, in particular in its institutional dimension, are also relevevant for the right to object.
23 → 12