Decision concerning Groupon International Limited

Acting in its capacity as lead supervisory authority, the DPC commenced an examination of a complaint originally received by the Polish Data Protection Authority. The complaint concerned cross-border processing in which the DPC was competent to act as lead supervisory authority. This complaint concerned Groupon’s practice at the time of the complaint of requiring data subjects to verify their identity with an electronic copy of a national identity card. This requirement applied when data subjects made certain requests, including requests for erasure of personal data, but the requirement did not apply when data subjects created a Groupon account. The decision-making followed the procedure set out in Article 60 of the GDPR for cross border processing. The procedure included an examination of the complaint by the DPC, including an attempt to amicably resolve the complaint; a Draft Decision circulated amongst the Concerned Supervisory Authorities; the DPC’s careful consideration of each relevant and reasoned objection received; a Revised Draft Decision circulated amongst the Concerned Supervisory Authorities; the adoption of the Final Decision; and finally the Polish Data Protection Authority was responsible for informing the complainant of the decision.

  • The decision found that Groupon infringed the principle of data minimisation in Article 5(1)(c) GDPR by requiring the complainant to verify their identity by submitting a copy of a national ID document in circumstances where a less datadriven solution to the question of identity verification (namely by way of confirmation of email address) was available to Groupon.
  • The decision also found that Groupon infringed Articles 12(2), 17(1)(a) and 6(1) in the circumstances of the complainant’s case.
  • The decision also reprimanded Groupon in respect of the infringements

For more information, you can download a copy of the full decision at this link: Groupon International Limited - December 2020  (PDF, 1,227 KB).

Inquiry into University College Dublin

This inquiry was commenced in respect of 7 personal data breaches that University College Dublin (‘UCD’) notified to the DPC between 8 August 2018 to 21 January 2019. The personal data breaches concerned instances where unauthorised third parties accessed UCD email accounts, or where the login credentials for UCD email accounts were posted online.

  • The decision found that UCD infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to process personal data on its email service in a manner that ensured appropriate security of the personal data using appropriate technical and organisational measures.
  • The decision found that UCD infringed Article 5(1)(e) of the GDPR by storing certain personal data in an email account in a form which permitted the identification of data subjects for longer than necessary for the purpose for which the personal data were processed.
  • The decision found that UCD had infringed Article 33(1) of the GDPR by failing to notify one of the personal data breaches to the DPC without undue delay. This personal data breach was notified 13 days after UCD became aware of it.

The corrective powers exercised

  • The decision imposed an administrative fine on UCD in the amount of €70,000 in respect of the infringements.
  • The decision ordered UCD to bring its processing operations concerning its email service into compliance with Articles 5(1)(f) and 32(1) of the GDPR.
  • The decision issued UCD with a reprimand in respect of the infringements.

For more information, you can download a copy of the full decision at this link: University College Dublin - December 2020 (PDF, 1,347 KB).

Decision concerning Ryanair DAC

Acting in its capacity as lead supervisory authority, the DPC commenced an examination of a complaint originally received by the U.K. Data Protection Authority. The complaint concerned cross-border processing in which the DPC was competent to act as lead supervisory authority. The complaint concerned a subject access request made by the complainant to Ryanair. Ryanair provided the complainant with certain personal data on foot of the request. However, it failed to provide the complainant with a copy of a recording of a call that the complainant had made. Due to the delay on Ryanair’s part in processing the request, Ryanair had since deleted the call recording in accordance with company policy and they had been unable to retrieve it.

The decision-making followed the procedure set out in Article 60 of the GDPR for cross border processing. The procedure included an examination of the complaint by the DPC, including an attempt to amicably resolve the complaint; a Draft Decision circulated amongst the Concerned Supervisory Authorities; the DPC’s careful consideration of each relevant and reasoned objection received, which in this case the DPC followed certain of the relevant and reasoned objections received, and declined to follow certain other relevant and reasoned objections; a Revised Draft Decision circulated amongst the Concerned Supervisory Authorities; the adoption of the Final Decision; and finally the U.K. Data Protection Authority was responsible for informing the complainant of the decision.

  • The decision found that Ryanair infringed Article 15 of the GDPR by failing to provide the complainant with a copy their personal data that was undergoing processing at the time of the request.
  • The decision also found that Ryanair infringed Article 12(3) of the General Data Protection Regulation by failing to provide the complainant information on action taken on their request under Article 15 within the statutory timeframe of one month.
  • The decision also reprimanded Ryanair in respect of the infringements

For more information, you can download a copy of the full decision at this link: Ryanair DAC - November 2020 (PDF, 150 KB).

Inquiry into Waterford City and County Council

This inquiry is one of a number of own-volition inquiries into a broad range of issues pertaining to surveillance technologies deployed by State authorities. The findings made in the decision include:

  • Findings that the Litter Pollution Act 1997 and the Waste Management Act 1996 do not provide a lawful basis for Waterford City and County Council’s use of covert CCTV and dash cams to detect illegal littering and dumping. The DPC comprehensively considered these Acts and found that they do not regulate this processing of personal data as is required by the Law Enforcement Directive, as transposed by the Data Protection Act 2018. Furthermore, the decision found that the Acts do not to meet the standards of clarity, precision, and foreseeability in respect of such processing as required by the case law of the Court of Justice of the European Union and the European Court of Human Rights.
  • A finding that Waterford City and County Council’s use of certain CCTV cameras for crime prevention and investigation is unlawful in the absence of authorisation from the Garda Commissioner in accordance with Section 38 of An Garda Síochána Act 2005.
  • A finding that Waterford City and County Council and An Garda Síochána are joint controllers in respect of certain CCTV cameras authorised under Section 38(3)(c) of An Garda Síochána Act 2005. In this regard, the decision found that Waterford City and County Council infringed Section 79 of the Data Protection Act 2018 by failing to implement an agreement in writing with An Garda Siochána.
  • The other findings in the decision include infringements relating to the adequacy of Waterford City and County Council’s policy in respect of its use of drones for monitoring compliance on permitted waste sites and preventing dumping on illegal waste sites, and its obligation to maintain a data log for specific accesses to CCTV recordings

The corrective powers exercised:

  • A temporary ban on the processing of personal data through certain specified CCTV cameras, covert CCTV cameras, and dash cams for law enforcement purposes.
  • Orders to Waterford City and County Council to bring its processing of personal data into compliance by taking certain action specified in the decision.
  • Reprimands in respect of Waterford City and County Council’s infringements

For more information, you can download a copy of the full decision at this link: Waterford City and County Council - October 2020  (PDF, 1,251 KB).

Inquiries concerning the Health Service Executive

Date of Decisions: 18 August 2020 & 29 September 2020

The DPC commenced inquiry IN-19-9-1 in respect of one personal data breach notified by the HSE to the DPC. The personal data breach occurred when documentation containing the personal data of 78 individuals, including special category personal data in respect of 6 of those data subjects, were disposed of in a public recycling centre. The list was created in Cork University Maternity Hospital, but was discovered by a member of the public in a public recycling area in Cork County.

  • The decision found that the HSE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its use and disposal of hardcopy documents containing patients’ personal data.

The DPC commenced Inquiry IN-19-9-2 in respect of a personal data breach that the HSE notified to the DPC on 1 May 2019. The personal data breach occurred when a member of the public found documentation that contained the personal data of 15 data subjects, including data relating to clinical information and treatments received. The documents were created in Our Lady of Lourdes Hospital, but were discovered by a member of the public in their front garden.

  • The decision found that the HSE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its use and disposal of hardcopy documents containing patients’ personal data.

The corrective powers exercised

  • Decision IN-19-9-1 imposed an administrative fine of €65,000 on the HSE for its infringements of Articles 5(1)(f) and 32(1) of the GDPR.
  • Decision IN-19-9-1 ordered the HSE to bring its processing operations regarding the use and disposal of hardcopy documents containing patients’ personal data into compliance with Articles 5(1)(f) and 32(1) of the GDPR.
  • Decision IN-19-9-1 issued the HSE with a reprimand in respect of its infringements of Article 5(1)(f) and 32(1) of the GDPR.
  • Decision IN-19-9-2 did not exercise further additional corrective powers in light of how decision IN-19-9-1 addressed the circumstances of the same infringements as were subsequently also identified in decision IN-19-9-1. Both decisions also concern the same processing operations, undertaken by the same controller, and concern the same time period.

For more information, you can download a copy of the full decision at this link: Health Service Executive - August and September 2020 (PDF,1,866 KB).

Inquiry into Tusla Child and Family Agency

This inquiry was commenced in respect of 71 personal data breaches notified by Tusla to the DPC. The decision considered a broad range of Tusla’s processing operations and the findings included:

  • Five distinct findings of infringements of Article 32(1) of the GDPR in respect of Tusla’s obligation implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its various processing operations.

  • A finding that Tusla infringed Article 32(4) of the GDPR by failing to take steps to ensure that any natural person acting under their authority does not process personal data except on instructions from Tusla.

  • A finding that Tusla infringed Article 5(1)(d) of the GDPR on the four occasions by failing to ensure that the personal data that it processed was accurate and, where necessary, kept up to date.

  • A finding that Tusla infringed Article 33(1) of the GDPR on 8 occasions by failing to notify the personal data breaches without undue delay.

The corrective powers exercised

  • The decision imposed two distinct administrative fines on Tusla for its infringements of Article 32(1) and Article 33(1) in circumstances where some of the processing operations under consideration were not “the same or linked processing operations” within the meaning of Article 83(3) of the GDPR. The amount of the fines were €50,000 and €35,000 respectively.

  • The decision ordered Tusla to bring its processing operations identified in the decision into compliance with Article 32(1) of the GDPR by implementing appropriate organisational measures to ensure a level of security appropriate to the risks.

  • The decision issued a reprimand to Tusla regarding its infringements of Articles 5(1)(d), 32(1), 32(4), and 33(1) of the GDPR.

For more information, you can download the full decision at this link: Inquiry into Tusla Child and Family Agency - August 2020 (PDF, 1.92mb).

Inquiry into Tusla Child and Family Agency

This inquiry was commenced in respect of one personal data breach notified by Tusla to the DPC. The personal data breach occurred when a social worker for Tusla wrote a safeguarding letter to the ex-partner of an individual against whom abuse allegations had been made. The purpose of this letter was to inform the ex-partner about the alleged abuse and to advise her of safeguarding procedures to ensure ongoing safety. However, the letter contained the names of three individuals who made the allegations and details of the allegations made. The ex-partner subsequently shared a photograph of the safeguarding letter on social media.

  • The decision found that Tusla infringed Article 32(1) of the GDPR by failing to implement appropriate organisational measures to ensure a level of security appropriate to the risk presented by its safeguarding letters processing operation.

  • The decision also found that Tusla infringed Article 33(1) of the GDPR by failing to notify the DPC of the third breach without undue delay.

The corrective powers exercised

  • The decision imposed an administrative fine of €40,000 on Tusla for its infringements of Article 32(1) and Article 33(1).

  • The decision ordered Tusla to bring its processing operations into compliance with Article 32(1) of the GDPR by implementing appropriate organisational measures to ensure a level of security appropriate to the risk.

  • The decision issued Tusla with reprimands in respect of the infringements of Articles 32(1) and 33(1) of the GDPR.

For more information, you can download the full decision at this link: Inquiry into Tusla Child and Family Agency - May 2020 (PDF, 1.90mb).

Inquiry into Tusla Child and Family Agency

This inquiry was commenced in respect of three personal data breaches notified by Tusla to the DPC. All three personal data breaches occurred in circumstances where Tusla failed to redact personal data when providing documents to third parties.

The first personal data breach occurred when Tusla unintentionally provided the father of two children in care with their foster carer’s address.

The second breach occurred when Tusla unintentionally provided an individual who was accused of child sexual abuse with the address of the child who made the complaint and with her mother’s telephone number.

The third breach occurred when Tusla unintentionally provided the grandmother of a child in care with the address and contact details of the child’s foster parents and the location of the child’s school.

  • The decision found that Tusla infringed Article 32(1) of the GDPR by failing to implement appropriate organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data in respect of its sharing of documents with third parties.

  • The decision also found that Tusla infringed Article 33(1) of the GDPR by failing to notify the DPC of the third breach without undue delay.

The corrective powers exercised

  • The decision imposed an administrative fine of €75,000 on Tusla for its infringements of Article 32(1) and Article 33(1).

  • The decision ordered Tusla to bring its processing operations into compliance with Article 32(1) of the GDPR by implementing appropriate organisational measures to ensure a level of security appropriate to the risk.

  • The decision issued Tusla with reprimands in respect of the infringements of Articles 32(1) and 33(1) of the GDPR

For more information, you can download the full decision at this link: Inquiry into Tusla Child and Family Agency (PDF, 1.91mb).

Inquiry into Kerry County Council

This inquiry is one of a number of own-volition inquiries into a broad range of issues pertaining to surveillance technologies deployed by State authorities. The findings made in the decision include:

  • A finding that the Litter Pollution Act 1997, the Waste Management Act 1996, and the Local Government Act 2001 do not provide a lawful basis for Kerry County Council’s use of CCTV to detect litter offences. The DPC comprehensively considered these Acts and found that they do not regulate this processing of personal data as is required by the Law Enforcement Directive, as transposed by the Data Protection Act 2018. Furthermore, the decision found that the Acts do not to meet the standards of clarity, precision, and foreseeability in respect of such processing as required by the case-law of the Court of Justice and the European Court of Human Rights.
  • The other findings in the decision include infringements relating to appropriate signage and general transparency, the lack of written rules or guidelines governing staff access to the CCTV, the use of smartphones or other recording devices in the CCTV monitoring room, the practice of sharing login details for accessing CCTV footage, auditing the audit trails of CCTV footage, and the requirement for Data Protection Impact Assessments, amongst others.

The corrective powers exercised

  • A temporary ban on the processing of personal data through the CCTV cameras at the five locations used for detecting and taking enforcement action against those engaged in littering and the CCTV cameras at Amenity Walk.
  • An order to Kerry County Council to bring its processing of personal data into compliance taking certain action specified in the decision.
  • A reprimand in respect of Kerry County Council’s infringements.

For more information, you can download a copy of the full decision at this link: Kerry County Council - March 2020 (PDF, 952 KB).

Inquiry into An Garda Síochána

This inquiry concerned Garda operated CCTV schemes pursuant to Section 38(3)(a) of the Garda Síochána Act 2005. The findings made in the decision include:

  • Findings that An Garda Síochána had infringed the following Sections of the 2018 Act in respect of its use of Automatic Number Plate Recognition (ANPR) cameras:
    • Section 75(3) of the 2018 Act by failing to implement an appropriate data protection policy; 
    • Section 76 of the 2018 Act by failing to implement the appropriate data protection by design and default safeguards in respect of the ANPR cameras; and
    • Section 84 by reason of its failure to carry out a data protection impact assessment on the ANPR surveillance system for which it is the data controller, to test the necessity of ANPR cameras and to demonstrate that the use of ANPR cameras is justified and proportionate.
  • The other findings in the decision include infringements relating to excessive access to monitoring rooms, appropriate signage and general transparency, governance issues relating to the CCTV systems, and the absence of written contracts between AGS and third party data processors.

The corrective powers exercised

  • A temporary ban on the processing of personal data involving the operation of ANPR cameras.
  • An order to An Garda Síochána to bring its processing of personal data into compliance taking certain action specified in the decision.
  • A reprimand in respect of An Garda Síochána’s infringements.

For more information, access the full decision as PDF Document