Inquiry into Allianz plc

This decision arose from an own-volition inquiry commenced by the DPC pursuant to section 110 of the Data Protection Act 2018 to consider whether Allianz had complied with the GDPR in relation to its processing operations.

The inquiry was initiated after Allianz had notified 49 personal data breaches to the DPC between 25 June 2020 to 31 December 2020. In total approximately 60 data subjects were affected by the personal data breaches.

The decision considered whether Allianz had complied with Article 32(1) GDPR and in particular whether Allianz had implemented appropriate technical and organisational measures to ensure a level of risk appropriate to the risks associated with its processing operations.

The decision found that Allianz had complied with its obligations under Article 32(1) GDPR. It was held Allianz had implemented policies, which were specifically tailored to the risks associated with the processing. Allianz also provided repeated training to sectors of the business, which were the most susceptible to personal data breaches of this kind. Allianz also took proactive measures to counter the increasing risk profile of some business units by implementing additional security measures after some personal data breaches occurred. These measures included an External Email Warning Tool and increased spot checks in the post room.

Accordingly, no corrective powers were exercised in this decision.

For more information, you can download a copy of the full decision at this link: Allianz plc - June 2022 (PDF, 348 KB).

Case Studies

 

CCTV in Restrooms

Each year the DPC receives numerous queries and complaints from various individuals complaining specifically about the use of CCTVs in restroom areas by various organisations such as public houses, nightclubs, restaurants and transport depots. More particularly, the complaints allege that the cameras are pointing over specific areas in restrooms where there is an increased expectation of privacy, such as over cubicles or urinals.

While, the DPC has engaged with organisations on a one-to-one basis, the issue of the lawfulness of the processing of personal data by way of CCTVs in restrooms needs to be considered more generally. Consequently, the DPC has examined these issues further and updated its Guidance on CCTVs for Data Controllers by including a specific section on ‘The use of CCTV in areas of an increased expectation of privacy.

Key Takeaway

  • Organisations should avoid using CCTV where a reasonably high expectation of privacy exists (for example, over cubicles). The threshold for the use of CCTV in restrooms more generally, remains very high, and requires data controllers to identify and examine all the legitimate issues arising and to assess and implement appropriate measures which adequately protect the interests of individuals using those facilities which must be evaluated prior to the deployment of any system.
  • The DPC strongly recommends that all data controllers familiarise themselves with this updated guidance.

Case Studies

 

Failure to respond to an Access Request

The DPC received a complaint with regard to an individual who made an access request under Article 15 of the GDPR to a public/state hospital for a copy of all personal information held concerning them. The response from the hospital remained outstanding after more than a month, whereas information provided to the DPC indicated that due the health of the individual this matter required urgent attention.  


The DPC contacted the Data Protection Officer for the Hospital Group by phone and email to inform them of the urgency of the complaint, and requested they respond to the individual’s representatives promptly, providing them with a copy of the individual’s personal information as part of the engagement. The hospital followed the instructions from the DPC.

Whilst the hospital acknowledged receipt of the request within one month of its receipt, the personal data the individual was entitled to was only provided to the individual following the intervention of the DPC.   

Key Takeaway

  • Organisations are required to implement appropriate organisational measures in place to ensure that they are in a position to respond to any rights requests within the stipulated timeframes under the GDPR. Organisations should not await the intervention of the Regulator to respond promptly to subject access requests.