Why the Belgian DPA rejection of a noyb complaint is a must-read

The Belgian DPA’s newest rejection of a NOYB complaint for reasons of fictional mandates (yes, again) is a must-read for both complainants (or complainant organisations) and controllers/processors who receive complaints from representative organisations.

Summary: “The method by which the complaint at the initiative of the representative seeks to raise a general predetermined practice, by addressing it accessorily in a complaint of an individual data subject, demonstrates that an artifice has taken place in the light of Article 80(1) GDPR in lodging this complaint in order to raise practices in a manner exclusively provided for under Article 80(2) GDPR”. [para 89]

The background:
– Article 80(1) GDPR allows representative organisations to file complaints on behalf of data subjects; Article 80(2) GDPR *allows* Member States to elect to allow representative organisations to file complaints even in the absence of a mandate from a specific data subject.

– As mentioned in a commentary of a previous Belgian DPA rejection of a NOYB complaint ( https://lnkd.in/eCxsvAit ), Belgium chose *not* to implement 80(2), so representative organisations need a mandate.

The decision:
– The Belgian DPA stresses that civil society can obviously play an important role, notably in facilitating complaints. “However, this is different from designing complaints for currently non-existent complainants” [88]

– By reference to the legal theory of abuse of rights, “the concept of abuse of rights may also apply to the exercise of procedural rights. Noyb’s conduct in this case appears to exceed the limits of a normal and proportionate exercise of the right to representation provided for in Article 80(1) GDPR” [68].
“The fact that the representative determines the manner in which a breach must be undergone in order to grant a mandate to exercise the right of complaint under Art. 77 & Art. 80(1) GDPR before the Belgian authority, means that the general standard of care is disregarded by the representative and thus constitutes an abuse of law.” [70]

– In addition, re NOYB employees/interns: “Art. 80.1 GDPR […] states that it is the data subject who retains the right to mandate an organisation to represent the person. The wording �data subject� shows, first of all, that personal data and associated processing in the context of the grievances raised had to already exist before (the coordination prior to) the mandate. In turn, the wording �to instruct� points to the fact that the instruction goes in one direction: from the complainant to the representative, not the other way around.

– Finally, the Belgian DPA says that NOYB may be pursuing *other* interests than those of data subjects – which isn’t the intent of Art. 80(1) GDPR but 80(2).

Decision (in Dutch): https://lnkd.in/eDMPasAb

data protection

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗