Еуропалық деректерді қорғау ережелерін сақтауды қамтамасыз ететін Ирландияның тәуелсіз органы
Data Protection Commissioner
Ирландияның Деректерді қорғау комиссиясы – ЕО-ның жеке деректерді қорғау ережелерін сақтауды қадағалайтын тәуелсіз ұлттық орган. GDPR, заңнама, 1981 ж. конвенция.
Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Мазмұны
Кіріспе
Еуроодақтың жеке деректерді қорғау ережелерін сақтауды қамтамасыз ететін тәуелсіз ұлттық орган.
Irish independent national authority tasked with enforcing EU privacy protections
Деректерді қорғау комиссарының кеңсесі (An Coimisinéir Cosanta Sonraí) (DPC), сондай-ақ Деректерді қорғау комиссиясы деп те белгілі, Ирландиядағы деректерді қорғау заңнамасына сәйкестікті күзеу және бақылау арқылы жеке тұлғалардың деректерге қатысты Еуроодақтың негізгі құқығын сақтауға жауапты тәуелсіз ұлттық орган болып табылады. Ол 1989 жылы құрылған.
The Office of the Data Protection Commissioner (An Coimisinéir Cosanta Sonraí) (DPC), also known as Data Protection Commission, is the independent national authority responsible for upholding the EU fundamental right of individuals to data privacy through the enforcement and monitoring of compliance with data protection legislation in Ireland. It was established in 1989.
Рөл мен операциялар
Деректерді қорғау жөніндегі комиссардың тәуелсіз рөлі мен өкілеттіктері 1988 және 2003 жылғы деректерді қорғау туралы заңдарда қарастырылған. Бұл заңдар Еуропа Кеңесінің 1981 жылғы деректерді қорғау конвенциясын (108-конвенция) және 1995 жылғы ЕО деректерді қорғау директивасын (95/46/ЕҚ) жүзеге асырады. Дегенмен, кейін бұл директива Еуропалық Одақтың жалпы деректерді қорғау регламентімен (GDPR) алмастырылды, ол Ирландия сияқты мүше мемлекеттерде тікелей қолданылады.
The independent role and powers of the Data Protection Commissioner are as set out in legislation in the Data Protection Acts 1988 and 2003. These Acts transpose the Council of Europe 1981 Data Protection Convention (Convention 108) and the 1995 EU Data Protection Directive (Directive 95/46/EC). However, the latter was then replaced by the EU General Data Protection Regulation (GDPR), which is directly applicable upon Members States such as Ireland.
Шағымдарды тергеу
Жеке тұлғалардың жеке мәліметтері заңға сәйкес қаралмайды деп санайтын шағымдары Деректерді қорғау заңдарының 10-бабы бойынша тексеріледі. Кеңсенің заңмен белгіленген міндеті – алдымен шағымдарды бейбіт жолмен шешуге тырысу. Егер бейбіт шешімге қол жеткізілмесе, Комиссар заң бұзылған деп санай ма, жоқ па, соған қарай шешім қабылдай алады. Шағымданушы немесе деректерді басқарушы Комиссардың қорытындысымен келіспесе, олар шешімді Апелляциялық сотқа шағымдануға құқылы. Шағым қабылданған жағдайда, ДСК-ның басты басымдығы – деректерді басқарушының заңға сәйкес келуін және мәселені түзетуін қамтамасыз ету болып табылады. Егер ұйым тергеуге ерікті түрде ынтымақтастық көрсетпесе, ДСК мұндай ынтымақтастықты талап етуге құқылы. 2015 жылы 932 шағым келіп түсті, олар тергеу үшін ашылды. 1015 шағым бойынша тергеу аяқталды. 2018 жылы Goosed редакторы Мартин Мини, өзінің крещение туралы деректерін жоюды сұрап, Оссори епархиясына қарсы ДСК-ге шағым берді. Бұл шағымнан кейін ДСК «шіркеудің крещение және басқа да католик динінің қағидалары туралы жеке деректерді сақтауы Еуроодақтың деректерді қорғау заңнамасына, атап айтақанда, Жалпы деректерді қорғау регламентіне сәйкес келе ме» деген сұрақ бойынша «өз бастамасымен тергеуді» бастады. 2022 жылы Мини ДСК-ға қарсы Жоғары соттағы сотқа дейінгі іс жүргізді. Ол ДСК-нің Католик шіркеуіне қатысты шағымын тергеуді аяқтамағанын мәлімдеді. 2021 жылы Макс Шремс құрған австриялық ҮЕҰ NOYB (None Of Your Business), ДСК Facebook-қа қарсы ұзаққа созылған шағымын жалғастыру үшін құпиялылық туралы келісімге қол қоюды талап еткені үшін австриялық заң бойынша сыбайлас жемқорлық жасады деп ДСК-ге шағым түсірді. NOYB ДСК өзінің қызметтерін пайдалану үшін бұқаралық ақпарат құралдарында жағымды жариялануды талап ете алмайды деп мәлімдеді. 2023 жылдың қаңтар айында Еуропалық деректерді қорғау кеңесінің тексеруі алғашқы айыппұл жеткіліксіз екенін анықтағаннан кейін ДСК Meta Platforms компаниясына салған айыппұлды арттыруға мәжбүр болды. Еуропалық деректерді қорғау кеңесі ДСК өзінің міндеттерін «жеткілікті сақтықпен» орындамағанын анықтады. Сыншылар Еуропалық деректерді қорғау кеңесінің қабылдаған 8 шешімінің 7-сі Ирландияның ДСК-сіне қарсы болғанын және ДСК «шешімге жету үшін ЕО заңдарын қарапайым қолданудың орнына әрдайым ең қиын, ұзақ және қымбат заңдық жолды таңдайды» деп атап көрсетті.
Complaints received from individuals who feel that their personal information is not being treated in accordance with the data protection law are investigated under section 10 of the Data Protection Acts. It is the statutory obligation of the Office to seek to amicably resolve complaints in the first instance. Where an amicable resolution cannot be achieved, the Commissioner may make a decision on whether, in her opinion, there has been a breach of the law. If the complainant or the data controller disagrees with the Commissioner's finding, they have the right to appeal the decision to the Circuit Court. The DPC's main priority, if a complaint is upheld, is that the data controller complies with the law and puts right the matter concerned. If an organization does not voluntarily cooperate with an investigation, the DPC has powers of compulsion to require such cooperation. In 2015, the Office received 932 complaints that were opened for investigation. Investigations into 1,015 complaints were concluded. In 2018, Martin Meany, editor of Goosed. ie, filed a complaint to the DPC against the Diocese of Ossory stating he wished for his baptismal records to be deleted. The complaint started a subsequent "own volition enquiry" by the DPC into "whether the church's holding of personal data on baptisms and other Catholic sacraments that individuals may have taken falls under the EU's data protection law, the General Data Protection Regulation". In 2022, Meany launched High Court Judicial Review proceedings against the DPC. He claims the DPC has failed to complete an investigation into his complaint against the Catholic Church. In 2021, NOYB (None Of Your Business), an Austrian NGO founded by Max Schrems, filed a complaint against the DPC for corruption under Austrian law after the DPC demanded that the group sign a non disclosure agreement in order to continue with their long running complaint against Facebook. NOYB argued that the DPC could not demand favourable media coverage as the price of using its services. In January 2023, DPC was forced to increase the fine issued to Meta Platforms after a review by European Data Protection Board found that the initial fine was insufficient. European Data Protection Board determined that DPC has failed to perform its enforcement responsibility with "due diligence". The critics have pointed out that 7 out of 8 decisions handed down by European Data Protection Board were against the Irish DPC, and that the DPC "always choose the most tortuous, lengthy and expensive legal route to a decision rather than a simple application of EU law".
Аудит
Заңның 10-бабының 1-А тармағында "Комиссар осы Заңның қағидаларын сақтауды қамтамасыз ету және оның ережелерін бұзудың кез келген жағдайларын анықтау мақсатында, қажет деп санаған тергеулерді жүргізе алады немесе жүргізуге мүмкіндік береді" делінген. Мұндай тергеулер көбінесе таңдалған ұйымдардың аудиті түрінде жүзеге асырылады. Аудиттің мақсаты – тексеріліп отырған ұйымның жеке деректерді басқару жолындағы қысымдық мәселелерді анықтау болып табылады. 2015 жылы DPC мемлекеттік және жеке сектордағы ұйымдардың 51-іне аудиттер мен тексерулер жүргізді.
Section 10 (1A) of the Acts provides that "the Commissioner may carry out or cause to be carried out such investigations as he or she considers appropriate in order to ensure compliance with the provisions of this Act and to identify any contravention thereof." These investigations often take the form of audits of selected organizations. The aim of an audit is to identify any issues of concern about the way the organization under scrutiny manages personal data. In 2015, the DPC carried out 51 audits and inspections of organizations in the public and private sectors.
Электрондық байланыс ережелеріне сәйкес құқық бұзушылықтар
Құпиялылық және электрондық байланыс (ЕО директивасы) 2003 жылғы Ережелерінің барлық бұзушылықтары, олар үшін Деректерді қорғау комиссиясы жауапты болып табылады – құқық бұзушылықтар. Бұл құқық бұзушылықтар негізінен электрондық тәсілдер арқылы сұралмаған жарнамалық хабарламаларды жіберумен байланысты. Құқық бұзушылықтар айыппұлмен жазаланады: қысқартылған сотта әрбір сұралмаған хабарлама үшін 5000 евроға дейін, ал жалпы сотта 250 000 евроға дейін айыппұл салынады. Деректерді қорғау комиссиясы осы Ережелер бойынша жасалған құқық бұзушылық үшін қысқартылған іс жүргізуді бастауға құқылы. Құқық қорғау жауапкершілігі Комиссиямен (ComReg) бөліседі.
All breaches of the Privacy and Electronic Communications (EC Directive) Regulations 2003 for which the Office of the Data Protection Commissioner has responsibility are offences. The offences relate primarily to the sending of unsolicited marketing communications by electronic means. The offences are punishable by fines – up to €5,000 for each unsolicited message on summary conviction and up to €250,000 on conviction on indictment. The Office of the Data Protection Commissioner may bring summary proceedings for an offence under the Regulations. Enforcement responsibility is shared with the Commission for Communications Regulation (ComReg).