Subject matter and scope
1. This Decision provides rules and procedures for the application of Regulation (EU) 2018/1725 by the Commission, and sets out implementing rules concerning the Data Protection Officer for the Commission (‘DPO’).
2. This Decision also lays down the rules to be followed by the Commission, in relation to the monitoring, investigative, auditing or consultative tasks of the DPO, to inform data subjects of the processing of their personal data in accordance with Articles 14, 15 and 16 of Regulation (EU) 2018/1725.
3. This Decision also lays down the conditions under which the Commission, in relation to the monitoring, investigative, auditing or consultative tasks of the DPO, may restrict the application of Articles 4, 14 to 17, 19, 20 and 35 of Regulation (EU) 2018/1725, in accordance with Article 25(1)(c), (g) and (h) thereof.
4. This Decision applies to the processing of personal data by the Commission for the purpose of or in relation to the tasks of the DPO referred to in Article 45 of Regulation (EU) 2018/1725, in particular the monitoring, investigative, auditing and consultative tasks of the DPO.
Controllership
For the purposes of this Decision, the Commission shall be considered to be the controller within the meaning of Article 3(8) of Regulation (EU) 2018/1725.
Definitions
For the purpose of this Decision, the following definitions apply:
(1)
‘Data Protection Officer’ (DPO) means the person whom the Commission has designated pursuant to Article 43 of Regulation (EU) 2018/1725;
(2)
‘DPO tasks’ means the DPO tasks referred to in Article 45 of Regulation (EU) 2018/1725, in particular the monitoring, investigative, auditing and consultative tasks of the DPO;
(3)
‘Data Protection Coordinator’ (DPC) means the Commission staff member whom a Directorate-General or Service of the Commission appointed to advise and assist that Directorate-General or Service in all aspects of the protection of personal data;
(4)
‘delegated controller’ means the Head of the Directorate-General, Service or Cabinet, which carries out a processing operation on behalf of the Commission in fulfilment of the mission of that Directorate-General, Service or Cabinet;
(5)
‘operational controller’ means the Commission staff member of middle or senior management level, designated by the delegated controller to ensure record keeping for the processing operation and to serve as primary contact point for data subjects in relation to that processing operation;
(6)
‘internal arrangement’ means any arrangement between two or more Directorates-General or Services to determine their respective responsibilities and coordinate the keeping of a record of processing regarding a processing operation which they carry out jointly or where one or more Directorates-General or Services carry out a part of the delegated controller’s processing operation;
(7)
‘informant’ means an individual who brings a matter alleging that a breach of the provisions of Regulation (EU) 2018/1725 has taken place to the attention of the DPO, or requests that the DPO investigate matters and occurrences directly relating to the DPO’s tasks, which that individual brings to the DPO’s notice.