Commission Decision
of 5 June 2014
on the protection of personal data in the European e-Justice Portal
(2014/333/EU)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
After consulting the European Data Protection Supervisor,
Whereas:
The Portal's objective is to contribute to the achievement of the European judicial area by facilitating and enhancing access to justice and leveraging information and communication technologies to facilitate cross-border electronic judicial proceedings and judicial cooperation.
The institutions, bodies, offices and agencies of the European Union as well as the Member States when they are implementing Union law must respect fundamental rights and observe the principles recognised by the Charter of Fundamental Rights of the European Union, in particular the right to the protection of personal data stipulated in Article 8 of that Charter.
Since the various Portal-related tasks and functions of the Commission and the Member States will entail different responsibilities and obligations as regards data protection, it is essential to delimit them clearly.
In accordance with the specific nature of activities linked to the e-Justice Portal, developed in cooperation between the Commission and the Member States, the role of the Commission in processing personal data through the Portal is limited. It should be clarified that the Commission has no responsibility for the content of interconnected national databases made available through the Portal.
In accordance with Regulation (EC) No 45/2001 the purposes of processing of personal data should be explicitly specified. Therefore, the processing of personal data by the Commission in the portal should only take place if it is done to provide access to interconnected national databases holding personal data, to provide interactive services allowing users to communicate directly with the appropriate authorities in another Member State, to provide access to public information targeted towards registered users, or to provide contact information.
The Commission should embed in the system technologies that reflect the concept of ‘data protection by design’. In implementing that concept, a privacy and data protection impact assessment should be carried out during the design phase of the functionality associated with the processing of personal data through the Portal, as well as of other Portal functionalities. That assessment will identify the potential data protection risks involved. It will also define the appropriate measures and safeguards to be incorporated in the system to protect personal data.
The Commission should perform continuous and appropriate security assessments insofar as work related to the interconnection of national databases is carried out.
Only publicly available information in the interconnected national databases can be accessed through the Portal. It should not be possible to combine information from different interconnected national databases for different purposes through the Portal,
HAS ADOPTED THIS DECISION: