23 March 2020Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The European Data Protection Board (EDPB) has issued an important statement on matters such as the processing of personal health data in particular and the processing of data necessary for employment during the coronavirus (COVID-19) pandemic. In my view it is an entirely sound opinion and one that is in keeping with the law. For our country too, it is capable of answering the questions raised in recent days, particularly about the processing of personal health data.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

STATEMENT ON THE PROCESSING OF PERSONAL DATA IN THE CONTEXT OF THE COVID-19 OUTBREAK

On 19 March 2020 the European Data Protection Board adopted the following statement:

Governments and public and private organisations in Europe are taking measures to contain COVID-19. In the context of these measures, different types of personal data may be processed.

Data protection rules (such as the GDPR) do not hinder the measures taken in the fight against the coronavirus pandemic. The fight against communicable diseases is a valuable goal shared by all nations and should therefore be supported in the best possible way. It is in the interest of humanity to curb the spread of diseases and to use modern techniques in the fight against scourges affecting great parts of the world. Even so, the European Data Protection Board would like to underline that, even in these exceptional times, the controller and the processor must ensure the protection of the personal data of data subjects.

Therefore, a number of considerations should be taken into account in order to guarantee the lawful processing of personal data, and it should be borne in mind that in all cases any measure taken must comply with the general principles of law and must not be irreversible. An emergency is a legal condition which may legitimise restrictions of freedoms, provided that these restrictions are proportionate and limited to the emergency.

1. Lawfulness of Processing

The GDPR is a broad piece of legislation and also provides for rules that apply to the processing of personal data in situations such as COVID-19. The GDPR allows public health authorities and employers to process personal data in the context of an epidemic, in accordance with national law and within the conditions set therein. For example, where processing is necessary for reasons of substantial public interest in the area of public health. Under those circumstances, there is no need to rely on the explicit consent of data subjects.

1.1 With regard to the processing of personal data, including special categories of data, by public authorities (e.g. public health authorities), the European Data Protection Board considers that Articles 6 and 9 of the GDPR enable the processing of personal data where it falls under the legal mandate of the public authority (in particular as provided by national legislation and the conditions laid down in the GDPR).

1.2. In the employment context, the processing of personal data may be necessary for compliance with a legal obligation to which the employer is subject (such as obligations relating to health and safety) or for the public interest (the control of diseases and other threats to health).

The GDPR also foresees, on the basis of Union or national law, (Article 9(2)(c)) derogations from the rules prohibiting the processing of special categories of personal data, such as health data, for reasons of public interest in so far as it is substantial in the area of public health (Article 9(2)(i)) or where the vital interests of the data subject need to be protected (recital 46 explicitly refers to the control of an epidemic).

1.3 With regard to the processing of telecommunications data, such as location data, the national laws implementing the ePrivacy Directive must also be complied with. In principle, location data can be used by the operator only when made anonymous or with the consent of the individuals concerned. However, Article 15 of the ePrivacy Directive enables Member States to introduce legislative measures to safeguard public security.

Such exceptional legislation is possible only if it constitutes a necessary, appropriate and proportionate measure within a democratic society. These measures must be in accordance with the European Charter of Fundamental Rights and the European Convention on Human Rights, and the measures taken are also subject to the review of the European Court of Human Rights. These measures, taken in an emergency, must remain limited to the duration of the emergency.

2. Core principles relating to the processing of personal data

Personal data that are necessary to attain the objectives pursued should be processed for specified and explicit purposes.

In addition, data subjects should receive transparent information on the processing activities carried out and their main features, including the retention period for the data collected and the purposes of the processing; this information should be easily accessible and provided in clear and plain language.

Adequate security measures preventing the disclosure of personal data to unauthorised persons should be taken and confidentiality policies adopted. The measures taken to manage the current emergency and the decision-making process should be appropriately documented.

3. Use of mobile location data

• Can Member State governments use personal data relating to individuals’ mobile phones in order to monitor, contain or mitigate the spread of COVID-19?

In some Member States, governments envisage using mobile location data as a possible way to monitor, contain or mitigate the spread of COVID-19. This means, for example, geolocating individuals or sending public health messages by telephone or text message to persons in a specific area. Public authorities should first seek to process location data in an anonymous way (that is, to process data aggregated in such a way that individuals cannot be re-identified), in a manner that could enable reports to be generated on the gathering/concentration of mobile devices at a certain location (“cartography”).

Personal data protection rules do not apply to data that have been appropriately anonymised.

Where it is not possible to process only anonymous data, the ePrivacy Directive enables Member States to introduce legislative measures to safeguard public security (Article 15).

If measures allowing for the processing of non-anonymised location data are introduced, a Member State is obliged to put in place adequate safeguards, such as granting the individuals to whom electronic communication services are provided the right to a judicial remedy.

The principle of proportionality also applies. The least intrusive solutions should always be preferred, taking into account the specific purpose to be achieved. Invasive/intrusive measures such as the “tracking” of individuals (e.g. the processing of non-anonymised location data) can be regarded as proportionate only under exceptional circumstances and depending on the concrete modalities of the processing.

However, all of this should be subject to scrutiny and safeguards in order to ensure respect for the data protection principles (proportionality of the measure in terms of duration and scope, limited data retention and purpose limitation).

4. Employment

• Can an employer require visitors or employees to provide specific health information in the context of COVID-19?

The application of the principles of proportionality and data minimisation is particularly important here. The employer should require health information only to the extent that national law allows it.

• Is an employer allowed to carry out medical checks on employees?

The answer depends on national laws relating to employment or to health and safety. Employers should access and process health data only if their own legal obligations require it.

• Can an employer disclose to an employee’s colleagues or to persons other than these that the employee has been infected with COVID-19?

Employers should inform staff about COVID-19 cases and take protective measures, but should not communicate more information than necessary. Where national law allows it and disclosure is necessary, the dignity and integrity of the employees concerned will be protected if they are informed in advance.

• What information processed in the context of COVID-19 can be obtained by employers?

Employers may obtain personal information in order to fulfil their duties and to organise work in accordance with national legislation.

For the European Data Protection Board

Member

Andrea Jelinek

For the original text of this statement, see: https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_statement_2020_processingperson aldataandcovid-19_en.pdf

Download PDF (in Turkish)

Related publications