Spanish Data Protection Agency
The Spanish Data Protection Agency (Spanish: Agencia Española de Protección de Datos, AEPD) is an agency of the government of Spain.
Legal basis and foundation
The AEPD was established by Royal Decree 428/1993 of 26 March, as amended by Organic Law 15/1999 on the Protection of Personal Data. This amendment implemented Directive 95/46/EC.[1] The agency was created in the context of the Spanish Constitution of 1978, Article 18.4, stating that "the law shall restrict the use of informatics in order to protect the honour and the personal and family privacy of Spanish citizens, as well as the full exercise of their rights",[2] as elaborated by Organic Law 5/1992.[1]
Self-description of major activities
According to the agency, it is a public law authority enjoying "absolute independence from the Public Administration", responsible for the following actions:[3]
- Information awareness about its activities and the right to protection of personal data (including 450 interviews and 850 'impacts' on media).
- Direct assistance in response to citizen queries (47,741 in 2007).
- Procedures to protect rights of individuals to access, rectify, cancel, and object. Most common are processes to cancel (62%) and access (32%).
- Registry of filing systems (1,,017,266 total entries)
- Inspection and sanction procedures (399 sanction procedures resolved with €19.6 million in fines)
- Advocacy leading to Royal Decree 1720/2007.
- Cooperation with international agencies and those of the Autonomous Communities of Catalonia, the Basque Country, and Madrid.
- Evaluation of emerging risks, including personal data on the Internet, generalisation of video surveillance systems, employer monitoring of labor by video surveillance, biometrics, and Internet usage, and intensification of international data flows.
In response to the latter point, the AEPD advocated:[3]
- "Developing procedures allowing copyright protection in a manner compatible with the fundamental right to data protection"
- "Regulating the anonymized publication of judgements passed by Courts of Law;"
- "Regulating internal whistleblowing systems available to workers within companies, outlining the activities in which it may be necessary to establish these systems and guaranteeing the confidentiality of those reporting and the rights of those being reported on;"
- "Development of specific public policy plans for the protection of minors on the Internet;"
- "Increased caution in order to prevent the undesirable exchange of sensitive personal data on the Internet via P2P networks;"
- "Fostering of self-regulation among the media to guarantee privacy and the protection of personal data, by encouraging more respect for the usage in relation to the data protection provisions;
- "Citizen guideline actions regarding the use of guarantees of confidentiality for the recipients of emails;"
- "Plan for the Fostering of Good Practices in terms of guaranteeing privacy in Official Gazettes and Journals, by adopting measures that, without affecting their purpose, will limit the gathering of personal information by Internet search engines;"
- "Local Strategy aimed at conforming the installation of traffic control cameras to the provisions on the protection of personal data."
Notable cases
The AEPD has had the authority to conduct anti-spam investigations since 2004, working with agencies such as the United States Federal Trade Commission.[4][5]
The AEPD has come into conflict with Google over information gathered from Wi-Fi networks as Google Street View images were taken, asserting that "it has been verified that data on the location of wifi networks, with the identification of their owners, and personal data of a diverse nature in communications, such as names and surnames, messages associated with such accounts and message services, or users codes or passwords among others" had been collected.[6][7] It has also demanded the removal of approximately 90 names from search results, claiming a "right to be forgotten".[8] Google is contesting both actions.
References
- ^ a b "Spain - Data Protection". Privireal. http://www.privireal.org/content/dp/spain.php.
- ^ See española de 1978: 03#Art_18 Wikisource for Spanish Constitution of 1978
- ^ a b "Spanish Data Protection Agency". Spanish Data Protection Agency. http://www.agpd.es/portalwebAGPD/canaldocumentacion/publicaciones/common/pdfs/AEPD_en.pdf.
- ^ "FTC, Spanish Data Protection Agency Working Together to Fight Illegal Spam". FTC. 2005-02-24. http://www.ftc.gov/opa/2005/02/spainspam.shtm.
- ^ "INTERNET LAW - The Spanish Data Protection Agency imposes a fine on a law firm for spam". Internet Business Law Services. http://www.ibls.com/internet_law_news_portal_view.aspx?id=1607&s=latestnews.
- ^ "Spanish Data Protection Agency moving against Google". Typically Spanish. 2010-10-18. http://www.typicallyspanish.com/news/publish/article_27554.shtml.
- ^ "Spanish DPA opens infringement procedures for Google Streetview". EDRI. 2010-10-20. http://www.edri.org/edrigram/number8.20/spanish-dpa-streetview-infringement.
- ^ Ciaron Giles (2011-04-20). "Internet 'Right to be Forgotten' debate hits Spain". Associated Press. http://hosted2.ap.org/txdam/633c954da7d9434f9de7ed15f38075aa/Article_2011-04-20-EU-Internet-Right-To-Be-Forgotten/id-f3b7262c8ea54809b5c05050ea992d4a.
External links