TL;DR for the DPO
The CNPD writes that verifying the Article 28(3) requirements must be SUBSTANTIVE and not formal, and cannot be reduced to picking some standard set of clauses. That sentence is worth the fine: signing the supplier's DPA without reading it is not compliance, it is documentary proof of the opposite.
The five findings
- Unlawful processing of health and religious data: the questionnaire did not make clear that those answers were optional, so people could not form an informed will.
- Breach of the information duties towards those answering the questionnaire.
- Breach of the duty of diligence in selecting the processor.
- Breach of the rules on international transfers, Articles 44 and 46(2).
- Failure to carry out a data protection impact assessment for the census operation as a whole.
The Article 28 point
INE entrusted the infrastructure to a supplier that had an office in Lisbon. The contract, however, was concluded with the company established in the United States, and provided that the court competent for disputes was the California court. The same contract allowed personal data to transit through any of the company's two hundred servers, expressly anticipating that data could be processed outside the European Economic Area.
The clauses were there. They were not enough.
The contract included the standard contractual clauses approved by the Commission for transfers to the United States. The CNPD still found a breach of Articles 44 and 46(2), because no supplementary measure was provided to prevent access to the data by government bodies of the third country, as Schrems II requires. It is precisely the logical leap you see everywhere: attach the clauses and consider the matter closed, without assessing the legal context of the destination.
What had happened before
During the census, after receiving several complaints, the CNPD opened an inquiry and ordered the immediate suspension of transfers of census data to the United States and other third countries lacking an adequate level of protection. The case closed only with the final decision, which imposed a single cumulative fine for the five infringements.
What to do now, across your clients
1) For every supplier in the processor register, check which legal entity signed the contract, not which office answers the phone. A European office is not enough if the contracting counterparty is outside the EU. 2) Read the jurisdiction clause: if it points to a non-EU court, ask yourself how you intend to enforce the Article 28 obligations on the day you need to. 3) If the contract allows data to transit unspecified infrastructure, that is a transfer and must be assessed, not ignored. 4) Standard contractual clauses are the starting point of the assessment, never the end of it: without documented supplementary measures, Article 46 is not satisfied. 5) Document the Article 28(3) verification with evidence and a date: it is the only way to show it was substantive.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free