The right to delete data, the possibility for citizens to seek compensation for material and non-material damage due to unlawful data processing, and fines of up to two million euros are just some of the novelties of the new regulations in the field of personal data protection.
On August 7, the Government adopted the Draft Law on the Protection of Personal Data and submitted it to the Parliament, with the suggestion that it be adopted as a matter of urgency.
The proposal stipulates that personal data must be “processed lawfully, fairly and transparently in relation to the data subject”, but also collected for specified and legitimate purposes and limited to what is necessary for that purpose.
The data controller, according to the Proposal, is responsible for complying with these rules and “must be able to demonstrate such compliance”.
When processing is based on consent, the draft regulation provides for the right of citizens to withdraw it at any time.
"Withdrawing consent must be as simple as giving it," the Bill states.
Special categories of data include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, as well as genetic, biometric and health data, and data concerning sex life or sexual orientation. Their processing is generally prohibited, except in cases prescribed by law.
However, the possibility of restricting certain rights of citizens when necessary for the sake of national security, defense and public safety is left.
“Right to be forgotten”
The proposal introduces a separate “right to erasure”, or “right to be forgotten”.
A citizen may request the deletion of personal data when it is no longer necessary for the purpose for which it was collected, when he withdraws his consent and there is no other legal basis for the processing, when he files an appropriate objection, or when the data has been processed unlawfully.
If the controller has made the data publicly available, he is obliged, taking into account available technology and costs, to take reasonable measures to inform other controllers that deletion of links, copies or reproduction of those data has been requested.
The right to be forgotten, however, is not absolute.
The draft law stipulates that erasure does not apply when processing is necessary "for the exercise of the right to freedom of expression and information", for the performance of a legal obligation or a task carried out in the public interest, for the protection of public health, for archiving, scientific or historical research, or for the establishment and defense of legal claims.
Damage compensation is obtained in court.
The draft law stipulates that “a person who has suffered material or non-material damage due to a violation of the provisions of this law has the right to compensation from the controller or processor.” If multiple responsible entities participated in the same processing, each of them may be liable for the entire damage, in order to ensure full compensation for the injured party.
"The right to compensation for damage is exercised before the competent court, in accordance with the law," the Bill states.
Protection is also provided for persons who report violations of the law. The competent authority, controller and processor are obliged to establish mechanisms for confidential reporting, and “a person who in good faith reports a violation of this law to the Agency, competent authority or other authorized entity shall not be exposed to any form of retaliation or discrimination for such a report”.
If the data is procured…
The controller and processor must implement technical and organizational measures appropriate to the risk and protect data against destruction, loss, alteration, unauthorized disclosure or access.
In the event of a data security breach, the controller is obliged to notify the supervisory authority - the Agency for Personal Data Protection and Free Access to Information "without undue delay", and where possible no later than 72 hours after becoming aware of the breach.
If the breach poses a high risk to the rights and freedoms of natural persons, the controller must also notify the person whose data has been compromised without undue delay.
When a certain type of processing, in particular with the use of new technologies, may result in a high risk to the rights and freedoms of citizens, the controller must conduct a data protection impact assessment before commencing the processing.
The assessment must contain a description of the planned processing, an assessment of its necessity and proportionality, the risks to citizens and measures to mitigate those risks.
Knowledge to protect data, but not free access to information
The draft regulation defines the Agency as an independent supervisory body, which monitors and ensures the implementation of the law, provides advice and opinions, acts on requests for the protection of rights and complaints, conducts supervision and cooperates with other supervisory bodies.
Although the same Agency also takes into account the implementation of the Law on Free Access to Information, it does not see this in the conditions for the selection of Council members and directors, because the proposal stipulates that they must have experience only in the field of personal data protection.
The Agency Council, according to the proposed text of the law, consists of a president and two members, elected and dismissed by the Parliament of Montenegro, upon the proposal of the competent parliamentary committee. Their mandate lasts five years, and the same person cannot be appointed more than twice.
The president or member of the Council must have Montenegrin citizenship, a four-year university degree, at least seven years of work experience and “professional knowledge and experience in the field of personal data protection”.
A member of the Council may not be appointed as a member of the Council by a deputy, councilor, member of the Government, a person who performs a function to which he or she was appointed or appointed by the Government, or an official of a political party. The President and a member of the Council may not have been convicted by a final judgment for a criminal offense for which prosecution is undertaken ex officio, regardless of the sanction imposed. They may not be spouses of a deputy, councilor, member of the executive branch, or a person appointed by the Government…
The Director of the Agency is appointed by the Council based on a public competition, also for a period of five years.
The candidate must have Montenegrin citizenship, a four-year law degree, at least five years of work experience with an appropriate level of qualification and at least three years of experience in management positions, as well as professional knowledge and experience in the field of personal data protection. The same restrictions apply to him as to the members of the Council.
Two types of sanctions, ranging from 150 to two million euros
The draft law provides for administrative and misdemeanor fines. Administrative fines are imposed by the Agency on companies, and the amount depends on the nature, severity and duration of the violation, as well as the number of persons to whom the data relates and the damage suffered. It takes into account whether the violation of rights was committed intentionally or through negligence, as well as which categories of personal data are affected by it…
This type of fine can be imposed, among other things, if companies fail to apply the basic principles of personal data processing, including the conditions for consent, or unlawfully transfer data to a third country or international organization. The penalty for these violations is up to two million euros.
The same sanction is also foreseen for "violation of the obligation to cooperate with the Agency or failure to act in accordance with an act of the Agency", as well as for failure to act in accordance with an order on temporary or permanent restriction of processing or suspension of data exchange issued by the Agency. The proposal also stipulates that an administrative fine shall not be imposed on a state body, state administration body, local self-government body, public institution...
Legal entities may also be subject to misdemeanor sanctions ranging from 150 to 2.000 euros. This applies to cases where a breach of personal data security is not reported to the Agency within 72 hours, professional secrecy is not maintained, an inspector is not provided with access to data collections, documentation, premises and electronic processing equipment, or mechanisms for confidential reporting of violations of the law are not established. For the same misdemeanors, a responsible person in a legal entity may be fined from 20 to 200 euros, an entrepreneur from 50 to 400 euros, and a natural person from 20 to 200 euros.
See more:
Download the app and follow the news
FOLLOW US ON