The net is closing in on data protection offenders

15th February 2023The net is closing in on data protection offenders

The net is closing in on data protection offenders.

A human rights group, The Irish Council for Civil Liberties (ICCL), has caused the European Ombudsman to create a new procedure which means that European Data Protection agencies will come under closer scrutiny from now on.

How and why is the net closing in on data protection offenders?

The reason the ICCL raised the complaint that resulted in the new procedure is that they were unhappy with the way that Ireland’s privacy regulator handled the whole Meta issue (which took many years and whose decision was eventually overturned by the European Ombudsman who increased a fine from 28 million to 390 million euros – you can read the background in a previous blog here).

Similarly, Privacy campaigner Max Schrems has indicated that he will take action against the privacy regulator in Luxembourg because they are taking too long over his complaint against Amazon.

The big tech companies are very much under fire, via the ‘local’ regulators who seem, in some instances, reticent to act against them.

The result is that the European Ombudsman is basically saying to their EU regulators – we need to keep an eye on you; we can’t and won’t be leaving you to your own devices.

What is the new procedure?

You can read the brief announcement from the European Ombudsman here.  In summary, it says that the local data protection authorities must share details of the ‘large-scale cross-border’ cases with them on a BI-MONTHLY basis.

According to the ICCL, the European Commission will now measure how long each procedural step in a case is taking and what the relevant data protection authorities are doing to progress the matter.

Dr Johnny Ryan, Senior Fellow of the ICCL, commented:

The European Commission’s new commitment should transform Europe’s data and digital enforcement. Previously, big cases lay dormant for years. Now, we should see an acceleration in investigation and enforcement, and it will be clear where the European Commission needs to take swift action against Member States that fail to apply the GDPR. This heralds the beginning of true enforcement of the GDPR and serious European enforcement against Big Tech.Irish Council for Civil Liberties

It feels like the net is closing in on organisations flouting the data protection legislation.  Whilst this procedure is aimed at substantial multi-national cases, it highlights that we must not rest on laurels – protecting personal data is under the microscope.  If you are unsure how compliant your organisation is or if you need to update your training, please get in touch.