Article 51
Supervisory authority
(62) Whereas the establishment in Member States of supervisory authorities, exercising their functions with complete independence, is an essential component of the protection of individuals with regard to the processing of personal data;
|
Regulation
Art. 51 1. Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’). 2. Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, the supervisory authorities shall cooperate with each other and the Commission in accordance with Chapter VII. 3. Where more than one supervisory authority is established in a Member State, that Member State shall designate the supervisory authority which is to represent those authorities in the Board and shall set out the mechanism to ensure compliance by the other authorities with the rules relating to the consistency mechanism referred to in Article 63. 4. Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to this Chapter, by 25 May 2018 and, without delay, any subsequent amendment affecting them. |
Directive
Art. 28 1. Each Member State shall provide that one or more public authorities are responsible for monitoring the application within its territory of the provisions adopted by the Member States pursuant to this Directive. These authorities shall act with complete independence in exercising the functions entrusted to them. 2. Each Member State shall provide that the supervisory authorities are consulted when drawing up administrative measures or regulations relating to the protection of individuals' rights and freedoms with regard to the processing of personal data. 3. Each authority shall in particular be endowed with: - investigative powers, such as powers of access to data forming the subject-matter of processing operations and powers to collect all the information necessary for the performance of its supervisory duties, - effective powers of intervention, such as, for example, that of delivering opinions before processing operations are carried out, in accordance with Article 20, and ensuring appropriate publication of such opinions, of ordering the blocking, erasure or destruction of data, of imposing a temporary or definitive ban on processing, of warning or admonishing the controller, or that of referring the matter to national parliaments or other political institutions, - the power to engage in legal proceedings where the national provisions adopted pursuant to this Directive have been violated or to bring these violations to the attention of the judicial authorities. Decisions by the supervisory authority which give rise to complaints may be appealed against through the courts. 4. Each supervisory authority shall hear claims lodged by any person, or by an association representing that person, concerning the protection of his rights and freedoms in regard to the processing of personal data. The person concerned shall be informed of the outcome of the claim. Each supervisory authority shall, in particular, hear claims for checks on the lawfulness of data processing lodged by any person when the national provisions adopted pursuant to Article 13 of this Directive apply. The person shall at any rate be informed that a check has taken place. 5. Each supervisory authority shall draw up a report on its activities at regular intervals. The report shall be made public. 6. Each supervisory authority is competent, whatever the national law applicable to the processing in question, to exercise, on the territory of its own Member State, the powers conferred on it in accordance with paragraph 3. Each authority may be requested to exercise its powers by an authority of another Member State. The supervisory authorities shall cooperate with one another to the extent necessary for the performance of their duties, in particular by exchanging all useful information. 7. Member States shall provide that the members and staff of the supervisory authority, even after their employment has ended, are to be subject to a duty of professional secrecy with regard to confidential information to which they have access. |
Spain
Artículo 44. Disposiciones generales. 1. La Agencia Española de Protección de Datos es una autoridad administrativa independiente de ámbito estatal, de las previstas en la Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público, con personalidad jurídica y plena capacidad pública y privada, que actúa con plena independencia de los poderes públicos en el ejercicio de sus funciones. Su denominación oficial, de conformidad con lo establecido en el artículo 109.3 de la Ley 40/2015, de 1 de octubre, de Régimen Jurídico del Sector Público, será «Agencia Española de Protección de Datos, Autoridad Administrativa Independiente». Se relaciona con el Gobierno a través del Ministerio de Justicia. 2. La Agencia Española de Protección de Datos tendrá la condición de representante común de las autoridades de protección de datos del Reino de España en el Comité Europeo de Protección de Datos. 3. La Agencia Española de Protección de Datos, el Consejo General del Poder Judicial y en su caso, la Fiscalía General del Estado, colaborarán en aras del adecuado ejercicio de las respectivas competencias que la Ley Orgánica 6/1985, de 1 de julio, del Poder Judicial, les atribuye en materia de protección de datos personales en el ámbito de la Administración de Justicia.
Disposición transitoria primera. Estatuto de la Agencia Española de Protección de Datos. 1. El Estatuto de la Agencia Española de Protección de Datos, aprobado por Real Decreto 428/1993, de 26 de marzo, continuará vigente en lo que no se oponga a lo establecido en el Título VIII de esta ley orgánica. 2. Lo dispuesto en los apartados 2, 3 y 5 del artículo 48 y en el artículo 49 de esta ley orgánica se aplicará una vez expire el mandato de quien ostente la condición de Director de la Agencia Española de Protección de Datos a la entrada en vigor de la misma. Artículo 57. Autoridades autonómicas de protección de datos. 1. Las autoridades autonómicas de protección de datos personales podrán ejercer, las funciones y potestades establecidas en los artículos 57 y 58 del Reglamento (UE) 2016/679, de acuerdo con la normativa autonómica, cuando se refieran a: a) Tratamientos de los que sean responsables las entidades integrantes del sector público de la correspondiente Comunidad Autónoma o de las Entidades Locales incluidas en su ámbito territorial o quienes presten servicios a través de cualquier forma de gestión directa o indirecta. b) Tratamientos llevados a cabo por personas físicas o jurídicas para el ejercicio de las funciones públicas en materias que sean competencia de la correspondiente Administración Autonómica o Local. c) Tratamientos que se encuentren expresamente previstos, en su caso, en los respectivos Estatutos de Autonomía. 2. Las autoridades autonómicas de protección de datos podrán dictar, en relación con los tratamientos sometidos a su competencia, circulares con el alcance y los efectos establecidos para la Agencia Española de Protección de Datos en el artículo 55 de esta ley orgánica.
Artículo 58. Cooperación institucional. La Presidencia de la Agencia Española de Protección de Datos convocará, por iniciativa propia o cuando lo solicite otra autoridad, a las autoridades autonómicas de protección de datos para contribuir a la aplicación coherente del Reglamento (UE) 2016/679 y de la presente ley orgánica. En todo caso, se celebrarán reuniones semestrales de cooperación. La Presidencia de la Agencia Española de Protección de Datos y las autoridades autonómicas de protección de datos podrán solicitar y deberán intercambiarse mutuamente la información necesaria para el cumplimiento de sus funciones y, en particular, la relativa a la actividad del Comité Europeo de Protección de Datos. Asimismo, podrán constituir grupos de trabajo para tratar asuntos específicos de interés común. --- Article 44. General Provisions. 1. The Spanish Data Protection Agency is an independent administrative authority of state scope, of those provided for in Law 40/2015, of October 1, on the Legal Regime of the Public Sector, with legal personality and full public and private capacity, which acts with full independence from the public authorities in the exercise of its functions.
Its official name, in accordance with the provisions of Article 109.3 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, shall be "Spanish Data Protection Agency, Independent Administrative Authority". It relates to the Government through the Ministry of Justice. 2. The Spanish Data Protection Agency shall be the common representative of the data protection authorities of the Kingdom of Spain in the European Data Protection Committee. 3. The Spanish Data Protection Agency and the General Council of the Judiciary shall collaborate for the proper exercise of the respective competences that the Organic Law 6/1985, of July 1, 1985, of the Judiciary, attributes to them in matters of personal data protection within the scope of the Administration of Justice.
First Transitory Provision. Statute of the Spanish Data Protection Agency. 1. The Statute of the Spanish Data Protection Agency, approved by Royal Decree 428/1993, of March 26, 1993, shall remain in force insofar as it does not oppose the provisions of Title VIII of this Organic Law. 2. The provisions of paragraphs 2, 3 and 5 of Article 48 and Article 49 of this Organic Law shall apply once the term of office of the person holding the position of Director of the Spanish Data Protection Agency on the entry into force of the same has expired.
Article 57. Autonomous data protection authorities. 1. The autonomous authorities for the protection of personal data may exercise, the functions and powers established in Articles 57 and 58 of Regulation (EU) 2016/679, in accordance with the autonomous regulations, when they relate to: a) Treatment for which the entities forming part of the public sector of the corresponding Autonomous Community or of the Local Entities included in its territorial scope or those who provide services through any form of direct or indirect management are responsible. b) Treatments carried out by individuals or legal entities for the exercise of public functions in matters within the competence of the corresponding Autonomous or Local Administration.
c) Treatments that are expressly provided for, where appropriate, in the respective Statutes of Autonomy. 2. The autonomous data protection authorities may issue, in relation to the processing operations under their jurisdiction, circulars with the scope and effects of the processing operations. established for the Spanish Data Protection Agency in Article 55 of this Organic Law.
Article 58. Institutional cooperation. The Presidency of the Spanish Data Protection Agency will convene, on its own initiative or when requested by another authority, the autonomous data protection authorities to contribute to the consistent application of Regulation (EU) 2016/679 and this Organic Law. In any case, bi-annual cooperation meetings shall be held. The Presidency of the Spanish Data Protection Agency and the regional data protection authorities may request and must mutually exchange the information necessary for the fulfillment of their functions and, in particular, that relating to the activity of the European Data Protection Committee. Likewise, they may set up working groups to deal with specific matters of common interest. |
