Ooni Koda
  1. Home
  2. /
  3. Newsfeed
  4. /
  5. GDPR: Investigation Procedure

GDPR: Investigation Procedure

November 7, 2018

By Cristina BOJICA, Partner, GRUIA DUFAUT Law Office The entry into force, on 25 May 2018, of Regulation (EU) 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, has determined not only compliance efforts made by data controllers, but also the regulation of the operation of the national supervisory body, namely the National Supervisory Authority for the Processing of Personal Data (ANSPDCP), which will investigate potential violations of the specific legislation. The investigation procedure that the ANSPDCP will have to comply with has recently been published in Official Journal no. 892 of 23 October 2018.   The Investigation Procedure ANSPDCP is authorized to start surveillance and legality monitoring investigations either ex officio or as a result of a prior complaint made by any concerned persons against a data controller. Ex officio investigations may be carried out either following a notification regarding a personal data security breach or for the purpose of checking certain data and information relating to personal data processing, obtained by ANSPDCP from sources other than those referred to in the complaint. Ex officio investigations may also be conducted on the basis of notifications or information provided by another supervisory or public authority. Also, ex officio investigations may also take the form of data protection audits. Investigations following a complaint are initiated by the authority as a result of the receipt of a complaint about a potential violation of the law by a data controller. In both cases, investigations can be conducted: on site, at the headquarters of the institution, in writing or at the headquarters of the authorities/public bodies. Detailed procedures are stipulated for each type of investigation. These procedures also stipulate the rights and obligations of the entities under investigation and how penalties for the violation of data protection provisions are applied. Thus, during on-site investigations (held at the headquarters, domicile, working point of the entity under investigation or in other premises where the entity operates), the inspectors may propose: The elaboration of an expert report; That the persons whose statements are considered relevant and necessary for the purposes of the investigation be heard; The application of one of the penalties provided by the law. For this purpose, the investigation report is both a debt instrument and a payment notice. If the inspectors are prevented from carrying out the investigation, ANSPDCP may request the issuance of a judicial authorization. A copy of the judicial authorization will be notified to the audited entity before the start of the investigation and, although it may be challenged before the High Court of Cassation and Justice, the dispute does not suspend the enforcement of the judicial authorization. Police intervention may also be requested. The investigations carried out at the headquarters of the Supervisory Authority are conducted on the basis of a notice sent to the representatives of the data controller under investigation. The notice must mention the obligation of the investigated entity to send documents, relevant registers and computer equipment to ANSPDCP headquarters, depending on the purpose of the investigation. As an exception, when the evidence is deemed sufficient to finalize the investigation, the law authorizes the conclusion of the investigation/penalty report at the headquarters of the authority without convening the representatives of the audited entity. Written investigations are conducted on the basis of a letter sent by the authority to the entity under investigation, whereby the authority requests the information, data and documents needed to resolve the case under investigation. The entity under investigation is required to answer in writing and attach evidence to the said answer in compliance with the deadline set by the National Supervisory Authority. Depending on the answer, the Authority may decide to continue the investigation in writing or on site, or even to finalize the investigation, by concluding an inspection/penalty report, at the headquarters of ANSPDCP.   Penalties The main penalties applied by the National Supervisory Authority for the Processing of Personal Data are the warning and the fine. Moreover, the National Supervisory Authority may issue a warning to the investigated entity, if the controller might violate the law through the personal data processing operations it intends to perform. Penalties are applied according to the investigation/penalty report concluded by the inspectors. If the amount of the fine exceeds the Lei equivalent of 300,000 Euros, the penalty will be applied according to the decision of the President of ANSPDCP. In addition to the penalties stipulated by law, the National Supervisory Authority for the Processing of Personal Data may order other corrective measures and make recommendations. www.gruiadufaut.com    

The post GDPR: Investigation Procedure appeared first on Nine O' Clock.

The text of this article has been partially taken from the publication:
https://www.nineoclock.ro/2018/11/07/gdpr-investigation-procedure/
Read in full - click here
Romania gives EUR 240 mln for gasification of 44,000 households

The Romanian government approved on March 6 an Emergency Ordinance allocating an additional RON 1.19 billion (EUR 240 million) for the completion of projects to expand, modernize, and convert natural gas transmission and distribution networks.  This measure will allow over 44,000 households across the country to have access to natural gas, thus reducing dependence on […]

Colliers: Romania's hotel market 4% above pre-pandemic peak, but there's room to grow

Romania's hotel market is experiencing a period of accelerated growth, reaching a record of more than 25 million overnight stays in 2024, the highest level in more than 30 years, driven by a rising number of foreign tourists and strong demand for modern hotels, according to Colliers' annual report.  Romania's international visibility is increasing, and […]

ING sees 1.6% economic growth in Romania this year, highlighting geopolitical risks

In an economic update report, ING Romania said it expects 1.6% economic growth this year under the baseline scenario, however noting that "geopolitical risks cloud the outlook." "With the May elections approaching, the evolving political landscape may influence the country's direction. The decisions made in the coming months will be pivotal, steering Romania's trajectory for […]

Romania's retail sales show signs of fatigue in January

Retail sales volume in Romania increased by 4.1% y/y in January, half the 8.6% y/y advance in 2024 and the 9.2% y/y in Q4 2024, according to data published by the statistics office INS. In seasonally and workday-adjusted terms, the retail sales inched up by 0.1% m/m. The slowdown was visible in both food and non-food […]

Elon Musk questions ECHR’s role after decision in Romanian Călin Georgescu’s appeal to election annulment

Billionaire Elon Musk has questioned the role of the European Court of Human Rights (ECHR) after the court declared as inadmissible the case brought by Călin Georgescu, a former ultranationalist presidential candidate, regarding the annulment of Romania's 2024 presidential election.  Reacting on X, Musk shared a post from conservative...

The Geo-Political Reality of 2025 Surpasses All Predictions. How Does the Romanian Business Sector View H1 2025? The 12th Edition of CONFIDEX Begins

The forecasts made by managers in the second half of 2024, as expressed in the CONFIDEX study, were more pessimistic than the actual economic reality of Romania. The onset of the year, however, marked by surprising events, international geo-political tensions, and the unpredictability of the upcoming presidential elections in Romania, may heighten the caution levels […]