PWC: The Personal Data Protection Authority imposed its first fine under the General Data Protection Regulation (GDPR)
According to the Authority, the case came before it following a complaint by the Association of Accountants and Auditors of the Attica Region ("ELEPA") against the company "PWC" for illegal processing of the personal data of its employees
It is even impressive that the PWC company held seminars regarding GDPR, as we can see here.
As specifically mentioned in the complaint, the managers of the reported company forced its staff to sign a «Statement of Acceptance of Personal Data Processing Terms» as well as new individual agreements (attached to the complaint), which contained clauses referring to the processing of personal data, demanding that they sign them, in violation of Law 2472/1997, taking advantage of the employer’s superior position over the employees, so that they were immediately forced to sign them.

As specifically mentioned in this complaint,
a) the specific statement requested the staff to give their consent and to explicitly and unconditionally allow the company to register and use their personal information, both those already registered and those in the future, in the databases it maintains, although the nature of the company's business activities does not provide any security reason that would make such registration and processing of employees' personal data acceptable.
b) employees were asked to agree with this statement for the further funneling of their personal data to third parties as well as to the company's clients, essentially requesting in writing the employees' consent to use and disclose their personal information to any third party, in any manner deemed to serve the company's business interests
c) in this way, further monitoring of them in the workplace is also initiated, such as with cameras , etc.

The Authority ruled that in order for personal data to be lawfully processed, i.e., processing in accordance with the requirements of the General Data Protection Regulation (GDPR) under No. 679/2016, the cumulative conditions for implementation and adherence to the principles of Article 5 paragraph 1 GDPR must be met.
The identification and selection of the appropriate legal basis from those provided for in Article 6(1) GDPR is closely linked to the principle of fair or equitable processing as well as to the principle of purpose limitation, and the controller must not only select the appropriate legal basis before the start of processing, internally documenting this choice in application of the principle of accountability, but also inform the data subject of its use, in accordance with Articles 13(1)(c) and 14(1)(c) GDPR, as the selection of each legal basis has a legal impact on the application of the rights of the subjects.
The central dimension of the compliance model adopted by the GDPR constitutes the principle of accountability within which the data controller must take the necessary compliance measures towards the principles of Article 5(1) GDPR and must demonstrate them on its own without even requiring the Authority, in the framework of exercising its research – supervisory powers, to submit specific – specialized queries and requests for verification of compliance.

It is noted that the Authority, because the first period of GDPR implementation is underway, submits specialized questions and requests within the exercise of related investigative – supervisory powers so as to facilitate the documentation of accountability by the data controllers.
The principles of lawful, legitimate (or fair) and transparent processing of personal data pursuant to Art. 5 para. 1 point a’ GDPR require the choice of consent as a legal basis pursuant to Art. 6 para. 1 GDPR only insofar as the other legal bases do not apply, so that after the initial choice it becomes impossible to change and switch to another legal basis. In the case where the data subject withdraws his consent, the continuation of processing personal data under another legal basis is not permitted.
When the legal basis of consent is correctly applied, in the sense that no other legal basis is applicable, the failure to provide or the withdrawal of it is equivalent to an absolute prohibition of processing personal data.
The consent of data subjects in the context of employment relationships cannot be considered free due to the inherent inequality of the parties. In this case, the choice of the legal basis for consent was incorrect as the processing of personal data was aimed at carrying out operations directly related to the performance of the employment contract, compliance with statutory obligations and the smooth and efficient operation of the enterprise.
Additionally, the company created a false impression among employees that it processes their personal data under’ the application of the legal basis of consent, while in reality it processed them under another legal basis, which the employees were never informed about, in violation of the principle of transparency and consequently in breach of the information obligation under’ article 13 paragraph 1 point γ’ and article 14 paragraph 1 point γ’ GDPR.

In cases where the data controller has doubts about the legality of the processing, they must lift those doubts before processing or refrain from processing until the doubts are cleared.
Finally, the Authority found in this case a violation by the controller of the principle of accountability under Article 5(2) of the GDPR, as, on the one hand, the company did not comply with its relevant obligation and in particular with the Authority's request to provide internal documentation of the choice of legal basis it applied.
Furthermore, the company transferred its compliance obligations to the employees, asking them to sign a statement according to which they acknowledge that the personal data it maintains and processes are directly related to the needs of the employment relationship and work organization, and that they also acknowledge that they are relevant and appropriate within the framework of the employment relationship and work organization.
In view of the above, the Authority concluded that the company PWC BS, as the data controller:
i. submitted to unlawful processing in violation of the provisions of article 5 para. 1 sec. a’ subpara. a’ GDPR the personal data of its employees as it applied an inappropriate legal basis.
ii. υπέβαλε σε μη θεμιτή και χωρίς διαφανή τρόπο κατά παράβαση των διατάξεων του άρθρου 5 παρ. 1 εδ. α’ περ. β’ και γ’ ΓΚΠΔ τα δεδομένα προσωπικού χαρακτήρα των εργαζομένων της καθώς τους δημιούργησε την εσφαλμένη εντύπωση ότι τα επεξεργάζεται κατ’ εφαρμογή της νομικής βάσης της συγκατάθεσης κατ’ αρ. 6 παρ. 1 εδ. α’ ΓΚΠΔ, ενώ στην πραγματικότητα τα επεξεργάσθηκε με άλλη νομική βάση, για την οποία ουδέποτε ενημερώθηκαν οι εργαζόμενοι.
iii. as the data controller, although it bore the responsibility, it was not in a position to demonstrate compliance with paragraph 1 of article 5 GDPR, as well as that it violated the accountability principle provided for by the provision of article 5 paragraph 2 GDPR, by transferring the burden of proof of compliance to the data subjects.
Following this, the Authority ruled that the examination of the remaining principles of Article 5 paragraph 1 point a’ GDPR is omitted, as well as the review of any other processing action subsequent to the illegal collection of personal data.

After the detection of GDPR violations, the Authority decided, under article 58 paragraph 2 of the GDPR, to exercise its corrective powers in this specific case by imposing corrective measures and decided to issue an order to the company as data controller within three (3) months:
– to make the processing activities of personal data of its employees, as described in the submitted Annex I, compliant with the provisions of the GDPR,
– to restore the proper application of the provisions of Article 5 paragraph 1 section a’ and paragraph 2 in conjunction with Article 6 paragraph 1 of the Criminal Code according to the findings in the reasoning of the decision,
– to subsequently restore and correctly apply the remaining provisions of Article 5 paragraph 1 point b-subsection’ GDPR to the extent that the identified violation affects the internal organization and compliance with the provisions of the GDPR, taking every necessary measure within the framework of the principle of accountability.
Furthermore, because the above corrective measure is not sufficient on its own to restore compliance with the breached provisions of the GDPR, the Authority concluded that in this specific case, based on the circumstances that were found, an additional and effective, proportionate and deterrent administrative monetary fine under’ the provision of article 58 paragraph 2 of the GDPR, θ’ GDPR should be imposed, which amounts to one hundred fifty thousand (150,000.00) euros, taking into account the published financial statements of the company for the period from 01-7-2017 to 20-6-2018 according to which the net turnover amounted to 41,936,426.00 euros.
Source: www.lawspot.gr
