MALTA Trends and Developments Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates
ments: at one instance it had reassured the com - plainant that it had provided him with all the per - sonal data it had, while on the other hand it was unable to divulge internal communications that contained his personal data. In its decision the Commissioner noted the following: in its response to the complainant, the controller failed to mention that it was only providing partial access and therefore such response lacked the necessary elements of transparency and fairness, and only after further questioning did the controller reveal that this was a partial access. The Commissioner concluded that the manner in which the controller handled the request by the complainant went against the principles of fairness and transparency as set forth in Article 5(1)(a) of the GDPR. Furthermore, upon investigation into the control - ler’s reasons for not sharing internal communica - tions that held personal data of the complain - ant – namely, to protect its employees who are bound by the professional secrecy laws – the Commissioner pointed out correctly that this internal correspondence pertained to the com - plainant within the context of a complaint lodged with the Office of the Arbiter for Financial Ser - vices case, and that the professional secrecy laws should not hinder the complainant from accessing his own personal data relating to a case that was res judicata at the time of receipt of the complainant’s access request. In its final decision, the Commissioner conclud - ed that the controller had failed to inform the complainant of the limitation invoked pursuant to Article 15(4) of the GDPR, and that the nec - essary elements of transparency and fairness as set under Article 5(1) of the GDPR were also breached. As a compromise, the Commissioner stated that in order to protect the bank’s employ -
ee’s internal communications, it could have shared such communications with any contact details, such as names, email addresses, etc, redacted and omitted before sharing. The Com - missioner ordered that such personal data be shared with the complainant as requested. Right to erasure (the right to be forgotten) The right to erasure as established under Arti - cle 17 of the GDPR was another basis of data protection complaints to the IDPC. In one deci - sion regarding this, the complainant requested the erasure of his personal data from an insur - ance company (the controller). The complainant had shared his personal data when requesting a quote for car insurance. However, having not received a quote, the complainant requested the insurance company delete the personal data he had previously shared when requesting a quote. The controller refused to erase such data, claim - ing it was obliged by insurance law to retain such data for a specific period of time. When investigating the case, the IDPC asked the controller which law obliged it to retain such data, to which the controller responded that there was no specific law except for that found under the GDPR, where a controller can retain personal data for up to five years. The Commis - sioner noted that, on the contrary, the GDPR does not impose such a legal obligation and in fact advocates for data minimisation (Article 5(1) (c)); therefore, the controller could not rely on this derogation from erasure found under Article 17(3)(b). The controller also stated that it was not obliged to erase such personal data because of its need to exercise a defence of legal claims, as under - pinned by Article 17(3)(e). The Commissioner established that such a defence cannot be a hypothetical – it must be proved that retaining
317 CHAMBERS.COM
Powered by FlippingBook