info@josefelgueroso.com
2023-09-29
The Court of Justice of the European Union (the "European Court") held that a bank customer was entitled to information about the nature, frequency, and purpose of the bank's access to his personal data, but it also held that the customer was not entitled to know the identity of the specific bank employees who accessed that data.
In 2014, J.M., both an employee and a customer of Pankki S, found out that bank staff accessed his data several times in late 2013. After losing his job at Pankki S, he asked the bank in 2018 about who checked his data, when, and why. Pankki S, responsible for the data (the "data controller") under the EU's General Data Protection Regulation (the "European Regulation"), did not reveal the names, claiming that the information was private employee information. They did explain that their internal team looked into J.M.'s data to see if there was a conflict of interest because another customer owed money to someone with J.M.'s last name. They wanted to be sure J.M. was not involved. After checking, the bank cleared J.M. of any suspicion. Unsatisfied, J.M. took his request to Finland's data protection authority, which sided with the bank in 2020. Disagreeing with the decision, J.M. sued before the Administrative Court of Eastern Finland (the "Referring Court").
The Referring Court submitted four questions to the European Court:
Application of the European Regulation to Situations that Occurred before its Entry into Force
The rules about data protection changed significantly when the European Regulation entered into force on May 25, 2018. Usually, new procedural rules only apply from the day they enter into force, whereas substantive rules may apply to situations before their entry into force if this follows from the terms and objectives of the rule. The provision of the European Regulation at issue lets people ask about and see how their personal information has been used.
The main issue in this case was about how data was used from November 1 to December 31 in 2013. This was before the European Regulation entered into force. But J.M. asked Pankki S about it after the European Regulation entered into force, specifically on May 29, 2018. Because the European Court considered the provision that J.M. used to access his data a procedural rule, it held that the European Regulation applied to J.M.'s request.
Categories of Data that the Data Controller Must Provide to the Data Subject
Under the European Regulation, individuals have the right to know whether their personal data is being processed. If it is, they can see that data and learn why it is being used and who it is being shared with. Personal data is any information about a person that can help identify that person. This is a broad definition and includes both objective facts and subjective opinions about the person.
This data can be something as simple as a name or as complex as their genetic details. It is not just about the data initially collected: it is also about any information derived from that data. Processing includes a wide range of actions like collecting, storing, or even just looking at the data. And the term 'recipient' of the data means anyone it is shared with.
The goal is transparency. People should clearly know how their data is being used. This right to know is there to help individuals ensure the proper use of their data and to challenge any misuse. They should be told the purpose of data use and who gets to see it.
But there are limits. While people have the right to see their data and know who it is shared with, they do not necessarily have the right to know the names of every single person who saw it if those people work for the data holder. And while the goal is to protect data subjects' rights, the rights of others involved must also be taken into account.
J.M. asked Pankki S to tell him about any times the entity looked at his personal data from November to December 2013. He wanted to know when it checked it, why it did, and who did the checking. The European Court indicated that by sharing the log data from those actions, Pankki S could answer J.M.'s questions.
The European Court stated that the times Pankki S looked at J.M.'s data count as 'processing' under the European Regulation. So J.M. had the right to know not just about his data, but also about the details of these checks. The European Regulation states that a person has a right get a copy of their personal data that is being processed. The logs that J.M. asked for fit this definition, as they are records of actions related to his personal data. So these logs should show whether Pankki S was complying with the rules.
The logs, however, had names of the persons who did the checking. These checkers are Pankki S employees, working under the bank's orders. J.M. was not requesting the names because he thought the employees did not follow orders. Instead, he seemed to doubt the reasons Pankki S gave him for why they looked at his data in the first place.
The European Court held that under the European Regulation, data subjects have the right to know when and why someone checked their personal data. This does not mean, however, that they are entitled to know the names of the employees who did the checking, unless it is absolutely needed for the exercise of the data subject's rights under the European Regulation. The European Court indicated that the rights of those employees must also be taken into account.
Potential Relevance of the Status of the Data Subject as an Employee of the Data Controller
The European Regulation does not differentiate based on the kind of work the data holder does or the status of the person whose data they have. While the European Regulation allows the law of member states to narrow down the rights and duties related to access to data, it is mainly for specific cases.
In J.M.'s case, there is no sign that Pankki S is under any such special law. And, whether J.M. was a customer or employee of Pankki S did not change his right to access his data under the European Regulation.
The European Court held that it does not matter whether the data holder is a bank or whether the person asking for their data was both a customer and employee there. Those factors do not change the person's right to see the data.
Proceedings brought by J.M. (Court of Justice of the European Union, 2023)