Transcription of Guidelines 01/2020 on processing personal data in ... - Europa
1 Adopted1 Guidelines01/2020onprocessing personal data in thecontext of connected vehicles and mobility on9 March 2021 Adopted2 version historyVersion March 2021 Adoption of the Guidelinesafter public consultationVersion of the Guidelines forpublic consultationAdopted3 Table of and data protection of and data protection by design and by of the data personal data to third of personal data outside the of in-vehicle Wi-Fi of a service by a third auto European Data Protection BoardHaving regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and ofthe Council of 27 April 2016 on the protectionof natural persons with regard to the processing ofpersonal data and on the free movement of such data, and repealing Directive 95/46/EC,(hereinafter GDPR ),Having regard to the EEA Agreement and in particular to Annex XI and Protocol 37 thereof, as amendedby the Decision of the EEA joint Committee No 154/2018 of 6 July 20181,Having regard to Article 12and Article 22 of its Rules of Procedure,HAS ADOPTED THE FOLLOWING of the 20th century economy, the automobile is one of the mass consumer productsthat has impacted society as awhole.
2 Commonly associated with the notion of freedom,cars are often considered as more than just a meansof transportation. Indeed, theyrepresent a private area in which people can enjoy a form of autonomy of decision, withoutencountering any external interferences. Today, as connected vehicles move into themainstream, such a vision no longer corresponds to the reality. In-vehicle connectivity israpidlyexpanding from luxury models and premium brands to high-volume midmarketmodels, and vehicles are becoming massive data hubs. Not only vehicles, but drivers andpassengers are also becoming more and more connected. As a matter of fact,many modelslaunched over the past few years on the market integrate sensors and connected on-boardequipment, which may collect and record, among other things, the engine performance, thedriving habits, the locations visited, and potentially even the driver s eye movements, his orher pulse, or biometric data forthe purpose of uniquely identifying a natural data processing is taking place in a complex ecosystem, which is not limited to thetraditional players of the automotive industry, but is also shaped by the emergence of newplayers belonging to the digital economy.
3 These new players may offer infotainment servicessuch as online music, road condition and traffic information, or provide driving assistancesystems and services, such as autopilot software, vehicle condition updates, usage-basedinsurance or dynamic mapping. Moreover, since vehicles are connected via electroniccommunication networks, road infrastructure managers and telecommunications operatorsinvolved in this process also play an important role with respect to the potential processingoperations applied to the drivers and passengers personal addition, connected vehicles are generating increasing amounts of data, most of whichcan be considered personal data since they will relate to drivers or passengers. Even if the1 References to Member States made throughout this document should be understood as references to EEAM ember States .2 Infographic Data and the connected car by the Future of Privacy Forum; collected by a connected car are not directly linked to a name, but totechnical aspectsand features of the vehicle, it will concern the driver or the passengers of the car.
4 As anillustration, data relating to the driving style or the distance covered, data relating to thewear and tear on vehicle parts, location dataor data collected by cameras may concerndriver behaviour as well as information about other people who could be inside ordatasubjects that pass technical data are produced by a natural person, and permithis/herdirect or indirect identification,by the data controller or by another can be considered as a terminal that can be used by different users. Therefore, asfor a personal computer, this potential plurality of usersdoes notaffect the personal natureof the 2016, the F d ration Internationale de l Automobile (FIA) ran a campaign across Europecalled My Car My Data to get a sentiment on what Europeans think about connected it showed the high interest of drivers for connectivity, it also highlighted the vigilancethat must be exercised with regard to the use of the data produced by vehicles as well asthe importance of complying with personal data protection legislation.
5 Thus, the challengeis, for each stakeholder, to incorporate the protection of personal data dimension fromthe product design phase, and to ensure that car users enjoy transparency and control inrelation to their datain accordance with recital 78 GDPR. Such an approach helps tostrengthen user confidence, and thus the long-term development of those vehicles have become a substantial subject for regulators over thelast decade,with a major increase in the last couple of years. Various works have thus been published atthe national and international levels concerning the security and privacy of connectedvehicles. Those regulations and initiatives aim at complementing the existing dataprotection and privacy frameworks with sector specific rules or providing guidance and international March 2018, a 112-based eCall in-vehicle system is mandatory on all new types ofM1 and N1 vehicles (passenger cars and light duty vehicles).
6 4,5In 2006, the Article 29 Working Party had already adopted a working document on data protection and privacyimplications in eCall addition, as previously discussed, the Article29 WorkingParty also adopted an opinion in October 2017 regarding the processing of personal data inthe context of Cooperative Intelligent Transport Systems (C-ITS). January 2017, the European Union Agency for Network and Information Security (ENISA)published a study focused oncyber security and resilience of smart cars listing thesensitiveassets as well as the corresponding threats, risks, mitigation factors and possible security3 Campaign My Car My Data ; interoperable EU-wide eCall; No 585/2014/EU of the European Parliament and of the Council of 15 May 2014 on the deploymentof the interoperable EU-wide eCall service Text with EEA relevance; document on data protection and privacy implications in eCall initiative; to September 2017, the International Conference of DataProtection and Privacy Commissioners (ICDPPC) adopted a resolution on , in April 2018, the International Working Group on Data Protection inTelecommunications (IWGDPT), also adopted a working paper on connected initiatives of European Data Protection Board (EDPB) January 2016, the Conference of the German Federal and State Data ProtectionAuthorities and the German Association of the Automotive Industry (VDA) published acommon declaration on the principles of data protection in connected and August 2017, the UK Centre for Connected and Autonomous Vehicles (CCAV)released a guide stating principles of cyber security for connected and automated vehiclesin order to raise awareness on the matter within the October 2017,the French data protection authority, the Commission Nationale de l'Informatique et desLibert s (CNIL)
7 , released a compliance package for connected cars in order to provideassistance to stakeholders on how to integrate data protection by design and by default,enabling data subjects to have effective control over their relevant EU legal framework is the GDPR. It applies in any case where data processingin the context of connected vehicles involves processing personal data of to the GDPR, directive 2002/58/ECas revised by 2009/136/EC(hereinafter ePrivacy directive ),sets a specific standard for all actors that wishto store or accessinformation stored in the terminal equipment of a subscriber or user in the EuropeanEconomic Area (EEA). , if most of the ePrivacy directive provisions ( , , etc.) only applyto providersof publicly available electronic communication services and providers of publiccommunication networks, (3)ePrivacy directiveis a general provision. It does not onlyapply to electronic communication services but also to every entity,private or public,thatplaces on or reads information from a terminal equipment without regard to the nature ofthe data being stored or security and resilience of smartcars; on data protection in automated and connected vehicles; paper on connected vehicles; protection aspects of using connected and non-connected vehicles; of cyber security for connected and automated vehicles; package for a responsible use of data in connected cars; the notion of terminal equipment , the definition is given by directive2008/63/CE13.
8 (a)definesthe terminal equipment as an equipment directly orindirectly connected to the interface of a public telecommunications network to send,process or receive information; in either case (director indirect), the connection may bemade by wire, optical fibre or electromagnetically; a connection is indirect if equipment isplaced between the terminal and the interface of the network; (b) satellite earth stationequipment . a result,provided that the aforementionedcriteriaare met,the connected vehicle anddevice connected to it shouldbe considered as a terminal equipment (just like a computer,a smartphone or a smart TV) and provisions of (3) ePrivacy directiveapply outlined by the EDPB in its opinion5/2019 on the interplay between the ePrivacydirective and the GDPR, (3) ePrivacy directive provides that, as a rule,and subject tothe exceptions to that rule mentioned in paragraph 17 below,prior consent is required forthe storing of information, or the gaining of access to information already stored, in theterminal equipment of a subscriber or user.
9 To the extent that the information stored in theend-user s device constitutes personal data, (3)ePrivacy directiveshall takeprecedence over regards to the activity of storing or gaining access to processingoperationsof personal data following the aforementionedprocessing operations, including processing personal data obtained by accessinginformation in the terminal equipment, must have a legal basis under orderto be the controller, when seeking consent for the storing or gaining of access to informationpursuant to art. 5(3) ePrivacy directive, will have to inform the data subject about all thepurposes of the processing including any processing following the aforementionedoperations(meaningthe subsequent processing ) consent under art. 6 GDPR willgenerally be the most adequate legal basis to cover theprocessingof personal datafollowingsuch operations(as far as the purpose of the following processing iscomprehended by the data subject s consent, see paragraphs53-54 below).
10 Hence, consentwill likely constitute the legal basis both for the storingand gaining of access to informationalready stored and thesubsequentprocessing of personal data17. Indeed, when assessingcompliance with art. 6 GDPR, one should take into account that the processing as a wholeinvolves specific activities for which theEU legislature has sought to provide , controllers must take into account the impact on data subjects 13 Commission Directive 2008/63/EC of 20 June 2008 on competition in the markets in telecommunicationsterminal equipment (Codified version ) (Text with EEA relevance); Data Protection Board,Opinion 5/2019 on the interplay between the ePrivacy Directive and theGDPR, in particular regarding the competence, tasks and powers of data protection authorities, adopted on 12 March 2019 (hereinafter- Opinion 5/2019 ), paragraph , paragraph , paragraph required by art. 5(3) of the ePrivacy directive and consent needed as a legal basis for theprocessing of data (art.)