Summary: Directive (EU) 2016/680 on protecting personal data that is used by police and criminal justice authorities (Law Enforcement Directive, LED)

WHAT IS THE AIM OF THE DIRECTIVE?

  • Directive (EU) 2016/680, the data protection law enforcement directive (LED), ensures the protection of personal data of individuals involved in criminal proceedings, be it as witnesses, victims or suspects.
  • It establishes a comprehensive framework to ensure a high level of data protection, while taking into account the specific nature of the police and criminal justice field.
  • It contributes to increased trust and facilitates cooperation in the fight against crime in Europe, by harmonising the protection of personal data by law enforcement authorities in European Union (EU) and Member States.
  • The directive is part of the EU data protection reform, along with the Regulation(EU) 2016/679 General data protection regulation (GDPR) and Regulation (EU) 2018/1725 on the protection of natural persons with regard to the processing of personal data by the EU institutions, bodies, offices and agencies.

KEY POINTS

The directive requires that the data collected by law enforcement authorities are:

  • processed lawfully and fairly;
  • collected for specified, explicit and legitimate purposes and processed only in a manner compatible with these purposes;
  • adequate, relevant and not excessive in relation to the purpose for which they are processed;
  • accurate and updated where necessary;
  • kept in a form which allows identification of the individual for no longer than is necessary for the purpose of the processing;
  • appropriately secured, including protection against unauthorised or unlawful processing, using appropriate technical or organisational measures.

Time limits

Member States must establish time limits for erasing the personal data or for a regular review of the need to store such data.

Individuals concerned (data subjects)

The directive requires that law enforcement authorities make a clear distinction between the data of different categories of persons, including:

  • those for whom there are serious grounds to believe they have committed or are about to commit a criminal offence;
  • those who have been convicted of a criminal offence;
  • victims of criminal offences or those whom it is reasonably believed could be victims of criminal offences;
  • those who are parties to a criminal offence, including potential witnesses.

Information to data subjects and access to data

Individuals have the right to have certain information made available – and in some cases provided – to them by the competent law enforcement authorities, including:

  • the name and contact details of the competent authority which decides the purpose and means of the data processing;
  • the purposes for processing their data;
  • the right to launch a complaint with a supervisory authority and the contact details of the authority;
  • the existence of the right to request access to and correction or deletion of their personal data, as well as the right to restrict processing of their personal data.

Individuals have the right to obtain confirmation from competent authorities as to whether their personal data are being processed, and to access such data and information relating to their processing.

Security and logging

National authorities must take technical and organisational measures to ensure a level of security for personal data that is appropriate to the risk. Where data processing is automated, a number of measures must be put in place, including:

  • denying unauthorised persons access to equipment used for processing;
  • preventing the unauthorised reading, copying, changing or removal of data media (i.e. Disks or other devices to store data);
  • preventing the unauthorised input of personal data and the unauthorised viewing, changing or deleting of stored personal data.

National authorities must keep logs with information such as the date and time of access to personal data and the names of those who have consulted the data or to whom the data have been disclosed. The logs shall mainly be used for verifying the lawfulness of the processing, ensuring the security and integrity of the processing and for criminal proceedings.


GDPR - Your rights over your personal data

Personal data protection - the regulatory framework of the Republic of Moldova

Summary: EU General Data Protection Regulation (GDPR)

Regulation (EU) 2018/1725 on Personal Data Processing by EU institutions (EUDPR)


BACKGROUND

  • Reform of EU data protection rules (European Commission)
  • EU data protection rules (European Commission)
  • Commission report: EU data protection rules empower citizens and are fit for the digital age – press release (European Commission)
  • Data protection reform – memo (European Commission)
  • Protection of personal data (European Commission).

RELATED DOCUMENTS

As part of European Union (EU) data protection reform, along with Directive (EU) 2016/680 (LED), it is also using the following EU key legislation:

  • Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation)
  • Regulation (EU) 2018/1725 on the protection of individuals with regard to the processing of personal data by the EU institutions, bodies, offices and agencies.
  • Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
Alexhost - Webhosting support of the e-Legal.md Diginet.md - Ecommerce Solutions and Internet Marketing OpenCode.md - Open Source products and Digital Public Goods e-Cont.md - Issuance and circulation of e-invoices for payment for business in Moldova (B2B)