2.3 The Supervising Authorities
In 2001, the Data Protection Act, with article 21, created an Independent Parliamentary Commission to oversee the processing of personal data, but it never came into
being. This was one of the main flaws of the initial legal regime on data protection in
Cape Verde and the main difference from the one inserted in the European Directive
on Data Protection and the Portuguese Data Protection Law,
91 though the possibility
of the establishment of a National Authority on Data Protection was discussed in
Parliament, but dismissed by the promoters with the justification that an oversight of
the Parliamentary Commission with the possibility of judicial review was sufficient
to guarantee data protection rights.
92
When the Law was amended in 2013, after criticism, particularly by the National
Commission for Human Rights and Citizenship,
93 of inadequacy of the system and
absence of meaningful supervision, it was substituted by a National Authority on
Data Protection. Internal reasons were provided justifying the adoption of another
institutional model, because according to the sponsoring members of parliament of
the new majority party in the National Assembly, the model was wrong because it
depended on members of parliament that were not suited to conducting that kind of
time consuming job directly associated with the nature of the powers and functions
of oversight of the organ established by the law and because it would, arguably,
violate the principle of separation of powers if Members of Parliament received such
administrative powers.
94
The new body has the functions of follow-up, evaluation and control of the
activities of legally competent entities for the processing of data, with the aim of
safeguarding the fulfilment of the Constitution and the Law, especially the fundamental rights, freedoms and guarantees of citizens (article 21). Thus, the Authority is
the supervisor of the national personal data processing system with the legal nature
of an independent administrative agency (article 22).
According to the previously mentioned National Authority on Data Protection
Act, the Authority consists of three members, all elected by the National Assembly
by a two-thirds majority of deputies present as long as they are superior to the
absolute majority of that legislative organ (article 13(1)), with the chairmanship
being assumed by rotation of all members for a period of 2 years each (article 13(2)).
However, this rule was not followed by Parliament when it elected one of the
members because it modified the order of the candidates, not following alphabetic
91 This was the main difference between the original Cape Verdean Model and the European and
Portuguese ones, as stressed previously by Traça and Embry (2011), p. 251; Pinheiro (2015), p. 564.
92 Parliamentary Records (2000), 30.11.2000 (audio version) (on file with author).
93 National Commission for Human Rights and Citizenship (2011), pp. 61–63.
94 Parliamentary Records (audio), 27.07.13, Morning Period (on file with author).
Data Protection in the Internet: Cape Verde’s National Report
93
In 2001, the Data Protection Act, with article 21, created an Independent Parliamentary Commission to oversee the processing of personal data, but it never came into
being. This was one of the main flaws of the initial legal regime on data protection in
Cape Verde and the main difference from the one inserted in the European Directive
on Data Protection and the Portuguese Data Protection Law,
91 though the possibility
of the establishment of a National Authority on Data Protection was discussed in
Parliament, but dismissed by the promoters with the justification that an oversight of
the Parliamentary Commission with the possibility of judicial review was sufficient
to guarantee data protection rights.
92
When the Law was amended in 2013, after criticism, particularly by the National
Commission for Human Rights and Citizenship,
93 of inadequacy of the system and
absence of meaningful supervision, it was substituted by a National Authority on
Data Protection. Internal reasons were provided justifying the adoption of another
institutional model, because according to the sponsoring members of parliament of
the new majority party in the National Assembly, the model was wrong because it
depended on members of parliament that were not suited to conducting that kind of
time consuming job directly associated with the nature of the powers and functions
of oversight of the organ established by the law and because it would, arguably,
violate the principle of separation of powers if Members of Parliament received such
administrative powers.
94
The new body has the functions of follow-up, evaluation and control of the
activities of legally competent entities for the processing of data, with the aim of
safeguarding the fulfilment of the Constitution and the Law, especially the fundamental rights, freedoms and guarantees of citizens (article 21). Thus, the Authority is
the supervisor of the national personal data processing system with the legal nature
of an independent administrative agency (article 22).
According to the previously mentioned National Authority on Data Protection
Act, the Authority consists of three members, all elected by the National Assembly
by a two-thirds majority of deputies present as long as they are superior to the
absolute majority of that legislative organ (article 13(1)), with the chairmanship
being assumed by rotation of all members for a period of 2 years each (article 13(2)).
However, this rule was not followed by Parliament when it elected one of the
members because it modified the order of the candidates, not following alphabetic
91 This was the main difference between the original Cape Verdean Model and the European and
Portuguese ones, as stressed previously by Traça and Embry (2011), p. 251; Pinheiro (2015), p. 564.
92 Parliamentary Records (2000), 30.11.2000 (audio version) (on file with author).
93 National Commission for Human Rights and Citizenship (2011), pp. 61–63.
94 Parliamentary Records (audio), 27.07.13, Morning Period (on file with author).
Data Protection in the Internet: Cape Verde’s National Report
93
