In addition, ordinary remedies and sanctions are also available. In this case, the
recourse to the ordinary courts can be civil, when the subject of data treatment is
entitled to sue and receive compensation as a result of an unlawful processing
operation and other acts incompatible with applicable laws in the domain of data
protection. Nevertheless, according to the General Data Protection Act, the controller can claim that it should be totally or partially exonerated from liability if it proves
that the fact that caused harm is not attributable to it (article 31).
In the criminal sphere, complaints are possible, but depending, in most of the
cases, on a decision by the State Prosecution’s Service to indict based in the
commission of crimes established by the Criminal Code (Crimes against the intimacy of private life: as private life abuse, computer abuse, breach of correspondence
or telecommunications; breach of secrecy, improper advantage of secrecy as well as
article’s 212 fraud through computerised means) or by special law that covers data
protection, namely by the general law: certain omissions of notification, presentation
of false information in the process of authorisation, misappropriation or uses incompatible with the purpose of collection, illegal combination of personal data, undue
access, invalidation and destruction of data, qualified non-compliance, violation of
duty of secrecy. Depending on the specific crime the sanction can be a fine or a
penalty that can go up to a maximum of 4 and a half years of imprisonment in the
case of a violation of duty of secrecy by a civil servant, or if the intention of the agent
was to obtain a material advantage or other unlawful gain or it adversely affects the
reputation, honour and esteem or the privacy of a person. In addition, the Cybercrime
Act incriminates certain relevant acts and omissions relevant to data protection
(informatics damage; informatics sabotage; illicit access to informatics systems;
illicit interception; revenge porn); additionally, under article 19 of the Republic’s
Information System Act, violation of rules on access, use or transfer of data is a
crime punishable with a penalty that can reach 3 years of imprisonment.
On the other hand, besides the administrative and judicial—civil, criminal and
constitutional—remedies mentioned, there is no specific remedy for protection of
personal data in the context of services provided from a distance, by electronic
means, at the individual request of a recipient of services, protection of personal data
in the context of electronic communications for marketing purposes, electronic
processing of personal data of employees, security of personal data processed by
electronic means, the processing of personal data in the electronic communications
sector; protection of personal data for the purpose of the investigation, detection and
prosecution of crimes through electronic means, to the electronic processing of
personal data for security and national defence purposes, though in some cases
other administrative services can intervene, like the National Direction of Labour
in the case of treatment of employee data.
There is no specific supervisory body with powers to impose a financial penalty
or to sanction for most of those areas, though, in the case of the Republic’s
Information Service under article 16 of the Republic’s Information System Act,
the Prosecutors’ Commission can impose the rectification or destruction of data
collected in violation of basic rights and institute criminal proceedings when justified
for the practice of specific crimes linked to data protection as violation of rules
106
J. Pina-Delgado
recourse to the ordinary courts can be civil, when the subject of data treatment is
entitled to sue and receive compensation as a result of an unlawful processing
operation and other acts incompatible with applicable laws in the domain of data
protection. Nevertheless, according to the General Data Protection Act, the controller can claim that it should be totally or partially exonerated from liability if it proves
that the fact that caused harm is not attributable to it (article 31).
In the criminal sphere, complaints are possible, but depending, in most of the
cases, on a decision by the State Prosecution’s Service to indict based in the
commission of crimes established by the Criminal Code (Crimes against the intimacy of private life: as private life abuse, computer abuse, breach of correspondence
or telecommunications; breach of secrecy, improper advantage of secrecy as well as
article’s 212 fraud through computerised means) or by special law that covers data
protection, namely by the general law: certain omissions of notification, presentation
of false information in the process of authorisation, misappropriation or uses incompatible with the purpose of collection, illegal combination of personal data, undue
access, invalidation and destruction of data, qualified non-compliance, violation of
duty of secrecy. Depending on the specific crime the sanction can be a fine or a
penalty that can go up to a maximum of 4 and a half years of imprisonment in the
case of a violation of duty of secrecy by a civil servant, or if the intention of the agent
was to obtain a material advantage or other unlawful gain or it adversely affects the
reputation, honour and esteem or the privacy of a person. In addition, the Cybercrime
Act incriminates certain relevant acts and omissions relevant to data protection
(informatics damage; informatics sabotage; illicit access to informatics systems;
illicit interception; revenge porn); additionally, under article 19 of the Republic’s
Information System Act, violation of rules on access, use or transfer of data is a
crime punishable with a penalty that can reach 3 years of imprisonment.
On the other hand, besides the administrative and judicial—civil, criminal and
constitutional—remedies mentioned, there is no specific remedy for protection of
personal data in the context of services provided from a distance, by electronic
means, at the individual request of a recipient of services, protection of personal data
in the context of electronic communications for marketing purposes, electronic
processing of personal data of employees, security of personal data processed by
electronic means, the processing of personal data in the electronic communications
sector; protection of personal data for the purpose of the investigation, detection and
prosecution of crimes through electronic means, to the electronic processing of
personal data for security and national defence purposes, though in some cases
other administrative services can intervene, like the National Direction of Labour
in the case of treatment of employee data.
There is no specific supervisory body with powers to impose a financial penalty
or to sanction for most of those areas, though, in the case of the Republic’s
Information Service under article 16 of the Republic’s Information System Act,
the Prosecutors’ Commission can impose the rectification or destruction of data
collected in violation of basic rights and institute criminal proceedings when justified
for the practice of specific crimes linked to data protection as violation of rules
106
J. Pina-Delgado
