Decisions on sanctions or other remedies made in such cases shall be mutually
agreed between the lead supervisory authority and other involved DPAs.
If processing of personal data falls within the scope of the GDPR and neither
controller nor processor(s) are established in the EU (or EEA respectively), they are
obliged to appoint a representative in the EU. In that case, the representative “shall
be established in one of the Member States where the data subjects, whose personal
data are processed in relation to the offering of goods or services to them, or whose
behaviour is monitored, are, and it shall be mandated by the controller or processor
to be addressed in addition to or instead of the controller or the processor by, in
particular, supervisory authorities and data subjects, on all issues related to
processing, for the purposes of ensuring compliance with this Regulation”—see
Art. 27(3),(4).
The mechanism of legal representatives that existed also under the previous
statutory regime demonstrates the above concerns over efficiency of cross-border
reach of EU data protection rules. It turns out that entities that process personal data
outside the EU and have no presence in the EU hesitate to appoint their representatives pursuant to Art. 27(1) of the GDPR or previously Art. 4(2) of the Directive
95/46/EC. In such cases, EU member states struggle to find measures to motivate
offshore controllers and processors to comply with this obligation.
The GDPR provides for liability claims in Art. 82(1) and (2) of the GDPR that
read as follows:
1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller
or processor for the damage suffered.
2. Any controller involved in processing shall be liable for the damage caused by processing
which infringes this Regulation. A processor shall be liable for the damage caused by
processing only where it has not complied with obligations of this Regulation specifically
directed to processors or where it has acted outside or contrary to lawful instructions of
the controller.
Basic procedural provision, including jurisdictional rules, is laid down in Art.
79 of the GDPR that reads as follows:
Article 79 Right to an effective judicial remedy against a controller or processor
1. Without prejudice to any available administrative or non-judicial remedy, including the
right to lodge a complaint with a supervisory authority pursuant to Article 77, each data
subject shall have the right to an effective judicial remedy where he or she considers that
his or her rights under this Regulation have been infringed as a result of the processing of
his or her personal data in non-compliance with this Regulation.
2. Proceedings against a controller or a processor shall be brought before the courts of the
Member State where the controller or processor has an establishment. Alternatively, such
proceedings may be brought before the courts of the Member State where the data subject
has his or her habitual residence, unless the controller or processor is a public authority of
a Member State acting in the exercise of its public powers.
In addition to the GDPR, the Czech Civil Code contains traditional liability
provisions for infringements of personality protection, whereas privacy is considered
a component of the concept personality. Consequently, certain cases of breaches of
156
R. Polčák et al.
agreed between the lead supervisory authority and other involved DPAs.
If processing of personal data falls within the scope of the GDPR and neither
controller nor processor(s) are established in the EU (or EEA respectively), they are
obliged to appoint a representative in the EU. In that case, the representative “shall
be established in one of the Member States where the data subjects, whose personal
data are processed in relation to the offering of goods or services to them, or whose
behaviour is monitored, are, and it shall be mandated by the controller or processor
to be addressed in addition to or instead of the controller or the processor by, in
particular, supervisory authorities and data subjects, on all issues related to
processing, for the purposes of ensuring compliance with this Regulation”—see
Art. 27(3),(4).
The mechanism of legal representatives that existed also under the previous
statutory regime demonstrates the above concerns over efficiency of cross-border
reach of EU data protection rules. It turns out that entities that process personal data
outside the EU and have no presence in the EU hesitate to appoint their representatives pursuant to Art. 27(1) of the GDPR or previously Art. 4(2) of the Directive
95/46/EC. In such cases, EU member states struggle to find measures to motivate
offshore controllers and processors to comply with this obligation.
The GDPR provides for liability claims in Art. 82(1) and (2) of the GDPR that
read as follows:
1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller
or processor for the damage suffered.
2. Any controller involved in processing shall be liable for the damage caused by processing
which infringes this Regulation. A processor shall be liable for the damage caused by
processing only where it has not complied with obligations of this Regulation specifically
directed to processors or where it has acted outside or contrary to lawful instructions of
the controller.
Basic procedural provision, including jurisdictional rules, is laid down in Art.
79 of the GDPR that reads as follows:
Article 79 Right to an effective judicial remedy against a controller or processor
1. Without prejudice to any available administrative or non-judicial remedy, including the
right to lodge a complaint with a supervisory authority pursuant to Article 77, each data
subject shall have the right to an effective judicial remedy where he or she considers that
his or her rights under this Regulation have been infringed as a result of the processing of
his or her personal data in non-compliance with this Regulation.
2. Proceedings against a controller or a processor shall be brought before the courts of the
Member State where the controller or processor has an establishment. Alternatively, such
proceedings may be brought before the courts of the Member State where the data subject
has his or her habitual residence, unless the controller or processor is a public authority of
a Member State acting in the exercise of its public powers.
In addition to the GDPR, the Czech Civil Code contains traditional liability
provisions for infringements of personality protection, whereas privacy is considered
a component of the concept personality. Consequently, certain cases of breaches of
156
R. Polčák et al.
