2.3 The Supervision Authorities
The role and nature of entities that supervise and control the processing of personal
data also differ considerably across the globe.
In Europe, such entities (as is the case of, e.g., in France, the Commission
Nationale Informatique et Libertés; in Greece, the Hellenic Personal Data Authority; in Italy, the Garante per la protezione dei dati personali; in Portugal, the
Comissão Nacional de Proteção de Dados; in Spain, the Agencia Española de
Protección de Datos; and, in Switzerland, the Eidgenössische Datenschutz- und
Öffentlichkeitsbeauftragte) play an essential role in this field.
According to the GDPR, each Member State shall provide, in accordance with its
constitutional organization, for the existence of one or more independent public
authorities, which shall be responsible for monitoring the application of the Regulation, in order to protect the fundamental rights and freedoms of natural persons in
relation to processing and to facilitate the free flow of personal data within the
Union. Such authorities shall act with complete independence in performing their
tasks and exercising their powers.
Supervising authorities’ tasks under the GDPR are manifold and include, inter
alia: (1) the monitoring and enforcement of the application of the Regulation; (2) the
promotion of public awareness and understanding of the risks, rules, safeguards and
rights in relation to processing; (3) advising public institutions on legislative and
administrative measures relating to the protection of natural persons’ rights and
freedoms with regard to processing; (4) handling complaints lodged by data subjects;
and (5) conducting investigations on the application of the Regulation.
In order to perform such tasks, supervisory authorities in EU Member States are
entrusted with a wide range of investigative, corrective, authorization and advisory
powers. The exercise of such powers is nevertheless subject to appropriate safeguards, including effective judicial remedy and due process.
37
Other countries have followed the European model of concentrating the supervision of data protection legislation in a single administrative body: such is the case of
Japan, which has created a Personal Information Protection Commission; of Singapore, where a Personal Data Protection Commission has been set up; and of
South Africa, where an Information Regulator was instituted. The legal status of
these bodies—notably their independence vis-à-vis constitutional powers—is however extremely varied: in Singapore, for example, the said Authority is under the
purview of the Info-Communications Media Development Authority, which is itself
under the Ministry of Communications and Information
38 ; and in South Africa the
Regulator is appointed by the President of the Republic.
39
A considerably different approach has prevailed in the U.S., where a public
agency specifically devoted to personal data protection does not exist. Instead, it is
37 See, on this, the European Union Special Report, Sect. 1.4.
38 See the Singaporean National Report, Sect. 2.3.
39 See the South African National Report, Sect. 3.
Data Protection in the Internet: General Report
9
The role and nature of entities that supervise and control the processing of personal
data also differ considerably across the globe.
In Europe, such entities (as is the case of, e.g., in France, the Commission
Nationale Informatique et Libertés; in Greece, the Hellenic Personal Data Authority; in Italy, the Garante per la protezione dei dati personali; in Portugal, the
Comissão Nacional de Proteção de Dados; in Spain, the Agencia Española de
Protección de Datos; and, in Switzerland, the Eidgenössische Datenschutz- und
Öffentlichkeitsbeauftragte) play an essential role in this field.
According to the GDPR, each Member State shall provide, in accordance with its
constitutional organization, for the existence of one or more independent public
authorities, which shall be responsible for monitoring the application of the Regulation, in order to protect the fundamental rights and freedoms of natural persons in
relation to processing and to facilitate the free flow of personal data within the
Union. Such authorities shall act with complete independence in performing their
tasks and exercising their powers.
Supervising authorities’ tasks under the GDPR are manifold and include, inter
alia: (1) the monitoring and enforcement of the application of the Regulation; (2) the
promotion of public awareness and understanding of the risks, rules, safeguards and
rights in relation to processing; (3) advising public institutions on legislative and
administrative measures relating to the protection of natural persons’ rights and
freedoms with regard to processing; (4) handling complaints lodged by data subjects;
and (5) conducting investigations on the application of the Regulation.
In order to perform such tasks, supervisory authorities in EU Member States are
entrusted with a wide range of investigative, corrective, authorization and advisory
powers. The exercise of such powers is nevertheless subject to appropriate safeguards, including effective judicial remedy and due process.
37
Other countries have followed the European model of concentrating the supervision of data protection legislation in a single administrative body: such is the case of
Japan, which has created a Personal Information Protection Commission; of Singapore, where a Personal Data Protection Commission has been set up; and of
South Africa, where an Information Regulator was instituted. The legal status of
these bodies—notably their independence vis-à-vis constitutional powers—is however extremely varied: in Singapore, for example, the said Authority is under the
purview of the Info-Communications Media Development Authority, which is itself
under the Ministry of Communications and Information
38 ; and in South Africa the
Regulator is appointed by the President of the Republic.
39
A considerably different approach has prevailed in the U.S., where a public
agency specifically devoted to personal data protection does not exist. Instead, it is
37 See, on this, the European Union Special Report, Sect. 1.4.
38 See the Singaporean National Report, Sect. 2.3.
39 See the South African National Report, Sect. 3.
Data Protection in the Internet: General Report
9
