CJEU case C-560/21 – CJEU Judgment (European Union, 2023)
CJEU judgment — not a DPA enforcement action
This is a Court of Justice ruling, not an enforcement action by a data protection authority. It is not included in cookie statistics or the Risk Calculator.
The Court of Justice ruled that KISA improperly dismissed its Data Protection Officer without a valid reason. This decision emphasizes the importance of protecting employees in such roles. Companies must ensure they follow proper procedures when dismissing someone responsible for data protection.
What happened
KISA dismissed its Data Protection Officer without a valid reason, claiming a conflict of interest.
Who was affected
The employee, ZS, who was serving as the Data Protection Officer at KISA.
What the authority found
The Court held that KISA did not have a compelling reason to dismiss ZS, violating the legal requirements for such actions.
Why this matters
This ruling highlights the need for companies to adhere to strict procedures when terminating Data Protection Officers. It serves as a reminder that protecting data privacy roles is crucial for compliance.
ZS is employed at KISA since the 1st January 2002. KISA, obliged according to the GDPR as well as the BDSG (Federal Data Protection Law) to nominate a DPO, nominated him the 27th February 2004 as Data Protection Officer. With letter the 15th August 2018 discmissed KISA ZS as DPO with effect 31st August 2018 and justified this, that a conflict of interest exists between his activity as DPO and his other professional activity. ZS argued that in this case there is a lack of an important reason justifying his dismissal. The Federal Data Protection Law stipulates that: The dismissal of the data protection officer shall be permitted only by corresponding application of Paragraph 626 of the Bürgerliches Gesetzbuch (German Civil Code). According to this law, dismissal is only legitimate if there are facts which justify, based on an important reason, the dismissal without notice. Article 626 of the Civil Code states: The service relationship may be terminated by either party to the contract for a compelling reason without complying with a notice period, if facts are present on the basis of which the party giving notice cannot reasonably be expected to continue the service relationship to the end of the notice period or to the agreed end of the service relationship, taking all circumstances of the individual case into account and weighing the interests of both parties to the contract. The second sentence of Article 38(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), must be interpreted as not precluding national legislation which provides the a DPO employed by a controller or a processor can be only dismissed due to an important reason, even when the dismissal is not in relation of his taks, as far as this rule does not undermine the achi
Outcome
CJEU Judgment
A judgment by the Court of Justice of the European Union, typically on a preliminary reference from a national court.
Related Cases (0)
No other cases found for CJEU case C-560/21 in EU
This is the only recorded case for this entity in this jurisdiction.
Details
Judgment Date
1 January 2023
Authority
Court of Justice of the European Union
GDPRhub ID
gdprhub-cjeu-4891About this data
Cite as: Cookie Fines. CJEU case C-560/21 - European Union (2023). Retrieved from cookiefines.eu
Last updated: