The Commissioner for Personal Data Protection in Cyprus recently announced the launch of an independent investigation in the controversial case of photos of children in school being shared on social media.
The case serves as an important reminder, not only of the rights of individuals to personal data protection but also of the powers that the Commissioner for Personal Data Protection has to initiate investigations into a potential breach of data protection regulations.
The Commissioner has the power to independently initiate investigations, even in the absence of a formal complaint.
The basis for ex officio investigations is found in Articles 57 of the GDPR which gives the responsibility to national supervisory authorities to monitor and enforce compliance with the GDPR and Article 58 of the GDPR, which empowers supervisory authorities to order controllers and processors, to provide any information they require for the performance of their tasks.
This means that compliance with all relevant regulations and standards is essential at all times, not just when a complaint is filed.
Regular audits, transparent data handling practices, and robust security measures are essential to prevent potential issues and avoid penalties. Companies should also be aware of their obligations under the General Data Protection Regulation (GDPR) and other relevant laws, as non-compliance can lead to significant fines and reputational damage.
We encourage all companies to regularly review and update their compliance procedures, conduct internal audits, and ensure that their operations align with the legal requirements.
Should you wish to find out more or book an internal training seminar concerning GDPR contact our team at info@paraschou.com.cy