Case C-141/12, Y.S – data processing and access to data [judgment 2014, ECLI:EU:C:2014:2081]
Where a body takes a negative decision against a person, does the EU’s Data Processing Directive 95/46 also require that body to grant the person access to the data about them which led to the negative decision?
Facts
In 2009, an individual applied for asylum in The Netherlands. Within six months, the application had been turned down. However, the Dutch Immigration Service subsequently withdrew its decision and issued a fresh one some three months later. The fresh decision, taken in 2010, once again refused asylum to the individual.
The individual asked the Immigration Service to look at the so-called ‘minuut’. This document often contains information about: the applicant’s origin and file history, the evidence submitted, declarations and details, and the legal provisions applicable to that individual’s application. The minuut also contains an assessment of that data in the light of those provisions.
However, the Immigration Service turned down the individual’s request. For whereas prior to July 2009, asylum seekers could request and would be supplied with a copy of the minuut; this practice had changed and the Immigration Service now described the minuut as ‘legal analysis’.
Because the Immigration Service’s refusal constituted a decision, the individual could, and did, appeal. The appeal was also dealt with by the Immigration Service. And the Immigration Service held the appeal to be without foundation.
The individual appealed again and this time the matter was heard by an administrative law judge. The judge at the Middelburg District Court noted that Dutch public law seemed contradictory. On the one hand, the Dutch Supreme Court had taken a broad approach to the right of accessing and inspecting files because people should be able to check the accuracy of the information held about them. On the other hand, the Dutch Council of State had ruled that the minuut did not fall within the concept of personal data, and not every document needed to be copied. Not only did there appear to be a contradiction in Dutch law but the judge found it difficult to square the Dutch Council of State’s approach to personal data and data protection with the approach of the EU’s Article 29 Data Protection Working Party in Opinion 4/2007 (on the concept of personal data).
Questions Referred
Appreciating that either party might well appeal the judge’s decision to the Dutch Council of State, the judge was concerned that the Council of State’s rulings about the legal status of the minuut might not be correct. Thus, for the sake of ensuring coherence in the legal order, the judge decided to refer a number of questions to the CJEU. According to the Curia website, the Questions read:
Are the data reproduced in the minute concerning the data subject and which relate to the data subject, personal data within the meaning of Article 2(a) of the Privacy Directive?
Does the legal analysis included in the minute constitute personal data within the meaning of the aforementioned provision?
If the Court of Justice confirms that the data described above are personal data, should the processor/government body grant access to those personal data pursuant to Article 12 of the Privacy Directive and Article 8(2) of the EU Charter?
In that context, may the data subject rely directly on Article 41(2)(b) of the EU Charter, and if so, must the phrase ‘while respecting the legitimate interests of confidentiality [in decision-making]‘ included therein be interpreted in such a way that the right of access to the minute may be refused on that ground?
When the data subject requests access to the minute, should the processor/government body provide a copy of that document in order to do justice to the right of access?
Outcome. On 17 July 2014 the Court ruled (ECLI:EU:C:2014:2081) that the legal analysis in an immigration case minute is not itself personal data — the applicant’s data contained in it are — and that the right of access can be satisfied by a full and intelligible summary rather than a copy of the document. Data protection is for checking one’s data, not a route to the file.
Comment
Y.S is one of three current references to the CJEU about data processing and privacy.
A second case, Digital Rights Ireland, is also about the state’s ability to control and retain data only this time it is on the basis of ensuring that certain data are available for the purposes of investigation, detection and prosecution of serious crime.
A third reference, Google Spain, is also about an individual’s ability to control the data about them which is used by third parties – do individuals have the right to be forgotten?
Update – the Dutch Council of State has made a reference about the ‘minuut’ and the application of EU data protection law, which the CJEU has docketed as Case C-372/12, Minister voor Immigratie, Integratie en Asiel, other parties: M. and S.