In a judgment of 14 January 2021, the Belgian Constitutional Court rejected the application brought by the “Federation of Enterprises in Belgium” (hereafter “FEB”) for annulment of Article 221§2 of the Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. When read in conjunction with Article 83§7 of the GDPR, this provision excludes the possibility for the Belgian Data Protection Authority of imposing administrative fines on public authorities that do not offer goods or services on a market in case of violations of data protection legislation.
The FEB argued that Article 221§2 violates Articles 10 and 11 of the Constitution as read in conjunction with numerous legislative provisions as it would create an exoneration for the application of administrative fines for public authorities and their servants or agents, except in the case of public authorities that offer goods or services on a market. It would consequently create an unjustified difference in treatment between these public authorities and all entities governed by private law which are subject to the rules of the GDPR.
The Court sided with the Belgian government and rejected these arguments. First of all, the Court stated that public authorities and private persons are sufficiently comparable categories of persons, since the concept of controller set out in the GDPR applies indiscriminately to the private and public sectors. Moreover, these categories of persons potentially process identical personal data.
However, the Court recalled that the principle of equality and non-discrimination does not preclude a difference in treatment between comparable categories of persons, provided that it is based on an objective criterion and is reasonably justified. The Court clarified that, in the case at hand, the possibility of imposing administrative fines on public authorities is excluded only where two objective criteria are met:
- The status: legal entities governed by public law only perform public service missions and must only serve the general interest;
- The activity: public authorities do not offer goods or services on a market, which implies that they are not likely to compete, in one way or another, with private actors subject to the obligations of the GDPR.
Finally, the Court relied on the preparatory works of Article 221 of the Law of 30 July 2018 to state that the non-application of administrative fines is motivated by the need to ensure the continuity of the public service and not to jeopardise the exercise of a mission of general interest. It stated that the legislator could reasonably consider that it was not necessary to subject the public authorities to the system of administrative fines because the latter are not the only measures capable of guaranteeing compliance with the GDPR. Indeed, the application of alternative measures, such as corrective measures or even criminal sanctions, also allows the reconciliation of the obligation to comply with the GDPR and the need to guarantee the continuity of the public service.
The Court also recalled that the right of any person to obtain compensation for damage suffered as a result of a breach of the GDPR, through damage claims, remains open against public authorities referred to in the contested provision.
For these reasons, the Constitutional Court denied the FEB’s request for a reference for a preliminary ruling to the Court of Justice of the European Union and rejected its application to annul Article 221§2 of the law of 30 July 2018.
Please contact Karel Janssens for further information about this case and/or for general legal advice relating to privacy and data protection.