Draft Amendments to Personal Data Legislation: What Should Businesses Prepare For?

The Council of Ministers of the Republic of Belarus has published for public consultation a draft Law of the Republic of Belarus “On Amendments to Laws concerning Personal Data Protection” (the “Draft Law”).

The Draft Law provides for amendments to Law of the Republic of Belarus No. 99-Z dated 7 May 2021 “On Personal Data Protection” (the “Law”), as well as to certain provisions of other laws.

The main objectives of the proposed amendments are:

  • to reduce the administrative burden on organisations processing personal data;
  • to enhance the protection of citizens’ personal data when it is processed using modern technologies;
  • to clarify certain functions of the National Centre for Personal Data Protection (the “NCPDP”).

If the Draft Law is adopted, organisations will need to review their agreements with authorised persons, consent collection procedures, audio and video recording rules, automated data processing procedures, and approaches to organising internal control.

What Amendments to the Law Are Proposed?

Controllers and Authorised Persons

  • The concept of “joint controllership” is to be introduced.

What does this mean for businesses?

Controllers will be able jointly to organise and/or carry out the processing of personal data. For this purpose, they will be required jointly to determine:

  • the common purposes of the processing;
  • the processing periods;
  • the scope of the data being processed;
  • the persons to whom the data may be disclosed.

Joint controllership will only be permitted on the basis of an agreement between the controllers.

The following rules will apply in relations with data subjects:

  • each controller will bear the burden of proving that the data subject has given consent to that controller’s processing of the data;
  • where a data subject refuses to give consent to one controller, this will constitute a refusal to give consent to all controllers;
  • a data subject will be entitled to approach any of the joint controllers in order to exercise their rights.

The list of mandatory terms to be included in an agreement between a controller and an authorised person will be expanded.

What does this mean for businesses?

Following the adoption of the Draft Law, controllers and authorised persons will need to review their existing agreements and include the following provisions:

the conditions for engaging other persons — sub-authorised persons — to process personal data, where such engagement is permitted;

  1. the obligation of the authorised person to assist the controller in monitoring compliance with the instructions relating to the processing of personal data;
  2. the obligation of the authorised person to notify the controller and the competent authority of any breaches of personal data protection systems without delay, but in any event no later than three working days after becoming aware of such breaches.

Legal Bases for Processing Personal Data

The Draft Law provides for the following amendments:

  1. the criteria for consent to be regarded as freely given, unambiguous and informed will be defined;
  2. the term for which consent is given may be determined by reference to a specific date, a period of time or an event that is certain to occur;
  3. consent given by a data subject in written or electronic form must specify the date on which it was given and contain the data subject’s handwritten signature or electronic digital signature;
  4. the list of circumstances in which the data subject’s consent is not required will be expanded.

In particular, it is proposed that consent will not be required where a controller distributes photographs or video recordings of individuals taken during events as part of news materials for the purpose of providing information about those events.

Automated Processing of Personal Data and Audio and Video Recording

A prohibition is to be introduced on decisions based solely on the automated processing of data.

What does this mean for businesses?

Where a decision is capable of affecting the rights of a data subject, namely by producing legally significant consequences for that person, it may not be based solely on automated data processing.

Exceptions will apply where the data subject has given consent or where such processing is permitted by law.

In all cases, the controller must inform the data subject before such processing begins.

A requirement is also to be introduced to take measures to prevent or minimise the audio and video recording of information that is unrelated to the purpose of the processing.

What does this mean for businesses?

It is proposed to introduce:

  • a prohibition on audio and video recording in areas intended for personal activities, including eating, changing clothes and carrying out personal hygiene procedures;
  • a prohibition on using video recording for the selective observation and monitoring of individual employees, recording working time, monitoring discipline or assessing performance;
  • mandatory notification of audio and video recording by means of special signs; in the case of a telephone call, such notification must be provided before the conversation begins.

Audio and video recording without the data subject’s consent will be permitted where the data subject contacts an emergency dispatch service.

Emergency psychological assistance services will be excluded from this exception.

The retention period for audio and video recordings must not exceed 30 calendar days.

Person Responsible for Internal Control

In order to comply with the requirement to have a person within the organisation responsible for exercising internal control over the processing of personal data, an organisation will be permitted to:

  1. establish a structural unit;
  2. create a separate staff position for an internal control specialist;
  3. assign the responsibilities of the person responsible for internal control to an authorised structural unit or official;
  4. engage a legal entity or individual entrepreneur providing the relevant services.

However, not all of these options will be available to every organisation:

  • Large and medium-sized organisations that have more than 100 employees and process the personal data of more than 100,000 data subjects will be required either to establish a structural unit or to create a separate staff position.
  • Small businesses processing the personal data of fewer than 1,000 data subjects will be permitted to engage a legal entity or individual entrepreneur under a services agreement.

What May Need to Be Reviewed Following the Adoption of the Draft Law?

Organisations should pay particular attention to:

  1. agreements with authorised persons;
  2. procedures for the joint processing of personal data;
  3. the form and validity periods of consents;
  4. automated decision-making processes;
  5. audio and video recording rules;
  6. the model used to organise internal control.

The REVERA team is ready to assess which provisions of the Draft Law affect personal data processing activities within your organisation and to identify which agreements and procedures will need to be reviewed following the adoption of the amendments.

 

Review Data Processing Procedures

Contact a lawyer for consultation