The Croatian authority explains the rules for public participation in school board meetings related to data protection
The Croatian Personal Data Protection Agency (AZOP) issued an opinion on balancing the transparency of school board meetings and data protection during the appointment of a principal.
Responding to a request regarding public attendance at a school board meeting concerning the appointment of an interim principal and the launch of a call for applications, AZOP clarified that the publicity of these meetings is governed by the Law on the Right of Access to Information and not by the GDPR. The disclosure of personal data during a public meeting constitutes processing that must be based on a legal basis under Article 6 of the GDPR and comply with the principles of Article 5. The right to data protection is not absolute and must be balanced against the public's legitimate interest in transparency, in accordance with Article 86 of the GDPR.
The appointment of a principal alone does not justify excluding the public. It is necessary to distinguish data whose disclosure is essential for transparency of the decision. The name, current position, qualifications, and relevant experience of the selected candidate may be disclosed. However, information such as the personal identification number (OIB), address, private contact details, bank data, special categories of data under Article 9, or data relating to criminal convictions under Article 10 must be protected. If discussion of protected data is unavoidable, the public should only be excluded for the relevant part of the meeting, with justification for this restriction. The school, as the data controller, must assess the proportionality of disclosure under Article 5 paragraph 2 and Article 24 of the GDPR, and consult its data protection officer in accordance with Article 39.
Responding to a request regarding public attendance at a school board meeting concerning the appointment of an interim principal and the launch of a call for applications, AZOP clarified that the publicity of these meetings is governed by the Law on the Right of Access to Information and not by the GDPR. The disclosure of personal data during a public meeting constitutes processing that must be based on a legal basis under Article 6 of the GDPR and comply with the principles of Article 5. The right to data protection is not absolute and must be balanced against the public's legitimate interest in transparency, in accordance with Article 86 of the GDPR.
The appointment of a principal alone does not justify excluding the public. It is necessary to distinguish data whose disclosure is essential for transparency of the decision. The name, current position, qualifications, and relevant experience of the selected candidate may be disclosed. However, information such as the personal identification number (OIB), address, private contact details, bank data, special categories of data under Article 9, or data relating to criminal convictions under Article 10 must be protected. If discussion of protected data is unavoidable, the public should only be excluded for the relevant part of the meeting, with justification for this restriction. The school, as the data controller, must assess the proportionality of disclosure under Article 5 paragraph 2 and Article 24 of the GDPR, and consult its data protection officer in accordance with Article 39.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire