14.2 Data Protection, Well-being & the Environment (DigComp 4.2–4.4)

Key Takeaways

  • Processing of personal data within EU institutions, bodies, offices, and agencies (EUIBAs) is governed by Regulation (EU) 2018/1725, supervised by the independent European Data Protection Supervisor (EDPS), operating in parallel with the GDPR (Regulation (EU) 2016/679).
  • The seven foundational data protection principles—lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability—must be demonstrably integrated into all administrative workflows.
  • Under Article 5 of Regulation 2018/1725, public authorities process personal data primarily on the basis of public interest or official statutory authority, whereas 'legitimate interests' cannot be invoked for tasks within an official administrative remit.
  • Data subject rights (including access, rectification, erasure, and objection) are legally enforceable within strict statutory deadlines (one month), requiring Data Protection Impact Assessments (DPIAs) when processing poses high risks.
  • DigComp 4.3 covers health and well-being (ergonomics, the 20-20-20 rule, technostress and the right to disconnect), and 4.4 covers the environmental footprint of digital technology.
Last updated: September 2026

14.2 Data Protection, Well-being & the Environment (DigComp 4.2–4.4)

Official Reference: European Commission Joint Research Centre (JRC) DigComp 2.2. Competence 4.2 (Protecting personal data and privacy), 4.3 (Protecting health and well-being) and 4.4 (Protecting the environment) cover legal data governance, privacy rights, occupational ergonomics, psychosocial balance and the environmental impact of digital technology.

In the European administrative space, the protection of personal data is elevated to the level of a fundamental right under Article 8 of the Charter of Fundamental Rights of the European Union and Article 16 of the Treaty on the Functioning of the European Union (TFEU). European administrators handle vast amounts of citizen and employee personal data, ranging from grant applications and procurement bids to asylum dossiers and personnel files. A thorough command of EU data protection law, coupled with practical strategies for maintaining physical and psychological health in intensive digital work settings, is essential for every AD5 official.


Competence 4.2: Protecting Personal Data and Privacy in the EU Framework

Data protection in the European Union is governed by a dual legislative architecture that harmonizes privacy standards across the single market while establishing rigorous oversight over the Union's own governing bodies.

The Dual Regulatory Architecture: GDPR vs. Regulation (EU) 2018/1725

While public discourse frequently refers to the GDPR as the universal privacy benchmark, European civil servants must distinguish between two primary legal instruments:

  • General Data Protection Regulation (GDPR - Regulation (EU) 2016/679): Applies directly across all EU Member States, governing the processing of personal data by private commercial enterprises, non-governmental entities, and national, regional, and municipal public authorities.
  • Regulation (EU) 2018/1725: Governs the processing of personal data by all European Union institutions, bodies, offices, and agencies (EUIBAs) (such as the European Commission, the Council, the European Parliament, the ECB, and decentralized agencies like EMA or Frontex). It aligns the internal operational standards of EU institutions with the high level of protection established under the GDPR.

The European Data Protection Supervisor (EDPS)

The European Data Protection Supervisor (EDPS) is the independent supervisory authority established under Article 52 of Regulation (EU) 2018/1725, tasked with monitoring and enforcing data protection compliance across all EUIBAs:

  • Supervision & Enforcement: Audits institutional data processing operations, investigates citizen and staff complaints, conducts formal inspections, and possesses binding corrective powers (including ordering the rectification or erasure of data, imposing administrative fines, and issuing temporary or definitive bans on processing).
  • Legislative Consultation: Formulates formal Opinions and Formal Comments on draft EU legislative proposals submitted by the Commission that impact personal data, ensuring emerging technologies and regulatory initiatives respect fundamental privacy rights.
  • Secretariat to the EDPB: Provides analytical and logistical support to the European Data Protection Board (EDPB), the body composed of national data protection authorities that ensures consistent interpretation and enforcement of the GDPR across all Member States.

The Seven Core Principles of Data Protection

Article 4 of Regulation (EU) 2018/1725 (mirrored in Article 5 GDPR) articulates seven foundational principles that must govern every administrative data lifecycle:

  1. Lawfulness, Fairness, and Transparency: Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Institutions must publish clear, accessible privacy statements outlining processing purposes.
  2. Purpose Limitation: Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those original purposes (with narrow exceptions for public interest archiving, scientific research, or statistical analysis).
  3. Data Minimisation: Data collected must be adequate, relevant, and strictly limited to what is necessary in relation to the purposes for which they are processed ("data parsimony").
  4. Accuracy: Personal data must be accurate and kept up to date. Every reasonable step must be taken to ensure inaccurate data are erased or rectified without delay.
  5. Storage Limitation: Data must be kept in an identifiable form for no longer than is necessary for the purposes for which the personal data are processed. Statutory retention schedules must define fixed disposal or anonymization triggers.
  6. Integrity and Confidentiality (Security): Data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage, using appropriate technical or organizational measures (e.g., role-based access control, encryption).
  7. Accountability: The data controller (the administrative unit or institution) is responsible for, and must be able to demonstrate compliance with, all preceding principles through documented policies, logs, and assessments.

Lawful Bases for Processing: The Public Sector Restriction

Every processing activity requires a valid legal basis under Article 5 of Regulation (EU) 2018/1725 (parallel to Article 6 GDPR):

  • Performance of a Task in the Public Interest (Article 5(1)(a)): The primary lawful basis for EU public administration. Processing is necessary for the management and functioning of the institutions or the execution of tasks assigned by Union acts.
  • Compliance with a Legal Obligation (Article 5(1)(b)): Processing necessary to satisfy a statutory legal requirement binding upon the institution (e.g., financial audit obligations under the Financial Regulation).
  • Performance of a Contract (Article 5(1)(c)): Processing necessary for entering into or executing a contract with the individual (e.g., public procurement tenders or employment contracts).
  • Explicit Consent (Article 5(1)(d)): Freely given, specific, informed, and unambiguous indication of the data subject's wishes. In public administration and employer-employee relationships, consent is rarely valid due to the imbalance of power, which compromises the requirement that consent be "freely given".
  • Vital Interests (Article 5(1)(e)): Processing necessary to protect an individual's physical life or bodily integrity during critical emergencies.
  • The "Legitimate Interests" Restriction: Crucially, while private commercial entities frequently rely on "legitimate interests", public authorities cannot rely on legitimate interests for processing carried out in the performance of their official administrative tasks.
Loading diagram...
Data Protection Impact Assessment (DPIA) Decision and Compliance Workflow

Data Subject Rights and Institutional Obligations

Regulation (EU) 2018/1725 provides data subjects with robust, actionable rights regarding their personal data:

Data Subject RightLegal Scope under Regulation 2018/1725Institutional Exceptions & Administrative Boundaries
Right of Access (Art. 17)Individuals can obtain confirmation of processing, a copy of their personal data, and details regarding processing purposes, recipients, and retention periods.May be restricted under Article 25 to safeguard ongoing judicial proceedings, internal audits, or national security.
Right to Rectification (Art. 18)Mandates the immediate correction of inaccurate personal data or completion of incomplete records without undue delay.Does not permit altering historical administrative records that accurately document past procedural events.
Right to Erasure ('Right to be Forgotten') (Art. 19)Individuals may request deletion when data are no longer necessary, consent is withdrawn, or processing is unlawful.Not absolute: Does not apply when retention is necessary for compliance with a legal obligation, public interest tasks, or legal claims defense.
Right to Restriction of Processing (Art. 20)Data processing is suspended (data stored but not modified or shared) while accuracy is verified or unlawful processing is investigated.Permitted during formal administrative appeals or verification periods.
Right to Data Portability (Art. 22)Individuals may receive their data in a structured, commonly used, machine-readable format (e.g., CSV, JSON) and transmit it to another controller.Only applies to automated processing based on consent or contract; inapplicable to statutory public tasks.
Right to Object (Art. 23)Data subjects may object to processing based on public interest tasks on grounds relating to their particular situation.Overridden if the institution demonstrates compelling legitimate grounds that supersede individual interests.
  • Response Deadlines: The institution must respond to data subject requests without undue delay and at the latest within one month of receipt. This period may be extended by two additional months where necessary, taking into account the complexity and number of requests, provided the individual is notified within the first month.

Data Protection by Design, DPOs, and DPIAs

  • Data Protection by Design and by Default (Art. 27): Technical safeguards (such as pseudonymisation, encryption, and strict default access controls) must be integrated into systems at the architectural planning stage, rather than retrofitted post-deployment.
  • Data Protection Officer (DPO): Every EU institution must appoint an independent DPO who advises the administration on compliance, monitors adherence to Regulation 2018/1725, acts as the contact point for the EDPS, and maintains a public register of processing activities.
  • Data Protection Impact Assessment (DPIA - Art. 39): When an intended processing operation is likely to result in a high risk to the rights and freedoms of individuals—particularly when deploying new technologies, conducting large-scale automated profiling, or processing special categories of data (e.g., biometric, health, or political data)—the controller must conduct a DPIA before commencing processing. If residual risks cannot be mitigated by reasonable technical safeguards, the institution must engage in prior consultation with the EDPS.

Competence 4.3: Protecting Health and Well-being

DigComp competence 4.3 asks users to avoid health risks and threats to physical and psychological well-being when using digital technologies, and to protect themselves and others from dangers such as cyberbullying.

Physical Ergonomics and Display Screen Equipment (DSE)

Prolonged computer use in administrative desk roles poses significant physical health hazards, including musculoskeletal disorders (MSDs) and computer vision syndrome (asthenopia). In alignment with EU occupational safety directives:

  • Workstation Configuration: Display screens should be positioned directly in front of the user, approximately 50 to 70 centimeters (arm's length) away. The top third of the monitor screen should sit at or slightly below eye level to promote a neutral neck posture. Chair height must allow feet to rest flat on the floor with thighs horizontal and knees at approximately a 90-degree angle, supported by adjustable lumbar support.
  • Upper Limb Alignment: Forearms should rest parallel to the desk surface, with wrists maintaining a neutral, straight position rather than extended upward or bent laterally, mitigating the risk of carpal tunnel syndrome. The use of ergonomic vertical mice and low-profile split keyboards reduces repetitive strain injuries (RSIs).
  • Visual Fatigue and the 20-20-20 Rule: To alleviate ciliary muscle strain caused by sustained near-point accommodation, administrators should follow the 20-20-20 rule: every 20 minutes, look away from the display screen and focus on an object located at least 20 feet (approximately 6 meters) away for at least 20 seconds. Workspaces should also balance ambient lighting to avoid harsh glare and excessive luminance contrast.

Digital Overload, Technostress, and the Right to Disconnect

The expansion of teleworking and ubiquitous mobile connectivity has introduced substantial psychosocial risks:

  • Technostress and Cognitive Fragmentation: Technostress manifests as mental exhaustion, anxiety, and diminished focus resulting from constant connectivity, continuous notification alerts, and frequent context-switching ("attention residue"). Rapid switching between collaborative chat channels, emails, and legislative drafting degrades complex analytical performance.
  • The Right to Disconnect: The European Parliament adopted a landmark resolution calling for an EU directive on the right to disconnect, establishing an employee's fundamental entitlement to disengage from work-related digital tools outside contractual working hours without fear of professional detriment. Within the Commission, the 2022 rules on working time and hybrid working recognise staff's right to disconnect outside working hours. In practice this means core contact hours and no expectation of replies in the evening or at weekends.

Competence 4.4: Protecting the Environment

DigComp competence 4.4 asks users to be aware of the environmental impact of digital technologies and their use.

Environmental Impact and Circular Electronics

Digital public services generate substantial physical environmental costs that must be actively managed under the European Green Deal and the Circular Economy Action Plan:

  • Energy Consumption of Data Centers: Data centers and enterprise networks powering cloud platforms account for significant global electricity consumption and water usage for server cooling. EU institutions prioritize data centers that operate on certified renewable energy and demonstrate low Power Usage Effectiveness (PUE) ratios.
  • E-Waste and Hardware Lifecycles: Rapid hardware obsolescence drives electronic waste (e-waste), which contains hazardous heavy metals and scarce critical raw materials. The EU Green Public Procurement criteria for computers encourage longer device lifespans, repairability, availability of spare parts and take-back for recycling. Electronic waste is governed by the Waste Electrical and Electronic Equipment (WEEE) Directive.
Test Your Knowledge

A Directorate-General of the European Commission plans to deploy an automated staff analytics tool to evaluate teleworking productivity by tracking keystroke activity, application usage durations, and webcam presence without prior employee consultation. The unit claims the processing is justified under the "legitimate interests" of the institution. Under Regulation (EU) 2018/1725, why is this legal justification invalid?

A
B
C
D
Test Your Knowledge

A citizen whose application for an EU traineeship was rejected files a formal request under Article 19 of Regulation (EU) 2018/1725 demanding the immediate erasure of all interview evaluation notes, committee scores, and HR assessments. The recruitment unit denies the request, stating that the records must be retained for two years to handle potential administrative appeals and European Ombudsman inquiries. Is the recruitment unit's refusal legally compliant?

A
B
C
D
Test Your Knowledge

To mitigate visual fatigue and digital eye strain during prolonged document drafting sessions, occupational health guidelines within EU institutions recommend the '20-20-20' rule. Which of the following describes the correct application of this ergonomic protocol?

A
B
C
D