04.02.21

Gemini version available ♊︎

The EPO Bundestagate — Part 4: Parroting the GDPR-Compliance Myth

Posted in Deception, Europe, Patents at 7:54 pm by Dr. Roy Schestowitz

Series index:

  1. The EPO Bundestagate — Part 1: How the Bundestag Was (and Continues to be) Misled About EPO Affairs
  2. The EPO Bundestagate — Part 2: Lack of Parliamentary Oversight, Many Questions and Few Answers…
  3. The EPO Bundestagate — Part 3: A “Minor Interpellation” in the German Bundestag
  4. You are here ☞ Parroting the GDPR-Compliance Myth

EPO's GDPR-Compliance Myth
What could possibly have led the German government to parrot the EPO’s bogus and self-serving claims about GDPR-compliance?

Summary: The EPO had been in violation of GDPR (EU) for years, both under Benoît Battistelli and António Campinos; but the lies persisted

Back in October 2019, the FDP submitted another “minor interpellation” entitled “Data protection in relation to cooperation with the EPO” (“Datenschutz bei EPA-Zusammenarbeit”Bundestag Printed Paper [PDF] no. 19/14490).

This interpellation contained a series of questions relating to the EPO’s data protection framework, in particular in the context of data exchanges with national authorities such as the German Patent & Trademark Office.

“This interpellation contained a series of questions relating to the EPO’s data protection framework, in particular in the context of data exchanges with national authorities such as the German Patent & Trademark Office.”Under point 7. of the interpellation, the FDP explicitly raised the issue of the compliance of the EPO’s data protection framework with the GDPR (which had entered into force over a year previously in May 2018).

The relevant passage of the interpellation reads as follows (in translation):

According to the knowledge of the Federal Government, is data processing at the EPO compliant with the provisions of the GDPR, or does it have any indications that would suggest a deviation from GDPR regulations?

The response of the Federal Government was published on 12 November 2019 (Bundestag Printed Paper [PDF] no. 19/15072).

The passage of the response which addresses point 7. of the FDP’s interpellation reads as follows (in translation):

The Federal Government has no indication that the EPO does not comply with the provisions of the European data protection standards. The Board of Auditors of the European Patent Organisation, which is appointed by the Administrative Council under Article 49(1) EPC and carries out its activities in accordance with Articles 49 and 50 EPC and its Rules of Procedure and professional auditing standards, stated the following in its audit report for the financial year 2018 (document CA/20/19) (warning: epo.org link). Although the EPO, as an international organization, is not directly subject to EU rules, the basic principles of the GDPR have nevertheless been implemented, as data of European citizens are processed at the EPO. In addition, it was noted that for the sake of transparency, the EPO has already established a data protection register in the past to record all processing of personal data. Upon request, the information can be made available (publicly) to the data subject, thus ensuring the right to information.

The government’s response is another classic piece of hand-waving and obfuscation about the atrociously deficient state of the EPO’s data protection framework.

It is however worth looking at this response more closely because it seems to have come straight from the EPO’s internal “echo chamber”. There is very little evidence of any independent thought or research on the part of those responsible for drafting the government’s statement of its position.

“It seems that the reader is supposed to accept these assertions on “blind faith”.”What is particularly noteworthy is the fact that the German government appears to rely solely on the EPO’s internal audit report for the financial year 2018 (CA/20/19) (warning: epo.org link) as the basis for its “considered opinion” that the EPO’s data protection framework is GDPR-compliant.

There’s just one small problem here.

Neither CA/20/19 nor any other internal “audit report” from the EPO contains a meaningful substantive assessment of the organisation’s data protection framework and its purported compliance with GDPR standards.

The available audit reports from the EPO (CA/20/18, CA/20/19, CA/20/20) (warning: all are epo.org links) only contain cursory self-serving assertions to the effect that the organisation’s data protection framework is “relatively closely aligned” with EU data processing regulations – whatever that is supposed to mean.

What is conspicuously absent is a credible independent audit of the EPO’s data protection framework that could be considered to substantiate the self-serving assertions emanating from the EPO’s senior management.

It seems that the reader is supposed to accept these assertions on “blind faith”.

“For this reason it’s a bit disconcerting to see the Federal Government of Germany still parroting the EPO’s manifestly bogus and self-serving assertions about GDPR-compliance in such a naïve and uncritical manner in November 2019.”However, this becomes difficult when it is recalled that back in 2016 the EPO staff union (SUEPO) commissioned a report about various aspects of EPO governance from external legal experts.

This report dated 31 May 2016 – which is publicly available – found that the EPO’s data protection framework was not compliant with EU data protection standards and that it was in urgent need of a radical overhaul.

Nothing of substance has changed since May 2016.

For this reason it’s a bit disconcerting to see the Federal Government of Germany still parroting the EPO’s manifestly bogus and self-serving assertions about GDPR-compliance in such a naïve and uncritical manner in November 2019.

In the next part we will consider how this curious state of affairs came about.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. Links 28/05/2023: eGates System Collapses, More High TCO Stories (Microsoft Windows)

    Links for the day



  2. IRC Proceedings: Saturday, May 27, 2023

    IRC logs for Saturday, May 27, 2023



  3. No More Twitter, Mastodon, and Diaspora for Tux Machines (Goodbye to Social Control Media)

    People would benefit from mass abandonment of such pseudo-social pseudo-media.



  4. Links 28/05/2023: New Wine and More

    Links for the day



  5. Links 27/05/2023: Plans Made for GNU's 40th Anniversary

    Links for the day



  6. Social Control Media Needs to be Purged and We Need to Convince Others to Quit It Too (to Protect Ourselves as Individuals and as a Society)

    With the Tux Machines anniversary (19 years) just days away we seriously consider abandoning all social control media accounts of that site, including Mastodon and Diaspora; social control networks do far more harm than good and they’ve gotten a lot worse over time



  7. Anonymously Travelling: Still Feasible?

    The short story is that in the UK it's still possible to travel anonymously by bus, tram, and train (even with shades, hat and mask/s on), but how long for? Or how much longer have we got before this too gets banned under the false guise of "protecting us" (or "smart"/"modern")?



  8. With EUIPO in Focus, and Even an EU Kangaroo Tribunal, EPO Corruption (and Cross-Pollination With This EU Agency) Becomes a Major Liability/Risk to the EU

    With the UPC days away (an illegal and unconstitutional kangaroo court system, tied to the European Union in spite of critical deficiencies) it’s curious to see EPO scandals of corruption spilling over to the European Union already



  9. European Patent Office (EPO) Management Not Supported by the EPO's Applicants, So Why Is It Still There?

    This third translation in the batch is an article similar to the prior one, but the text is a bit different (“Patente ohne Wert”)



  10. EPO Applicants Complain That Patent Quality Sank and EPO Management Isn't Listening (Nor Caring)

    SUEPO has just released 3 translations of new articles in German (here is the first of the batch); the following is the second of the three (“Kritik am Europäischen Patentamt – Patente ohne Wert?”)



  11. German Media About Industry Patent Quality Charter (IPQC) and the European Patent Office (EPO)

    SUEPO has just released 3 translations of new articles in German; this is the first of the three (“Industrie kritisiert Europäisches Patentamt”)



  12. Geminispace Continues to Grow Even If (or When) Stéphane Bortzmeyer Stops Measuring Its Growth

    A Gemini crawler called Lupa (Free/libre software) has been used for years by Stéphane Bortzmeyer to study Gemini and report on how the community was evolving, especially from a technical perspective; but his own instance of Lupa has produced no up-to-date results for several weeks



  13. Links 27/05/2023: Goodbyes to Tina Turner

    Links for the day



  14. HMRC: You Can Click and Type to Report Crime, But No Feedback or Reference Number Given

    The crimes of Sirius ‘Open Source’ were reported 7 days ago to HMRC (equivalent to the IRS in the US, more or less); but there has been no visible progress and no tracking reference is given to identify the report



  15. IRC Proceedings: Friday, May 26, 2023

    IRC logs for Friday, May 26, 2023



  16. One Week After Sirius Open Source Was Reported to HM Revenue and Customs (HMRC) for Tax Fraud: No Response, No Action, Nothing...

    One week ago we reported tax abuses of Sirius ‘Open Source’ to HMRC; we still wait for any actual signs that HMRC is doing anything at all about the matter (Sirius has British government clients, so maybe they’d rather not look into that, in which case HMRC might be reported to the Ombudsman for malpractice)



  17. Links 26/05/2023: Weston 12.0 Highlights and US Debt Limit Panic

    Links for the day



  18. Gemini Links 26/05/2023: New People in Gemini

    Links for the day



  19. IRC Proceedings: Thursday, May 25, 2023

    IRC logs for Thursday, May 25, 2023



  20. Links 26/05/2023: Qt 6.5.1 and Subsystems in GNUnet

    Links for the day



  21. Links 25/05/2023: Mesa 23.1.1 and Debian Reunion

    Links for the day



  22. Links 25/05/2023: IBM as Leading Wayland Pusher

    Links for the day



  23. IRC Proceedings: Wednesday, May 24, 2023

    IRC logs for Wednesday, May 24, 2023



  24. Links 25/05/2023: Istio 1.16.5 and Curl 8.1.1

    Links for the day



  25. Gemini Links 25/05/2023: On Profit and Desire for Gemini

    Links for the day



  26. SiliconANGLE: Sponsored by Microsoft and Red Hat to Conduct the Marriage Ceremony

    SiliconANGLE insists that paying SiliconANGLE money for coverage does not lead to bias, but every sane person who keeps abreast of SiliconANGLE — and I read their entire feed every day — knows that it’s a ludicrous lie (Red Hat/IBM and the Linux Foundation also buy puff pieces and “event coverage” from SiliconANGLE, so it’s marketing disguised as “journalism”



  27. Links 24/05/2023: Podman Desktop 1.0, BSDCan 2024, and More

    Links for the day



  28. Gemini Links 24/05/2023: Razors, Profit, and More

    Links for the day



  29. [Meme] When the Patent Office Controls Kangaroo Patent Courts and Judges

    The EPO has been hijacked by industry and its lobbyists; now the same is happening to EU patent courts, even though it is illegal and unconstitutional



  30. The Illegally 'Revised' Unified Patent Court Agreement (UPCA) is Disgracing the Perception of Law and Order in the European Union

    The Unified Patent Court (UPC) isn’t legal, the Unified Patent Court Agreement (UPCA) is being altered on the fly (by a person patently ineligible to do so), and so it generally looks like even patent courts across Europe might soon become as corrupt as the European Patent Office, which has no basis in the Rule of the Law and is basically just a front for large corporations (most of them aren’t even European)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts