Abstract
In this paper we propose the idea that compliance of a producer of official statistics to the basic principles of data protection in the preparation of a survey, while imposing additional burden, complexity or even restrictions to the process, can actually prove to be an effective tool to ensure and demonstrate compliance with the Fundamental Principles of Official Statistics and the European Statistics Code of Practice. To show the validity of this idea we utilize the Greek Population and Housing Census of 2021, conducted in 2021 by the Hellenic Statistical Authority (ELSTAT), as a representative example of statistical survey, which was built from the beginning with a primary look to the basic data protection principles of the General Data Protection Regulation of the European Union (GDPR). While preparing the Census we came across the intrinsic interplay that exists between principles of the GDPR and the Fundamental Principles and the Code. In the paper we analyze this interplay as we came across it in the Census and show that it can be used as a tool to strengthen the implementation of basic principles of official statistics in all statistical production processes.
Keywords
Introduction
The collection and analysis of population data through Censuses is a need of the modern state, enabling countries to form policy based on their knowledge of reality and providing social and economic actors with necessary information for their function. The ongoing developments and the setting mentality in the field of data protection, especially in Europe, following the adoption of the General Data Protection Regulation of the European Union (hereinafter “the GDPR”) [1] in 2016, are driving the social and economic landscape and are inevitably intersecting with the production of official statistics.
Censuses are regularly designed on the basis of the Fundamental Principles of Official Statistics (hereinafter “the Fundamental Principles”) [2] and, in the European area in particular, following the principles of the European Statistics Code of Practice [3]. The 2021 Population and Housing Census “in Greece was designed and executed on the basis of these principles, with the introduction of a new element this time: a new personal data protection environment, under which the processes surrounding the raw material of the Census – personal data – was seen not only as a part of the statistical process, but also as a separate activity of processing under the GDPR regiment. Personal data protection legislation was also in force during the previous Census (2011) [4], but the GDPR elevated personal data protection into a distinct, highly organized process, equipped with specific tools, processes that need to be followed and outcomes that need to be realized.
The 2021 Census in Greece [5], being a traditional Census, aimed to reach the entirety of the population. It took place from November 10, 2021 to February 21, 2022, with reference date the 22nd of October 2021. Operations were deployed in stages, beginning with the self-enumeration of people through an application running on the public sector digital portal (
This system was built for optimal results, taking into account existing operational conditions.
A Population Census is by nature a highly intrusive project that involves extensive and varied personal data processing operations on the national scale. The 2021 Census in Greece in particular would ultimately lead to the collection of data on multiple identification features, personal, social, economic, residential, educational and family status for all habitants of Greece, through both automated procedures and the use of contractors that would handle collection. All these data would then be permanently stored in Registers, linked to administrative databases and undergoing continuous updates throughout the years. During its planning the specific privacy and data protection requirements, arising in the European legal space after the introduction of the GDPR, led to a heightened focus on data protection, implemented in a significantly more organized manner in this Census compared to the preceding ones (the Privacy by Design Principle, implemented in this Census, is a distinct example of this).
What we found during this process was that these now highly organized considerations of privacy, while at first seen as posing just another source of legal liability and obligation for the Statistical Office, in reality they presented us with specific tools to fulfill and complement the Fundamental Principles of Official Statistics and the European Statistics Code of Practice, using GDPR principles and techniques.
We begin our analysis with the introduction and we present the idea that we put forward. We then describe the Census and its data protection elements, focusing on the Privacy by Design principle it was built upon in points (1) through (5) below. In point (6) we show how data protection principles interact with the official statistical production in general, particularly how they can lead to restrictions and add complexity to the statistical production, but also how they can be complementary to basic statistical principles and then in point (7) we show how the particular measures and actions that were implemented to build Privacy by Design in the Hellenic 2021 Housing and Population Census actually led to the implementation of basic Fundamental Principles and principles of the Code. Finally, we conclude by summarizing lessons learnt and proposing a way to move forward into the future.
More specifically, after we propose the idea of the paper and describe the way we intend to show its validity, we describe the method of the Census and the reasons that led to its crafting, mainly the prevailing social and political conditions of the time (1), we describe the legal basis of processing which ELSTAT identified as the appropriate one according to article 6 of the GDPR and provide a general account of legal bases that producers of official statistics can rely on for the realization of Censuses and other surveys (2), we account the elements of the Census relating to personal data, i.e. the particular types of data processed, the specific processing activities across the different phases of the Census, the purposes of use of data, and the utilization of data processors (3), we identify the various data protection considerations that arose during the planning of the Census given its method (4), we elucidate how the Census was built on the ’Privacy by Design’ principle of the GDPR taking into account the existing operational limitations and identified data protection considerations (5), we describe how the basic principles of data protection, as found in the GDPR, interact with the basic principles of official statistical production, as found in the Fundamental Principles and the Code (6), and then we show how the specific measures and actions to implement Privacy by Design in the 2021 Hellenic Census also led to the implementation of basic Fundamental Principles and principles of the European Statistics Code of Practice (7). Finally, we conclude by proposing a way to move forward into statistical production for the future, using GDPR tools to strengthen and better communicate the implementation of the Fundamental Principles and the Code.
The proposed idea
In this paper we propose the idea that compliance of a producer of official statistics to the basic principles of data protection, as found in the GDPR, in the preparation of a statistical, while imposing additional burden, complexity and restrictions to the process, can also – and in our view should also – be used as a tool to ensure compliance with the Fundamental Principles of Official Statistics and the European Statistics Code of Practice, and to demonstrate this compliance to the users. To show the validity of this idea we use the Greek Population and Housing Census of 2021, which ELSTAT conducted in 2021, as a representative example of statistical survey, which was built from the beginning with a primary look to the basic data protection principles of the GDPR. We analyze this interplay of GDPR principles and basic official statistics principles as we came across it in the Census and show that it can be used as a tool to strengthen the implementation of basic principles of official statistics in all statistical production processes.
The crafting of the method of the census
The need for flexibility – The design of a data processing system to serve quality, relevance and non-excessive burden to respondents
The introduction of new reporting obligations in European Union regarding population statistics as well as the growing user needs for more granular and timely accurate information on population statistics, were the two main reasons that advocated for a change in the production system. Decennial census data, gathered solely through direct interviews with only the people that were finally reached, cannot serve as a basis for annual compilation of population statistics and it cannot provide accurate and timely information to users.
Under the risk-centric approach of the GDPR a fully electronic Census with the use and combination of administrative sources would be the optimal choice from the privacy perspective, as it would eliminate data exposure to people – the main source of data breach incidents and the main reason of respondent hesitance – and the information would be protected through measurable IT tools. However, the lack of suitable registers and unique identifiers and the institutional and regulatory uncertainty for data transmission and reuse rendered this approach inapplicable and sustained the need to find ways to reach people on a physical level, which traditionally means face to face contact. At the same, the combination of increased informational needs for future statistics (which are not adequately collected though just the traditional face-to-face Census) and the reluctance of parts of the population to respond due to the highly intrusive nature of the face-to-face interviews (combined with the practical and legal difficulties of face-to-face contact created by the coronavirus crisis) made the traditional face-to-face enumeration with an interviewer a sub-optimal choice. A self-enumeration procedure through electronic means would ultimately prove to be the answer to this, as, through the elimination of human exposure and the use of automated procedures, people would be more confident that they would have their data protected and their privacy respected, therefore overcoming reluctance and becoming more personally vested in the whole endeavor. Remaining reluctance, mainly politically rooted, and low familiarization with technology of parts of the population created the need of a parallel procedure of traditional face-to-face contact for those that would not self-enumerate. This traditional count through face-to-face interviews would allow ELSTAT to reach the parts of the population that were either reluctant or unable to use the self-enumeration tools and the final supplementation process through public records – given the fact that unique identifiers (social security and tax identification number) had been gathered through the self-enumeration and were now available – would allow for a complete and accurate account of the population. The set-up of Statistical Registers of Population and Buildings, built from the 2021 Census data, and their interconnection to public databases to serve as the tool for continuous updated information, made necessary by the future legal need for annually updated population data, would be the last step to the creation of this new flexible production system. Finally, the personnel shortage within ELSTAT to execute collection activities – a shortage self-explanatory in projects as extended as a General Census – created the need to contract Enumerators, who would act as data processors. It was in this way that the Census process was crystallized in the three-step process described above, with the use of ELSTAT personnel and external contractors allocated throughout it.
The choice of the legal basis
The need for clarity – The choice of a legal basis to serve the selected processing system pursuant to the principles of a clear mandate for data collection, clarity and transparency
The 2021 Census would involve extensive automated processing activities, including data sharing and reuse amongst public agencies and the running of a permanent dynamically changing register of all natural persons residing in Greece, collection and storing of vast amounts of data and use of tens of thousands of contractors, serving as data processors. Both technical and legal issues arise from such an endeavor, regarding personal data protection and handling, largely tied to GDPR related exposure, resulting from the extensive and varied processing activities concerning the entirety of the population and the use of processors. Adding the compilation of Registers, i.e. a further processing activity, deviating from the initial purpose of collection, elevates the exposure, under the GDPR principle of purpose limitation,1 that requires a clear and declared purpose for processing personal data, prohibiting the use of these data for other purposes. Further processing for statistical purposes is considered to be compatible use, but only under article 89 requirements,2 thus making it a matter of debate.
After consideration, and following a consultation with the National Data Protection Authority, it was decided that the best way to address these issues would be the formation of a solid legal ground for the Census with the introduction of a law.
According to GDPR rules, data processing activities require a concrete legal basis, as particularly indicated in article 6,3 i.e. a specific reason that justifies processing. Legal bases relevant to Census operations would be either element c of article 6, i.e. processing necessary for compliance with a legal obligation of the controller, or element e, i.e. processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority. Following the accountability principle under article 5 par. 2 of the GDPR,4 the use of the legal basis of public interest to conduct processing operations necessary for the Census would result in the need for ELSTAT to identify the specific public interest pursued and justify each processing activity as a necessary one to serve this public interest. This would create a continuous legal insecurity surrounding the Census. The second consideration with public interest as a legal basis is that it would evoke the power of distinct rights under the GDPR: the right to object, which in turn triggers the right to restrict processing or to erase, as well as the right to rectify. Possible exercise of these rights would also create an insecure environment and the need to assess and respond to each individual request, while restricting processing or erasing data at the request of the data subject is directly contradictory to the need of statistical production. The compilation of statistical registers and the additional use of them as sampling frames for future surveys would present an additional complication, as it would constitute further processing for a purpose deviating from the original purpose of collection.
Legislation governing the 2021 population-housing census in Greece.
Legislation governing the 2021 population-housing census in Greece.
In contrast, conducting these processing operations on the basis of a legal obligation and in the way a law dictates does not allow for arguments surrounding the legality of processing. This basis of legal obligation also does not allow for the exercise of the right to object, restrict or erase, nor is the creation of Registers pursuant to it considered to be further processing. A legal obligation as a basis for processing creates the clarity and solidity that is necessary to ensure the smooth conduct of the Census and the set-up and operation of the new flexible production.
As a result of these personal data considerations Law 4772/2021 was introduced and put into force to regulate the Census specifically and in detail, in contrast to past practices of conducting it on the basis of an ad-hoc generic mandate. This would allow for all matters of the Census to be openly discussed in public, for the people to have access to all information about the Census, establishing both transparency and involvement of all stakeholders throughout the legislative procedure and subjecting the Census to public, scientific and parliamentary scrutiny. This in turn would ensure that a clear mandate for the collection of data would be offered and that the statistical processes of the Census would be communicated to the public in an accessible, clear and transparent way.
Consequently, ELSTAT’s legal basis for processing personal data in the 2021 Census, under article 6 of the GDPR, is the legal obligation it carries to conduct the Census (article 6 par. 1 c).
The specific legislation regulating the Census is as depicted in Table 1.
This legislation provides for all matters relating to the organization and execution of the 2021 Census. In the matter of personal data processing in particular it regulates the legal obligation ELSTAT carries to perform the Census, the legal obligation of all people in the country to provide the requested information, the legal obligation of all public agencies in the country to provide all necessary assistance, as well as access to all necessary administrative databases, the scope and objective of the Census, thus setting the purpose of the relevant data processing activities, the specific processing activities that are to be conducted, the bodies and people responsible to perform all processing activities, a detailed list of data that is to be collected and the power to the President of ELSTAT to decide on details for every matter relating to the Census.
Legislation regulating personal data in the 2021 population-housing census in Greece.
The particular articles of legislation tied to each of the above data processing related matters are indicatively shown in Table 2.
Information collected in the 2021 population-housing census in Greece.
The 2021 Census resulted in the collection of a vast amount of personal information on buildings,5 residential status, individual people and family relationships, collective accommodations and people living in them, as well as immigration outflows in connection to the “brain drain” phenomenon. The information collected specifically are as cataloged in Table 3. The purpose of a General Census is to collect current data on the demographic, economic and social characteristics of the population and of housing conditions, through which the country can produce statistical information on all aspects of society. This statistical information will allow for the formation of solid state policies, reflecting actual needs, and for the accommodation of national obligations toward the European Union and international organizations. The subsequent purposes of use then of the collected data in the Census are:
The production of statistical information The aggregated information that will be created and made available to society through the 2021 Census includes: the number of individuals who reside permanently in each Region, Regional Unit, Municipality, Municipal Unit, Community and autonomous settlement, regardless of citizenship and residence status (the Resident Population), the number of citizens registered in each Municipality and Municipal Unit (the Registered Population), the number of dwellings by type and their main characteristics and amenities, the number and composition of households and nuclear families, the demographic, social, educational and economic characteristics of the resident population and the number of individuals who left the country in the last decade for economic/professional reasons and their specific characteristics. The Compilation of Registers for people and buildings The data that was collected in the 2021 Census was to serve as the pool for the compilation of Statistical Population and Buildings Registers. These will then be subjected to continuous updating processes, using linking tools to other administrative records and databases and information from other surveys of ELSTAT. Annual population statistics will be produced through this process, thus accommodating the methodological and informational needs deriving from the new European reporting framework for population statistics, but it will also allow for the production of significantly more granular information for users. Sampling frames The information in the Registers also served as a sampling frame for other surveys, replacing the prior sampling compilation projects that needed to be performed prior to the conduct of certain surveys. Data in the Census were collected through extensive gathering operations, conducted by ELSTAT and tens of thousands of data processors, i.e. the Enumerators,6 that ELSTAT contracted. The data was either inserted in ELSTAT’s database by the data subjects themselves through the Census app, running on the digital portal of the public sector (
Processing activities by phase of operation in the 2021 population-housing census in Greece.
Processing activities by phase of operation in the 2021 population-housing census in Greece.
Processing activities per phase of the Census in particular are as indicated in Table 4.
As analyzed above in point 1, the design of the Census system was dictated by the need to be effective within the specific prevailing socio-political conditions of the time, which made the methods of a fully electronic Census through administrative registers, a fully electronic self-enumeration and a traditional face-to face approach all inadequate for the purposes of this Census and shaped the designed system which combined all methods.
In this system, the main privacy consideration was data exposure to humans – as is the case in all processing activities. And that is because human error is identified as the main source of data breach incidents worldwide [6]. An electronic census through registers and an electronic self-enumeration would both be ideal to minimize this danger, but it was not a plausible solution. The subsequent use of Enumerators (it took tens of thousands to cover the entirety of the country), i.e. external contractors that had to be selected in a very short time frame, multiplied the dangers of privacy breaches by a factor similar to their number. Measures were taken to mitigate these dangers within the implementation of the Privacy by Design principle in the planning of the Census (see point 5 below).
The other key privacy consideration was one that would be found during the next face of the Census, i.e. the creation of a Population Register and its linking to other registers to make production more efficient, timely, less burdensome and of higher quality. Such linking however is a processing activity of elevated dangers for the data subjects, as the quantity of the combined information could allow the creation of profiles and a possible breach would be highly dangerous. Measures were taken to mitigate these dangers within the implementation of the Privacy by Design principle in the planning of the Census (see point 5 below).
The crafting of the ‘Privacy by Design’ principle of the GDPR into the census
What was expected a. Privacy by design is one of the cornerstones of the GDPR data protection era. The principle holds that organizations consider privacy at the initial design stages and throughout the development of new products, processes or services that involve processing personal data. They need to endorse a proactive way of operations, thinking in advance at the planning stages in order to prevent or even exclude possible risk to data, addressing the entire data lifecycle, from acquisition to disposal, rather than simply react or try to remedy damage when it happens. b. There are seven foundational principles for building Privacy by Design into a product, service or procedure [7]. Of these, we will analyze the five most suited for a procedure such as the ones identified in the Census:
Have privacy as the default setting a. Tied to the data minimization principle, this essentially means that the only information that is asked is the information that is actually needed. Embed privacy into the design i. This principle reflects the need for the so-called “data protection triad” (minimization, security, impact reduction) to be incorporated in the design of the procedure, i.e. for the procedure to be built in a way that:
results in asking, collecting, processing and storing the least information possible (data minimization), reduces the risk of data being breached (data security) and limits the impact to data subjects upon a possible data breach (impact reduction). Be proactive not reactive; preventive not remedial i. There needs to be monitoring and reviewing throughout the execution of the procedure, in order to identify data protection needs, new regulatory requirements or risks in advance. Implement end-to-end security – full lifecycle protection i. Security needs to be incorporated throughout the data lifecycle. This is achieved with the use of security and protection techniques and tools, such as encryption, pseudonymization, secure, restricted and monitored access to data, web security techniques, automatic deletion procedures, processing rules and procedures for the personnel etc. Ensure visibility and transparency i. All information about data processing and data protection needs to be clearly communicated to the data subject in plain language in advance. A single contact point needs to be available and easily contacted for questions and requests. Questions must be answered comprehensively and swiftly. What was done These foundational principles are the basis of Privacy by Design. The actual implementation though depends on individual circumstances – who you are, what you are doing, the resources available to you and the nature of the data you process. The specific conditions prevailing (point 1 above) and the privacy considerations that were identified during the planning of the Census (point 4 above) dictated the way Privacy by Design would be incorporated into it. As shown above in point 1, the basic boundaries for the design of the Census system were as follows:
the lack of suitable administrative registers to support an automated census through records, the lack of a population register to serve as a basis, the lack of a unique identifier for citizens and dwellings, preventing linking of administrative registers to the Census database, undefined regulatory environment on data transmission and reuse amongst different administrations and possible lack of trust, that would inhibit the use of administrative data, possible hostility or reluctance of parts of the population and low familiarization with technology, inhibiting a fully electronic self - enumeration, which would result in the elimination of personal contact of data subjects with data processors, lack of adequate ELSTAT staff to conduct collection operations. These were the conditions that made the methods of a fully electronic Census through administrative registers, a fully electronic self-enumeration and a traditional face-to face approach all inadequate for the purposes of this Census and shaped the designed system which combined all methods. It was then under these assumptions that the Privacy by Design principle was incorporated into the Census planning. The approach, taking these social and operational conditions and the privacy considerations identified into account, was oriented towards four main goals:
To minimize danger by:
Carefully deciding which data would be requested and excluding any unnecessary or not suitable information. This was achieved by the careful design of the questionnaire solely on the basis of legally required information or information that resulted from prior extensive consultation with users and the exclusion of information that was not soundly documented as both necessary and appropriate for the specific process (e.g. there were no sensitive data collected, as the collection method, i.e. the completion of the questionnaire from a representative of the household for all members, creates a highly intrusive environment, non-suitable for the gathering of sensitive data). (see focus area a. below) Identifying beforehand all sources of danger and eliminating them from the process all together, if possible, through the alteration of the process (mainly the exclusion of human involvement as much as possible and the use of privacy-enhancing technologies). This was achieved by the conduct of a dedicated Data Protection Impact Assessment (DPIA) that helped expose points of high danger in the procedure and offered alternative courses of action, the introduction of the self-enumeration face, the electronic enumeration face and the supplementation with public registers, which all but eliminated human contact with the collected data and offered data protection tools built into the systems. (see focus area b. below). i. To address danger, where its elimination was not possible, by proactively establishing IT protection tools, solid and specific procedures for data handling and implementing processes for the training and monitoring of personnel, correcting errors and minimizing harm as soon as possible. This was unavoidable given the inability to eliminate all danger or to even exclude processes of high danger, such as the use of thousands of contractors, because of the aforementioned prevailing conditions and purposes of the Census. (see focus area c. and d. below) ii. To create a transparent environment fostering public trust in the procedure (see focus area e. below). iii. To make sure that the creation and future linking of Registers would be a processing activity performed on the legal basis of compliance with a legal obligation (article 6 par. 1 c GDPR) and that it would be transparent and fair, which is why Law 4772/2021 dictates that the compilation of Registers will take place via a Decision of the President of ELSTAT and the linking with administrative registers will need a Common Decision of the President of ELSTAT and the Minister of Digital Governance. Focus areas of Privacy by Design and corresponding actions per area and per Privacy by Design principle
Focus areas and corresponding actions The implementation of the goals focused in these particular focus areas:
Taking care to process only the personal data that was needed and suitable in relation to the identified purposes
Actions to implement goal in the focus area: The Census questionnaire was designed according to the UNECE Recommendations. The variables requested were those mandatory by European Regulation (Regulation 763/2008 on Population and Housing Censuses), and others identified following consultation with public agencies and stakeholders, such as the Advisory Committee of the Hellenic Statistical System (SYEPELSS), Ministries, the e-Government Center for Social Security (IDIKA SA), the Independent Authority for Public Revenue (AADE), the Earthquake Planning and Protection Organization (OASP), the National Confederation of Disabled People of Greece, the users’ conferences of ELSTAT, Municipalities, etc. In that context it was also decided that no sensitive personal data were collected, even though this was a request of groups of users. Furthermore, the collection of the tax identification number and the social security number of each person allowed for the link to data from administrative registers, which would in turn allow for the prevention of unnecessary future exposure of data to people (ELSTAT employees or data processors), that would be asking for them in future surveys, even though these data are already available in administrative records and reachable through automated electronic tools.
Considering data protection issues as part of the design of systems, procedures and practices for the Census
Actions to implement goal in the focus area: There were extensive talks from the early stages of planning procedures on the matter of privacy and data protection, beginning with a consultation with the Data Protection Authority for guidance, consultations with stakeholders and the performance of a DPIA by an independent specialized company to identify issues early on.
Establishing automatic protection features in IT systems and building specific policies for data handling per each phase of the Census for personnel and data processors
Actions to implement goal in the focus area: All applications and systems, either built in-house or from private companies, incorporated protection features and techniques. The core application was the web-based data collection application, which supported both self-enumeration by the citizens as well as data entry functions for the Enumerators. A mobile application was also developed for the support of the buildings enumeration, providing also geo-location features. A suite of applications supported the functions of Enumerator selection and management (retirements, allocation of sectors, replacements, etc.) and progress monitoring per enumerator and per sector. All people handling data under any capacity in the Census were given concrete written directions, procedures, rules and policiesand received training accordingly. Direct employee training on the specific nature of data considerations was administered throughout the Census, a rulebook was created and given to data processors on how to collect, store and handle the data they would acquire, a policy was in place on how to enter private properties and how to ask for data, as well as concrete rules for handling sensitive health information of data processors (test results for covid and vaccination status) when performing training seminars and a written concrete data breach handling procedure.
Making sure that the identity and contact information of those responsible for data protection were available within the organization and to individuals
Actions to implement goal in the focus area: ELSTAT’s Data Protection Officer’s information was easily found on the website of the Organization and within the internal system. The contact information of all ELSTAT departments are also available by name, telephone number and email on the website.
Adopting a ‘plain language’ policy for any public communication about the Census, so that individuals easily understand what is happening with their personal data
Actions to implement goal in the focus area: All information about the Census, the way it would be conducted, the specific questions, the choices people had, the reason and purposes of it etc. was communicated through a simple, structured and clear Q&A section in the website, the actual questionnaire, short videos, infographics, common questions and other relatable features, posted also on social media. Privacy by Design Principles and corresponding actions Actions: The personal data that was asked were the ones needed. The Census questionnaire was designed according to the UNECE Recommendations. The variables were mandatory by European legislation or identified following consultation with public agencies and stakeholders. No sensitive personal data were collected, even though this was a request of groups of users, as they were deemed not suitable for Census procedures. The collection of the tax identification number and the social security number allowed for the link to data from administrative registers, preventing unnecessary future exposure of data to employees or data processors. Actions: The data that was asked were strictly limited to the necessary ones for the Census purposes. Self enumeration procedures enabled data subjects to provide information in privacy, without the need to expose their data to more people than those absolutely necessary. For the data for which exposure to employees and data processors was unavoidable there were procedures and policies in place, in order for exposure to be as non-intrusive as possible. An electronic Management and Monitoring System was developed in-house and used throughout the Census to manage the project. It allowed for real-time monitoring of data collection and for the implementation of automatic completeness and correctness controls. All applications and IT systems, either built in-house or commissioned in private companies, incorporated technical and operational protection features and techniques, e.g.:
to the secure authentication of the citizens that selected the self-enumeration option we used the Central Authentication Services for the public sector, through which every Greek citizen can connect to governmental applications using their unique TAXISNET codes (sso) the administration of the applications was allowed to a limited number of authorized users, while data masking techniques were applied, when appropriate, in order to restrict the personal information displayed for the data collection and storage, ELSTAT opted for the use of cloud services with servers located within E.U. territory (database-as-a-service) with embedded security features and measures (e.g. WAF) the mobile application used for the Buildings Census supported cryptography for the local storage of the selected data, as well as for their transmission to the servers all applications had embedded security features before the launch of the project, ELSTAT performed penetration tests and network vulnerability assessment, in order to identify and address potential risks and vulnerabilities in the internal IT ecosystem. Personnel and data processors were trained on concrete procedures, rules and policies for handling data. Direct employee training on the specific nature of data considerations was administered throughout the Census, a rulebook was created and given to data processors on how to collect, store and handle the data they would acquire, a policy was in place on how to enter private properties and how to ask for data, as well as concrete rules for handling sensitive health information of data processors (test results for covid and vaccination status) when performing training seminars. Incidents relating to personal data were handled on the basis of a specific data breach policy, which had been communicated beforehand to those processing data. Incidents were assessed regarding gravity and possible danger to data subjects, were reported to the Data Protection Authority and communicated to affected people to limit the possible impact. Actions: An impact assessment evaluation and stakeholder consultations were conducted to identify basic elements and considerations for the Census. These consultations revealed user needs, allowing for the choice of data that would be requested to be limited to the necessary and relevant ones. They also revealed the operational and legal limitations that would shape Census operations and data protection mechanisms. A consultation with the Data Protection Authority was carried out for guidance. A DPIA7 was outsourced to an independent specialized company to identify data protection issues early on. The procedures that were set in the law that regulated the Census were aligned to the Digital Transformation Bible’s rules on the interconnection of administrative registers. This allowed for the provision of administrative data, which were necessary for the completion of the Census and the future operation of Registers. Institutional arrangements were made with the administrative data holders, capitalizing on the pre-established excellent cooperation environment. Actions: All available security and protection techniques and tools were used in the IT systems, such as encryption, pseudonymization, secure, restricted and monitored access to data, web security techniques, automatic deletion procedures. Written, detailed and precise processing rules and procedures were given to the personnel and data processors, in addition to the training schemes they underwent. Actions: All information about the Census, the way it would be conducted, the specific questions, the choices people had, the reason and purposes of it e.t.c. were communicated through a simple, structured and clear Q&A section in the website, the actual questionnaire, short videos, infographics, common questions and other relatable features, posted also on social media.
ELSTAT Data Protection Officer’s (DPO) information, as well as the contact information of every department of ELSTAT, was made available and was easily found on the website of the Organisation and within the internal system.
People’s questions and requests regarding their data were answered by the DPO immediately.
Interactions of basic principles of data protection with basic principles of official statistical production
The GDPR is the core personal data protection law in the European Union, introducing a set of principles to be followed whenever processing of personal data takes place. These principles provide that such data must be processed in a way that is:
Lawful, meaning that you process data with a valid legal basis (consent or other), fair, meaning that processing is in the best interest of the person the data is about and that the scope of the processing can be reasonably expected by the person, and transparent, meaning that you clearly communicate what, how, and why you process data to those whose data you process. Of a specific and limited purpose, meaning that you should only process personal data for the purpose that you originally intended and clearly stated. Minimizing data use and based on storage limitation, meaning that data is not to be hoarded and you should not gather or keep more personal data than what you need to fulfill your declared purpose. Accurate, meaning that the data you process must be correct and up to date and that you are responsible to take reasonable measures to ensure that. Ensuring integrity, availability and confidentiality, meaning that you are responsible to implement technical and organizational measures to ensure that data cannot be manipulated by others, that you can uninhibitedly use them when you need to and that only those with a legitimate reason should be able to access them. Based on accountability of the data controller, meaning that you are responsible for the processing of personal data and your compliance with the principles and that you need to be able to demonstrate this compliance at all times.
The GDPR intersects in several areas with the statistical production process and this intersection can result in restrictions for statistical production in terms of data collection and initial and further processing.
For example:
the data minimization principle could limit the scope of a statistical operation, as it dictates that only the data that is absolutely necessary for the cause it is to be used for are allowed to be collected and used (necessity element) and it also imposes a proportionality consideration, as the data that are to be collected must also be deemed to not be extremely intrusive to the data subject’s privacy, regardless of their necessity (proportionallity element). the purpose limitation principle is in a position to create constraints for a statistical operation and limit the potential use of data for secondary purposes (analysis, creation of registers, linking, sample frames), reducing its utility for policymaking and research, as it dictates that data that were initially collected for a specific purpose (e.g. for business) cannot be used for another purpose later on, unless this further processing is found to be compatible with the initial purpose per articles 5,6 and 89 of the GDPR. transparency and the data subject right to be informed (GDPR articles 12 and 13–14) create the necessity for an analytical and easy-to-understand account of all processing that is to take place, which needs to be adequately communicated to the public beforehand, adding complexity to the statistical work and bringing the matter of resources into light. privacy by default and by design (GDPR article 25) also seem to be straining the statistical procedure, as they require specific and highly resource-intensive technical and organizational measures to be incorporated into the entire lifecycle of the statistical process, from design to beyond completion.
At the same time GDPR intersections with the Fundamental Principles and the Code of Practice8 seem to also be complementary, with certain GDPR principles echoing statistical principles, e.g. in the areas of protection of privacy, data minimization and purpose limitation, accountability, lawfulness and transparency, accuracy and accountability.
In particular:
Protection of privacy is found in statistical confidentiality The core data protection principle of respect of privacy correlates with the core statistical principle of confidentiality of individual data. While starting from diverging points of interest (privacy is thought to be an individual personal right that needs to be protected in by itself, while statistical confidentiality is designed to serve as an incentive, to create confidence in the statistical process in order for people to provide necessary information), they both place the protection of an individual’s personal information to the center of the system. The confidentiality principle calls for the use of individual data exclusively for statistical purposes and the non-disclosure of information that can lead to the identification of the individual, serving GDPR requirements for respect of privacy in an absolute manner. Data minimization and purpose limitation is found in the non excessive burden on respondents and relevance Minimization of data is a GDPR requirement allowing only for the collection of what is necessary for the declared purpose and limitation of purpose leads to the use of data only for the purpose it was initially collected. These requirements align with the statistical principle of avoiding any unnecessary burden on respondents and of not collecting or keeping data that are not used, as well as with the principle of relevance of statistical information to user needs, which dictates data collection to be designed upon specific needs for specific statistical outputs. Accountability of the data controller is found in commitment to quality, professional independence and ethical practices The GDPR introduces the principle of accountability, requiring data controllers and processors to be responsible for and able to demonstrate compliance with the regulation. This is mirrored in the commitment to quality, professional independence and adherence to sound methodological standards and ethical practices within the statistical system, ensuring that statistical authorities are accountable for their statistical processes and outputs. Lawfulness and transparency is found in impartiality, objectivity, accessibility and clarity, as well as the mandate for statistical collection Personal data under the GDPR are to be processed in a lawful, fair and transparent manner. The lawfulness and fairness requirement correlates to the statistical principle of a need for a clear legal mandate, impartiality and objectivity, while transparency is served through the statistical principles of accessibility and clarity, leading to methodological transparency and allowing users to know how their data are being used. Accuracy is found in statistical quality and reliability of statistics The accuracy principle in personal data legislation requires that those processing personal data make sure that they are kept accurate throughout their lifecycle. This is implied in the statistical principles of assurance of quality and reliability of the statistical products.
It is in this light that can be seen how GDPR compliance can ultimately lead not to a restrictive environment for Official Statisticians, but rather to a constructive one. GDPR compliance needs actually provide Statistical Offices with a comprehensive legal framework, sitting on a full arsenal of highly structured methodological toolkits, detailed guidelines and implementation techniques developed by official GDPR Authorities, the utilization of which actually complements the principles of official statistical production. Our position in this paper is that we can use these individual privacy tools to introduce further measurable structures in the statistical production system, creating good practices beyond the quality framework. Through these structures we can easily document and publicly communicate both the fairness, legality and social benefit resulting from the use of data and the assurance of data protection, thus promoting trust in official statistical work. To illustrate how such a GDPR structure could be incorporated in the statistical production to the above effect, we present below an example of the most complex and large-scaled statistical work for every country, the Census, and more specifically the 2021 Population and Housing Census in Greece, which was designed using Privacy by Design techniques of the GDPR.
The example of the 2021 Population and Housing Census in Greece – How specific measures and actions to implement Privacy by Design in the Census also led to the implementation of basic Fundamental Principles and principles of the European Statistics Code of Practice
The Privacy by Design principles implemented by ELSTAT in the 2021 Census by the actions detailed in point 5 above, in the end articulated in practice Fundamental Principles of official statistics and principles of the Code of Practice, even though that was not their declared purpose, nor their initial planning. The reasons for implementing these actions were solely based on privacy considerations, but in practice they resulted in the realization of specific statistical principles as well. They eventually served as tools to implement these statistical principles and in some cases they even allowed ELSTAT to convince stakeholders for the need and correctness of certain decisions, that were actually made on statistical and methodological considerations of quality, in a more clear and relatable way, as GDPR principles are in many cases much clearer to the public than the principles of official statistics.This was for example the case with ELSTAT’s refusal to incorporate questions for information of a sensitive nature (health, sexual orientation etc.) in the questionnaire, even though there were specific such requests from users. We made this decision to refuse mainly based on our evaluation that the information collected would be of poor quality, because of the collection method (one member of the household responding for all). i.e. on methodological considerations. We found however that it was easier to communicate this decision based on the obvious privacy considerations it also attracts, as privacy is much easier for the people to relate to.
More specifically:
The actions taken to implement principle 1. “Have privacy as the default setting” effectively led to the implementation of these statistical principles:
The non-excessive burden on respondents principle, as
the data asked of people were the minimum possible, defined either by a legal requirement or by concrete requests by users coupled by specific methodological documentation the set-up of interlinkable Registers will serve as a source of continuous information that will significantly reduce reporting obligations of people in the immediate future. The relevance principle, as data collection was designed upon specific needs for specific statistical outputs, defined either by a legal requirement or by concrete requests by users. The methodological soundness principle, as the data asked of people were defined through specific methodological documentation (because of the need to justify them in light of the minimization requirements of the privacy as the default principle). The clear mandate for the collection of data principle, as a dedicated law, detailing all Census related issues, was introduced (for reasons solely based on privacy considerations, as detailed above, see section “C.2. What was done – The need for clarity – The choice of the legal basis to serve the selected processing system”), thus creating a clear and indisputable mandate. The professional independence of the Statistical Office principle, as extensive consultation with various stakeholders from the administration and the society illustrated the ways a Statistical Office operates. The respect of privacy of individuals principle, as information requested was as little as possible and no sensitive information was collected. The actions taken to implement principle 2.“Embed privacy into the design” effectively led to the implementation of these statistical principles:
The quality principle, as self-enumeration and relevant procedures introduced to reduce the intrusive nature of the Census allowed respondents to provide information in the ease of their privacy, without the need to expose their data face to face to a stranger, which allowed for more detailed and truthful information to be collected. The accuracy principle, as the electronic Management and Monitoring System that was used throughout the Census to manage the project allowed for real-time monitoring of data collection and for the implementation of automatic completeness and correctness controls. The protection of privacy of the individuals and the confidentiality of the information principle, as
self-enumeration and relevant procedures to create an environment as non-intrusive as possible all but eliminated human contact with the data, the technical and operational protection features and techniques incorporated in all applications and IT systems and the concrete rules and policies for all data handlers promoted data security. The action taken to implement principle 3.“Be proactive not reactive; preventive not remedial” effectively led to the implementation of these statistical principles:
The methodological soundness principle and the relevance principle, as the DPIA conducted necessitated the formation of sound methodological descriptions for the data requested, and data requested needed to be tied to specific user needs because of the data minimization processes. The professional independence principle, as collaboration with administrative data holders to prepare for the set-up of Registers deepened the bonds between the Statistical Office and the administration. The actions taken to implement principle 4.“Implement end-to-end security – full lifecycle protection” effectively lead to the implementation of these statistical principles:
The protection of privacy of the individuals and the confidentiality of the information principle, as the technical and operational protection features and techniques incorporated in all applications and IT systems and the concrete rules and policies for all data handlers promoted data security. The actions taken to implement principle 5.“Ensure visibility and transparency” effectively led to the implementation of these statistical principles:
The transparency and clarity principle, as the entirety of the procedures, the reasons and objectives of the Census, available tools, possible considerations of the public etc. were all made accessible to all, clearly presented and easily understood.
Lessons learnt and next steps
The 2021 Census in Greece was a turning point for official statistics in Greece. Being the first Census to be conducted under the scope of the GDPR and built on the Privacy by Design principle it allowed for the introduction of a new, flexible system of production for population statistics, paving the way for the modernization of other statistical products as well.
Through the elevated privacy requirements of the GDPR we were able to identify new ways to better protect the privacy of individuals and we solidified the belief that transparency and openness is key in presenting official statistics to the public. We also found that openly admitting mistakes and taking steps to correct them, as the GDPR requires through its data breach reporting provisions and the transparency principle, can actually lead to positive outcomes and the building of a more trusting relationship with the public.
The implementation of the Privacy by Design principle in the Census, mandatory now because of the introduction of the GDPR, was initially thought that it would be an additional and perhaps excessive burden, especially taking into account the very restricted human resources available for the Census. However, what we found was that the specific actions needed to implement Privacy by Design actually also led to the implementation of basic principles of official statistical production, such as the non-excessive burden on respondents, relevance, methodological soundness, clear mandate for the collection of data, professional independence, confidentiality, clarity etc. We also found that the GDPR and its mandatory force in official statistics can be used as an effective tool to convince stakeholders for the need of certain methodological decisions regarding the process of a survey in a more clear and relatable way, as the GDPR and data protection are seem to be much clearer to the public than the principles of official statistics, as was the case with ELSTAT’s refusal to requests of users to incorporate in the Census questionnaire questions that would lead to the collection of special categories of personal data (sensitive). The reason for this refusal were statistical quality considerations, we found however that it was easier to communicate it on the basis of the privacy considerations it also attracts, as privacy is much easier for the people to relate to.
For our next steps moving forward into statistical production for the future, we believe that we need to use more GDPR tools in our statistical processes and to rethink our methodology of statistical processes under the GDPR light. We need to act in a proactive manner and structure statistical processes based on the minimization principle, searching for the way to produce statistics that is the least intrusive to privacy, making more privacy oriented decisions from the planning of the process and communicate all this in an open and transparent manner. This was, using the GDPR, once seen as a burden in official statistics, now as a strong tool, we can effectively and elegantly demonstrate our commitment to the Fundamental Principles of Official Statistics and the European Statistics Code of Practice.
