ITI - The Information Technology Industry Council

ITI · Trade and business associations · US

Kategorija
Trade and business associations
Būstinė
Washington, D.C. US
Registruota
2015-01-05
Deklaruotos metinės išlaidos
50 000–99 999 € (pačios deklaruota)
Svetainė
http://www.itic.org
Skaidrumo registras
061601915428-87 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

20181201932020620211120228202322024320252920266

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 69 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2026-06-08Communications Networks, Content and TechnologyExchange of views on copyright and AI
2026-04-20Cabinet of Executive Vice-President Henna VirkkunenTech Sovereignty Package
2026-03-18Taxation and Customs Union…the taxation omnibus Pillar 2 simplification and the taxation of the digital economy
2026-03-04Communications Networks, Content and TechnologyCommission proposal on Cybersecurity Act 2.0
2026-02-17TradeWTO and EU-US relations
2026-01-14Cabinet of Commissioner Michael McGrathExchange of views on digital policy
2025-12-09Communications Networks, Content and TechnologyExchange of views on the simplification agenda and the digital omnibus
2025-11-25Internal Market, Industry, Entrepreneurship and SMEsParticipate as speaker at ITI Europe Committee meeting
2025-11-17Cabinet of Executive Vice-President Henna VirkkunenEU tech competitiveness agenda
2025-11-13Communications Networks, Content and TechnologyDigital Omnibus proposal and revision of the Cybersecurity Act
2025-11-12Cabinet of Executive Vice-President Henna VirkkunenEuropean tech sovereignty
2025-10-14EnvironmentITI Sustainability Committee
2025-09-11Communications Networks, Content and TechnologyExchange of views on copyright and AI
2025-05-22TradeDigital trade policy
2025-05-15Communications Networks, Content and TechnologyState of play on the Cloud and AI Development Act.
2025-05-15Cabinet of Commissioner Magnus BrunnerProtectEU Strategy
2025-04-29EnvironmentImplementation of the Ecodesign for Sustainable Products Regulation (ESPR)
2025-04-28Climate ActionDigitalization for decarbonization in industry
2025-04-23Communications Networks, Content and TechnologyExchange of views on AI Act implementation
2025-03-27Cabinet of Commissioner Dan JørgensenDigitalisation and energy
2025-03-27Cabinet of Commissioner Dan JørgensenDigitalisation and energy
2025-03-26Cabinet of Commissioner Wopke HoekstraDiscussion on how the global tech industry can support the EU’s climate goals
2025-03-26Cabinet of Commissioner Wopke HoekstraDiscussion on how the global tech industry can support the EU’s climate goals
2025-03-13Cabinet of Commissioner Valdis DombrovskisSimplification
2025-03-13Cabinet of Executive Vice-President Henna VirkkunenEU digital policy
2025-03-13Cabinet of Commissioner Maroš Šefčovič- EU-U.S. relations on key technology and trade topics - WTO - The digital dimension of the EU Economic Security Strategy & associated EU initiatives - Standardization Regulation revision and trade implications
2025-03-13Cabinet of Commissioner Maroš Šefčovič- EU-U.S. relations on key technology and trade topics - WTO - The digital dimension of the EU Economic Security Strategy & associated EU initiatives - Standardization Regulation revision and trade implications
2025-03-13Cabinet of Commissioner Maroš ŠefčovičInternational trade developments
2025-03-13Cabinet of Commissioner Maroš ŠefčovičInternational trade developments
2025-03-12Justice and ConsumersInform and discuss the Commission's work on the Digitalisation of Justice, AI and data, and consumer law - Digital Fairness Act.
2025-03-12Justice and ConsumersInform and discuss the Commission's work on the Digitalisation of Justice, AI and data, and consumer law - Digital Fairness Act.
2025-03-11Cabinet of Executive Vice-President Stéphane SéjournéPriorities related to the competitiveness compass
2025-03-11Cabinet of Executive Vice-President Stéphane SéjournéPriorities related to the competitiveness compass
2025-03-11EnvironmentExchange of views on the Green Deal legislation and EU’s sustainability goals.
2025-03-11EnvironmentExchange of views on the Green Deal legislation and EU’s sustainability goals.
2024-01-24Cabinet of Vice-President Věra JourováAI
2024-01-24Communications Networks, Content and TechnologyDigital issues
2024-01-24Cabinet of Vice-President Věra JourováAI
2023-11-14Cabinet of Vice-President Věra JourováArtificial Intelligence, EU-U.S. cooperation, cyber-security
2023-11-14Cabinet of Vice-President Věra JourováArtificial Intelligence, EU-U.S. cooperation, cyber-security
2022-10-06Cabinet of Executive Vice-President Margrethe VestagerData Act, AI Act, EU-US Trade and Technology Council
2022-09-16Cabinet of Commissioner Thierry BretonProduct liability directive
2022-09-16Cabinet of Commissioner Thierry BretonProduct liability directive
2022-09-16Cabinet of Commissioner Thierry BretonProduct liability directive
2022-06-29Communications Networks, Content and TechnologyData & Cloud
2022-06-29Communications Networks, Content and TechnologyData & Cloud
2022-05-18Cabinet of Executive Vice-President Margrethe VestagerDigital Services Act, Data Act
2022-04-26Cabinet of Commissioner Didier ReyndersData transfer
2021-10-13Cabinet of Vice-President Věra JourováPrivacy, data flow,transatlantic cooperation
2021-10-13Cabinet of Vice-President Věra JourováPrivacy, data flow,transatlantic cooperation
2021-06-07Cabinet of Commissioner Ylva JohanssonMeeting on the global debate on government access to data, notably within the OECD.
2021-02-25Cabinet of Executive Vice-President Valdis DombrovskisEU-US trade relations; Trade Policy Review; Digital trade, including EU's position on e-commerce and Digital taxation.
2021-02-25Cabinet of Executive Vice-President Valdis DombrovskisEU-US trade relations; Trade Policy Review; Digital trade, including EU's position on e-commerce and Digital taxation.
2021-02-19Cabinet of President Ursula von der LeyenEU policy files relevant to the technology industry - transatlantic trade & data flows, Digital Decade, digital & green, Artificial Intelligence, Digital Services Act, Digital Markets Act
2021-02-19Cabinet of President Ursula von der LeyenEU policy files relevant to the technology industry - transatlantic trade & data flows, Digital Decade, digital & green, Artificial Intelligence, Digital Services Act, Digital Markets Act
2021-02-19Cabinet of Executive Vice-President Margrethe VestagerDSA, DMA, AI
2021-02-11Cabinet of Vice-President Věra JourováDSA, DMA, AI, Privacy and data flows
2021-02-11Cabinet of Vice-President Věra JourováDSA, DMA, AI, Privacy and data flows
2021-02-02Cabinet of Commissioner Thierry BretonDigital priorities for Europe
2020-03-05Cabinet of Commissioner Phil HoganTrade Issues
2020-03-03Cabinet of Commissioner Didier ReyndersPresentation ITI + discuss the priorities with regards to privacy and data protection
2020-01-28Cabinet of Executive Vice-President Margrethe VestagerIntroduction association; artificial intelligence & data strategy; digital services act
2020-01-28Cabinet of Commissioner Thierry BretonPriorities for tech regulation, single market and enforcement
2020-01-28Cabinet of Executive Vice-President Margrethe VestagerIntroduction association; artificial intelligence & data strategy; digital services act
2020-01-28Cabinet of President Ursula von der LeyenOverall digital policy, including technological sovereignty, open multilateral economic governance, trade in technology, data strategy
2019-03-21TradeEU-U.S. trade, WTO, international data flows
2019-03-20Communications Networks, Content and TechnologyAI incl draft ethics guidelines, ePrivacy, GDPR, cybersecurity, Next Generation internet, US digital policies
2019-03-18Justice and Consumers…courtesy
2018-10-09Communications Networks, Content and TechnologyConnect Initiatives: AI, cybersecurity, ePrivacy

Ką pateikė viešoms konsultacijoms

2025-09-10 · Simplification of administrative burdens in environmental legislation ↗ originalus šaltinis
The Information Technology Industry Council (ITI) welcomes the European Commissions initiative to reduce administrative burdens under environmental legislation while maintaining the EUs high level of environmental protection. We believe that the design of a variety of legislative instruments affecting the tech sector is at times overlapping, inconsistent, or redundant in several areas. We have made this clear through our report Simplifying the EUs Tech Rulebook, where we recommend a variety of simplification initiatives that could be undertaken to improve the current situation and make industry less overwhelmed and more competitive, while fully preserving the objectives of legislation.…
2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
The Information Technology Industry Council (ITI) is the premier voice, advocate, and thought leader for the global information and communication technology (ICT) industry. Our member companies include the worlds leading innovation companies, with headquarters worldwide and value chains distributed around the globe. ITI member companies represent the breadth of the technology ecosystem, including semiconductor and computer hardware and software companies, network equipment manufacturers and suppliers, cybersecurity providers, and leading Internet services and consumer technology companies. Privacy and trust are central to our member companies businesses and global operations. Together with…
2023-09-04 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
The Information Technology Industry Council (ITI) the global association of the tech industry appreciates the opportunity to provide feedback on the European Commission's Proposal for a Regulation laying down additional procedural rules relating to the enforcement of the GDPR in cross-border cases (the GDPR Procedural Regulation). We welcome its main goal to make the handling of cross-border GDPR cases more efficient by harmonising certain aspects of administrative procedures and are broadly supportive of this proposal. However, we believe that many improvements could also be made by SAs without new legislation, and achieved by changing how the GDPR is enforced in practice, in particular by…
2023-03-24 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
The Information Technology Industry Council (ITI) is the premier global advocate for technology, representing the worlds most innovative companies. Founded in 1916, ITI is an international trade association with a team of professionals on four continents. We promote public policies and industry standards that advance competition and innovation worldwide. Our diverse membership and expert staff provide policymakers with the broadest perspective and thought leadership from technology, hardware, software, services, and related industries. ITI appreciates the opportunity to comment at an early stage on the Commissions initiative aimed at improving the GDPR enforcement in the cross-border…
2020-04-16 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Dear Sir or Madam, Please find attached our submission commenting on the two-year review of the GDPR. We thank you in advance for considering our views. Best regards, Vivien Zuzok on behalf of the Information Technology Industry Council (ITI)

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 8 p.

ITI response to the European Commission’s Call for Evidence on the Application of the General Data Protection Regulation February 8, 2024 The Information Technology Industry Council (ITI) is the premier voice, advocate, and thought leader for the global information and communication technology (ICT) industry. Our member companies include the world’s leading innovation companies, with headquarters worldwide and value chains distributed around the globe. ITI member companies represent the breadth of the technology ecosystem, including semiconductor and computer hardware and software companies, network equipment manufacturers and suppliers, cybersecurity providers, and leading Internet services and consumer technology companies. Privacy and trust are central to our member companies’ businesses and global operations.

…technology companies. Privacy and trust are central to our member companies’ businesses and global operations. Together with our members, ITI works with governments, regulators, and stakeholders around the world to strengthen and align approaches towards data protection and privacy that safeguard individual rights and promote innovation. I. General Comments The General Data Protection Regulation (GDPR) has had a significant impact on EU and global data governance practices over the past five years. It has helped set a framework of data subject rights and controller/processor obligations that has improved understanding of data processing activities and increased EU and global awareness of the need for secure and responsible personal data management.

…activities and increased EU and global awareness of the need for secure and responsible personal data management. At the same time, the application of such a major piece of complex legislation has been challenging for stakeholders – including citizens, organizations and regulators – and more can be done to improve how it functions in future. ITI considers there are two key areas for improvement which can be achieved without legislative change. First, there needs to be a more proportionate and pragmatic application of the rules that is focused on good consumer outcomes.

…needs to be a more proportionate and pragmatic application of the rules that is focused on good consumer outcomes. This means a reprioritization of the Regulation’s underlying risk-based approach, an emphasis on working with industry to improve outcomes (enforcement cannot be the only measure of success), and greater legal certainty on core GDPR concepts, such as the legal bases for data processing, via guidance and other tools available to supervisory authorities. Second, the EU needs to promote a more flexible system for international data transfers that maintains high standards while recognizing different legitimate legal and cultural approaches to data protection around the world.

…standards while recognizing different legitimate legal and cultural approaches to data protection around the world. Organizations should be encouraged to make full use of the different GDPR transfer tools available, including certification and codes of conduct, so that more scalable solutions can be found at the global level. Ref. Ares(2024)965021 - 08/02/2024 2 The GDPR will also need to adapt and integrate with future EU data frameworks such as the AI Act, Digital Markets Act and Data Act. This will require further engagement with industry and global fora to move forward in a cohesive and proportionate way when it comes to approaches to personal and non-personal data, evolving technologies, and the need for consistency across different enforcement bodies.

…and non-personal data, evolving technologies, and the need for consistency across different enforcement bodies. ITI does not support a broad reopening of the GDPR during the Commission’s 2024-29 term, as this would lead to a further prolonged period of legal instability and confusion among consumers and businesses. We are supportive of narrower reforms, such as through guidance, that introduce legal certainty and support data innovation subject to prior consultation with stakeholders. Separately, we continue to actively engage on the GDPR Enforcement Regulation to ensure the integrity of the One- Stop-Shop mechanism, a fairer more consistent and predictable complaints handling process, and stronger rights of defense for parties under investigation. II.

…and predictable complaints handling process, and stronger rights of defense for parties under investigation. II. Exercise of Data Subject Rights Greater attention should be paid to ensure quick resolution of complaints for consumers through procedural improvements. For example, all Supervisory Authorities (SAs) should require complainants to exhaust a company's internal process first before submitting a matter to a SA. This is consistent with the accountability principle, allows non-GDPR complaints to be identified and addressed quickly, ensures quick resolution of non-complex GDPR complaints, and allows SAs to devote most resources to more complex and egregious complaints. Complaints, including cross border complaints, should be routinely referred to an amicable resolution process and there should be a duty on LSAs to facilitate such resolution.

…routinely referred to an amicable resolution process and there should be a duty on LSAs to facilitate such resolution. Greater clarity is needed on what constitutes a data subject request that is “manifestly unfounded or excessive” (Article 12(5) GDPR). This would help reduce the current administrative burden of proving the inadmissibility of such requests, and enable businesses to respond more effectively to large volumes of inadmissible requests. This is particularly challenging in an employment context where there have been examples of employees relying on GDPR rights as a tool to further egregious employment claims. While the GDPR allows for a two-month extension for organizations to respond to a Data Subject Request, this period can be insufficient in cases where a data subject is unable to or refuses to narrow down the scope of the request.

…can be insufficient in cases where a data subject is unable to or refuses to narrow down the scope of the request. We would recommend regulators exploring options for further flexibility on extended deadlines when dealing with overly broad requests. Inconsistencies remain in relation to DSAR exemptions across Member States despite EDPB issuing Guidelines 01/2022 on Data Subject Rights. This means in practice that different levels of disclosure are provided to data subjects depending on the Member State where the DSAR is exercised. In addition, some Member States (such as Ireland) provide for a list of documented exemptions in its data protection law, whereas others (such as Spain) do not. The absence of written DSAR exemptions further generates uncertainty in these Member States. 3 III. Application of the GDPR to SMEs N/A IV. Use of representative actions under Article 80 GDPR N/A V.

States. 3 III. Application of the GDPR to SMEs N/A IV. Use of representative actions under Article 80 GDPR N/A V. Experience with Data Protection Authorities DPAs have generally taken an overly narrow and at times conflicting interpretation of the GDPR in tension with its underlying economic objectives, making it harder for companies to responsibly innovate and create new services. There needs to be more structured regulatory dialogue between DPAs, industry and other stakeholders to provide a more balanced view of data privacy alongside economic and public interest matters. This would help DPAs stay abreast of cutting-edge data innovations and assess the broader impacts of their decisions, and create a clearer framework for companies to confidently share and test out new ideas (e.g. though EU-wide regulatory sandboxes).

…clearer framework for companies to confidently share and test out new ideas (e.g. though EU-wide regulatory sandboxes). There is a general concern among industry that a narrow reading of the GDPR can lead to poorer consumer outcomes, especially regarding cybersecurity and service performance. Privacy is not an absolute right and should be balanced against other competing fundamental rights including consumers’ right to the benefits of innovation and choice in digital markets. There are many examples of where DPAs or the EDPB have put forward strict privacy rules and guidelines that undermine the GDPR’s risk-based approach and make it harder for businesses to respond to the practical challenges of good data governance.

…risk-based approach and make it harder for businesses to respond to the practical challenges of good data governance. This includes overly strict interpretations of the legal bases for processing (including the legitimate interest standard), impractical approaches to the use of anonymized data (requiring a near-zero risk of re-identification), and burdensome obligations for international transfers. Further clarification is also needed around best practices for the lawful processing of special categories of data, especially in the context of employers driving Diversity and Inclusion programs or organizations training AI systems to remove bias and improve accuracy and fairness. Above all, ITI supports a reaffirmation of the GDPR’s risk-based approach and a clear acknowledgement from DPAs that good data governance is grounded in sound risk-management practices. VI.

35 → 12

originalus šaltinis (PDF) ↗

Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 6 p.

…4 September 2023 ITI comments on the European Commission’s Proposal for a GDPR Procedural Regulation ITI – the Information Technology Industry Council – is the global association of the tech industry, representing 80 of the world’s leading information and communication technology companies from all the segments of the tech sector. Privacy and user trust are central to our member companies’ businesses and global operations. Together with our members, ITI works with European and global institutions as well as supervisory authorities (SA) around the world to strengthen and align approaches towards data protection and privacy that safeguard individual rights and promote innovation.

…and align approaches towards data protection and privacy that safeguard individual rights and promote innovation. 1. Introductory remarks ITI appreciates the opportunity to provide feedback on the European Commission's Proposal for a Regulation laying down additional procedural rules relating to the enforcement of the GDPR in cross- border cases (the GDPR Procedural Regulation). We welcome its main goal to make the handling of cross- border GDPR cases more efficient by harmonising certain aspects of administrative procedures and are broadly supportive of this proposal. As mentioned in our response to the Commission’s consultation on the GDPR enforcement, regular reviews are important so that the GDPR continues to build confidence and drive the right outcomes among individuals and businesses. Businesses of all sizes should benefit from a fair, transparent, and consistent application of…

…businesses. Businesses of all sizes should benefit from a fair, transparent, and consistent application of the GDPR. 2. ITI’s main concerns about the GDPR Procedural Regulation Proposal In general, we believe that many improvements to the functioning of the GDPR could be made without any new legislation, and achieved by changes to the way in which the GDPR is enforced. Good data protection outcomes for individuals should be the measure of success of the GDPR, and enforcement action should be considered as a last resort. This could be done by aiding company compliance, developing timely guidance for fast-moving sectors of the economy, and resolving complaints quickly and amicably.

…timely guidance for fast-moving sectors of the economy, and resolving complaints quickly and amicably. Regarding the latter, complainants should be required to exhaust an organisation's reasonable internal processes first before the complaint is submitted to an amicable resolution process, including in cross-border cases, and finally to the Supervisory Authority (SA). Such a “hierarchy of resolution mechanisms” already exists in other areas, such as in consumer protection law, and permits non- contentious and straightforward complaints to be resolved quickly in the individual’s interest. This does not prevent a lead supervisory authority (LSA) from opening a formal investigation if the matter remains unresolved.

…prevent a lead supervisory authority (LSA) from opening a formal investigation if the matter remains unresolved. Where both company complaint mechanisms and amicable settlement options have been exhausted, clear harmonised thresholds for admissibility of complaints should be set and applied fairly and consistently to cases which a SA recommends for further investigation. Ref. Ares(2023)5987666 - 04/09/2023 2 Instead of prioritising providing tools for dispute resolution between SAs, the proposed Regulation should therefore contain measures for avoiding such disputes in the first place, by requiring, among others, complainants to exhaust an organisation’s internal processes first (as described above) and establishing a specific duty of cooperation between the SAs to agree early consensus and resolution.

…above) and establishing a specific duty of cooperation between the SAs to agree early consensus and resolution. More specifically, we recommend that the Commission and co-legislators take account of the following issues in their consideration of the final Regulation: 1. The proposed Regulation must not weaken the OSS mechanism and LSA independence. 2. The investigated parties’ right to be heard must be effective in practice at all stages; in particular, the investigated parties’ effective right to be heard before the European Data Protection Board (EDPB) must be added. 3. Correspondence and exchange of views between the LSA and CSAs, as well as RROs must be included in the content of the administrative file. Rules on identification and protection of confidentiality must be accompanied by deterrent sanctions to make them work in practice. 4.

…and protection of confidentiality must be accompanied by deterrent sanctions to make them work in practice. 4. More transparency is needed from the very beginning of the investigation. This means that the parties under investigation must be receive all complaints from the LSA. The proposed Regulation must also incentivise early resolution as well as enhance cooperation and amicable resolutions at all stages. The following comments address these main concerns in more detail. We will also provide concrete amendments to the co-legislators at a later stage. 2.1. The OSS mechanism and LSA independence must not be weakened. While we welcome the Commission’s efforts to better align both procedural rules and the substantive application of the GDPR, these efforts should not affect the One-Stop Shop (‘OSS’) concept.

…rules and the substantive application of the GDPR, these efforts should not affect the One-Stop Shop (‘OSS’) concept. This means in particular that the proposal should not touch upon or dilute the “leading” competence of the lead supervisory authority (LSA) or affect the limits of interventions by relevant and reasoned objections (RROs) made by the concerned supervisory authorities (CSAs). Maintaining the competences of the LSA under Article 56 of the GDPR is the most effective method for ensuring the efficient handling of complaints. Maintaining the competences of the LSA should be particularly reflected in Chapter III of the proposal (cooperation between SAs in cross-border cases). We recognise that early cooperation is essential to make the handling of cross-border GDPR cases more efficient.

We recognise that early cooperation is essential to make the handling of cross-border GDPR cases more efficient. However, it is important to ensure that these rules on cross-border cooperation – in particular Article 8 and Article 9 on the information that must be provided by the LSA – will not contribute to increasing the already significant pressure on the LSAs. Similarly, while we understand that there can be practical difficulties with identifying the scope of the investigation (as previously highlighted by the EPDB), we believe that the above-mentioned rules are likely to impinge on the LSA’s independence and margin of discretion to assess the elements of each case. CSAs should not be able to originally co-determine the delineation of the scope of the original 3 investigation, even in complaint-based investigations.

…co-determine the delineation of the scope of the original 3 investigation, even in complaint-based investigations. It is sufficient that the LSA is bound to the principles established by the Court of Justice of the EU on the SA’s obligations and discretion in how to treat complaints and what to investigate. Article 18 of the proposed Regulation sets out rules on the content of RROs, according to which they must a) be based exclusively on factual elements included in the draft decision, and b) not change the scope of the allegations by raising points amounting to new GDPR infringements or changing the intrinsic nature of the allegations raised. We welcome this approach and suggest clarifying further that the latter restriction should not only concern infringements not investigated by the LSA, but also those which the LSA investigated but where it found no infringement.

…not investigated by the LSA, but also those which the LSA investigated but where it found no infringement. It is crucial that the co-legislators will not expand into what is and should remain at the sole discretion of the LSA, particularly fact finding and determination of sanctions. 2.2. The investigated parties’ right to be heard must be effective in practice at all stages. Section 3 of Chapter III of the proposal seeks to harmonise the investigated parties' right to be heard. According to Article 14, LSA must submit its preliminary findings to the parties under investigation, setting out all the facts, the entire legal assessment raised against them, and the corrective measures the LSA intends to use. Where the LSA intends to impose a fine, it must also list in the preliminary findings the relevant elements on which it relies while calculating the fine.

…it must also list in the preliminary findings the relevant elements on which it relies while calculating the fine. The parties under investigation must also be heard under Article 17 where the LSA considers that the revised draft decision raises elements which they should have the opportunity to make their views known. We welcome that the right to be heard in the above-mentioned articles covers both the factual and legal elements raised in the investigation. However, the investigated parties should also be given the opportunity to provide their views under Article 9. According to Article 9, the LSA is required to prepare a summary of key issues before it communicates to a party under investigation. Therefore, the LSA will likely only be relying on the information provided by the complainant, which may be sometimes incorrect and partial.

29 → 12

originalus šaltinis (PDF) ↗

Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 7 p.

ITI comments to the European Commission Initiative further specifying procedural rules relating to the enforcement of the General Data Protection Regulation March 24, 2023 The Information Technology Industry Council (ITI) is the premier voice, advocate, and thought leader for the global information and communication technology (ICT) industry. Our member companies include the world’s leading innovation companies, with headquarters worldwide and value chains distributed around the globe. ITI member companies are leading Internet services and e-commerce companies, wireless and fixed network equipment manufacturers and suppliers, computer hardware and software companies, security and access control providers and consumer technology and electronics companies. 1.

…software companies, security and access control providers and consumer technology and electronics companies. 1. Introductory Remarks ITI appreciates the opportunity to provide early input to inform European Commission (‘Commission’) proposals aimed at improving GDPR enforcement in the cross-border context. The GDPR has become a leading global data protection standard, and regular reviews are important so that it continues to build confidence and drive the right outcomes among individuals and businesses. We remain strong supporters of the One-Stop Shop (‘OSS’) concept, and we encourage efforts to better align both procedural rules and the substantive application of the regulation. At a high-level, we note four key areas for improvement: • Enforcement action should be balanced with other important work to ensure that the GDPR delivers good outcomes for citizens, businesses, and society.

…with other important work to ensure that the GDPR delivers good outcomes for citizens, businesses, and society. Enforcement should not become the primary measure of success for EU regulation and should be better balanced with other activities that create a predictable and stable environment for all stakeholders. This work includes aiding company compliance, resolving consumer complaints quickly and amicably, and developing timely guidance for fast-moving sectors of the economy. Enforcement action should be a last resort. • Businesses of all sizes would benefit from a fair, transparent, and consistent application of the GDPR. Recent Article 65 enforcement decisions show that national Supervisory Authorities (‘SAs’) within the EU differ on the interpretation of important GDPR provisions, such as the scope of certain legal bases for core data processing activities.

…of important GDPR provisions, such as the scope of certain legal bases for core data processing activities. Misalignment is also evident among SAs regarding the remit of the Lead Supervisory Authority (‘LSA’) and of the European Data Protection Board (‘EDPB’). GDPR enforcement in practice has also evidenced concerning practices that have jeopardized the right to due process, including businesses’ right to be heard at the EDPB level, the EDPB’s lack of accountability regarding its decisions, and the lack of confidentiality of the proceedings. We look forward to continued engagement with the Commission and SAs to ensure that GDPR enforcement ensures the Ref. Ares(2023)2140164 - 24/03/2023 2 respect for due process and provides regulatory certainty for individuals and businesses alike.1 • Enforcement activity should take account of wider policy developments.

…for individuals and businesses alike.1 • Enforcement activity should take account of wider policy developments. GDPR enforcement should serve to empower organisations to use information responsibly and confidently, with policymakers and regulators pushing forward a coherent, fair and consistent approach. This becomes more challenging, however, when there is a disconnect between certain SA activities and broader EU policy positioning. For example, regarding investigations and prohibitions on transfers to the US that are unrelated to businesses’ commercial privacy practices but rather founded on theoretical government access and use, and efforts to swiftly finalise the EU-US Data Protection Framework further to the EU and US’s political agreement on the matter.

…to swiftly finalise the EU-US Data Protection Framework further to the EU and US’s political agreement on the matter. • Ongoing stakeholder engagement is needed to ensure the GDPR functions correctly and consistently as new EU data rules are established, such as the EU Artificial Intelligence Act, Data Act, Digital Markets Act (DMA), and Network and Information Security Directive (NIS2). NIS2, for example, complements and further defines and clarifies the scope of the GDPR lawful basis for processing personal information for network and information security purposes2. Whereas the DMA, for example, regulates very different areas with concrete and separate objectives that should not undermine or conflict with the GDPR.

…very different areas with concrete and separate objectives that should not undermine or conflict with the GDPR. At the same time, there is an increasing need for SAs to discuss and align regulatory approaches with other relevant sectoral authorities to avoid companies being caught between competing compliance requirements. Overall, this consultation should be the first step in a broader phase of stakeholder engagement to reach a common understanding around a fair and balanced interpretation of the GDPR that delivers strong data subject protections and enables responsible personal data flows. 2.

…of the GDPR that delivers strong data subject protections and enables responsible personal data flows. 2. Procedural Rules Relating to GDPR Enforcement Cross-border GDPR enforcement cases are becoming more common and more complex and it is important that any changes to procedural rules ensure due process, carefully consider interactions with national procedural rights, and encourage transparency and consistency.

…process, carefully consider interactions with national procedural rights, and encourage transparency and consistency. The following comments are based on ITI members’ understanding of the upcoming initiative based on the Commission’s call for evidence document3 and the EDPB’s October 2022 letter to the Commission on 1 We welcome references to further guidance in the EDPB 2023/24 Work Programme and look forward to opportunities for engagement in these https://edpb.europa.eu/system/files/2023- 02/edpb_work_programme_2023-2024_en.pdf 2 See Recital 121 of Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.

…and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. 3 https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/13745-Further-specifying- procedural-rules-relating-to-the-enforcement-of-the-General-Data-Protection-Regulation_en 3 GDPR procedural aspects4. We look forward to further opportunities to comment on specific proposals once drafted. Improving the Complaint Handling Process Greater attention should be paid to ensuring quick resolution of complaints for consumers and avoiding lengthy and costly litigation which unnecessarily delays resolution for consumers. Many procedural improvements can be made without the need for further regulation. For example, all Supervisory Authorities (SAs) should require complainants to exhaust a company's internal process first before submitting a matter to a SA.

(SAs) should require complainants to exhaust a company's internal process first before submitting a matter to a SA. This is consistent with the accountability principle, allows non-GDPR complaints to be identified and addressed quickly, ensures quick resolution of non- complex GDPR complaints, and allows SAs to devote most resources to more complex and egregious complaints. Complaints, including cross border complaints, should be routinely referred to an amicable resolution process. There should be clear thresholds for admissibility, and these should be applied fairly and consistently to cases which a SA recommends for further investigation. This should include steps to identify and assess vexatious complainants to ensure fairness and avoid outcomes that result in unequal enforcement between competing companies.

…complainants to ensure fairness and avoid outcomes that result in unequal enforcement between competing companies. There should be clear and consistent (and published) thresholds for initiating own volition investigations. A great deal of SA resources can be tied up in such investigations and this impacts resources available for other activities. Greater use of regulatory dialogue could resolve cases without invoking Article 60 and would deliver better outcomes for consumers. SAs should also consider sector specific engagement and guidance to ensure fair interpretation and application of GDPR rules among firms operating in the same market. Risks in Specifying Arbitrary Procedural Deadlines The EDPB has proposed introducing additional deadlines for aspects of cross-border enforcement cases, which will entail changes to the GDPR subject to the appropriate legislative instrument.

31 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 4 p.

Promoting Innovation Worldwide 16 April 2020 ITI comments on the two-year review exercise of the General Data Protection Regulation (GDPR) The Information Technology Industry Council (ITI) is the leading global trade association representing the technology industry. We advocate for policies that promote innovation, open markets, and enable the transformational opportunities that our companies are creating in Europe and beyond. Our members represent the entire spectrum of the technology industry: from internet companies, to hardware and networking equipment manufacturers, to software developers. ITI's diverse membership and staff provide a broad perspective and insight on policy activities around the world.

ITI's diverse membership and staff provide a broad perspective and insight on policy activities around the world. Our industry shares the goal of safeguarding privacy, and together with our members, we are working with the European Commission and Data Protection Authorities (DPAs) around the world on key data protection and privacy issues, including the General Data Protection Regulation (GDPR). In this context, ITI has recently released its Policy Recommendations for a European Tech Agenda 2020- 2024, outlining concrete steps that the EU can take to advance a compelling European tech agenda for the 21st century. This includes several specific recommendations on future privacy policy.

European tech agenda for the 21st century. This includes several specific recommendations on future privacy policy. The GDPR has catalysed a rethinking of data protection at every level, resulting in wide implementation of industry standards, starting from the engineering and product design phases, to internal documentation of risk assessment and compliance efforts. Companies are adapting their conversations with customers by raising the awareness of data protection globally. Another positive impact is the increased attention in the U.S. to call for a comprehensive federal privacy regime over the past two years. While Congressional progress has been slow, we welcomed the U.S. National Institute of Standards and Technology’s (NIST) efforts in releasing their Privacy Framework, which provides guidance to companies on how to comply with privacy regulatory requirements.

…their Privacy Framework, which provides guidance to companies on how to comply with privacy regulatory requirements. GDPR has further served as a global benchmark for new privacy regimes and has inspired legislation in Canada, Japan, California, India and Brazil. Nevertheless, most EU Member State Data Protection Authorities (DPAs) have pointed to a lack of resources and systemic bottlenecks as challenges to efficient and timely enforcement actions within their countries along with resource-intensive cross-border investigations, while at the same time the EDPB recognised that the effective application of the powers and tasks attributed by the GDPR to supervisory authorities are dependent on the resources available to them. These developments highlight a need to assess how to improve harmonised enforcement of the GDPR across Europe.

…to them. These developments highlight a need to assess how to improve harmonised enforcement of the GDPR across Europe. This submission outlines challenges identified by our member companies in advance of the publication of the European Commission’s GDPR report later this year. We hope that our feedback can facilitate a constructive exchange and provide insights to policymakers. Ref. Ares(2020)2084896 - 16/04/2020 2 Key challenges identified by our industry Our industry wholeheartedly welcomed the increased harmonisation the regulation has brought across the EU, which are key for the development and take up of competitiveness-enhancing technologies and services such as Cloud Computing and Artificial Intelligence. However, we have identified a set of challenges that should be borne in mind in an upcoming annual report on the GDPR:

However, we have identified a set of challenges that should be borne in mind in an upcoming annual report on the GDPR: 1. Enhancing cooperation between Member State DPAs: The lack of a consistent approach by DPAs across Member States remains a challenge. Some Member State’s national data protection rules have not been fully aligned with the GDPR; diverging national interpretations, including on the competency to investigate/decide a matter, create inconsistency and insecurity. This could be reduced by DPAs by acknowledgement that when investigating cross-border data processing activities, they will take into consideration the requirements and guidelines of the Lead Authority and follow the procedure outlined in Article 56 of the GDPR. A genuine, strong cooperation among the EU’s DPAs is essential for a coherent application and enforcement of the GDPR across Europe. We would therefore…

…should diverging views emerge. This role also includes the production of harmonised guidance when it is missing. 2. Upholding the one-stop-shop (OSS) mechanism: The OSS mechanism is at the very foundation of the GDPR. A central promise of the GDPR was not only to harmonise the substance of data protection across the EU, but also to harmonise the mechanism by which obligations would be enforced. This would reduce administrative burden and provide legal certainty to both companies and individuals. However, there is a risk that this mechanism is being weakened by some DPAs who are challenging the OSS by pointing to bottlenecks and lack of resources for DPAs. In particular, some DPAs are continuing to initiate proceedings, either directly in front of the main establishment without consideration of the lead authority, or in front of local establishments. At the same time, companies have…

…must ensure appropriate funding for national DPAs to enable them to carry out their work in the best way possible. 3. Ensuring high standards for AI applications: In light of upcoming regulatory approaches to artificial intelligence (AI) and data governance in Europe, we acknowledge that availability of but also responsibility for securing personal data and ethical standards are key, as many promising uses of AI rely on personal data. By leveraging large and diverse datasets and increased computing power and ingenuity, AI developers and other stakeholders innovate across industries to find solutions that will meet the needs of individuals and society in unprecedented ways. We therefore caution against an overly restrictive approach that could risk AI systems being trained on a very restrained set of data due to data protection limitations as this could lead to bias and stifle…

…the right to object, along with the incentive for organisations to take steps to anonymise data for these purposes. 4. Encouraging development of additional guidance: While we appreciate several guidance documents have been published by the EDPB in the past two years, uncertainty prevails around how the GDPR has to be applied in specific circumstances. We would hence encourage additional guidance from the EDPB to be published on certain topics such as data subject rights, Privacy Impact Assessments and risk-based approach in order to increase legal certainty for companies and securing growth and innovation.

…and risk-based approach in order to increase legal certainty for companies and securing growth and innovation. 5. Promoting efficiency, effectiveness and clarity via Codes of Conduct: As stated above, there continues to be divergence between the national laws of EU Member States, DPAs and outstanding guidance from the EDPB. Approval of Codes of Conduct, in particular of general validity and certification mechanisms, seals and marks would go towards addressing these issues, yielding significant benefit for consumers, businesses and regulators. Codes of Conduct can help create clarity on controller/processor obligations, and lead to gains in efficiency and effectiveness in terms of overall compliance and enforcement. Such mechanisms would ease the compliance burden for large and small businesses alike.

…compliance and enforcement. Such mechanisms would ease the compliance burden for large and small businesses alike. 6. Promoting global data flows: In light of the growing importance of global data transfers, we welcome the European Commission’s work on privacy adequacy decisions and encourage continued efforts to promote global legal frameworks to enable data transfers. The adoption of transfer mechanisms pursuant to Article 46 GDPR, including Codes of Conduct, Binding Corporate Rules (BCRs) and certification mechanisms, is appropriate to enhance the efficiency of international data transfers while ensuring compliance with GDPR standards. We welcome that the ongoing revision of Standard Contractual Clauses (SCCs) included also processor-to-processor clauses. A modular mechanism to replace the existing version of SCCs and a sufficient transition period for companies should be guaranteed.…

…timely review and approval, in order to create more certainty around data transfers and reduce administrative burden. 7. Clarifying data processing for Human Resources (HR) purposes: Employers process a diverse array of employee and applicant personal data. When faced with an employee or applicant data subject request, the GDPR (both the Articles and Recitals) provides limited guidance on responses. For example, Article 15(4) states that access requests may be limited where production would “adversely affect the rights and freedoms of other”, but the scope of such rights and freedoms is unduly vague. The recitals only specifically identify such rights as trade secrets, intellectual property and copyrights protecting software. Some EU Member States have further listed the rights and freedoms to be taken into consideration (such as protecting the privacy rights of others), but uniformity…

13 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Digital Single Market and tech policy in general, privacy, intermediaries/platforms issues, international data flows, e-evidence, trade, competition policy, artificial intelligence, data governance, cybersecurity, taxation, sustainability, standardisation, procurement