ASNEF · Trade and business associations · ES
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 2 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2026-06-24 | Cabinet of Commissioner Maria Luís Albuquerque | Exchange on consumer credit |
| 2026-06-24 | Cabinet of Commissioner Maria Luís Albuquerque | Exchange on consumer credit |
Velázquez, 64-66, 2ª planta - 28001 MADRID www.asnef.com - [email protected] CIF: G28516003 Página 1 February 5th, 2024 ASNEF comments on the application of the General Data Protection Regulation ASNEF, as the trade association of regulated financial institutions of Spain, with EU transparency register number 11218815591-29, presents the following comments with regards to the application of the General Data Protection Regulation (“GDPR”) to assist the Commission in identifying potential challenges in the application of the GDPR. The principle of accountability and the development of codes of conduct (art. 5 and 40) Our experience with the implementation of the principle of accountability has been challenging.
…conduct (art. 5 and 40) Our experience with the implementation of the principle of accountability has been challenging. Due to the principle of accountability, Data Protection Authorities (DPAs), in some occasions, have refrained from expressing opinions regarding the potential development of sector-specific Best Practices Guidelines, as they do not strictly qualify as a “Code of Conduct”. In this regard, organizations would welcome, to ensure legal certainty and transparency, constructive feedback and guidance from the DPAs and their alignment with GDPR principles. DPAs and the European Data Protection Board (EDPB) should play a role in assisting organizations, especially those operating within highly regulated sectors like financial services, with GDPR compliance.
…especially those operating within highly regulated sectors like financial services, with GDPR compliance. In this regard, we advocate for a more collaborative, cooperative and supportive approach between DPAs, the EDPB and the industry, where authorities provide support, insights, and general guidance without necessarily endorsing or formally evaluating specifics. This approach would enhance legal certainty, promoting a culture of compliance without compromising the independence of DPAs and the EDPB and providing greater legal certainty to business sectors in the interpretation of the GDPR. Exercise of right of access, right to rectification and right to erasure by the data subject (arts.
…of the GDPR. Exercise of right of access, right to rectification and right to erasure by the data subject (arts. 15-17) In relation to the exercise of data protection rights of interested parties, we have encountered some difficulties, specifically, in addressing the right of access, to rectification and to erasure. An example of this difficulty is the compliance with the duty to inform the data subject when there is a limited space or entities use interfaces to interact with data subjects, specifically through mobile apps. Regarding the right of access, entities face difficulties when determining the information that shall be provided to the data subject, specifically, with regards to creditworthiness assessments and the minimum information that the response must contain.
…specifically, with regards to creditworthiness assessments and the minimum information that the response must contain. Likewise, data subjects’ requests may sometimes be ambiguous or excessively generic, which makes it difficult for entities to determine in which cases to consider such requests as exercises of the right of access or just an information request about the specific contract that the client maintains with the entity.
…right of access or just an information request about the specific contract that the client maintains with the entity. In relation to the requests received with the aim of rectifying the data of the data subjects due to inaccuracies or because these data subjects are not the holders of the data thereof, entities have encountered difficulties when verifying that the personal data contained in their internal systems does not belong to the contract holders, as the data subject may fail to provide the necessary justificatory documentation, and that results in a delay in addressing the exercise of the right as well as increased costs for the entities, since they must request additional documentation or go beyond their obligation to respond such requests. Ref.
…entities, since they must request additional documentation or go beyond their obligation to respond such requests. Ref. Ares(2024)936857 - 07/02/2024 Velázquez, 64-66, 2ª planta - 28001 MADRID www.asnef.com - [email protected] CIF: G28516003 Página 2 On the other hand, another relevant issue is related to the right of erasure. Entities face situations in which data subjects request the erasure of their data and, subsequently, they exercise the right of access. In these cases, we request further clarifications, guidelines, or criteria with regards to what to respond in situations in which the entities have the data properly blocked, since the Spanish Organic Law that transpose the GDPR is clear, stating that entities must block the data at the disposal of the authorities. The role played by DPAs in giving advice (art.
…entities must block the data at the disposal of the authorities. The role played by DPAs in giving advice (art. 57) We believe that there seems to be room for improvement in terms of responsiveness and the level of support provided to private sector entities by the DPAs and the EDPB in order to make criteria clear to ensure legal certainty. Thus, financial entities and organizations have encountered challenges in receiving timely and constructive guidance from the DPAs and the EDPB when seeking clarifications on GDPR compliance matters. Regarding DPAs’ guidelines and tools, they have been useful in correctly interpreting and applying the GDPR. However, it is crucial to ensure that these guidelines and tools are regularly updated to align with new criteria and rulings.
…it is crucial to ensure that these guidelines and tools are regularly updated to align with new criteria and rulings. Failure to do so may lead to legal uncertainty, casting doubt on the criteria to be considered when applying and complying with the GDPR. In addition, for proper compliance and application of the GDPR, it is imperative for DPAs to issue official publications and notices in the event of changes in criteria. Although DPAs’ orders and penalty resolutions are publicly accessible on web portals, these important criteria changes or updates in guidelines must be more accessible to all data controllers and processors. Currently, entities may even encounter contradictory documentation on the DPAs' own web portals. In any case, the sector emphasizes the need for DPAs not to apply changes in criteria after the initiation of sanctioning procedures.
…sector emphasizes the need for DPAs not to apply changes in criteria after the initiation of sanctioning procedures. The publication of new guidelines and official criteria, as well as their implementation and application, should take place prior to the initiation of sanctioning procedures, the imposition of administrative fines, or other supervisory penalties under GDPR. The need for a more collaborative, guiding, and supportive supervisory approach is once again highlighted. The role played by the EDPB in supporting the practical application of the GDPR (art. 70) The guidelines adopted by the EDPB have been helpful in providing a common interpretation and understanding of the GDPR across the EU. They serve as valuable references for organizations.
…common interpretation and understanding of the GDPR across the EU. They serve as valuable references for organizations. However, we believe that more efforts could be made to ensure harmonization within the EU and consistency in the interpretation of the GDPR among national DPAs to avoid confusion and facilitate compliance. ***** Madrid, 5 de febrero de 2024 Observaciones de ASNEF a la aplicación del Reglamento General de Protección de Datos La Asociación Nacional de Establecimientos Financieros de Crédito (en adelante, “ASNEF” o la “Asociación”), domiciliada en la Calle Velázquez 64-66, de Madrid con número en el registro de transparencia de la UE 11218815591-29, es una Asociación que agrupa en su seno a entidades cuya actividad principal es la financiación del crédito al consumo, siendo todas ellas reguladas y supervisadas.
…cuya actividad principal es la financiación del crédito al consumo, siendo todas ellas reguladas y supervisadas. Esta Asociación comparece Velázquez, 64-66, 2ª planta - 28001 MADRID www.asnef.com - [email protected] CIF: G28516003 Página 3 ante la Comisión Europea y realiza las siguientes observaciones en relación con la consulta pública previa sobre la aplicación del Reglamento General de Protección de Datos (RGPD). El principio de responsabilidad y la elaboración de buenas prácticas sectoriales (arts. 5 y 40) En cuanto a la implementación del principio de responsabilidad, el sector ha enfrentado desafíos. En concreto, debido al principio de responsabilidad, las autoridades nacionales de control (DPAs), en ocasiones, no se han pronunciado respecto de la posible elaboración de Guías de Buenas Prácticas sectoriales, al no ser estrictamente un “Código de Conducta”.
20 → 12
Velázquez, 64-66, 2ª planta - 28001 MADRID - Teléfono: 91.781.44.00 - Fax: 91.431.46.46 www.asnef.com - [email protected] CIF: G28516003 Página 1 April 28th, 2020 Initial identification of issues in the application of the General Data Protection Regulation The Spanish Finance Houses Association (hereby “ASNEF” or “Associaton”) calls for a uniform application of the General Data Protection Regulation (GDPR) since sanctions and real application in the different Member States are not the same. The GDPR seems to be more of a Directive tan a Regulation. Concerning digitalization, the GDPR is not helping to achieve a complete digital transition. A clear example of this is the regulatory limitations within the application of cookies. ASNEF calls for a specific Regulation on E-privacy. Aspects on the GDPR that should be addressed are data auto-filling and data sharing among finance entities.
E-privacy. Aspects on the GDPR that should be addressed are data auto-filling and data sharing among finance entities. Also, international data transfer processes are not uniform. Other aspects of the GDPR that should be addressed: - Consumer Profiling (lack of uniform criteria in the EU). - Storage periods. Furthermore, there is a lack of necessary coordination between the regulatory requirements of financial institutions regarding the control of financial risks, especially responsible lending and over-indebtedness and the limitations of the Regulation and its interpretation and development in certain jurisdictions. Also, ASNEF calls for the mainstreaming of the GDPR with the CCD, regarding aspects consumer consent and legitimate interest. Ignacio Pla Secretary General Ref. Ares(2020)2296369 - 29/04/2020