Interesų grupė
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 3 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2022-09-16 | Cabinet of Commissioner Thierry Breton | Product liability directive |
| 2022-09-16 | Cabinet of Commissioner Thierry Breton | Product liability directive |
| 2022-09-16 | Cabinet of Commissioner Thierry Breton | Product liability directive |
DevelopersAlliance.org +1 571 458 7458 [email protected] 1201 Wilson Blvd Floor 27 Arlington VA 22209 The Developers Alliance Response To The Stakeholder Consultation On The Report On The Implementation Of The General Data Protection Regulation (GDPR) Following the call for feedback on the implementation of the General Data Protection Regulation (GDPR), 2 years after its entry into application, please accept the Developers Alliance’s contribution. 1 Our response will highlight the main challenges encountered by our members in complying with the Regulation. According to Article 97 of the GDPR, the Commission's Report should particularly consider the international transfer of personal data to non-EU countries and the cooperation and consistency mechanism between national data protection authorities (DPAs), therefore our contribution will focus on these issues. I. General…
(DPAs), therefore our contribution will focus on these issues. I. General Considerations On The Impact Of GDPR 1. The impact on startups and SMEs have been considerable: legal and compliance costs, legal uncertainty, impact on the business model and investor confidence, resulting in certain cases in product abandonment, entrepreneurial discouragement (and even business closures), and generally in startups and SMEs struggling to accommodate the cost of compliance. As the Multistakeholder Expert Group Report of June 2019 also mentions, SMEs allocated substantial resources to comply with the Regulation. Companies' reactions embraced different ways to implement compliance, according to their business needs. External expertise (consultants, lawyers) represented the main solution to interpret all the rules and to identify the best ways for compliance.
…lawyers) represented the main solution to interpret all the rules and to identify the best ways for compliance. The cost of such expertise is highly burdensome for small businesses. Moreover, in certain cases the advice received didn’t provide the necessary legal certainty since the interpretation of some provisions or concepts remains at the discretion of DPAs and/or courts. EDPB guidelines are welcomed but sometimes not sufficient in addressing the inconsistencies between the national implementation frameworks leading to different legal interpretations and enforcement discrepancies. From a technical perspective, compliance efforts were also significant. It was essential to re-assess the data collection and processing practices. Adapting internal systems already in place or creating new ones required not only investment but also incremental human resources.
…systems already in place or creating new ones required not only investment but also incremental human resources. Unintended effects, such as innovation-constraints, should be considered and properly assessed. Developers have worked to build solutions to make the products and services compliant (personal data inventories, documentation, privacy-friendly interfaces, product architecture, data processes inventories and reconfiguring processes, appropriate data storage locations, and so on). Many startups and SMEs couldn’t rely on in-house expertise and resources alone and were obliged to seek external innovative solutions for ensuring compliance (privacy technology), but at the same time they were forced to abandon ideas, projects, product features, and even entire products and services due to compliance cost and/or compliance uncertainty.
…projects, product features, and even entire products and services due to compliance cost and/or compliance uncertainty. Data collecting restrictions have reduced access to data for data-driven businesses. Consumer product optimization and location-based services have been impacted. The issue is highly relevant in particular for the field of artificial intelligence, where the quantity and quality of datasets is critical. Another unintended negative effect of the regulation is the specific impact on European ventures relative to their counterparts in the US and the rest of the world. These negative effects were found to manifest in the number and amounts raised in 2 financing deals and is particularly pronounced for newer, data-related, and business- to-consumer ventures.
…raised in 2 financing deals and is particularly pronounced for newer, data-related, and business- to-consumer ventures. Beyond this, the Regulation cements the standing of the largest The Developers Alliance is the leading advocate for the global software developers workforce and the companies that depend on them, supporting the 1 industry’s continued growth and promoting innovation. The Developers Alliance teams in Washington, DC and Brussels work with members and policymakers to better understand industry and technological changes and to create an environment that promotes and rewards innovation. The Short-Run Effects of GDPR on Technology Venture Investment 2 Ref.
…environment that promotes and rewards innovation. The Short-Run Effects of GDPR on Technology Venture Investment 2 Ref. Ares(2020)2277225 - 28/04/2020 DevelopersAlliance.org +1 571 458 7458 [email protected] 1201 Wilson Blvd Floor 27 Arlington VA 22209 companies (who can absorb the compliance cost and have the experts they need) while creating barriers for SMEs to grow. After 2 years of implementation, more evidence and proper assessment are needed in order to quantify the benefit to users and to better understand the tradeoffs involved. Some figures already suggest that GDPR may not actually be delivering that much 3 value to the majority of users, while revenue impacts and high compliance costs place a clear burden on many startups and SMEs. 2.
…majority of users, while revenue impacts and high compliance costs place a clear burden on many startups and SMEs. 2. The GDPR’s extraterritorial impact has created incentives for foreign regulators to extend their own laws into the EU, creating overlapping and conflicting requirements for companies both inside and outside the EU. Two recent notable examples come from the US: The California Consumer Privacy Act (CCPA) is enforced on businesses located outside of the state of California and without a physical presence there if any of their users reside in the state. The US Children's Online Privacy Protection Act (COPPA) applies to foreign-based websites that are either directed to children in the US or which knowingly collect personal information from children in the US.
…that are either directed to children in the US or which knowingly collect personal information from children in the US. This regulatory approach is clearly inspired by the extraterritorial scope of the GDPR and one can be expected to see similar attitudes from other regulators across the world. The GDPR may be celebrated in Europe as a blueprint for data protection and privacy, but its extraterritorial reach encourages and ignores conflicts with international law. The CJEU landmark Judgment in Case C-507/17 on the right to be forgotten 4 demonstrates the limits of global regulation; underlining the fact that the balance between the right to privacy and the protection of personal data, on the one hand, and the freedom of information of internet users, on the other, is likely to vary significantly around the world.
…hand, and the freedom of information of internet users, on the other, is likely to vary significantly around the world. The large majority of software developer businesses are targeting multiple markets. Developers tend to have a global market perspective from the start, and in many cases, their operations are pursued in several jurisdictions bounded only by the internet’s reach. The conflict of laws represents a source of legal uncertainty with a direct impact on their business decisions. The context of Brexit is adding another layer of legal uncertainty for those companies operating within the UK's jurisdiction. The difficulty again resides mainly in the GDPR’s approach in mandating extraterritorial enforcement of its provisions, ignoring other jurisdictions' regulatory power and political will, and thus endangering the continuity of cross border operations for many companies.
…regulatory power and political will, and thus endangering the continuity of cross border operations for many companies. 3. The GDPR correlation with other sectoral legislation and legislative initiatives (e.g. the proposal on the ePrivacy Regulation) should be carefully considered in order to preserve its risk-based approach and to avoid interfering with the enforcement mechanisms established by the Regulation. In particular, since the framework provided by the GDPR is still evolving, any new regulation which impacts related digital services (cybersecurity, AI, IoT, etc. ) should be put off until GDPR has stabilized. II. International Transfer Of Personal Data To Non-EU Countries
IoT, etc. ) should be put off until GDPR has stabilized. II. International Transfer Of Personal Data To Non-EU Countries 1. Cross-border transfers of data, some of it personal, to third countries or international organisations are a vital part of our modern technology sector. The development of digital businesses would be impossible without such data transfers. The GDPR approach to restrict data flows between the EU and other countries, ab initio, and to compel the enforcement of its provision by each country, represents a structural flaw. The extraterritorial scope of the Regulation is often defended as an effective step in creating uniform regulation at the international level. In reality, the enforcement of an EU regulation by relying on foreign enforcement authorities ignores their regulatory autonomy. The adequacy mechanism, based on a country by country assessment, is insufficient for…
24 → 12