Computer & Communication Industry Association (CCIA)

Interesų grupė

Kategorija
Būstinė
Registruota
Deklaruotos metinės išlaidos
(pačios deklaruota)
Skaidrumo registras
15987896534-82
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

201622021220221320236

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 23 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2023-11-28Cabinet of Vice-President Věra JourováEuropean Media Freedom Act
2023-11-28Cabinet of Vice-President Věra JourováEuropean Media Freedom Act
2023-06-27Cabinet of Commissioner Thierry BretonTelecom and digital policies
2023-06-27Cabinet of Commissioner Thierry BretonTelecom and digital policies
2023-06-21Cabinet of Executive Vice-President Margrethe VestagerOpen finance
2023-06-21Cabinet of Executive Vice-President Margrethe VestagerOpen finance
2022-09-29Cabinet of President Ursula von der LeyenTo learn more about the Commission President’s legislative plans for the Fall, notably on a possible internet traffic usage fee.
2022-09-29Cabinet of President Ursula von der LeyenTo learn more about the Commission President’s legislative plans for the Fall, notably on a possible internet traffic usage fee.
2022-09-19Cabinet of Commissioner Thierry BretonContribution to network investment
2022-09-19Cabinet of Commissioner Thierry BretonContribution to network investment
2022-09-16Cabinet of Commissioner Thierry BretonProduct liability directive
2022-09-16Cabinet of Commissioner Thierry BretonProduct liability directive
2022-09-16Cabinet of Commissioner Thierry BretonProduct liability directive
2022-06-02Cabinet of Executive Vice-President Margrethe VestagerTelecom infrastructure fee, CSAM proposal, Digital Services Act.
2022-06-02Cabinet of Executive Vice-President Margrethe VestagerTelecom infrastructure fee, CSAM proposal, Digital Services Act.
2022-04-04Cabinet of Vice-President Věra JourováPolitical Advertising
2022-04-04Cabinet of Vice-President Věra JourováPolitical Advertising
2022-01-26Cabinet of Executive Vice-President Margrethe VestagerData Act, Artificial Intelligence Act, Digital Service Act
2022-01-26Cabinet of Executive Vice-President Margrethe VestagerData Act, Artificial Intelligence Act, Digital Service Act
2021-02-10Cabinet of Executive Vice-President Margrethe VestagerDSA, DMA, AI, data
2021-02-10Cabinet of Executive Vice-President Margrethe VestagerDSA, DMA, AI, data
2016-04-07Communications Networks, Content and TechnologyOnline platforms – OTT/telecoms - Copyright reform- Free flow of data initiative – AVMS/portability
2016-04-07Communications Networks, Content and TechnologyOnline platforms – OTT/telecoms - Copyright reform- Free flow of data initiative – AVMS/portability

Ką pateikė viešoms konsultacijoms

2023-03-23 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
The Computer & Communications Industry Association (CCIA Europe) welcomes the opportunity to share our views on the European Commissions plan to introduce new procedural rules to improve the enforcement of cross-border data protection cases. Since the last GDPR implementation report, we have observed several procedural shortcomings in cross-border cases which undermine the rights of the defendants and the consistent enforcement of the GDPR across the EU. CCIA Europe invites the European Commission to consider addressing the following deficiencies as a matter of priority, in close cooperation with relevant stakeholders including businesses: (1) EDPB decisions must be subject to judicial…
2020-04-28 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
CCIA appreciates the opportunity to provide feedback to the European Commission on the application of the General Data Protection Regulation (‘GDPR’). CCIA firmly believes that the GDPR is a success and should not be reopened. The GDPR strikes the right balance between the protection of European citizens’ personal data and enabling data-driven growth in Europe. Furthermore, we observe that the reach of the GDPR has extended well beyond the EEA, with companies across the world embracing the GDPR accountability model within their own organisation and across their supply chain. However, we do observe several shortcomings in the implementation and enforcement of the GDPR. Some of them can be…

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 7 p.

CCIA Europe | Rue de la Loi 227, 1040 Brussels | www.ccianet.org | Transparency Register #: 15987896534-82 1 CCIA response on the review of the application of the General Data Protection Regulation General comments CCIA firmly believes that the General Data Protection Regulation (GDPR) is a success and should not be reopened. The GDPR strikes the right balance between the protection of European citizens’ personal data and enabling data-driven growth in Europe. The GDPR has extended well beyond the EEA, with companies across the world embracing the GDPR accountability model within their own organisation and across their supply chain. However, we observe several deficiencies in the implementation and enforcement of the GDPR.

…across their supply chain. However, we observe several deficiencies in the implementation and enforcement of the GDPR. They range from (1) a failure to implement all international data transfer instruments, (2) slow and unharmonised guidance for companies to comply with specific aspects of the Regulation, and (3) enforcement actions which undermine the One-Stop-Shop principle. While some of them can be resolved through modest and practical improvements, others arise from structural deficiencies (local SAs) and fail to live up to the objectives and spirit of the GDPR. The GDPR remains a living regulation and CCIA is concerned that the enforcement status quo would, in the long term, bring severe discredit to what is otherwise a robust piece of legislation. CCIA appreciates the opportunity to submit our detailed observations and suggestions for improvements on the following aspects:

…the opportunity to submit our detailed observations and suggestions for improvements on the following aspects: 1. Data transfer instruments ............................................................................................................................... 2 • Adequacy decisions .......................................................................................................................... 2 • Standard Contractual Clauses ......................................................................................................... 3 • Binding Corporate Rules .................................................................................................................. 3 • Codes of Conduct and Certifications .............................................................................................. 4 • Intra-EU transfers within the same group of undertakings…

…transfers within the same group of undertakings .......................................................... 4 2. Consistency and cooperation mechanisms ................................................................................................. 4 • One-Stop-Shop at risk ...................................................................................................................... 5 • Discrepancies between national guidance and practices on harmonized data protection rules ..................................................................................................................................................... 6 Ref. Ares(2020)2276782 - 28/04/2020 CCIA Europe | Rue de la Loi 227, 1040 Brussels | www.ccianet.org | Transparency Register #: 15987896534-82 2 1.

Europe | Rue de la Loi 227, 1040 Brussels | www.ccianet.org | Transparency Register #: 15987896534-82 2 1. Data transfer instruments Since the GDPR entered into force, most organisations transferring data outside the EEA have had 2 out of 5 transfer mechanisms at their disposal, namely Standard Contractual Clauses (SCCs) and adequacy decisions. There is a pressing need to develop other transfer mechanisms already contemplated in the GDPR, especially at a time when the legality of both the SCCs and Privacy Shield decisions are being questioned in court. Supervisory Authorities (SAs) have an important role to ensure that European and international organisations have the full range of data transfer instruments at their disposal and prevent any interruption of data flows between the EU and the rest of the world.

…instruments at their disposal and prevent any interruption of data flows between the EU and the rest of the world. These alternative mechanisms would complement SCCs and Privacy Shield, that we consider should be preserved. Overall, there is a growing discrepancy between the urgency felt on the ground to develop additional transfer mechanisms, and the limited resources available to most SAs to conduct their work efficiently in this respect. At the same time, we are cognizant of the fact that SAs’ lack of resources is a larger structural issue that affects other aspects of GDPR enforcement. We therefore urge Member States to allocate appropriate resources to their SA and ensure an efficient implementation of all aspects of the GDPR, including the review and approval of binding corporate rules (BCR), draft codes of conduct and certifications.

…including the review and approval of binding corporate rules (BCR), draft codes of conduct and certifications. We provide additional observations on all data transfer instruments and recommendations for improvements further below. Adequacy decisions (a) General comments CCIA was pleased to see the recent adoption of the Commission adequacy decision applicable to the transfers of personal data to Japan. We encourage the Commission to continue exploring opportunities for additional adequacy decisions in other third countries, in line with 2017 Communication on Exchanging and Protecting Personal Data in a Globalised World (COM(2017) 7). (b) EU-UK personal data transfers We take note of the provisions on cross-border data flows and personal data protection in the Draft text of the Agreement on the New Partnership with the United Kingdom (UKTF (2020) 14).

…data protection in the Draft text of the Agreement on the New Partnership with the United Kingdom (UKTF (2020) 14). CCIA appreciates the Commission’s efforts to review the adequacy of the United Kingdom within the transition period. Consistent with the EU’s approach to international data protection negotiations, we believe the UK adequacy assessment should be performed and completed within this timeframe regardless of the outcome of the on-going trade negotiations between the two parties. Lastly, we believe that the adequacy review of the UK should be prioritised over any other adequacy assessment given the strong data-driven economic relationship between the EU and the UK.

…over any other adequacy assessment given the strong data-driven economic relationship between the EU and the UK. (c) EU-US Privacy Shield Framework CCIA and our Members appreciate the Commission’s continuous and rigorous review of the EU-US Privacy Shield Framework, and we remain committed to provide as much information as needed to help the Commission assess the functioning of this transatlantic framework. We believe that the degree of scrutiny brings additional credibility to the transfer of personal data to Privacy Shield certified organisations. For this reason, we encourage the Commission to replicate this review exercise to other adequate jurisdictions where it sees fit.

…we encourage the Commission to replicate this review exercise to other adequate jurisdictions where it sees fit. CCIA Europe | Rue de la Loi 227, 1040 Brussels | www.ccianet.org | Transparency Register #: 15987896534-82 3 Standard Contractual Clauses CCIA appreciates the Commission’s commitment to review the existing decisions on SCCs. In doing so, we encourage the Commission to reflect on the need to amend Decision 2016/2297 so that model clauses may be used by controllers established outside the European Union. We note that Article 2 and Clauses 9 and 11 of Decision 206/2297 currently restrict the use of model clauses to ‘data exporters’/controllers established in the EU. Yet, neither Article 46 nor any other provision of the GDPR preclude ‘data exporters’/controllers established outside the Union from using standard contractual clauses to transfer data overseas.

…exporters’/controllers established outside the Union from using standard contractual clauses to transfer data overseas. We also encourage the Commission to adopt model clauses that may be used for the transfer of data from a processor to a sub-processor. As it stands, Decision 2016/2297 allows controllers only to export data outside the European Union. Yet in practice, processors often export data to sub- processors, for instance in the case of multi-cloud solutions and technology stacks1. While clause 11 does address sub-processing scenarios, the definitions of ‘data exporter’ and ‘data importer’ and the obligations and liability thereof are drafted with a controller-to-processor relationship in mind. New SCCs should address the specificities of processor-to-processor relationships.

…relationship in mind. New SCCs should address the specificities of processor-to-processor relationships. Binding Corporate Rules BCRs can be a useful alternative data transfer instrument that the GDPR has now codified. However, the slow pace of the review and approval process significantly undermines the attractiveness and usefulness of this transfer mechanism. Two years after the entry into force of the GDPR, we note that the review and approval process take at least 12 months and up to 4 years depending on the competent SA involved. A common observation is a prolonged lack of feedback from SAs throughout the review and implementation process. We also note that the European Data Protection Board (‘EDPB’) also experiences significant delay in approving national decisions related to BCRs2.

35 → 12

originalus šaltinis (PDF) ↗

Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 9 p.

…ccianet.org • @CCIAeurope RESPONSE TO EC CONSULTATION ON GDPR ENFORCEMENT RULES Enhancing the Effectiveness and Credibility of GDPR Enforcement 23 March 2023 Executive summary The Computer & Communications Industry Association (CCIA Europe) welcomes the opportunity to share our views on the European Commission’s plan to introduce new procedural rules to improve the enforcement of cross-border data protection cases. Since the last GDPR implementation report,1 we have observed several procedural shortcomings in cross-border cases which undermine the rights of the defendants and the consistent enforcement of the GDPR across the EU. CCIA Europe invites the European Commission to consider addressing the following deficiencies as a matter of priority, in close cooperation with relevant stakeholders including businesses: 1. EDPB decisions must be subject to judicial oversight;

…cooperation with relevant stakeholders including businesses: 1. EDPB decisions must be subject to judicial oversight; 2. The defendant’s right to be heard should be given utmost consideration at national and EDPB levels; 3. New rules should oblige authorities to cooperate with one another in GDPR cases initiated by authorities other than data protection Supervisory Authorities (SAs); 4. To prioritise faster cooperation procedure, the EDPB should have an obligation to assess whether the objections raised by Concerned Supervisory Authorities (CSAs) are ‘relevant’ and ‘reasoned’; 5.

…to assess whether the objections raised by Concerned Supervisory Authorities (CSAs) are ‘relevant’ and ‘reasoned’; 5. Swift fixes to ensure faster case-handling, including: (a) mandatory exhaustion of company’s internal processes before complaints can be made to SAs, (b) new rules specifying to what extent a Supervisory Authority can initiate proceedings with a controller whose main establishment is situated in another Member State, (c) fair and consistent admissibility threshold, and (d) automatic closure of cross-border complaints past a given period of inactivity. We would also like to share some observations and concerns related to the European Data Protection Board’s (EDPB) wish list, published on 10 October 2022,2 insofar as the European Commission is considering some or all of those options to improve cooperation between Supervisory Authorities (SAs) in cross-border cases.

…some or all of those options to improve cooperation between Supervisory Authorities (SAs) in cross-border cases. In addition, CCIA Europe invites the European Commission to explicitly extend the scope of the One-Stop-Shop and Consistency mechanisms in GDPR, to all laws where SAs have been assigned data protection enforcement competencies, including for instance the AI Act or the Platform Work Directive. This would help streamline enforcement, clarity, legal certainty and consistency across the board. 2 EDPB Letter to the EU Commission on procedural aspects that could be harmonised at EU level, 10 October 2022; 1 COM(2020) 264 final, 24 June 2020 available on https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020DC0264 Rue de la Loi 227, First Floor • 1040 Brussels • Belgium pg.1 Ref.

…de la Loi 227, First Floor • 1040 Brussels • Belgium pg.1 Ref. Ares(2023)2099460 - 23/03/2023 ccianet.org • @CCIAeurope Last but not least, we are concerned that enforcement, including the sheer number of cases, the speed of case-handling, and the sanctions imposed on high profile companies, has become the main metric of success of the GDPR. This trend is creating significant legal and commercial uncertainty for businesses, and risks having lasting impacts on confidence in the digital economy on innovation and investments in the EU. In our view, fair application and consistent levels of compliance should be a more holistic way to measure the success of GDPR, or any regulation for that matter.

…levels of compliance should be a more holistic way to measure the success of GDPR, or any regulation for that matter. While CCIA Europe welcomes a review of cross-border enforcement, we invite the European Commission to encourage SAs to rebalance enforcement with greater investment in aiding companies’ compliance efforts, including via sectoral engagement and sector-specific, practical guidance where needed, and in enabling timely resolutions for consumers and educating citizens about data-driven services. 1. EDPB decisions must be subject to judicial oversight Controllers and processors must have a right to appeal an EDPB binding decision following the Article 65 GDPR dispute resolution procedure.

…must have a right to appeal an EDPB binding decision following the Article 65 GDPR dispute resolution procedure. An EDPB decision “concerning” a specific company in a dispute resolution procedure necessarily affects the company’s legal position insofar as the Lead Supervisory Authority (LSA) has no discretion to depart from the EDPB’s findings in its final decision, consistent with Article 65(2) GDPR. However, the EU General Court recently ruled otherwise3 and effectively rescinded the right of any company subject to a cross-border dispute resolution procedure from contesting an EDPB decision on procedural grounds.

…company subject to a cross-border dispute resolution procedure from contesting an EDPB decision on procedural grounds. As such, the EDPB is de facto unaccountable for any alleged procedural violations which may affect the fundamental rights of the defence, including among others the right to good administration, the right to access relevant documents in the proceedings, the right to be heard, and the presumption of innocence. Further, we note that companies have currently no guarantee to be able to challenge the very substance of an EDPB decision directly affecting them. Although Recital 143 GDPR states that a national court must refer the question of validity of an EDPB decision to the EU Court of Justice, in practice however, the national court has sole discretion to decide whether the complaint it receives pertains to the validity of the LSA decision, or the underlying EDPB decision.

…decide whether the complaint it receives pertains to the validity of the LSA decision, or the underlying EDPB decision. CCIA Europe expects the dispute resolution procedure to become the main procedural avenue to handle cross-border cases, not least because the EDPB has shown little appetite to thoroughly scrutinise whether the objections it receives from Concerned Supervisory Authorities (CSAs) are in fact “reasoned” and “relevant.” It is therefore essential that anyone affected by an EDPB binding decision “concerning” him or her has a meaningful right to judicial redress.

…that anyone affected by an EDPB binding decision “concerning” him or her has a meaningful right to judicial redress. Incidentally, it would seem contradictory if anyone in the EU were to be deprived of their right to an effective redress while the EU 3 Order of the General Court in Case T-709/21 (WhatsApp Ireland v European Data Protection Board), 7 December 2022; Rue de la Loi 227, First Floor • 1040 Brussels • Belgium pg.2 ccianet.org • @CCIAeurope (rightfully) expects third countries to observe this right in order to be recognised as providing a level of protection which is “essentially equivalent” to the EU.

…this right in order to be recognised as providing a level of protection which is “essentially equivalent” to the EU. For all those reasons, CCIA Europe strongly encourages the European Commission to explicitly clarify that any controller or processor subject to a case escalated at EDPB level pursuant to the Article 65 GDPR procedure may appeal an EDPB decision before the EU General Court, pursuant to Article 263 TFEU. 2. Strengthening the right to be heard at national and EDPB levels CCIA Europe calls on the European Commission to ensure that a party subject to an investigation has an opportunity to be heard before any decision which adversely affects him or her is taken.

…to an investigation has an opportunity to be heard before any decision which adversely affects him or her is taken. The right to be heard is a general principle of EU law enshrined in Article 41 of the Charter of Fundamental Rights (CFR), and must therefore be applied broadly, even where no specific legislative provision provides for it.4 As such, the right to be heard must fully apply in cross-border proceedings conducted by the competent national SA and by the EDPB when it is tasked to settle disputes between the LSA and CSAs in the context of a dispute resolution procedure. At national level, CCIA Europe observes that the right to be heard is applied differently from one Member State to another. We therefore call on the European Commission to harmonise at Article 60 and 65 GDPR level the right to a fair hearing and the corresponding right to obtain pertinent records.

40 → 12

originalus šaltinis (PDF) ↗