EUTA · Trade and business associations · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 91 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
EUTA’s Feedback on the General Data Protection Regulation’s Report February 2024 The adoption of the General Data Protection Regulation (GDPR) marked a significant milestone, setting the stage for data protection principles in the EU economy and enhancing consumer trust. GDPR has also become an international standard, inspiring other non-EU countries to adopt similar laws. Members of the EUTA invested significantly to align their services with GDPR requirements. Despite GDPR's ambition to ensure a harmonised EU application, diverging interpretations by national data protection authorities across the EU create legal uncertainty. Companies face high costs in adapting to localised requirements and challenges in determining what good compliance looks like across multiple jurisdictions. A more consistent and harmonised approach should be embraced.
…good compliance looks like across multiple jurisdictions. A more consistent and harmonised approach should be embraced. While the new GDPR procedural regulation marks progress, it falls short of achieving full harmonisation. The interpretation of the GDPR has so far been very legalistic, neglecting the practical implications for businesses and their operational realities. Presently, DPAs overlook the risk-based approach, which should ensure a more equitable balance between the right to personal data and other fundamental rights. DPAs should not have readings that disadvantage certain companies unfairly, leading to distortions in competition. Furthermore, to ensure legal clarity, DPAs should foster greater engagement with the industry.
…in competition. Furthermore, to ensure legal clarity, DPAs should foster greater engagement with the industry. Currently, most DPAs primarily function as GDPR enforcers, unable to support companies in achieving compliance by facilitating or endorsing codes of conduct and certifications. Interactions between DPAs, controllers/processors, and subjects remain intricate and resource-intensive. Additionally, navigating new guidelines and litigation developments poses challenges in keeping abreast of these advancements. Last but not least, the interaction with other laws should also be addressed, particularly concerning conflicts between GDPR and the e-Privacy Directive.
…with other laws should also be addressed, particularly concerning conflicts between GDPR and the e-Privacy Directive. Exercise of data subject rights ● The access to data (Article 15), and data portability (Article 20), seem to either overlap or clash, especially given the rarity of portability requests and the absence of established standards. While the concept of data portability appears sound in theory, its practical application remains, to our knowledge, largely un-used by data subjects. This means that companies have to invest considerably to prepare for potential demands that may never materialise. ● The access to data right should remain proportional and have a clear benefit for the data subject. DPAs should not lose sight of the important workload and cost that such requests can represent for companies.
DPAs should not lose sight of the important workload and cost that such requests can represent for companies. ● The transparency requirements present a challenge, as being simultaneously precise and easy to understand can be incompatible. Moreover, access requests are increasingly The European Tech Alliance | Square de Meeûs 35 | 1000 Brussels, Belgium | [email protected] 1 Ref. Ares(2024)933960 - 07/02/2024 being used strategically, weaponized to gather evidence or support claims against companies rather than upholding data protection rights. ● Exemptions to subject rights, such as ‘legal privilege', lack standardisation across EU jurisdictions, posing challenges in their concrete application. ● The need for similar technical standards extends to consent management.
…challenges in their concrete application. ● The need for similar technical standards extends to consent management. As SAAS and cloud-based solutions become more prevalent in workplaces, the absence of international technical standards for consent data capture and withdrawal persistence is surprising and inefficient. Establishing these standards could benefit software providers, enabling them to incorporate standardised processes into their products and services. ● Right to erasure: Personal data for which the data subject exercises the right of erasure/right to object or withdraw consent may also be used to train an algorithmic model. Therefore the limits of these rights should also be interpreted in light of the current technological developments and within the limits of how far a model can “unlearn”.
…interpreted in light of the current technological developments and within the limits of how far a model can “unlearn”. ● There is an intrinsic tension between the obligation to implement privacy-by-design measures such as pseudonymisation and the need to identify the data subject to properly respond to a right request and to limit the risk of unauthorised access to data. Reliance on an ID card may be a solution but some DPAs have been refusing this as being too intrusive. Companies are therefore left in a very difficult situation, facing an impasse, despite their willingness to do things right. ● It would be welcomed if the Commission could try to ensure that legal cases are serving the purpose of the GDPR and have enough merit to go to Court. The Courts should also recognise that companies live in a data driven economy.
…and have enough merit to go to Court. The Courts should also recognise that companies live in a data driven economy. ● For information, the malicious use of data subject rights was already mentioned in the first GDPR multi stakeholder report in 2020 (see page 9). Use of representative actions under Article 80 GDPR Article 80 of the GDPR is more and more used, especially in the framework of collective redress mechanisms. The representative actions are intended to guarantee that legal proceedings prioritise safeguarding the rights of individuals rather than serving as avenues for financial gains for legal practitioners.
…safeguarding the rights of individuals rather than serving as avenues for financial gains for legal practitioners. To address disparities, forestall redundant actions, and ease the administrative strain on local courts and companies stemming from numerous claims under Article 80 of the GDPR concerning the same issue, we propose considering a more consistent approach between Member States. Experience with Data Protection Authorities The interpretation of the GDPR has so far been very legalistic, often overlooking the practical implications for businesses and their day-to-day operations. Data Protection Authorities (DPAs) and the European Data Protection Board (EDPB) should strive for greater engagement with industry stakeholders, including trade associations and companies.
(EDPB) should strive for greater engagement with industry stakeholders, including trade associations and companies. This engagement is crucial not only to ensure legal certainty but also to grasp market dynamics, prevalent practices, and the potential or actual risks to individuals. An approach grounded in shared practices and practical examples will foster innovation while addressing the prevailing confusion surrounding sanctions imposed by DPAs. Moreover, it will ensure the GDPR's adaptability to technological advancements. Currently, most DPAs primarily The European Tech Alliance | Square de Meeûs 35 | 1000 Brussels, Belgium | [email protected] 2 function as enforcers of the GDPR and do not adequately support companies in achieving compliance.
…as enforcers of the GDPR and do not adequately support companies in achieving compliance. In some countries, engaging with DPAs and gaining their insights into data protection practices or market realities can be extremely challenging. While there have been some positive developments, such as the establishment of regulatory sandboxes and legal assistance programmes, the number of selected projects remains insufficient to meet industry needs. Such collaboration should extend to the drafting of guidelines. European tech companies would appreciate the opportunity to contribute to the initial drafts of guidelines issued by DPAs and the EDPB. DPAs need a clearer understanding of industry practices when providing guidance. To facilitate this collaboration with the industry, DPAs and the EDPB should enhance transparency in their activities and functioning (e.g.
…with the industry, DPAs and the EDPB should enhance transparency in their activities and functioning (e.g. better explain how subgroups operate or explain why certain inputs to consultation are accepted or rejected). It is essential that guidelines remain confined to interpreting the law and do not impose additional obligations on companies beyond the GDPR's requirements. The legal status of numerous EDPB guidelines requires clarification, as does the extent to which companies are bound by them and how courts should consider them. The issuance of guidelines by DPAs at the national level poses challenges, as the GDPR calls for full harmonisation. Ideally, all guidelines should be issued by the EDPB, except for provisions allowing for national specifications. The multitude of national guidelines creates complexity and confusion for European companies engaged in cross-border activities.
34 → 12