Non-governmental organisations, platforms and networks and similar · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 20 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
…22 March 2023 Access Now’s feedback to the European Commission Consultation on “Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation” Introduction 2 1. The Regulation should apply to national and cross-border cases (Scope of the law) 6
Regulation” Introduction 2 1. The Regulation should apply to national and cross-border cases (Scope of the law) 6 2. The Regulation will harmonise the following procedurals rules for data protection complaints 6 a. Right to lodge a complaint: Data subjects will be provided with clear information on how to exercise their right to lodge a complaint in their chosen official language 6 b. Admissibility and scope of complaints: DPAs shall review admissibility of complaints only once and based on criteria detailed in this Regulation 8 c. Guarantee the Fundamental Right to Good Administration 9 i. Right to be heard and party: Both the complainant and defendant are parties and have a right to be heard by the Lead Supervisory Authority and the European Data Protection Board 10 ii. Access to documents: Both parties, as well as all EDPB members and secretariat, will have access to documents…
…will have access to documents related to the cases 11 iii. Decision: The LSA will always issue a reasoned decision 12 3. The Regulation should established a detailed process and timeline for cooperation in cases under mechanisms detailed by Article 60 and 65 of the GDPR 13 4. The Regulation could introduce a “fast-track” process for the resolution of selected cases 15 5. The Regulation could requires all members of the EDPB to appoint an EU data protection Commissioner or point person tasked with cooperation 15 6. The Regulation should mandate the creation of a new IT system for case monitoring, cooperation, and reporting 15 Conclusion 17 Annex I : Right to be heard in Administrative laws of EEA States 18 1 Ref.
…and reporting 15 Conclusion 17 Annex I : Right to be heard in Administrative laws of EEA States 18 1 Ref. Ares(2023)2086222 - 22/03/2023 Introduction Access Now supports the initiative launched by the European Commission aimed at strengthening and improving the application and enforcement of the General Data Protection Regulation (GDPR).1 Since the GDPR became applicable in May 2018, Data Protection Authorities (DPAs) across the European Economic Area (EEA) have levied a total of 1,538 fines for € 2,760,480,432.2 Yet despite these results, alarm bells over the unequal and slow enforcement of the GDPR have been ringing in Brussels and across Member States for a few years now.3 The resolution of complaints, in particular cross-border ones, is often facing hurdles due to discrepancies and difficulties in the way national DPAs work together.
…ones, is often facing hurdles due to discrepancies and difficulties in the way national DPAs work together. While the GDPR has established a cooperation mechanism for DPAs to resolve cases together, most of them rely on their national administrative procedure to operate within this European system.
…cases together, most of them rely on their national administrative procedure to operate within this European system. A 2022 study conducted by the Data Protection Law Scholars Network for Access Now shows that, in practice, data subjects across the European Union do not have an equal right to lodge a complaint under the GDPR as DPAs apply different and sometimes contradictory practices to handle complaints.4 This happens despite the principle of primacy of EU law and the existence of guidance from the European Data Protection Board (EDPB) on how to apply the GDPR which indicates that “an interpretation of a given provision must not undermine the effectiveness of EU law”.5 6 Faced with difficulties in filing cases with DPAs or obtaining a decision, people and NGOs have been considering directly turning to courts to enforce the GDPR.
DPAs or obtaining a decision, people and NGOs have been considering directly turning to courts to enforce the GDPR. When the European Commission proposed the GDPR in 2012, it specifically sought to address the difficulties people had in getting remedy in relation to data protection violations via the courts.7 The European Commission therefore 7 The Impact Assessment accompanying the proposal for the GDPR pointed out that: “(d)espite the fact that many cases where an individual is affected by an infringement of data protection rules also affect a considerable number of other individuals in a similar situation, in many Member States judicial remedies, while available, are very rarely pursued in practice”.
…in a similar situation, in many Member States judicial remedies, while available, are very rarely pursued in practice”. European Commission, Impact Assessment accompanying the proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of 6 European Data Protection Board, Guidelines 02/2022 on the application of Article 60 GDPR, Version 1.0, March 2022. https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-022022-application-article-60-gdpr_en 5 See from EUR-Lex: “The principle of the primacy (also referred to as ‘precedence’ or ‘supremacy’) of European Union (EU) law is based on the idea that where a conflict arises between an aspect of EU law and an aspect of law in an EU Member State (national law), EU law will prevail.
…arises between an aspect of EU law and an aspect of law in an EU Member State (national law), EU law will prevail. If this were not the case, Member States could simply allow their national laws to take precedence over primary or secondary EU legislation, and the pursuit of EU policies would become unworkable. The principle of the primacy of EU law has developed over time by means of the case law (jurisprudence) of the Court of Justice of the European Union.” The main rulings of the Court of Justice of the EU establishing this principle are Van Gend en Loos v Nederlandse Administratie der Belastingen (Case 26/62) and Costa v ENEL (Case 6/64). https://eur-lex.europa.eu/EN/legal-content/glossary/primacy-of-eu-law-precedence-supremacy.html 4 Data Protection Law Scholars Network (DPSN), The right to lodge a data protection complaint: OK, but then what?
Data Protection Law Scholars Network (DPSN), The right to lodge a data protection complaint: OK, but then what? An empirical study of current practices under the GDPR, June 2022. https://www.accessnow.org/cms/assets/uploads/2022/07/GDPR-Complaint-study.pdf 3 WIRED, Matt Burgess, How GDPR Is Failing, 23 May 2022. https://www.wired.co.uk/article/gdpr-2022 2 Data from https://www.enforcementtracker.com/?insights as of 21 March 2023. 1 Access Now is an international NGO that defends and extends the digital rights of users at risk around the world. https://www.accessnow.org/issue/data-protection/ We are a member of the European Commission multistakeholder expert group to support the application of Regulation (EU) 2016/679 (E03537).
…the European Commission multistakeholder expert group to support the application of Regulation (EU) 2016/679 (E03537). https://ec.europa.eu/transparency/expert-groups-register/screen/members/consult?memberId=67585&memberTypeId=3 &lang=en&fromExpertGroups=true 2 proposed a new enforcement model under the GDPR, which was further developed and then adopted by the co-legislators: the so-called one-stop-shop mechanism. Under this mechanism, the DPAs should cooperate, investigate, and work together to address GDPR complaints. This system should have simplified and harmonised the resolutions of complaints through coordinated actions of the data protection authorities.
…simplified and harmonised the resolutions of complaints through coordinated actions of the data protection authorities. Going back to courts for data protection violation may offer some resolutions for complainants, but there is a high risk of lack of harmonisation in the protection of rights as national courts do not have to cooperate with each other. What is more, courts across the EEA may not have the necessary expertise in the area of data protection. It is therefore critical for the European Union to ensure that the enforcement and application of the GDPR by DPAs works efficiently to provide equal rights and protection to data subjects.
72 → 12