Interesų grupė
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 18 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
Konfederacja Lewiatan ul. Zbyszka Cybulskiego 3 00-727 Warszawa tel. +48 22 55 99 900 [email protected] www.lewiatan.org. NIP 5262353400 KRS 0000053779 Sąd Rejonowy dla m. st. Warszawy w Warszawie XIII Wydział Gospodarczy - 1 - Warsaw, 24th March 2023 KL/125/47/AM/2023 Polish Confederation Lewiatan position paper on procedural rules on enforcement of the General Data Protection Regulation I. Preliminary Points a. Competence of the European Commission (EC) • We have concerns that the scope of the proposals in the initiative appear to go beyond those matters the EC has legal competence to regulate.
…the scope of the proposals in the initiative appear to go beyond those matters the EC has legal competence to regulate. • Article 61(9) GDPR grants the EC the power to adopt implementing acts to specify the format and procedures for mutual assistance between Supervisory Authorities (SAs) and the arrangements for the exchange of information between SAs and between SAs and the European Data Protection Board (EDPB) under Article 67 GDPR. • Under the GDPR, the EC has no further power to adopt implementing or delegated acts. • We presume that any procedural rules adopted by the EC as a result of this Initiative will fall strictly within the prescribed legal framework. • Any rules that go beyond this framework could only be established through the ordinary legislative procedure, Article 16 TFEU. b.
…that go beyond this framework could only be established through the ordinary legislative procedure, Article 16 TFEU. b. Equality of Rights • The GDPR provides for a comprehensively harmonised and conclusive ‘regulatory framework’ for the public enforcement of data subject rights by independent SAs (Article 51(ff) GDPR) with fixed competences, tasks, and powers. • The GDPR also created a comprehensive system of cooperation and consistency. This system is organised according to the ‘one-stop-shop’ (OSS) principle, under which the Lead Supervisory Authority (LSA) of the controller’s main establishment is the only point of contact competent for this controller’s cross-border processing operations (Article 56(1) GDPR). • In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR).
…56(1) GDPR). • In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR). This harmonised regulatory framework, like the substantive provisions of the GDPR, serves to achieve two equal goals of the GDPR, i.e. the same high level of protection of natural persons and the removal of obstacles to personal data flows within the Union, and an adequate balance of the data subject’s and controller’s fundamental rights, Ref. Ares(2023)2155032 - 24/03/2023 Konfederacja Lewiatan ul. Zbyszka Cybulskiego 3 00-727 Warszawa tel. +48 22 55 99 900 [email protected] www.lewiatan.org. NIP 5262353400 KRS 0000053779 Sąd Rejonowy dla m. st. Warszawy w Warszawie XIII Wydział Gospodarczy - 2 - and where applicable, those of third parties in the Union at the administrative and procedural level.
Gospodarczy - 2 - and where applicable, those of third parties in the Union at the administrative and procedural level. • We trust that the EC’s proposals will not jeopardise the balanced system established by the GDPR for the benefit of both data subjects and controllers concerned. • The one-stop-shop mechanism allows companies carrying out cross-border personal data processing to deal with one lead supervisory authority, and not 27, making it simpler for companies to do business in the EU and ensuring business certainty. Therefore, this mechanism should be maintained and the consulted initiative should only reinforce procedural issues, which will enable more effective cooperation between authorities on cross-border issues. • Firstly, it is important to strengthen that the practice of the application of the GDPR by different national authorities varies.
…is important to strengthen that the practice of the application of the GDPR by different national authorities varies. Observed activity of the local European data protection offices allows the conclusion that there are visible differences in GDPR interpretation and application across different countries. Resignation from the OSS formula (so introduction of multiple-shops formula) would be more conducive to deepening the differences between member states rather than supporting further harmonisation. It would also significantly reduce the predictability of the processes since these local differences will have to be addressed by companies carrying out cross-border personal data processing. For instance, in Germany there exists a visible expectation that e-commerce platforms should always make it possible to make a purchase without registration.
…a visible expectation that e-commerce platforms should always make it possible to make a purchase without registration. This opinion is not shared commonly and the Polish office does not share that opinion. In case of an OSS formula the e-commerce platform registered in Poland offering e-shopping options to German clients can rely on the Polish Data Protection Office requirements. In case of multiple-shops formula such a company shall also follow the German opinion. In the case of multi-country platforms it is not possible to limit the potential range of clients, and in such a case the only solution granting any real supervision is to have one authority (one-stop).
…of clients, and in such a case the only solution granting any real supervision is to have one authority (one-stop). • Secondly, it is also worth noting that introduction of the multiple-stop mechanism would open the complex issue of foreign law application and obligation for companies operating cross-border to monitor 27 national laws and follow 27 interpretations of GDPR. This would result in the very complex legal situation of such businesses. • Therefore, maintenance of the one stop shop formula is essential. The OSS mechanism allows companies to operate with greater legal certainty, predictability and doesn't add extra operating costs. Legal solutions which are implemented in cross-border issues are by definition more complex than domestic ones, but in terms of collision law there is still a possibility to establish a direct legal link to a given governing law (e.g.
…in terms of collision law there is still a possibility to establish a direct legal link to a given governing law (e.g. choice of law, Konfederacja Lewiatan ul. Zbyszka Cybulskiego 3 00-727 Warszawa tel. +48 22 55 99 900 [email protected] www.lewiatan.org. NIP 5262353400 KRS 0000053779 Sąd Rejonowy dla m. st. Warszawy w Warszawie XIII Wydział Gospodarczy - 3 - performance of the contract etc.) and to have control over it. This allows to estimate risks, create processes, offer simple solutions for customers - in general terms the whole process is predictable. One-stop formula enhances the above mentioned predictability. • In addition, the multiple-shops formula is, in our view, unfavorable from the point of view of the e-commerce market, assuming the need to align the Administrator's conduct with the position of more than one supervisory authority.
…assuming the need to align the Administrator's conduct with the position of more than one supervisory authority. The preferred form is, of course, to be under the supervision of a single authority (one-stop). Especially, in terms of collision of laws, one-stop mechanism, would give a possibility to create a legal link between governing laws and establish simpler solutions for both - market and customers. • Another advantage of the OSS formula is the possible cooperation with the local authorities that have the best knowledge on the interplay between GDPR and specific local provisions, including specific national context, legal traditions etc. This becomes even more important since GDPR provisions, including art. 6, often refer to national provisions which are often supervised by local offices or authorities.
…art. 6, often refer to national provisions which are often supervised by local offices or authorities. • In the call for evidence the European Commission informed that the impact assessment will not be prepared for this initiative since “the initiative will not affect the rights of data subjects, the obligations of data controllers and processors, or the lawful grounds for processing personal data as set out by the GDPR”. Therefore, it is necessary to ensure that the planned initiative focuses on cooperation between national data protection authorities and does not contain provisions that will affect the data subjects, controllers or processors. c.
…authorities and does not contain provisions that will affect the data subjects, controllers or processors. c. Procedural clarification As this Initiative responds inter alia to the list published by the EDPB on 10 October 2022 identifying procedural aspects of the cooperation between SAs in cross-border cases that could benefit from further harmonisation at EU level, we share below concerns based upon this list d. We would like to point out that the sectoral approach to privacy or data protection rights included in the recently adopted legislation (e.g. the Digital Services Act) or still in the pipeline (e.g. the Directive on platform workers) imposes additional standards on certain groups of actors beyond those set out in the GDPR.
38 → 12