Trade unions and professional associations · FR
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 10 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2026-06-03 | Communications Networks, Content and Technology | Proposal for the Cloud and AI Development Act |
| 2026-06-03 | Communications Networks, Content and Technology | Proposal for the Cloud and AI Development Act |
| 2026-05-13 | Cabinet of Commissioner Dan Jørgensen | Q & A's on various energy issues |
| 2026-05-13 | Cabinet of Commissioner Dan Jørgensen | Q & A's on various energy issues |
| 2025-11-06 | Cabinet of Executive Vice-President Henna Virkkunen | Cybersecurity Framework |
| 2025-11-06 | Cabinet of President Ursula von der Leyen | To discuss European technological autonomy |
| 2025-06-24 | Communications Networks, Content and Technology | Digital Policies in Europe |
| 2025-06-11 | Cabinet of Executive Vice-President Stéphane Séjourné | Exchange of views on tech sovereignty of the internal digital market. |
| 2025-06-11 | Trade | Discussion on EU dependency in the fields of cloud and software |
| 2025-06-11 | Cabinet of Executive Vice-President Stéphane Séjourné | Exchange of views on tech sovereignty of the internal digital market. |
- 1 - Created 50 years ago, Cigref brings together 150 major French public and private organizations, which are exclusively users of digital services and which together account for 1,700 billion euros in cumulative turnover and 50 billion euros in overall IT budgets. Financed by its members' subscriptions, Cigref is totally independent of ICT suppliers and consultants. Our mission is to promote the use of digital services, to develop the capacity of its members to integrate and master the digital world. Cigref organized among its members a dedicated session to collect feedback on the application of the General Data Protection Regulation. This document is a summary of the main points underlined by business users of digital services. GDPR increased certainty for businesses on how they can process with personal data. Companies. GDPR led to a higher awareness for data protection.
…businesses on how they can process with personal data. Companies. GDPR led to a higher awareness for data protection. Yet there are several challenges that businesses must deal with and that raised legal uncertainties. If the EDPB guidelines are seen as helpful in the interpretation of the GDPR, the documents are also seen complex, requiring resources to be analyzed. The dialogue with the national authorities works well. Reporting obligations are burdensome. The level of information expected from companies can be burdensome. The reporting obligations can be disproportionated and would require clarification on what is really needed to comply with the regulation. The implementation of the information obligation means a great deal of effort. The implementation of the GDPR in a complex business environment requires resources.
…means a great deal of effort. The implementation of the GDPR in a complex business environment requires resources. Implementing a risk-based approach would be welcomed to facilitate the conformity with the GDPR while considering the burden of the reporting obligations. The burden of proof requirement is heavy. Companies are not always sure that they have fulfilled all the obligations to a sufficient level. Application of the GDPR in non-EU States. Several companies shared issues in cross-border situations, especially when there is no adequacy decision with third countries. It is often unclear how the GDPR is applied with the specific regulations of different third countries. Ref. Ares(2024)939944 - 07/02/2024 - 2 - Since the ECJ ruling on Schrems II, additional measures must be introduced to secure personal data if the level of data protection does not correspond to that of the GDPR.
…must be introduced to secure personal data if the level of data protection does not correspond to that of the GDPR. Situations where personal data is transferred to third countries as part of international business operations are also perceived as challenging. This requires a lot of efforts for the companies to comply with the rules and raises question regarding the legal certainty of the framework in which they operate. For instance, not all data transfers can be technically secured. For instance, the CJEU’s ruling “Schrems II” puts data controllers in a situation to investigate a third country’s legal situation. Analyzing the legislation of the destination country requires large resources for companies and even the bigger one’s face challenges. International harmonization should be encouraged. The European Commission should continue working on adequacy decisions.
…harmonization should be encouraged. The European Commission should continue working on adequacy decisions. There are strong expectations regarding a robust framework for EU-US data transfers. Industrial planning needs legal certainty. Unbalanced responsibility of the data holder. A significant challenge in the application of the GDPR is linked with the interpretation of some provisions perceived as unclear and the implementation of some obligations at company level. One area of uncertainty concerns the level of responsibility held by data controllers for the entire subcontracting chain's data transfers and how the assessment of the entire subcontracting chain should be practically verified, especially with subcontractor operating outside the EU. Proceeding to a transfer impact assessment to third countries requires resources to evaluate a foreign legal situation and authority practices.
…impact assessment to third countries requires resources to evaluate a foreign legal situation and authority practices. Regular monitoring of all requirements is costly, especially as subcontractors may update their website, without notice. Finding the right information might be difficult. It would be useful to encourage suppliers to automatically mention changes made in their practice regarding personal data. Moreover, it is often challenging for data controllers to assess the contractual relationships between their subcontractors and the subcontractors further down the chain, as well as to obtain information about the associated risks. There is a need to better balance the way responsibility is shared between data controllers and the providers throughout the chain. Several provisions are burdensome for companies, especially for the Data Protection Impact Assessments (DPIAs).
…chain. Several provisions are burdensome for companies, especially for the Data Protection Impact Assessments (DPIAs). Yet they are held responsible as data holders, but they are not in a situation to get information from their subcontractors, especially when they are large international IT providers. For instance data holders are not always in a situation when they can impose to their IT subcontractors, provisions, especially on how they secure the data. The same points always arise in the negotiations, for example audit rights, disclosure of sub-service providers, etc. European data holders are not in a - 3 - position to negotiate with major IT providers and the negotiations about GDPR conformity are long. Unclear provisions leading to interpretation.
…major IT providers and the negotiations about GDPR conformity are long. Unclear provisions leading to interpretation. In a practical business environment, the division of roles into data controllers and processors in not as straightforward as it is described in the GDPR. Data processors often also act as data controllers. Therefore, the application of several provisions of the GDPR is confusing. Moreover, international companies often have separate legal entities operating in different countries, which act both as data controllers and participate in the same processing activities. This situation raised questions regarding the application of the cross-border processing provisions. Application of the GDPR and the different legislatives texts Since the adoption of the GDPR in 2018, several legislative texts have been adopted or will be.
…legislatives texts Since the adoption of the GDPR in 2018, several legislative texts have been adopted or will be. This increases the complexity of the compliance, especially when definitions are not fully aligned. This would be very helpful if the Commission could provide a concordance table of the different provisions and definitions. Developing GDPR conformity label regarding some tools that are used by companies would also be appreciated. Business users are also looking forward a clear framework regarding how artificial intelligence system may impact the GDPR, especially for the implantation of the regulation and when it comes to data transfers. Cigref is at the disposal of the European Commission to provide more information and ensuring a solid implementation of the GDPR. ***