RÚZ · Trade and business associations · SK
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 2 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2025-06-03 | Energy | REPowerEU, AEAP |
| 2025-06-03 | Energy | REPowerEU, AEAP |
GDPR Revision – Some thoughts on the path ahead This paper outlines some considerations on the GDPR in the context of the Commission’s call for evidence as part of the periodical report the Commission adopts every 4-years on the implementation and effectiveness of this fundamental legislation. The EC has consulted the GDPR Multistakeholder Group and both the Council of the EU and the EDPB have provided feedback. The report by the EC is expected before the Summer of 2024 and may include diverse future policy options, unknown for the moment. Exercise of data subject rights The GDPR grants data subjects expansive rights in the areas of data access and portability. Developing the systems to comply with these rights is not only costly but comes with counterbalancing risks and may strain the bounds of what is technically feasible.
…is not only costly but comes with counterbalancing risks and may strain the bounds of what is technically feasible. For instance, providing “all instances” of personal data may lead to an overwhelming “data-dump” of repetitive low risk data that customers cannot comprehend and “porting” such data may in fact engender Data Security risk. The lack of practical guidance on resolving these tensions from the EDPB and DPA’s, as well as detail on what is actually expected with respect to controls under the Accountability Principle (and understanding of how such expectations may change over time), makes it hard for companies to reasonably anticipate or plan for compliance while bearing a disproportionate risk of turnover penalties should their good-faith solutions be deemed insufficient.
…while bearing a disproportionate risk of turnover penalties should their good-faith solutions be deemed insufficient. The sanction is particularly disproportionate where there is no substantive privacy harm to the data subject and considering unintended circumstances where such rights have been invoked (e.g., as a discovery tool in employment litigation). Experience with Data Protection Authorities DPAs are often unwilling to provide tailored guidance which is needed given the horizontal and principles-based nature of the GDPR based on professed resourcing constraints.
…which is needed given the horizontal and principles-based nature of the GDPR based on professed resourcing constraints. This is likely due to DPAs being overburdened with a large number of technical breach notifications and formal complaint- handling rather than prioritising their activities based on risks and harms to individuals and focusing their regulatory resources on proactive engagement with organisations and thought leadership activities. The EDPB should create a framework for data controllers to voluntarily reach out to DPAs in good faith, and the DPAs should play a more proactive role in engaging with other regulators to clarify their areas of competence to avoid conflicting rulings. Member States must also ensure that DPA’s are appropriately resourced.
…of competence to avoid conflicting rulings. Member States must also ensure that DPA’s are appropriately resourced. Data protection officers (DPOs) The requirement to appoint a data protection officer (DPO) helped ensure that organisations that traditionally did not have staff responsible for data protection would integrate one into their structure to help assist with GDPR compliance. But, while the DPO can serve as a useful bridge between an organization and regulatory authorities, there is a risk that its appointment becomes too prescriptive.
…between an organization and regulatory authorities, there is a risk that its appointment becomes too prescriptive. In particular, there are counterbalancing requirements in the GDPR for the DPO to be “conflict free” but also “informed” and “appropriately qualified.” In practice, these requirements are in tension, as pressing on the “conflict free” requirement likely will mean that DPO’s are less senior individuals who have lesser expertise and are not well positioned to appropriately comment on the business practices under discussion with suitable sophistication. This is particularly true if DPA’s begin to assert that in fact a conflict exists merely because a DPO is a member of either management or even the legal department. Ref.
…that in fact a conflict exists merely because a DPO is a member of either management or even the legal department. Ref. Ares(2024)966053 - 08/02/2024 Indeed, DPA’s should not read hard additional requirements into GDPR that do not exist in the text, but instead must provide suitable discretion for companies to operate within the spirit of the legislation. It is essential that discretion is given to data controllers in appointing their DPOs. DPAs should clarify that there is not a one size fits all solution to the DPO Role and should provide suitable deference in application of the requirement. Controller/processor relationship (Standard Contractual Clauses) Under ECJ Case Law, the data controller still needs to undertake a Data Transfer Impact Assessment when using Standard Contractual Clauses (to analyze the risks of the transfer).
…a Data Transfer Impact Assessment when using Standard Contractual Clauses (to analyze the risks of the transfer). The details of the Transfer Impact Assessment are not set forth in GDPR, yet the guidance from the EDPB remains impractical when considering the multitude of required use cases. Future guidance must consider what is practically feasible versus a best of all world’s solution. Particularly when the requirement is not set forth in the GDPR itself it is inappropriate for the EDPB to “legislate” their preferred format. International transfers GDPR requires data transfers to be grounded in mechanisms such as model clauses promulgated by the European Commission or the Privacy Shield.
…to be grounded in mechanisms such as model clauses promulgated by the European Commission or the Privacy Shield. While mandating certain safeguards where organisations transfer data out of the EEA is understandable, many of the solutions favoured under the GDPR (e.g., model clauses) have resulted in onerous administrative burdens for businesses, taking years for approval, and it is unclear whether the tangible benefits for data subjects are proportionate to this cost. It is also not sustainable for companies to risk turnover fines despite acting in good faith. The constant interruption of international data flows, especially between the EU and US, is not sustainable. The high level of legal uncertainty also carries a risk of high fines for organisations transferring data outside of the EU, despite acting in good faith and within the framework of the EU’s adequacy decision.
…data outside of the EU, despite acting in good faith and within the framework of the EU’s adequacy decision. As for binding corporate rules (BCRs), many companies have yet to use them. From our perspective, the administrative procedure should be simplified, comparable to Standard Contractual Clauses, to enable accountability and transparency. GDPR certifications and codes of conduct have the potential value as comprehensive accountability mechanisms. While the regime surrounding GDPR certifications and codes of conduct have still not been effectuated, there is still positive potential in implementing these tools. Although no scalable means of implementation currently exist, we encourage their realization. Fragmentation/use of specification clauses While the GDPR aims to harmonise data protection rules in the EU, it fell short of this aim.
…of specification clauses While the GDPR aims to harmonise data protection rules in the EU, it fell short of this aim. Member States’ differing implementation of the GDPR led to the creation of diverging rules in practice. For example, the ‘age of consent’ is given flexibility in the GDPR, but more consistency on parental consent is needed as Member States interpret these rules differently. Similarly, DPAs have taken divergent positions on the requirement of a Guest Check Out feature for online shopping. The EDPB could also play a more proactive role in driving true consistency in the way DPAs interpret and approach data protection rules, compliance, and enforcement while also ensuring that DPA’s do not take on a quasi- legislative remit by overstepping the requirements set forth in GDPR.
…also ensuring that DPA’s do not take on a quasi- legislative remit by overstepping the requirements set forth in GDPR. GDPR and innovation / new technologies Although the GDPR is intended to be future-proof and adaptable to emerging technologies and new uses of data, this is not entirely the case. Several of its provisions may lead to tensions with artificial intelligence applications, developing biotechnology, and blockchain. Moreover, the overlap between GDPR and sector-specific legislation is vague, leading to significant ambiguities regarding the intersection of GDPR with legislation including the e-Privacy Regulation, DMA, and AI Act. The risk- based approach in the GDPR would permit the GDPR to stay future-proof and continue to adapt to new technologies.
16 → 12