CCIA Europe · Trade and business associations · US
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 51 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
…ccianet.org • @CCIAeurope Call for Evidence – Feedback Report on General Data Protection Regulation February 2024 The Computer & Communications Industry Association (CCIA Europe) welcomes the opportunity to provide feedback on the General Data Protection Regulation (GDPR) and its application, six years after the rules entered into effect. For the GDPR to continue acting as a landmark horizontal framework, certain adjustments are needed. These could be introduced in the form of guidance on, or further harmonisation of, implementation and enforcement. Below you will find CCIA Europe’s main reflections and recommendations regarding the GDPR’s application and possible follow-up actions. I. Continue ensuring unhindered, safe data flows CCIA Europe supports the European Commission’s efforts on adequacy frameworks, as well as standard contractual clauses, but would welcome further adequacy…
…possible as well as more proportionality when it comes to guidelines that have been developed. Recommendations: 1. Adopt more adequacy decisions for jurisdictions meeting appropriate standards 2. Pay attention to tension between data protection and need for security 3. Ensure proportionality in guidelines developed by the EDPB II. Respect the different legal bases for processing of data The GDPR sets out a range of legal bases for processing of personal data. While each basis has to meet certain conditions, there should be no hierarchy between them. Recommendations: 4. Avoid a restrictive interpretation of the different legal bases 5. Make consent work in practice III. Guarantee harmonised implementation The GDPR created a new architecture for the protection of personal data which needs to be adequately and uniformly implemented and enforced across the board. Recommendations:
…of personal data which needs to be adequately and uniformly implemented and enforced across the board. Recommendations: 6. Ensure coherent implementation of the GDPR across all EU legislation 7. Strengthen the One-Stop-Shop mechanism 8. Avoid fragmentation in Member State implementation Rue de la Loi 227, First Floor • 1040 Brussels • Belgium pg.1 Ref. Ares(2024)938464 - 07/02/2024 ccianet.org • @CCIAeurope Introduction Since its entry into force, the General Data Protection Regulation (GDPR) has had a tremendous impact on the way organisations across the European Union gather, use, and store personal data. It has set the standard for higher protection of personal data worldwide, with many companies adapting their global data protection policies in response.
…protection of personal data worldwide, with many companies adapting their global data protection policies in response. The GDPR has brought a number of benefits, including an increase in accountability and transparency on how private and public organisations collect, process, and use personal data. It also led to an increased awareness of data subjects about their rights, paired with a higher investment in data protection by companies complying with the rules. Nevertheless, organisations also face a number of challenges resulting from the GDPR, including an increased complexity with regards to the legislative framework and its application, the cost incurred by companies of all sizes to comply with the rules, as well as uncertainty with regard to the interpretation and enforcement of GDPR, both at Member State and European level.
…well as uncertainty with regard to the interpretation and enforcement of GDPR, both at Member State and European level. While welcoming the new proposed rules on GDPR enforcement as a complement to the existing data protection framework, CCIA Europe believes this proposal falls short of addressing important enforcement deficiencies we have observed since the entry into application of the GDPR. After six years, it is necessary to take stock of these rules and how they have been applied. CCIA Europe welcomes the opportunity to reflect upon the application of the GDPR and would like to respectfully offer the following recommendations. I.
…to reflect upon the application of the GDPR and would like to respectfully offer the following recommendations. I. Continue ensuring unhindered, safe data flows CCIA Europe supports the European Commission’s efforts on adequacy frameworks, as well as standard contractual clauses, but would welcome further adequacy decisions to the extent possible as well as more proportionality when it comes to guidelines that have been developed. 1. Adopt more adequacy decisions for jurisdictions meeting appropriate standards The GDPR introduced a number of helpful novelties for data transfers, codifying binding corporate rules and introducing certifications and codes of conducts for companies that seek to transfer data outside of Europe. However, these haven’t been used as much as they could have.
…companies that seek to transfer data outside of Europe. However, these haven’t been used as much as they could have. Organisations based in Europe still primarily rely on standard contractual clauses (SCCs) and adequacy decisions. The European Commission has issued a low trickle of adequacy decisions throughout the past years, the last one on Japan in 2019.1 Countries across the world are increasingly adopting laws establishing a safer environment for the treatment of personal data and guaranteeing appropriate standards for transfers of data.
…a safer environment for the treatment of personal data and guaranteeing appropriate standards for transfers of data. Consistent with the Council’s 1 European Commission adopts adequacy decision on Japan, creating the world’s largest area of safe data flows: https://ec.europa.eu/commission/presscorner/detail/en/IP_19_421 Rue de la Loi 227, First Floor • 1040 Brussels • Belgium pg.2 ccianet.org • @CCIAeurope position on the application of GDPR,2 further adequacy decisions and more flexibility as regards the mechanisms for international data transfers would facilitate transfers across our EU borders and create more legal certainty for a great number of businesses.3 In an era where significant economic value derives from unencumbered personal data flows,4 it is necessary for the Commission to work together and align with other global actors in order to develop stronger interoperability…
…order to develop stronger interoperability between data flow systems in the European Union and other third countries. 2. Pay attention to tension between data protection and need for security The importance of cross-border data transfers cannot be understated. However, in recent years, CCIA Europe’s Members have experienced an increased tendency among EU regulators to view localisation as a way to protect personal data originating in the European Union.5 This trend could limit businesses’ ability to deploy state-of-the-art security threat detection and mitigation measures that rely on cross-border data transfers, thereby undermining industry’s efforts to ensure the integrity of EU personal data.
…on cross-border data transfers, thereby undermining industry’s efforts to ensure the integrity of EU personal data. This would also contradict the obligation under Article 32 of the GDPR which mandates controllers and processors to take “into account the state of the art” and to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk”. The tendency to increasingly push for the localisation of data also threatens information sharing among different industry players, as well as between those players and government agencies for security purposes. Moreover, when it comes to international data flows, the treatment of IP addresses as personal data has also become problematic, as this treatment makes them subject to GDPR rules for data transfers.
…as personal data has also become problematic, as this treatment makes them subject to GDPR rules for data transfers. With IP addresses increasingly being treated as personal data, the GDPR would apply to those IP addresses ostensibly linked to EU residents and these would not be able to be processed in third countries with no adequacy decision. The unrestricted flow of IP addresses is crucial, both for the global functioning of the internet and to ensure advanced cybersecurity applications that depend on IP addresses and additional metadata sourced globally. 5 A hard data localisation requirement features in various drafts of the upcoming EU Certification Scheme for Cloud Services (EUCS).
…localisation requirement features in various drafts of the upcoming EU Certification Scheme for Cloud Services (EUCS). The EDPB supports the introduction of this requirement: https://edpb.europa.eu/our-work-tools/our-documents/letters/edpb-letter-enisa-regarding-european-cybersec urity_en; Article 27 of the Data Act also creates a separate regime for non-personal data transfers for cloud services providers subject to third party countries’ data access requests, based on IP protection afforded in third countries. Because cloud providers cannot distinguish personal from non-personal data, an enforcement decision suspending the flow of non-personal data would necessarily affect personal data, and potentially collide with adequacy decisions, SCCs or other transfer tools under GDPR.
34 → 12