ESOMAR

ESOMAR · Trade and business associations · NL

Kategorija
Trade and business associations
Būstinė
Amsterdam NL
Registruota
2009-12-15
Deklaruotos metinės išlaidos
100 000–199 999 € (pačios deklaruota)
Svetainė
http://www.esomar.org
Skaidrumo registras
29952722795-07 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

2020120261

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 2 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2026-06-05Communications Networks, Content and TechnologyDigital Omnibus proposal
2020-03-03Cabinet of Executive Vice-President Margrethe VestagerData Strategy; E-Privacy

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
This paper attached is submitted on behalf of: EFAMRO the European Federation of Associations of Market Research Organisations. Founded in 1992, EFAMRO represents the interests of market, opinion and social research in Europe. Its members are national trade associations for research businesses in across Europe. ESOMAR the global voice of the data, research, and insights community since 1947, gathers more than 8,000 individual and corporate members in over 130 countries. ESOMAR promotes professional and ethical standards and the value of market, opinion and social research in decision making. EFAMRO and ESOMAR represent the research and insights sector, accounting for a reported annual…
2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Please see document attached.
2020-04-29 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
ESOMAR is the global voice for the data, research and insights community, representing a sector with a reported annual turnover of €10billion. Market, opinion and social research and data analytics is the systematic gathering and interpretation of information about individuals or organisations using the statistical and analytical methods and techniques of the applied social sciences to gain insight or support decision making.

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 22 p.

Ref. Ares(2024)965285 - 08/02/2024 Joint Comments by ESOMAR, SCOPE Europe, Selbstregulierung Informationswirtschaft and FEDMA 5 Years of GDPR | Key Challenges and Recommendations Page | 2 Publishers ESOMAR Burgemeester Stramanweg 105 1101 AA Amsterdam https://esomar.org [email protected] Register Number: 29952722795-07 FEDMA AISBL Avenue des Arts, 43 1040 Brussels https://www.fedma.org [email protected] Register Number: BE 0464157569 Selbstregulierung Informationswirtschaft e.V. Großbeerenstraße 88 10963 Berlin https://sriw.de [email protected] Register Number: VR 30983 B, Amtsgericht Charlottenburg SCOPE Europe s.r.l. Rue de la Science 14 1040 Brussels https://scope-europe.eu [email protected] Register Number: BE 0671.468.741 Joint Comments by ESOMAR, SCOPE Europe, Selbstregulierung Informationswirtschaft and FEDMA 5 Years of GDPR | Key Challenges and Recommendations Page | 3 1 KEY MESSAGES

Informationswirtschaft and FEDMA 5 Years of GDPR | Key Challenges and Recommendations Page | 3 1 KEY MESSAGES 1. It is strongly recommended to set the risk-based approach as the decision-making compass in the interpretation and implementation of the GDPR by: ▪ Applying in a consistent manner the GDPR risk-based approach stemming from the general principle of proportionality. ▪ Reconciliating the fundamental right of data protection with other fundamental rights and public policy objectives. ▪ Fostering and promoting stakeholders’ driven initiatives supporting the balancing involved in the processing of personal data with adequate protection of data subject rights.

…supporting the balancing involved in the processing of personal data with adequate protection of data subject rights. 2. It is strongly recommended to promote the added value of Legitimate Interest for data subjects by: ▪ Promoting a more balanced narrative that does not set consent as the default legal basis with the highest level of effective data protection. ▪ Incentivizing and clarifying reliance on legitimate interest subject to full compliance with the GDPR. ▪ Enabling a constructive dialogue with relevant stakeholders for developing templates for legitimate interest balancing assessments (LIA) for different types of activities via Codes of Conduct and certifications.

…interest balancing assessments (LIA) for different types of activities via Codes of Conduct and certifications. 3. It is strongly recommended to encourage organizations to invest in pseudonymization and anonymization techniques by: ▪ Fostering a common approach to pseudonymization methodology across the EU through guidelines and Codes of Conduct. ▪ Incentivizing companies in investing resources to process pseudonymous data. ▪ Adopting a risk-based approach to the concept of anonymous data in light of existing international standards such as ISO/IEC 27559:2022.

…approach to the concept of anonymous data in light of existing international standards such as ISO/IEC 27559:2022. 4. It is strongly recommended to ensure that the roles and responsibilities of controllers, processors and third parties are clear and proportionate by: ▪ Refraining from relying solely on simplistic examples and instead considering the complexity of data processing chains. Recognizing the complexity inherent in such endeavours is crucial for crafting effective policies that accommodate diverse (e.g., research) requirements. ▪ Striking a balance regarding granularity requirements for Codes of Conduct. Given the inherent challenges in comprehensively describing all types of processing activities, such codes should prioritize overarching Joint Comments by ESOMAR, SCOPE Europe, Selbstregulierung Informationswirtschaft and FEDMA 5 Years of GDPR | Key Challenges and…

This approach ensures that Codes of Conduct remain relevant and adaptable to various contexts, including research. 5. It is strongly recommended to further streamline the approval and operationalization of GDPR Codes of Conduct: ▪ By reviewing the procedural requirements in receiving a Code of Conduct’s approval and a Monitoring Body’s accreditation. ▪ Generally, the legal framework and EDPB’s guidelines are considered suitable, if applied consistently. Specifically for transnational Codes of Conduct, it is recommended to ensure harmonized interpretation, because projects suffer delays, e.g., by means of consistently and mutually determining the competent data protection supervisory authorities. ▪ Periods as indicated by GDPR are not yet met in practice.

…the competent data protection supervisory authorities. ▪ Periods as indicated by GDPR are not yet met in practice. So, it is recommended to adapt such periods to more realistic timelines and to clarify that in case data protection supervisory authorities cannot by majority determine undisputable conflicts with GDPR, Codes of Conduct shall be deemed in accordance with GDPR. ▪ In regards of third country transfers, a general validity by implementing act is required. It is strongly recommended to ensure that procedural efforts will be streamlined preventing any unreasonable delays in operationalizing such projects. ▪ Safeguarding third country transfers is one of the key elements subject to legal, political and operational discussions.

…third country transfers is one of the key elements subject to legal, political and operational discussions. ▪ Codes of Conduct may act as a safeguard provide that, next to the formalities to be met for transnational Codes of Conduct in any case, general validity will be granted. ▪ Considering the procedural steps of deciding on an implementing act, it is strongly recommended to allow for a material assessment by the European Commission and the EDPB in parallel. Joint Comments by ESOMAR, SCOPE Europe, Selbstregulierung Informationswirtschaft and FEDMA 5 Years of GDPR | Key Challenges and Recommendations Page | 5 Table of Contents 1 KEY MESSAGES ..................................................................................................................................

........................................................................................................................ 3 2 INTRODUCTION ................................................................................................................................. 6 3 ABOUT THE AUTHORS ....................................................................................................................... 7 3.1 ESOMAR ................................................................................................................................................ 7 3.2 FEDERATION OF EUROPEAN DATA AND MARKETING (FEDMA) ........................................................... 7 3.3 Selbstregulierung Informationswirtschaft e.V. (SRIW) and SCOPE Europe: .........................................

…7 3.3 Selbstregulierung Informationswirtschaft e.V. (SRIW) and SCOPE Europe: ......................................... 7 4 GDPR RISK-BASED APPROACH: Setting the risk-based approach as the decision-making compass in the interpretation and implementation of the GDPR ................................................................................. 8 Recommendations ................................................................................................................................. 9 5 GDPR LEGAL BASES: Promoting the added value of Legitimate Interest for data subjects ................. 10 Recommendations ...............................................................................................................................

........................................................................................................................ 11 6 PRIVACY ENHANCING TECHNOLOGIES (PETs): Encouraging organizations to invest in pseudonymization and anonymization techniques .................................................................................. 12 Recommendations ............................................................................................................................... 13 7 CONTROLLERS, PROCESSORS, AND THIRD PARTIES: Ensuring clear roles and proportionate responsibilities ........................................................................................................................................ 14 Recommendations ...............................................................................................................................

........................................................................................................................ 15 8 Article 40 GDPR CODES OF CONDUCT: Further streamlining their approval and operationalization. . 16 8.1 GDPR codes of conduct as tools supporting harmonization and consistent enforcement of GDPR .. 16 8.1.1 Sector-specific particularization and harmonization .......................................................................... 17 8.1.2 Codes of conduct as tools supporting enforcement ...........................................................................

96 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 4 p.

EFAMRO and ESOMAR Position Paper A Response to the Call for Evidence “Report on the General Data Protection Regulation” (Adopted on 8 February 2024) This paper is submitted on behalf of: EFAMRO the European Federation of Associations of Market Research Organisations. Founded in 1992, EFAMRO represents the interests of market, opinion and social research in Europe. Its members are national trade associations for research businesses in across Europe. ESOMAR the global voice of the data, research, and insights community since 1947, gathers more than 8,000 individual and corporate members in over 130 countries. ESOMAR promotes professional and ethical standards and the value of market, opinion and social research in decision making. EFAMRO and ESOMAR represent the research and insights sector, accounting for a reported annual turnover of €20.87 billion in Europe. 1.

…represent the research and insights sector, accounting for a reported annual turnover of €20.87 billion in Europe. 1. About Market, Opinion and Social Research 1.1. Market research is comprised of all forms of market, opinion, and social research (“Market Research”). 1.2. Market Research is the systematic gathering and interpretation of information about individuals or organisations using the statistical and analytical methods and techniques of the applied social, behavioural and data sciences to gain insight or support decision making. 1.3. Market Research stands at the heart of well-informed commercial, social and political decisions. Its purpose is to deliver information and insights about people’s behaviour, needs and attitudes to inform decision making by providers of goods and services, governments, individuals, and society at large.

…attitudes to inform decision making by providers of goods and services, governments, individuals, and society at large. Insight into what makes a product, business initiative, consumer or government policy strategy is often the hidden – yet defining – factor between success and failure. It is our sector that provides the deeper intelligence needed for our world today by representing citizens’ authentic voices, from all levels of society, in an unbiased and representative way by applying the tenets of statistical and scientific methods. 1.4. Market Research associations apply a comprehensive framework for self-regulation to ensure that researchers meet their ethical, professional, and legal responsibilities to Ref. Ares(2024)973348 - 08/02/2024 the individuals whose data they use in research and to the clients and organisations which commission research.

…individuals whose data they use in research and to the clients and organisations which commission research. Members subscribe to self-regulation schemes that protect respondents’ and participants’ rights.

…commission research. Members subscribe to self-regulation schemes that protect respondents’ and participants’ rights. 2. Purpose of our Response: With this paper we wish to provide our perspective on the delineation of roles and proportional responsibilities concerning controllers, processors, and third parties. Through this paper, we seek to contribute to the ongoing discussion surrounding the clarity and efficacy of these roles within relevant frameworks. The determination and attribution of the controller, processor, or third-party role has practical implications for the parties involved in complex data processing activities, e.g. a research data chain. Through the attribution of the role, the liability and responsibility for safeguarding the processing of personal data changes as does the ability to exercise control over and determine further uses of the personal data. Under the…

…themselves accordingly and ensure that this designation is respected by the other parties in the data chain. 3. The Data, Research and Insights Context In the context of this controller, processor and third-party debate, the dichotomy of controller and processor is not always clear nor should regulators conclude too easily in their guidance with the risk of creating legal uncertainty. This is, for example, reflected in the opinion of some German DPAs (e.g. Baden-Württemberg, Berlin) according to which the use of third-party data from list owner of third-party addresses for postal promotion leads to a joint-controllership.

…use of third-party data from list owner of third-party addresses for postal promotion leads to a joint-controllership. As such, rather than imposing a one-size-fits-all approach in determining controllers, processors, and joint controllership relationships solely based on the nature of the processing, we believe a case-by-case assessment is necessary, taking into account the nature of the partnership, the degree of instruction, and the personal data flow, to determine ultimately who is controller, processor, or third party distinct from the commercial relationship which is bringing the parties together. Emerging case law and guidance seem to indicate a default requirement engendered by the GDPR and related case law which situates controllership with the client of a research project, due to the assumption from non-practitioners that the client determines the ‘purpose’.

…client of a research project, due to the assumption from non-practitioners that the client determines the ‘purpose’. Often this purpose refers to identifying the research question to be addressed and paying for the research to answer the question, rather than establishing the purpose limitation and processing operations. In these scenarios, the blanket approach of automatically allocating the controllership role to research clients prescribed by the narrow interpretation of GDPR distorts the genuine nature of the research chain, erodes confidentiality, and diminishes autonomy over resources across the chain. The client often does not determine the methodology or specific detailed purposes, nor do they receive any personal data, yet the overall responsibility of control is being attributed to the client by default.

…they receive any personal data, yet the overall responsibility of control is being attributed to the client by default. In the data, research and insights environment, for example, where clients commission research agencies to support them to resolve, through an independent evidence-base, concrete business or strategic questions, the complexity of research data chains and the processing activities that they entail highlight the difficulties of applying the GDPR concepts in a data-rich world. As such, these “research projects” are often deconstructed into different singular activities and then grouped in phases as this can be much more effective in resolving uncertainties in the role attribution. The determination will then depend highly on the level of specificity of the client brief given to the supplier and the level of specification that comes from it.

…the level of specificity of the client brief given to the supplier and the level of specification that comes from it. A consumer brand or government body which asks an agency to understand how to improve its advertising effectiveness without specifying to the agency how it should derive its recommendations is more likely to not be deemed a controller compared to a consumer brand which specifies to an agency that it is looking to conduct a study with 1000 individuals belonging to a specific demographic. Another notable example can be found in the case of ‘blinded surveys’. In this scenario it is recommended that participants are informed at the beginning of the interview about the delayed disclosure of the client's identity until the conclusion of the survey.

…beginning of the interview about the delayed disclosure of the client's identity until the conclusion of the survey. This precautionary measure aims to prevent potential response bias that could arise from upfront disclosure of this information, e.g. when the client’s identity is immediately communicated to the research participant in compliance with GDPR’s transparency requirements. We therefore underscore that it is important that regulators do not automatically associate the commercial relationship with the data processing relationship, and to consider the extent by which the vagueness of a client request impacts the role that they play within a data chain.

…to consider the extent by which the vagueness of a client request impacts the role that they play within a data chain. Relying on the nature of the partnership, the degree of instruction, and the personal data flow may thus prove more effective for all parties involved in the data processing activity as well as to ensure effective communication to the data subjects rather than adopting an approach that artificially simplifies the processing activity. Acknowledging the abovementioned complexities, it shall be highlighted that research sector stakeholders would appreciate enhanced legal certainties and collaboration with supervisory authorities to resolve pressing challenges of complex processing chains. Such collaboration and continuous exchange may, besides others, be addressed by the development of codes of conduct.

14 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 3 p.

…4 March 2020 Page 1 of 3 Response to the public consultation on GDPR roadmap April 2020 About data research and insights ESOMAR is the global voice for the data, research and insights community, representing a sector with a reported annual turnover of €10billion. Market, opinion and social research and data analytics is the systematic gathering and interpretation of information about individuals or organisations using the statistical and analytical methods and techniques of the applied social sciences to gain insight or support decision making. Market, opinion and social research and data analytics is robustly self-regulated by a family of national and international Codes of Conduct, ensuring that data collected for research is strictly limited to research only, preventing harm or adverse consequences to individuals.

…collected for research is strictly limited to research only, preventing harm or adverse consequences to individuals. Compliance with both legal and ethical requirements for the treatment of personal data is vital for maintenance of consumer trust. These Codes are also supported by detailed guidance on specific aspects of research methodologies and underpinned by disciplinary processes. Our Codes drawn up by researchers for researchers, help to protect providers, buyers and data subjects alike. They promote confidence, safeguard standards and champion professionalism. Most importantly, we consider them as living documents that need to be constantly updated in order to ensure that they continue to reflect evolving ethical best practice and significant changes in the data protection framework and the accelerated speed and progress of technological development and data use.

…the data protection framework and the accelerated speed and progress of technological development and data use. We consider it crucial for practitioners to easily understand, access and use our Codes of Conduct and that they are also easily accessible to members of the public. Introduction We welcome the opportunities the European Commission provides on giving feedback on the General Data Protection Regulation (GDPR). We are convinced that the trust of the data subject and the protection of their personal information should always remain an essential priority and the GDPR is instrumental to safeguard such trust. As a sector, we are also actively exploring the opportunity offered by GDPR and specifically Article 40 to develop a robust GDPR Research Code that provides specific guidance on GDPR compliance requirements for market, opinion and social research and data analytics.

…provides specific guidance on GDPR compliance requirements for market, opinion and social research and data analytics. We believe that the framework set by the GDPR has created a global standard, which enables companies to operate while safeguarding the data subject’s fundamental right to date protection. While we believe the GDPR is successful in this regard we nevertheless like to take this opportunity to provide feedback on how the GDPR is being implement. Assigning the roles of Controller and Processor A critical aspect of the GDPR is assigning the roles of controller and processor. While the legal definitions are clear, their interpretations and how to operationalise them tends to vary between regulators.

…the legal definitions are clear, their interpretations and how to operationalise them tends to vary between regulators. In the data, research and insights environment, clients commission research agencies to support them to resolve, through an independent evidence-base, concrete business or strategic questions, this is the role of our sector. The nature of the partnership, and the degree of instruction, and the personal data flow are the key factors that determine ultimately who is controller, processor, or third party distinct from the commercial relationship which is bringing the parties together. Ref. Ares(2020)2298643 - 29/04/2020 4 March 2020 Page 2 of 3 The guidance that has been published e.g. by the Dutch1, British2 regulators as well as the former Art.

…2 of 3 The guidance that has been published e.g. by the Dutch1, British2 regulators as well as the former Art. 29 Working Party3 and the European Commission4 underscore the reasons for ESOMAR’s position that the dichotomy of controller and processor in the context of research is not clear cut nor should regulators be rushing to conclusions in their guidance either way. We therefore call for a unified interpretation that does right to complex context. This interpretation should account for the fact that every research project is different and avoid a one size fits all approach. Application of Article 89 We welcome the fact that the GDPR recognises under Article 5.1(b) that scientific research is not incompatible with further processing and acknowledge that additional safeguards should be in place when benefitting from the degradation provided under Article 89.

…that additional safeguards should be in place when benefitting from the degradation provided under Article 89. However, different national implementations have taken different approaches whether they enable derogations foreseen under Article 89 and safeguards that should be applied. This leads to a fragmented market, limiting the effectiveness of the digital single market and the European Research Area as understood by Article 179(1) TFEU. Furthermore, it remains unclear when Article 89 can be applied; in particular whether it an optional clause or any scientific research project should follow the conditions irrespective of derogations are applied or data is further processed for scientific research purposes. We therefore call on the European Commission to clarify the application of Article 89 and the requirements under which it can applied.

…on the European Commission to clarify the application of Article 89 and the requirements under which it can applied. Different national interpretation While the GDPR aims to harmonise the data protection framework in the EU Members States, its enforcement remains with national, and sometime regional, Supervisory Authorities. This has resulted in cases where different countries have interpreted the law in different ways. We believe it is essential for a successful GDPR to have a unified approach within different Member States. We therefore call upon the Commission to continue its work to support national Supervisory Authorities harmonising the interpretation of the GDPR, in particular through the mechanisms the European Data Protection Board provides.

…the interpretation of the GDPR, in particular through the mechanisms the European Data Protection Board provides. 1 Autoriteit Persoonsgevens website https://autoriteitpersoonsgegevens.nl/sites/default/files/atoms/files/voorbeeldlijst_verwerkers_def.p df 2 ICO Website https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general- data-protection-regulation-gdpr/controllers-and-processors/how-do-you-determine-whether-you- are-a-controller-or-processor/ 3 Article 29 Working Party website https://ec.europa.eu/justice/article-29/documentation/opinion- recommendation/files/2010/wp169_en.pdf 4 European Commission website https://ec.europa.eu/info/law/law-topic/data- protection/reform/rules-business-and-organisations/obligations/controller-processor/what-data- controller-or-data-processor_en 4 March 2020 Page 3 of 3 Contact Details ESOMAR Founded in 1948, ESOMAR is the…

…3 of 3 Contact Details ESOMAR Founded in 1948, ESOMAR is the global voice of the data, research and insights community. It gathers more than 6000 professionals and over 600 organisations providing or commissioning research. For further information on ESOMAR, contact Kim Smouter, Head of Public Affairs and Professional Standards. Address Atlas Arena, Azië building - 5th floor, Hoogoorddreef 5, 1101 BA Amsterdam, Netherlands Telephone +32 4 85 86 53 97 Email [email protected] Website https://www.esomar.org

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Currently, our advocacy activities are centred on the following topics:
- Data protection and privacy
- AI development/deployment
- Responsible research and innovation
- ePrivacy
- Copyright, text and data mining
- Self- and Co-Regulation
- Freedom to conduct opinion polling research
- Audience measurement
- Demographics measurement
- DE&I
- Platform Workers Directive