CIPL · Think tanks and research institutions · US
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 19 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
CIPL’s response to the European Commission’s call for evidence on further specifying procedural rules relating to the enforcement of the General Data Protection Regulation Centre for Information Policy Leadership (CIPL) 23 March 2023 Ref. Ares(2023)2123715 - 23/03/2023 23 March 2023 2 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP. The Centre for Information Policy Leadership1 (CIPL) welcomes the opportunity to provide input for the European Commission’s (EC) call for evidence on Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation (GDPR).
…on Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation (GDPR). This initiative aims to streamline cooperation between national data protection supervisory authorities (SA) when enforcing the GDPR in cross-border cases by harmonising some aspects of the administrative procedures that are applied by data protection SA in these cases. CIPL took into consideration the issues identified by the EC in the report on the application of the GDPR2 as well as the European Data Protection Boards’ list3 of GDPR procedural aspects that could benefit from further harmonisation at the EU level when preparing this feedback. Our response structure follows the EC’s suggested high-level policy options to harmonise administrative procedures in cross-border cases.
…follows the EC’s suggested high-level policy options to harmonise administrative procedures in cross-border cases. Namely, (1) specify procedural deadlines for cooperation between data protection supervisory authorities on cross-border cases (under Articles 60 and 65 GDPR); (2) provide tools to data protection supervisory authorities to promote cooperation early in the investigation process; (3) clarify the position of complainants in the procedural steps, including the possibility for complainants to make their views known; (4) streamline the way the parties under investigation are heard during the procedure; (5) clarify how information is to confidentially be shared between the investigating data protection supervisory authority and the concerned supervisory authorities at the various stages of the procedure, including in the steps leading to a binding opinion by the EDPB.
…authorities at the various stages of the procedure, including in the steps leading to a binding opinion by the EDPB. 1 CIPL is a global privacy and data policy think tank in the law firm of Hunton Andrews Kurth LLP and is financially supported by the law firm and 85+ member companies that are leaders in key sectors of the global economy. CIPL’s mission is to engage in thought leadership and develop best practices that ensure both effective privacy protections and the responsible use of personal information in the modern information age. CIPL’s work facilitates constructive engagement between business leaders, privacy and security professionals, regulators, and policymakers around the world. For more information, please see CIPL’s website at http://www.informa- tionpolicycentre.com/.
…around the world. For more information, please see CIPL’s website at http://www.informa- tionpolicycentre.com/. Nothing in this submission should be construed as representing the views of any individual CIPL member company or of the law firm of Hunton Andrews Kurth. 2 Communication from the Commission to the European Parliament and the Council, Data protection as a pillar of citizens’ empowerment and the EU’s approach to the digital transition - two years of application of the general data protection regulation, (swd(2020) 115 final), available at https://eur-lex.europa.eu/legal- content/EN/TXT/?uri=CELEX%3A52020DC0264. 3 EDPB Letter to the EU Commission on procedural aspects that could be harmonized at EU level, available at https://edpb.europa.eu/our-work-tools/our-documents/letters/edpb-letter-eu-commission-procedural- aspects-could-be_en.
…t https://edpb.europa.eu/our-work-tools/our-documents/letters/edpb-letter-eu-commission-procedural- aspects-could-be_en. 23 March 2023 3 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP. I. INTRODUCTION CIPL has been at the forefront of GDPR implementation both prior to and after the adoption of the law and has published numerous papers and studies and provided responses to numerous consultations. CIPL has built strong GDPR thought leadership, engaging with regulated entities and regulators alike to drive an approach to enforcement approaches that enable responsible data use while protecting individual’s rights. CIPL believes that any changes, even targeted ones such as this initiative, must be seen in a larger context to ensure the GDPR lives up to its full potential.
…ones such as this initiative, must be seen in a larger context to ensure the GDPR lives up to its full potential. The GDPR brought tangible benefits to organisations and individuals and turned privacy into a mainstream business issue beyond just legal and compliance. However, certain elements still need to be addressed or explored further, such as: 1. GDPR legal bases. The misperception persists that the GDPR imposes any kind of hierarchy on the available legal bases for processing – it does not; in particular, GDPR does not favour consent over other legal bases. More clarity is also required with respect to the understanding of GDPR’s legal basis in the context of other digital legislation, such as the DMA.
…with respect to the understanding of GDPR’s legal basis in the context of other digital legislation, such as the DMA. 2. Need for greater availability of GDPR accountability tools. GDPR introduced several accountability-based tools to improve compliance and privacy outcomes, yet certifications and codes of conduct remain rarely available or, where available, impose strict requirements that depart from accountability and risk-based approaches enshrined in the GDPR. Strengthening accountability measures also maximises opportunities for conflict resolution before enforcement actions are contemplated.
…measures also maximises opportunities for conflict resolution before enforcement actions are contemplated. 3. Promotion of wider use of BCR. The current BCR adoption process is burdensome and requires significant time and labour investment. In addition, some of the BCR requirements are stricter than other available transfer mechanisms and lack interoperability and mutual recognition across jurisdictions. 4. Incentivising the adoption of PET technologies. Privacy Enhancing Technologies or Privacy Preserving Technologies (PETs or PPTs) are quintessentially privacy by design and hold enormous potential to allow unlocking the full potential of data to the benefit of the digital economy and society at large without compromising privacy. CIPL intends to provide a more in-depth paper on these issues in advance of the next full GDPR review process.
…privacy. CIPL intends to provide a more in-depth paper on these issues in advance of the next full GDPR review process. Importance of the One-Stop Shop CIPL wants to express its unequivocal support for the GDPR’s innovative approach to SA cross-border enforcement, generally referred to as the One Stop Shop (OSS). The OSS is a ground-breaking tool to introduce an integrated and consistent pan-EU enforcement with respect to cross-border processing activities to enable the free flow of data and reinforce the objectives for an EU single market. 23 March 2023 4 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP.
…market. 23 March 2023 4 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP. The obvious and significant advantage introduced by the OSS is the fact that organisations can rely on one sole interlocutor with respect to enforcement decisions relating to cross- border processing, the Lead Supervisory Authority (LSA), instead of many or potentially all supervisory authorities, depending on the business model. Through this, the LSA has been able to develop a body of knowledge about and expertise in the operations of the relevant organisations. The LSA has been able to leverage their greater understanding of the organisations they supervise to propose appropriate regulatory responses with a view to ensuring compliance for the benefit of individuals.
…to propose appropriate regulatory responses with a view to ensuring compliance for the benefit of individuals. As processing activities are increasingly performed across multiple countries to serve clients/users in multiple countries or to support multi-country corporate operations, the OSS creates greater legal certainty for all stakeholders and efficiencies in compliance and enforcement. CIPL strongly supports the OSS as an innovative and essential tool for consistent implementation of the GDPR, providing legal certainty for the benefit of organisations and individuals alike, and any changes to the legal framework should involve careful consideration so as not to undermine the overall functioning of the OSS and, in particular, the special position of the LSA.
36 → 12
Comments on Proposal for a Regulation laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679 Centre for Information Policy Leadership (CIPL) Ref. Ares(2023)5978009 - 03/09/2023 3 September 2023 2 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP. The Centre for Information Policy Leadership (CIPL)1 welcomes the opportunity to provide comments on the proposal for a Regulation laying down additional procedural rules relating to the enforcement of the GDPR issued by the European Commission on July 7, 2023.
…additional procedural rules relating to the enforcement of the GDPR issued by the European Commission on July 7, 2023. We commend the Commission’s efforts to further streamline and harmonise the GDPR enforcement process, and we are encouraged to see that a number of our suggestions raised during the initial call for evidence2 have been considered and integrated into the proposal text, especially where it comes to the right defence and to be heard. In the context of this proposal, CIPL emphasises that any initiative must not introduce rules that increase procedural complexity but must aim to further strengthen the harmonised approach as envisaged in the GDPR. With this in mind, we provide the comments below on the proposal. I.
…the harmonised approach as envisaged in the GDPR. With this in mind, we provide the comments below on the proposal. I. COOPERATION MECHANISM CIPL is a strong advocate for the One-Stop-Shop (OSS) as a vital instrument for the consistent implementation of the GDPR, establishing legal certainty for both organisations and individuals.3 We recognise the OSS's role in facilitating cooperation and efficiency in enforcement, and we emphasise that any amendments to the legal framework must maintain the overall functioning of the OSS and, specifically, preserve the unique role and authority of the Lead Supervisory Authority (LSA). In particular, CIPL would like to emphasise again that cooperation between LSAs and concerned supervisory authorities (CSAs), also prior to the submission of any draft decision, must be sincere, respectful and in the spirit of mutual trust.
…also prior to the submission of any draft decision, must be sincere, respectful and in the spirit of mutual trust. While CIPL certainly welcomes the proposals for enhanced coordination, we caution against the procedure prescribed in Articles 9 and 10 (Summary of key issues and Use of means to reach consensus), where they have the potential to undermine the role of the LSAs as intended by the GDPR. The unique position of the LSA allows it to develop a body of 1 CIPL is a global privacy and data policy think tank in the law firm of Hunton Andrews Kurth LLP and is financially supported by the law firm and 85+ member companies that are leaders in key sectors of the global economy. CIPL’s mission is to engage in thought leadership and develop best practices that ensure both effective privacy protections and the responsible use of personal information in the modern information age.
…both effective privacy protections and the responsible use of personal information in the modern information age. CIPL’s work facilitates constructive engagement between business leaders, privacy and security professionals, regulators, and policymakers around the world. For more information, please see CIPL’s website at http://www.informationpolicycentre.com/. Nothing in this submission should be construed as representing the views of any individual CIPL member company or of the law firm of Hunton Andrews Kurth.
…construed as representing the views of any individual CIPL member company or of the law firm of Hunton Andrews Kurth. 2 Centre for Information Policy Leadership, Response to the European Commission’s Call for Evidence on further specifying procedural rules relating to the enforcement of the General Data Protection Regulation, available at: https://www.informationpolicycentre.com/uploads/5/7/1/0/57104281/cipl_response_to_ec_call_for_evidenc e_-_gdpr_procedural_rules_harmonisation_23_march_2023.pdf. 3 Centre for Information Policy Leadership, GDPR Enforcement Cooperation and the One-Stop-Shop – Learnings from the First Three Years, available at: https://www.informationpolicycentre.com/uploads/5/7/1/0/57104281/cipl_discussion_paper_- _gdpr_enforcement_cooperation_and_the_one-stop-shop__23_sept_2021_.pdf.
…uploads/5/7/1/0/57104281/cipl_discussion_paper_- _gdpr_enforcement_cooperation_and_the_one-stop-shop__23_sept_2021_.pdf. 3 September 2023 3 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP. knowledge with respect to the organisations it oversees and expertise in their operations to facilitate more effective enforcement. Advocate General Bobek also stressed the elevated role of the LSAs when he noted that “vis-à-vis cross-border processing, the competence of the LSA is the rule, and the competence of other supervisory authorities is the exception”.4 To that extent, where Articles 9 and 10 are frontloading the cooperation process through the consensus on the "Summary of key issues”, this process must be undertaken in the spirit of mutual trust, including in the OSS and the specific role of the LSA, to be effective.
…be undertaken in the spirit of mutual trust, including in the OSS and the specific role of the LSA, to be effective. Mutual trust is supported by developing a common understanding of best practices in regulation, exchanging information, rules around the accuracy of sharing information regarding investigations, and shared training. Such increased trust would foster mutual respect between SAs and a common understanding that objections on the “summary of key issues” should be used by CSAs only in exceptional cases. In the alternative, Article 10(4) would only lead back to an urgent binding decision of the Board where the LSA and CSA cannot reach a consensus at the "Summary of key issues" stage. This could have the Board potentially decide on the scope of an investigation, for instance, and as a result, would dilute the OSS mechanism.
…potentially decide on the scope of an investigation, for instance, and as a result, would dilute the OSS mechanism. As opposed to the LSA, the EDPB has no investigative powers itself, nor can it order SAs to conduct specific investigations into matters. The LSA, on the other hand, does have the discretion to conduct fact-finding and to make determinations regarding a fine.
LSA, on the other hand, does have the discretion to conduct fact-finding and to make determinations regarding a fine. It is important to highlight that the EDPB, as a body created by and under EU law, has the power to monitor the application of the GDPR but without prejudice to the tasks of SAs.5 In this context, CIPL would like to point out again that Recital 129 GDPR makes clear that: “The adoption of a legally binding decision implies that it may give rise to judicial review in the Member State of the supervisory authority.”6 Recital 143 GDPR refers to the procedure for a direct challenge by a party to a decision of the EDPB under Article 263 of the Treaty on the Functioning of the European Union (TFEU), where: “The act is addressed to that person, and it is either of direct and individual concern to them or is a regulatory act which is of direct concern to them.” This is a limited…
…where the decision of the institution is legally invalid; it is not an appeal on the facts, law or merits of a case. It should, therefore, also not limit the right of a party to mount a challenge to the national court on the facts, law or merits of a case, or a national court from hearing such an appeal, and, in an appropriate case, referring the matter to the Court of Justice in cases of EDPB binding decisions.7 4 Opinion of Advocate General Bobek in Case C-645/19, para 47. 5 Comments by the Centre for Information Policy Leadership on the European Data Protection Board’s Draft Guidelines 03/2021 on the application of Article 65(1)(a) GDPR (https://www.informationpolicycentre.com/uploads/5/7/1/0/57104281/cipl_comments_on_edpb_article_65_ draft_guidelines__28_may_2021_.pdf).
…ormationpolicycentre.com/uploads/5/7/1/0/57104281/cipl_comments_on_edpb_article_65_ draft_guidelines__28_may_2021_.pdf). 6 Under Article 78, each natural or legal person must have the right to an effective judicial remedy against a legally binding decision of an SA concerning them. Recital 143 GDPR further sets out the right to appeal to the national courts, as provided by Article 78 GDPR. 7 Ibid, p. 5. 3 September 2023 4 Copyright © 2023 by the Centre for Information Policy Leadership at Hunton Andrews Kurth LLP. Finally, for an efficient and timely consensus process, we recommend that the Board specify rules for the consensus process itself, in addition to the restrictions on comments proposed under Article 9(5). II. AMICABLE SETTLEMENTS CIPL generally supports the introduction of amicable settlement provisions, providing that clear rules and commitments accompany these.
20 → 12