Companies & groups · GB
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 32 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
RELX response to Commission request for feedback on GDPR evaluation 1 RELX welcomes the opportunity to provide feedback on the Commission’s report on the application of the EU General Data Protection Regulation (GDPR). RELX is a global provider of information-based analytics and decision tools for professional and business customers. We help scientists make new discoveries, doctors and nurses improve the lives of patients and lawyers win cases. We prevent online fraud and money laundering and help insurance companies evaluate and predict risk. Our events enable customers to learn about markets, source products and complete transactions. In short, we enable our customers to make better decisions, get better results and be more productive.
…transactions. In short, we enable our customers to make better decisions, get better results and be more productive. Increased trust and legal certainty The EU GDPR has sought to achieve harmonisation of applicable rules, increased transparency of data handlers’ responsibilities in the EU and beyond and raise general public awareness of privacy. This has undoubtedly helped to increase the level of trust society has in the data economy. The GDPR has – to a large degree – provided business with legal certainty as to how data can be processed. The ability to gather, store, analyse and trade data is at the heart of the on-going development of public and consumer services. RELX supports data protection and usage laws which balance the protection of personal data with the ability to deliver significant societal and economic benefits.
…which balance the protection of personal data with the ability to deliver significant societal and economic benefits. In order to take full advantage of the benefits of data-driven services, companies and consumers must be able effortlessly to move data across borders. Rules that create a barrier to the free flow of data between states or which mandate local storage stifle competition and discourage innovation. The GDPR provides multiple mechanisms that can be used by organisations to comply with the Regulation’s general principles and specific requirements when transferring personal data outside the EU and EEA. Among these mechanisms are adequacy decisions and standard contractual clauses (SCCs).
…data outside the EU and EEA. Among these mechanisms are adequacy decisions and standard contractual clauses (SCCs). Clarity and ease of business in data flows to third countries RELX takes the view that data adequacy agreements with third countries provide businesses that rely on cross-border data flows the most amount of legal certainty with the least amount of red tape. Whilst it is positive that to-date the Commission has deemed thirteen third countries to provide adequate data protection, we would encourage the Commission to strike more of such agreements. As signatory to the EU-US Privacy Shield framework, we understand and support efforts to continuously improve Privacy Shield. At the same time, we would stress the need for such a framework to facilitate Transatlantic data flows, as many of our data flows from Europe to the US and vice versa.
…a framework to facilitate Transatlantic data flows, as many of our data flows from Europe to the US and vice versa. An EU-UK data adequacy agreement is equally important. While both the EU and UK have reiterated their aspirations of setting up such a framework, we would call on the Commission to not let go of this aim. With challenging deadlines around a future EU-UK partnership, innovative solutions for data adequacy, like grace periods until full adequacy has been reached, need to be considered as not to hamper the uninterrupted flows of data across the Channel. In the cases where there is no third country data adequacy agreement in place, Article 46 of the GDPR offers other mechanisms that enable data to flow internationally, such as standard contractual clauses.
…46 of the GDPR offers other mechanisms that enable data to flow internationally, such as standard contractual clauses. SCCs can be an essential part of the day-to-day operations of companies across Europe, to transfer data with affiliates, vendors, customers and suppliers. Whilst SCCs thus do provide certainty for business, they are complex and unwieldy to put together and cannot easily be adapted to the rapid pace of the evolution of technology. Some SCCs are outdated or no longer fit for purpose. The Commission would do well to update these to provide businesses – large and small – with an appropriate toolbox to transfer data from Ref. Ares(2020)2291693 - 29/04/2020 RELX response to Commission request for feedback on GDPR evaluation 2 the EU to third countries.
- 29/04/2020 RELX response to Commission request for feedback on GDPR evaluation 2 the EU to third countries. In particular the long-awaited processor-to-processor SCC, currently absent from the set of instruments the Commission offers, could help businesses to achieve greater legal certainty with relatively less administrative burden. Harmonised implementation & application of GDPR in coherence with other legislation The proposed ePrivacy Regulation limits the legal processing bases outlined in GDPR thereby denying its full use for companies in practice. The ePrivacy proposal should achieve its intentions of aligning with the GDPR and not create a separate track of privacy law that will throw the EU data protection policy framework into contention. Either the e-Privacy regulation should be completely removed, or it should only cover matters not captured by GDPR.
Either the e-Privacy regulation should be completely removed, or it should only cover matters not captured by GDPR. The lack of harmonisation is partially due to the large number of open-ended derogation clauses. For example, Article 10 in relation to the possibility of processing of personal data relating to criminal convictions and offences differs across Member States. This means that some businesses in certain jurisdictions can easily do background checks in relation to opening bank accounts or signing export agreements with other nations while others cannot. This lack of coherence across the EU significantly hampers anti-money laundering, counter-terrorist financing and anti-bribery & corruption efforts, with serious consequences for Europe’s economy and society.
…financing and anti-bribery & corruption efforts, with serious consequences for Europe’s economy and society. Even for those GDPR provisions which are fully harmonised cross-border, Member State Data Protection Authorities (DPAs) continue to take unilateral action on the basis of their own views. Interpretation is based on pre-existing and differing historical frameworks. For example, the Dutch Data Protection Authority in November 2019 issued guidance on legitimate interest, stating that “profit maximisation” should not be considered as a valid reason to process data using legitimate interest as a processing ground. This interpretation deviates from other DPAs’ guidance (Ireland, UK) and that of the Article 29 Working Party on legitimate interest and commercial exploitation.
…guidance (Ireland, UK) and that of the Article 29 Working Party on legitimate interest and commercial exploitation. Finally, the lack of a harmonised, clear approach to how the Supervisory Authority (SA) relates to a data- processing organisation still exists. Whilst the Commission’s intention of the GDPR with the introduction of the ‘one-stop-shop' was to make “life easier and cheaper for companies doing business in the EU”, there have been decisions and fines against companies by DPAs not being their SA. This only adds additional layers of complexity for data companies. RELX welcomes the opportunity and stands ready to continue to engage with the Commission in its formal review of the application of GDPR.