Asociación Española de Economia Digital

Adigital · Trade and business associations · ES

Kategorija
Trade and business associations
Būstinė
Barcelona ES
Registruota
2022-05-03
Deklaruotos metinės išlaidos
50 000–99 999 € (pačios deklaruota)
Svetainė
www.adigital.org
Skaidrumo registras
367588046372-04 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

2025620262

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 8 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Adigital Contribution COMMISSION 2024 REPORT ON THE APPLICATION OF THE GDPR European Commission Open Feedback Period The General Data Protection Regulation (GDPR) is the main piece of EU legislation guaranteeing the fundamental right to data protection. The GDPR entered into application on 25 May 2018, repealing and replacing Directive 95/46/EC. It sets out the rights of individuals and imposes obligations on organisations and businesses that process the personal data of people in the EU, with a two-fold objective: (i) to protect fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data; and (ii) to allow the free flow of personal…
2023-03-24 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
Adigitals comments on European Commissions call for evidence on Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation [Please find attached the entire document] I. Preliminary Points a. Competence of the European Commission (EC) We have concerns that the scope of the proposals in the initiative appear to go beyond those matters the EC has legal competence to regulate. Article 61(9) GDPR grants the EC the power to adopt implementing acts to specify the format and procedures for mutual assistance between Supervisory Authorities (SAs) and the arrangements for the exchange of information between SAs and between SAs and the European Data…

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 6 p.

Adigital’s comments on European Commission’s call for evidence on Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation I. Preliminary Points a. Competence of the European Commission (EC) ● We have concerns that the scope of the proposals in the initiative appear to go beyond those matters the EC has legal competence to regulate. ● Article 61(9) GDPR grants the EC the power to adopt implementing acts to specify the format and procedures for mutual assistance between Supervisory Authorities (SAs) and the arrangements for the exchange of information between SAs and between SAs and the European Data Protection Board (EDPB) under Article 67 GDPR. ● Under the GDPR, the EC has no further power to adopt implementing or delegated acts.

(EDPB) under Article 67 GDPR. ● Under the GDPR, the EC has no further power to adopt implementing or delegated acts. ● We presume that any procedural rules adopted by the EC as a result of this Initiative will fall strictly within the prescribed legal framework. ● Any rules that go beyond this framework could only be established through the ordinary legislative procedure, Article 16 TFEU. b. Equality of Rights ● The GDPR provides for a comprehensively harmonised and conclusive ‘regulatory framework’ for the public enforcement of data subject rights by independent SAs (Article 51(ff) GDPR) with fixed competences, tasks, and powers. ● The GDPR also created a comprehensive system of cooperation and consistency.

…fixed competences, tasks, and powers. ● The GDPR also created a comprehensive system of cooperation and consistency. This system is organised according to the ‘one-stop-shop’ (OSS) principle, under which the Lead Supervisory Authority (LSA) of the controller’s main establishment is the only point of contact competent for this controller’s cross-border processing operations (Article 56(1) GDPR). ● In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR). This harmonised regulatory framework, like the substantive provisions of the GDPR, serves to achieve two equal goals of the GDPR, i.e.

…regulatory framework, like the substantive provisions of the GDPR, serves to achieve two equal goals of the GDPR, i.e. the same high level of protection of natural persons and the removal of obstacles to personal data flows within the Union, and an adequate balance of the data subject’s and controller’s fundamental rights, and where applicable, those of third parties in the Union at the administrative and procedural level. Ref. Ares(2023)2146640 - 24/03/2023 ● We trust that the EC’s proposals will not jeopardise the balanced system established by the GDPR for the benefit of both data subjects and controllers concerned. c.

…the balanced system established by the GDPR for the benefit of both data subjects and controllers concerned. c. Procedural clarification ● As this Initiative responds inter alia to the list published by the EDPB on 10 October 2022 identifying procedural aspects of the cooperation between SAs in cross-border cases that could benefit from further harmonisation at EU level, we share below concerns based upon this list II. Specifying Procedural Deadlines for Cooperation Between DPAs on Cross-Border Cases ● We understand that the EDPB is concerned that the absence of deadlines in the GDPR may cause undue delay and/or disparity in the finalisation of cases.

…that the absence of deadlines in the GDPR may cause undue delay and/or disparity in the finalisation of cases. ● The EDPB suggests that the introduction of deadlines for a number of procedural steps (both at national level and in the context of cross-border cooperation) would be useful to avoid undermining the credibility of enforcement and may help alleviate public concern from complainants that cases are being handled too slowly. ● The EDPB considers that deadlines should be specified, e.g. to start an investigations, to issue a draft decision, or to prepare a revised draft decision after relevant and reasoned objections are sent. The EDPB recognises that such deadlines should take into account the specificity and complexity of each case.

…are sent. The EDPB recognises that such deadlines should take into account the specificity and complexity of each case. ● The LSA would then have to provide justifications where it is not possible to meet these deadlines, and would face consequences for failing to comply with the newly established procedural deadlines. ● We submit that the length of time required to complete each procedural step depends on the complexity of the subject matter of the inquiry in question. We are concerned that providing for arbitrary and fixed deadlines for procedural steps which apply to all inquiries without discrimination, with no regard for the complexity of the subject matter, would likely operate to the detriment of the party under investigation and undermine the fair, properly reasoned, efficient, and consistent application of the GDPR.

…party under investigation and undermine the fair, properly reasoned, efficient, and consistent application of the GDPR. ● The commencement of an investigations, issuing of a draft decision, and preparation of a revised draft decision are complex procedural steps that must be made carefully, and should not be constrained by artificial deadlines. ● It is relevant to note in this regard that the exercise by the SA of their powers must be “subject to appropriate safeguards, including…due process set out in Union and Member State law in accordance with the Charter” (Article 58(4) GDPR), as is the exercise by the SAs of their power to impose administrative fines (Article 83(8) GDPR).

(Article 58(4) GDPR), as is the exercise by the SAs of their power to impose administrative fines (Article 83(8) GDPR). ● It is unclear how such deadlines could be compatible with a case-by-case analysis taking into account the specificity and complexity of the investigation in question and the procedural safeguards provided for under the applicable national law, which must be respected in accordance with Articles 58(4) and 83(8). ● It is equally unclear how the fundamental rights of the party subject to investigation could be respected were such arbitrary deadlines to apply to all inquiries, regardless of the circumstances. We note in this regard that the EDPB has itself expressed concern and frustration in respect of the fixed deadlines imposed by the Article 65 process and queries why it would seek to impose such deadlines on the SAs.

…fixed deadlines imposed by the Article 65 process and queries why it would seek to impose such deadlines on the SAs. ● We further submit that the imposition of arbitrary procedural deadlines will result in rushed decisions and, as such, is likely to result in more decisions being challenged by the parties under investigation and subsequently overturned by the courts. ● If there are concerns about the ability of the SA to progress investigations in a timely manner, while also affording the subject of the inquiry due process, this should be addressed by ensuring that the SAs have the necessary human and financial resources to perform their tasks in a timely manner, and not by curtailing the procedural safeguards to which controllers are entitled. This is particularly so in light of the magnitude of the administrative fines which may be imposed under the GDPR. III.

This is particularly so in light of the magnitude of the administrative fines which may be imposed under the GDPR. III. Providing Tools to DPAs to Promote Cooperation Early in the Investigation Process ● The EDPB suggests that there is a need to clarify that the amicable settlement achieved in the OSS context on a specific case also requires cooperation on the legal questions behind the individual case (either by demonstrating it as an isolated case or by explaining what follow-up actions are intended to be taken regarding the breach of GDPR provisions by the controller). ● While we are generally supportive of clarifying the framework for amicable settlements, especially in Member States which currently do not have a legal framework for this, any such initiative should ensure that settlements are not burdened by too far-reaching coordination obligations.

…this, any such initiative should ensure that settlements are not burdened by too far-reaching coordination obligations. ● Otherwise, this could unreasonably deprive the LSA of its prerogatives and could have the effect of turning settlements, which are intended to be quick and simple solutions in the interests of both data subjects and controllers into long and more complex processes. It could also deter the amicable settlement of disputes, an outcome which would clearly be contrary to the objectives of the GDPR. ● We stress the importance of not distorting the enforcement system in cross-border cases established by the GDPR through procedural rules. While ensuring efficient and harmonious enforcement between SAs in such cases is an important objective, it is essential to preserve the LSAs independence and prerogatives established by the GDPR.

26 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 10 p.

Adigital Contribution COMMISSION 2024 REPORT ON THE APPLICATION OF THE GDPR European Commission Open Feedback Period The General Data Protection Regulation (GDPR) is the main piece of EU legislation guaranteeing the fundamental right to data protection. The GDPR entered into application on 25 May 2018, repealing and replacing Directive 95/46/EC. It sets out the rights of individuals and imposes obligations on organisations and businesses that process the personal data of people in the EU, with a two-fold objective: (i) to protect fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data; and (ii) to allow the free flow of personal data and the development of the digital economy across the internal market.

(ii) to allow the free flow of personal data and the development of the digital economy across the internal market. In line with Article 97 GDPR, the Commission must examine, in particular, the application and functioning of Chapter V, on the transfer of personal data to third countries or international organisations with particular regard to decisions adopted pursuant to Article 45(3) of this Regulation and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC; and Chapter VII, on cooperation and consistency. The first report on the evaluation and review of the GDPR was adopted in 2020. The next report is expected to be adopted by mid-2024. Adigital welcomes the opportunity to provide feedback to this initiative, which will report on how the rules have been applied, 6 years after their entry into application.

…to this initiative, which will report on how the rules have been applied, 6 years after their entry into application. The following document presents Adigital’s inputs to the European Commission’s open feedback period, answering the questions that the Commission posed to its GDPR Multistakeholder Group in September 2023. Ref. Ares(2024)960666 - 08/02/2024 QUESTIONS 1. General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? ● As for the benefits, the GDPR has become a driver for change for organisations, consumers, and countries around the world – this was largely due to the scale of penalties that focused the minds of corporates and forced change.

…the world – this was largely due to the scale of penalties that focused the minds of corporates and forced change. It has also generated greater awareness from consumers, and who know clearly now understand their rights and are more invested in how their data is being used. Moreover, the Brussels effect of the GDPR is increasingly evident, as numerous jurisdictions around the world have taken the example of the EU and adopted their own version of the GDPR. It has triggered many global privacy laws to be formed, and is often used as the blueprint, which is helpful, however a global standard would be much more beneficial in the long term.

…used as the blueprint, which is helpful, however a global standard would be much more beneficial in the long term. The One-Stop-Shop principle, has been essential to the GDPR in creating a single regulator for EU businesses and has created an efficient process for addressing cross- border complaints without the burden and cost of a company having to engage with 27 separate regulators. In sum, the GDPR allows for a principles-based approach and provides solid legal basis, allowing for data protection and as well as a level of flexibility. ● Despite these benefits, there are a number of shortcomings with the application of the GDPR, it is important to note that addressing these issues can be done through further guidance and dialogue, thus avoiding the need the need for further legislation.

…issues can be done through further guidance and dialogue, thus avoiding the need the need for further legislation. Issues have included: ○ The use of privacy rights incorrectly as a due diligence mechanism or as a way to force settlement. ○ The technological reality in complying is often inconsistent with the regulatory requirements or expectations from DPAs. It is difficult to interpret and implement the law at times, given the pace of technological change and the complexity of data systems. ○ DPAs have adopted an approach that interprets and enforces the GDPR in an overly rigid way. The risk-based approach in the text of the Regulation was inserted as a key guiding principle and has not been properly applied.

…approach in the text of the Regulation was inserted as a key guiding principle and has not been properly applied. Instead, we have seen the right to the protection of personal data treated as an absolute, without any weighing against the legitimate interests of data controllers and others’ rights and interests. ○ Clarity on the extent and applicability of the right to object is important – and the balancing of rights regarding who is able to override who. This point also relates to clarity that is missing on Legitimate Interests. ○ There is a need for more support on corporate governance, controllership, representatives, DPOs etc., and how to structure this in global organisations.

…on corporate governance, controllership, representatives, DPOs etc., and how to structure this in global organisations. DPOs, for example, could benefit from increased information and clarity regarding when DPOs are required, their roles and responsibilities within the structures of global organisations, how to deal with conflicts. ○ The GDPR would benefit from clarifications on the interplay between the GDPR and other regulations with an impact on privacy and data protection. For example, while under the GDPR legitimate interest might be a more suitable basis for processing in some cases, the concurrent application of the e-Privacy Directive necessitates the use of consent instead. Many of the clarifications and inconsistencies could be addressed through the revision of the ePrivacy Directive.

Many of the clarifications and inconsistencies could be addressed through the revision of the ePrivacy Directive. ○ Further clarity would be useful on controller/processor status in more complex multi-party arrangements, e.g. Generative AI, white-label solutions etc. ○ How to set up helpful sector-based codes of conduct, as this seems impossibly difficult right now but could be helpful. ○ International data transfer regimes no longer reflect the practical reality of data processing. The internet is global and no longer is data packaged up in a little box and shared from one place to another akin to a physical filing system. The regulatory world has to mature their view on this and move towards the controls to protect the data, rather than the prevention/limitation of transfer.

…view on this and move towards the controls to protect the data, rather than the prevention/limitation of transfer. ■ GDPR should cover a risk-based approach regarding international data transfers where the nature of the data, as well as other key circumstances (including factual information on whether the importer has received national security data requests or is likely to receive one). Also, not just the US has national laws permitting access to data for national security purposes: all others have similar provisions. So efforts from the EU institutions to achieve an international treaty covering this is essential. ○ There needs to be a set of technical and organisational measures that deem a transfer possible, based on a proportionate and risk-based approach. It is imperative that transfers are made possible by putting the right protections in place.

…and risk-based approach. It is imperative that transfers are made possible by putting the right protections in place. The current regime is overly cumbersome and unclear. Simplify and enhance the Code of Conduct approval process, which takes a couple of years to be approved, discourages many organisations, which cannot invest so much effort inefficiently. ○ There are concepts that could be clarified in the potential GDPR revision, taking into account the historical necessity of interpretations made by the European Data Protection Board and the different Supervisory Authorities.

…necessity of interpretations made by the European Data Protection Board and the different Supervisory Authorities. ■ For example, the GDPR does not provide a definition for “international transfer of personal data”, “Data Protection Officer'', “compelling legitimate interest”, “legitimate interest”, or the “legal effects” produced by automated processing of the data subjects or when they are affected “similarly significantly”, to name a few. After five years since the GDPR entered into force, maybe it is a good moment to review the GDPR to include those concepts that have obtained a standardisation by the abovementioned Authorities.

42 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

REGLAMENTO DEL PARLAMENTO EUROPEO Y DEL CONSEJO relativo a un mercado único de servicios digitales (Ley de servicios digitales) y por el que se modifica la Directiva 2000/31/CE
REGLAMENTO DEL PARLAMENTO EUROPEO Y DEL CONSEJO sobre mercados disputables y equitativos en el sector digital (Ley de Mercados Digitales)
Directiva (UE) 2019/2161 del Parlamento Europeo y del Consejo de 27 de noviembre de 2019 por la que se modifica la Directiva 93/13/CEE del Consejo y las Directivas 98/6/CE, 2005/29/CE y 2011/83/UE del Parlamento Europeo y del Consejo, en lo que atañe a la mejora de la aplicación y la modernización de las normas de protección de los consumidores de la Unión (Texto pertinente a efectos del EEE)
Directiva (UE) 2019/770 del Parlamento Europeo y del Consejo, de 20 de mayo de 2019, relativa a determinados aspectos de los contratos de suministro de contenidos y servicios digitales (Texto pertinente a efectos del EEE.)
Directiva (UE) 2019/771 del Parlamento Europeo y del Consejo, de 20 de mayo de 2019, relativa a determinados aspectos de los contratos de compraventa de bienes, por la que se modifican el Reglamento (CE) n.° 2017/2394 y la Directiva 2009/22/CE y se deroga la Directiva 1999/44/CE (Texto pertinente a efectos del EEE.)
REGLAMENTO DEL PARLAMENTO EUROPEO Y DEL CONSEJO POR EL QUE SE ESTABLECEN NORMAS ARMONIZADAS EN MATERIA DE INTELIGENCIA ARTIFICIAL (LEY DE INTELIGENCIA ARTIFICIAL) Y SE MODIFICAN DETERMINADOS ACTOS LEGISLATIVOS DE LA UNIÓN
Propuesta de REGLAMENTO DEL PARLAMENTO EUROPEO Y DEL CONSEJO sobre normas armonizadas para un acceso justo a los datos y su utilización (Ley de Datos)
Propuesta de Regl. Parlamento Europeo y del Consejo por el que se modifican los Regl. (UE) 2024/1689 y (UE) 2018/1139 en lo que respecta a la simplificación de la aplicación de normas armonizadas sobre inteligencia artificial (Omnibus Digital sobre IA)
Propuesta de Reglamento del Parlamento Europeo y del Consejo por el que se modifican los Reglamentos (UE) 2016/679, (UE) 2018/1724, (UE) 2018/1725, (UE) 2023/2854 y las Directivas 2002/58/CE, (UE) 2022/2555 y (UE) 2022/2557 en lo que respecta a la simplificación del marco legislativo digital, y se derogan los Reglamentos (UE) 2018/1807, (UE) 2019/1150, (UE) 2022/868 y la Directiva (UE) 2019/1024 (Ómnibus Digital)