EOS Holding GmbH

Companies & groups · DE

Kategorija
Companies & groups
Būstinė
Hamburg DE
Registruota
2019-02-05
Deklaruotos metinės išlaidos
100 000–199 999 € (pačios deklaruota)
Svetainė
http://www.eos-solutions.com
Skaidrumo registras
423430433865-84 ↗
0
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Ką pateikė viešoms konsultacijoms

2024-02-07 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Please note that an attachment has been included with the form, containing the contribution of the EOS Group to the public consultation on the evaluation of the General Data Protection Regulation (GDPR).
2021-04-27 · Review of the VAT rules for financial and insurance services ↗ originalus šaltinis

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 3 p.

EOS Holding GmbH Steindamm 71 ∙ D-20099 Hamburg ∙ T +49 40 2850 0 ∙ F +49 40 2859 1400 ∙ [email protected] ∙ eos-solutions.com Board of Directors: M. Ramcke (Chairman), J. Hecking-Veltman, A. Kropp, Dr. S. Ohlmeyer, C. Tidow, Dr. A. Witzig Chairwoman of the Supervisory Board: P. Scharner-Wolff ∙ AG Hamburg HRB 124966 ∙ VAT Reg. No DE 813348056 Bank Account: Commerzbank Hamburg ∙ BIC COBADEHHXXX ∙ IBAN DE26 2004 0000 0614 2780 00 Page 1/3 EOS Holding GmbH Steindamm 71 ∙ 20099 Hamburg EOS Group´s Contribution to the Public Consultation on the Evaluation of the General Data Protection Regulation 2024-02-07 On behalf of the EOS Group, we would like to participate in the public consultation on the evaluation of the General Data Protection Regulation (GDPR) initiated by the European Commission. The EOS Group is an international, technology-driven expert in receivables management.

…by the European Commission. The EOS Group is an international, technology-driven expert in receivables management. With over 50 years of experience, we offer our customers in 24 countries around the world smart solutions for all their receivables management needs. Our core business includes the acquisition of secured and unsecured debt portfolios. We primarily serve the sectors of banking, utilities, real estate, and e-commerce. With more than 6,000 employees, we are part of the Otto Group. Our goal is to create win-win solutions that improve our clients' cash flow, allowing them to focus on their core business. We view the GDPR as an important pillar in promoting trust in the digital economy and ensuring the protection of personal data within and outside the EU.

…in promoting trust in the digital economy and ensuring the protection of personal data within and outside the EU. In our response, we would like to address the experiences and challenges we have faced as an internationally active company in the field of receivables management in the context of the GDPR. We would also like to make suggestions on how the GDPR could be further developed to strengthen data protection, while also ensuring the efficiency and effectiveness of business processes in the digital economy. We thank you for the opportunity to participate in this consultation and look forward to sharing our perspectives and suggestions with you. Should you require any further information or wish to discuss the matters in more detail, please do not hesitate to contact Stephan Bovermann at [email protected] or on his mobile at +49 151 25163572. Ref.

…not hesitate to contact Stephan Bovermann at [email protected] or on his mobile at +49 151 25163572. Ref. Ares(2024)940939 - 07/02/2024 Page 2/3 Input on question 2: Data Subject Rights a. In providing transparency information under Articles 13/14 of the GDPR, there is significant variation in the interpretation by national supervisory authorities. While some authorities consider a brief form with a reference to a website sufficient, others expect the full details to be provided in writing. In light of increasing digitalization, a uniform interpretation by all data protection authorities of the member states is desirable, particually concerning the provision of transparency information to individuals. b. We are increasingly receiving requests from data subjects for access to the data we process, a principle of transparency we are keen to follow.

…requests from data subjects for access to the data we process, a principle of transparency we are keen to follow. However, we also observe a rising number of requests, which, followed by the subsequent interventions of data subjects up to complaints directed at data protection authorities, are evidently not intended to serve transparency but to distract from the actual purpose of data processing. We also note the use of the right of access to data by insolvency practitioners and estate administrators for their own purposes. Legislative relief to justify unsubstantiated and excessive invocations of the right of access would be desirable to ensure that data protection law is not misused to divert attention from the actual purpose of the data processing.

…to ensure that data protection law is not misused to divert attention from the actual purpose of the data processing. Input on question 5: Experiences with Data Protection Authorities The operational methods of the data protection authorities in the member states vary significantly, and a harmonization of the interpretation of the GDPR, would be of utmost importance for multinational companies in the following aspects: a. Among the data protection authorities of the member states, we experience cooperation with authorities that are open and accessible for consultation requests and strive to actively shape data protection. Unfortunately, we also encounter the opposite: data protection authorities that consistently refuse any request for consultation.

…we also encounter the opposite: data protection authorities that consistently refuse any request for consultation. A clarification of the GDPR's stipulated task of the authority to provide advice upon request and legal remedies outside of local administrative law would be desirable. b. Additionally, as a multinational organization, we endeavor to interpret our application of data protection in accordance with the guidelines of the EDPB (European Data Protection Board). In our daily work, we encounter individual data protection authorities who are either unaware of the guidelines or, when acknowledging them, represent different interpretations. Data protection authorities are urged to adhere to the guidelines adopted in conjunction with the European Data Protection Board (EDPB) when applying the GDPR, to ensure consistency and fairness in its enforcement. (1) (2) (3) (4) Page 3/3 c.

Board (EDPB) when applying the GDPR, to ensure consistency and fairness in its enforcement. (1) (2) (3) (4) Page 3/3 c. Moreover, in the management of complaints by data protection authorities, the influence of national administrative practices is markedly evident. Therefore, transparency regarding ongoing activities cannot be ensured. It is particularly noteworthy that the data protection authorities usually do not provide final information to the data controller upon the conclusion of a complaint resolution or individual case review, preventing a definitive clarification of matters and leaving them perpetually open. Legislators must ensure transparency from data protection authorities towards Data Controllers as well. d. Furthermore, during audits conducted by authorities, we observe varied approaches.

…towards Data Controllers as well. d. Furthermore, during audits conducted by authorities, we observe varied approaches. A few regulatory bodies are constructive and open to dialogue, whereas others seem to make their decisions in theory without involving the data controller. This, from our perspective, leads to unfounded decisions by data protection authorities. Our only remedy is to engage in administrative court proceedings, which demand significant resources. To avoid those, we would hope for more openness and a predisposition towards a constructive dialogue from the side of all data protection authorities before they finalize their decisions. e. We encounter difficulties with the interpretation of Data Controller and Data Processor.

…finalize their decisions. e. We encounter difficulties with the interpretation of Data Controller and Data Processor. Following the regulations of the GDPR, the analysis of who holds the role of the Data Controller and that of the Data Processor is pleasingly well defined. The supplementary guidelines of the EDPB (European Data Protection Board) leave little room for questions. However, the interpretation by various data protection authorities differs. For example, it is common for a claim managed by our company to not be economically owned by the company that performs the management and thus the data processing. However, many data protection authorities define the role of the Data Controller exclusively based on economic ownership and not on the actual decision-making regarding the purposes and means of data processing.

…based on economic ownership and not on the actual decision-making regarding the purposes and means of data processing. It should be clearly stated in article 4 of the GDPR that the designation of the role of a Data Controller hinges upon the determinations regarding the purposes and means of data processing, not on economic ownership. Input on question 12: Codes of Conduct a. A Code of Conduct is a meaningful tool for specifying the GDPR to meet the specific requirements of industries. In collaboration with FENCA, our industry’s umbrella organization, we engaged in a year-long process to develop such a Code of Conduct. The initial draft was constructively processed by the first supervisory authority we approached, but, after a lengthy and sluggish procedure, it was unreasonably rejected by a second authority without justification.

…but, after a lengthy and sluggish procedure, it was unreasonably rejected by a second authority without justification. Due to the lack of direct legal remedies provided by the GDPR, our only recourse is a cumbersome administrative court procedure. Therefore, we request clear, uniform guidelines for data protection authorities regarding the approval process of industry-specific Codes of Conduct. (6) (7) (8) (5)

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

NPL Action Plan and relating initiatives / legislation including the NPL Directive, Regulation on the law applicable to the third-party effects of assignments of claims, EU securitisation framework, financial regulation including Consumer Credit Directive / Mortgage Credit Directive, GDPR, e-Privacy Directive, Anti Money Laundering legislation, AI Regulation, DORA, FiDA, NIS 2