Trade and business associations · IE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 71 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
GDPR – Procedural Rules on Enforcement Call for Evidence, Ref. Ares (2023) 1378380 March 24, 2023 Ref. Ares(2023)2160686 - 24/03/2023 2 Ibec Policy Submission Contents Introduction 3 Comments 3 Proportionality 3 Fungibility 3 Certainty 4 GDPR – Procedural Rules on Enforcement (Call for Evidence, Ref. Ares (2023) 1378380) 3 Introduction Ibec, the Irish business representative group (EU Transparency Register with identification number 479468313744-50) welcome the opportunity to offer a principled response to your call for evidence. Any intervention should consider proportionality, fungibility and certainty in safeguarding the privacy of EU citizens and the needs of a modern economy. Comments Proportionality The data privacy ecosystem is becoming more rather than less complex. Particularly with the arrival of adjacent EU laws in the broader digital policy space.
…more rather than less complex. Particularly with the arrival of adjacent EU laws in the broader digital policy space. While a review of cross-border enforcement is welcome, this effort should be concentrated in strengthening the One Stop Shop Mechanism (OSS) and needs to be balanced with efforts in other areas including support for company compliance, sectoral engagement and sector-specific guidance where needed (to ensure fair interpretation and application of GDPR) and educating consumers about services that rely on data processing. In addition, new initiatives should be mindful of the potential regulatory burden for small and medium sized businesses across the EU.
…initiatives should be mindful of the potential regulatory burden for small and medium sized businesses across the EU. Fungibility Data Protection Supervisory Authorities (DPSAs) should also be supported in ongoing efforts to improve their own operations and processes in other areas without the need for further regulation that could hamper the goals of the centralised enforcement system provided for under the OSS. DPSAs can take meaningful steps, quickly and easily, within their current powers and without new EU regulation. 4 Ibec Policy Submission Certainty We support further efforts on ensuring: 1. Complaint handling processes are uniform and more predictable for all organisations and individuals.
…on ensuring: 1. Complaint handling processes are uniform and more predictable for all organisations and individuals. 2. Quick resolution of complaints for individuals with a focus on alternative and amicable dispute resolution avoiding lengthy and costly litigation which unnecessarily delays resolution for data subjects. 3. Predictability in complaint handling ‘flow’. a. DPSAs should require complainants to have sought recourse directly from the organisation, at a minimum, and follow an organisation's internal process first before submitting a matter to their relevant DPSA, following international best practices. i. This is consistent with the accountability principle, allows non-GDPR complaints to be filtered out and addressed quickly, ensures quick resolution of non-complex GDPR complaints, and ensures that DPSA resources are devoted to more complex and high impact complaints. b.
…non-complex GDPR complaints, and ensures that DPSA resources are devoted to more complex and high impact complaints. b. Next, unresolved complaints submitted to their relevant DPSA should be routinely considered for an amicable resolution process, including cross-border cases. c. Where a case cannot be resolved through the organisation’s internal process and subsequently through alternative resolution, there should be clear thresholds for admissibility of cases for further investigation and these should be applied fairly and consistently to cases which a DPSA recommends for further investigation. This should include steps to identify and assess vexatious complaints to ensure fairness and avoid outcomes that result in unequal and/or uneven enforcement between competing firms or within segments of the digital economy: i.
…that result in unequal and/or uneven enforcement between competing firms or within segments of the digital economy: i. Greater use of regulatory dialogue could resolve issues without invoking Art 60. ii. DPSAs should also consider sector specific engagement and guidance to ensure consistent interpretation and application of GDPR. iii. DPSAs should have clear (and published) thresholds for initiating own volition investigations. Considerable resources may be tied up in such investigations and this impacts resources available for other activities. iv. Consider closing cases if the complainant or the originating DPSA fails to respond to the controller/processor’s response within a statutorily defined period. This would avoid a scenario where a cross-border complaint can remain open indefinitely, long after the company has responded.
…avoid a scenario where a cross-border complaint can remain open indefinitely, long after the company has responded. GDPR – Procedural Rules on Enforcement (Call for Evidence, Ref. Ares (2023) 1378380) 5 We support further efforts on ensuring:
Procedural Rules on Enforcement (Call for Evidence, Ref. Ares (2023) 1378380) 5 We support further efforts on ensuring: 4. Article 60/EDPB processes are enhanced. a. Enhance cooperation between data protection supervisory authorities. Support the One Stop Shop concept. b. Harmonise administrative procedures applied in cross-border cases. Ensure that efforts to streamline the process are proportionate. Avoid scenarios where inflexibility in procedural deadlines come at the expense of due process and honouring each party’s procedural rights. c. Strengthen the right to be heard, particularly where new facts or legal interpretations are introduced. d. Safeguard confidentiality. Avoid disclosures to anyone who are not a party to the proceedings. Finally, we support the European Commission, the co-legislators and regulators in ongoing efforts to adopt a new adequacy decision for transatlantic…
Technology Ireland view on the European Commission’s ‘Report on the General Data Protection Regulation’ Introduction Technology Ireland, the Ibec group representing the technology industry, welcomes the opportunity to comment on the European Commission’s ‘Report on the General Data Protection Regulation’. We outline below some key overarching observations and issues. Technology Ireland’s view: ● Six years into the implementation of the General Data Protection Regulation (GDPR), Europe’s digital legal landscape has undergone significant transformations. From evolving case law from the EU’s Court of Justice (CJEU) to the completely new pieces of legislation stemming from the AI Act and the European data strategy, Europe’s regulatory environment has become much more complex.
…stemming from the AI Act and the European data strategy, Europe’s regulatory environment has become much more complex. ● Our vision for Europe in 2030 underscores the emergence of potential internal market barriers and a fresh challenge to the unified European data market due to recent data regulations. It urges the European Commission to prioritise the implementation of the existing data strategy rather than introducing additional regulations. ● As the GDPR now undergoes a second review, new challenges have arisen, particularly with the introduction of additional digital rules. The AI Act, the Data Act and other parts of the data strategy will all significantly impact organisations’ data processing operations, often conflating personal and non-personal data. The impact of these new laws is yet to be determined, but the potential for overlaps and erratic enforcement is real.
The impact of these new laws is yet to be determined, but the potential for overlaps and erratic enforcement is real. We have already sounded the alarm regarding the potential negative impact on data flows, but these issues permeate other aspects of data processing. Ref. Ares(2024)963199 - 08/02/2024 ● Before the impact of these new regulations is clear, a reopening of the GDPR is premature. The current GDPR review should focus on addressing interpretation issues and fostering companies’ compliance. ● We support maintaining and respecting key principles of GDPR such as the One-Stop-Shop (OSS) mechanism. It is crucial to consider the potential drawbacks of opening or altering it for both organizations and individuals. The benefits of the OSS are clear: it reduces the administrative burden for organizations and makes it simpler for individuals to exercise their rights.
…it reduces the administrative burden for organizations and makes it simpler for individuals to exercise their rights. ● The review should highlight the need to prevent diverging interpretations and enforcement across legislation and Member States. It should aim to forecast and reconcile the responsibilities of data protection authorities (DPAs) and other competent authorities under new regulations like the AI and Data Acts. It should address areas of friction between the GDPR and new regulations, promoting collaboration between the Commission, competent authorities and industry stakeholders. ● The European Data Protection Board (EDPB) should prioritise practical guidance to strengthen harmonisation, and to reduce compliance burden whenever the GDPR text allows.
…practical guidance to strengthen harmonisation, and to reduce compliance burden whenever the GDPR text allows. These include guidance on anonymisation, pseudonymisation, privacy-enhancing technologies, distinguishing personal from non-personal data, research and innovation in health and AI, tools to support SMEs, joint controllership, compensation thresholds for non-material damage, and tools for data subject rights compliance. ● Work should be pursued to enhance adequacy decisions and other data transfer tools. This includes advancing work at a global level on mutual recognition of standard contractual clauses (SCCs), fostering more consistent recommendations from DPAs, facilitating binding corporate rules (BCRs), and the development of pan-European codes of conduct and certification.
…facilitating binding corporate rules (BCRs), and the development of pan-European codes of conduct and certification. ● Industry needs a focused GDPR review that addresses interpretation challenges and promotes compliance for companies, strengthening Europe’s Single Market. It must prepare alignment with new regulations, promote practical guidance from the EDPB, secure international data transfers, and the full use of GDPR mechanisms. The next review in 2028 will be better able to assess the impact of recently adopted data strategy legislation, ensuring a more comprehensive evaluation of the evolving digital landscape.
…recently adopted data strategy legislation, ensuring a more comprehensive evaluation of the evolving digital landscape. General Observations Alignment with new regulations in the digital sector The aspiration to establish a seamless flow of data within Europe faces a renewed challenge due to the influx of recent legislation overseeing data processing, frequently blurring the lines between personal and non-personal data. Despite their intent to enhance legal clarity, these new regulations compound the existing GDPR rules, potentially complicating data processing procedures for European companies. The introduction of diverse sets of rules for identical processing operations poses a significant risk, as it may lead to conflicting interpretations and enforcement measures from various authorities.
…a significant risk, as it may lead to conflicting interpretations and enforcement measures from various authorities. As the EDPB’s own contribution to the GDPR evaluation notes, the GDPR’s remit under new regulations remains unclear and lacks consistency.1 The comprehensive coverage of personal data by the Data Act and the creation of new enforcement authorities, along with the designation of potentially new competent authorities under the AI Act, underscore the urgency for a well-defined framework. The absence of effective cooperation mechanisms among these diverse laws and authorities heightens uncertainty for European companies.
…effective cooperation mechanisms among these diverse laws and authorities heightens uncertainty for European companies. The existing issue of divergent interpretations from various types of authorities has already posed challenges in Member States, a situation that should not be exacerbated.2 It is crucial for the upcoming GDPR review to comprehensively map out areas of friction between the GDPR and these new regulations. The European Commission and competent authorities should collaborate with industry to address the complexities arising from the coexistence of these regulatory frameworks. 1 P. 5, Contribution of the EDPB to the report on the application of the GDPR under Article 97, available at https://edpb.europa.eu/system/files/2023-12/edpb_contributiongdprevaluation_20231212_en.pdf.
Article 97, available at https://edpb.europa.eu/system/files/2023-12/edpb_contributiongdprevaluation_20231212_en.pdf. 2 For instance, Finland has seen different interpretations of the Payment Services Directive (Directive (EU) 2015/2366), the Anti-Money Laundering Directive (Directive (EU) 2015/849) and the Vehicle General Safety Regulation (Regulation (EU) 2019/2144). Areas for practical guidance from the EDPB The EDPB’s guidelines play a crucial role in supporting the practical implementation of the GDPR and establishing a standard for adherence across Member States.
…in supporting the practical implementation of the GDPR and establishing a standard for adherence across Member States. Despite this, there remain several areas where harmonisation and guidance from the EDPB are lacking, as highlighted in the 2020 report.3 Revised and more pragmatic guidelines on the concepts of personal data and anonymisation are pivotal for the successful application of the GDPR, especially in light of forthcoming legislation such as the Data Act. It is essential that these guidelines strike a balance, offering realistic solutions without imposing additional requirements, staying true to both the spirit and explicit language of the GDPR. Moreover, the guidelines should cater to real-world situations, providing practical and balanced interpretations of the GDPR.
…the guidelines should cater to real-world situations, providing practical and balanced interpretations of the GDPR. This approach becomes particularly vital for smaller companies without extensive legal teams, enabling them to meet legal requirements effectively. To ensure the inclusivity of stakeholders and foster a collaborative approach, more effective industry are necessary. This could include in-person public consultation meetings that allow for a meaningful exchange of ideas. It is essential that these consultations go beyond passive listening and foster an active dialogue between DPAs, the EDPB and stakeholders. Such engagements would contribute to a more comprehensive understanding of practical challenges, and lead to guidelines that are not only legally sound but also feasible for diverse organisations.
21 → 12
European Commission’s Report on the General Data Protection Regulation Call for evidence Ref. Ares(2024)182158 Ibec Observations & Recommendations February 8, 2024 Ref. Ares(2024)974596 - 08/02/2024 2 Ibec Policy Submission Ibec1 welcomes the opportunity to comment on the European Commission’s ‘Report on the General Data Protection Regulation (GDPR2)’. Our observations and recommendations to the Commission are outlined below. We hope they prove constructive to the Commission’s process and stand ready to engage further. Our key observations and recommendations to the Commission include: 1. Reopening of GDPR would be premature 2. Support regulatory alignment and certainty while avoiding fragmentation 3. Intensify focus on helping interpretation and compliance 4. Enable and safeguard international data transfers
Intensify focus on helping interpretation and compliance 4. Enable and safeguard international data transfers 5. Maintain and respect key principles of GDPR Observations and Recommendations: 1. Reopening of the GDPR would be premature. Europe’s case law and regulatory environment is evolving and has become more complex since the introduction of the GDPR3. For example, the impacts of the AI Act and Data Strategy4 are unknown but the potential for regulatory overlap and uncertainty remain a real concern for business. Implementing these new digital regulations in a way that is coherent with the GDPR should be prioritised over the introduction of further regulation. The next review in 2028 would be better able to evaluate the impact of this new digital regulatory landscape on the GDPR. 2. Support regulatory alignment and certainty while avoiding fragmentation.
…digital regulatory landscape on the GDPR. 2. Support regulatory alignment and certainty while avoiding fragmentation. The EDPB, while acknowledging that new responsibilities may be placed on Supervisory Authorities (SAs) and/or EDPB regarding the supervision and enforcement of new legal acts5, has highlighted a consequent need for greater resources, clarity and harmonisation in the role and powers of SAs in this evolution6. A lack of regulatory alignment can only mean fragmentation and uncertainty for investment. This uncertainty will be most acute for SMEs. The GDPR review should identify areas of interplay and uncertainty between the GDPR and the evolving regulatory framework. The Commission, SAs and industry should then collaborate to address uncertainties in this regulatory interplay.
The Commission, SAs and industry should then collaborate to address uncertainties in this regulatory interplay. 1 Ibec is Ireland’s largest lobby and business representative group, EU Transparency Register identification number 479468313744-50 (www.ibec.ie) 2 Regulation (EU) 2016/679 3 Zenner, Marcus and Sekut, 2023 A dataset on EU legislation for the digital world. 4 COM(2021) 206 final. The European data strategy includes most importantly, the Data Act (Regulation (EU) 2023/2854), the Data Governance Act (Regulation (EU) 2022/868) and the proposed European Health Data Space (EHDS) (COM(2022) 197/2). 5 e.g., DGA, DSA, DMA and AI 6 EDPB (2023) Contribution of the EDPB to the report on the application of the GDPR under Article 97 European Commission Report on GDPR 3
…of the EDPB to the report on the application of the GDPR under Article 97 European Commission Report on GDPR 3 3. Intensify focus on helping interpretation and compliance. Support compliance with further guidance and maximising the use of GDPR mechanisms. Encourage and support further/updated guidance from the EDPB in the application of the GDPR as highlighted in the 2020 report7 and in response to the evolving regulatory landscape. To assist SMEs, we recommend that guidance reflect relatable real- world situations and pragmatic interpretations of GDPR. This would reinforce harmonisation and reduce regulatory burden where allowed. Beneficial guidance could include: • Anonymisation and pseudonymisation, e.g. scenarios where privacy-enhancing technologies (PETs) reduce the risk of identifiability to a negligible level; • Distinguishing personal from non-personal data, important in context…
…engagement from SAs. Streamline processes and coordination efforts to promote the recognition of codes of conduct. 4. Enable and safeguard international data transfers. Further Commission efforts to reinforce adequacy frameworks and extend them globally are welcome8. Advancing ongoing work on mutual recognition of SCCs should also be prioritised, as the primary tool used by business for international data transfers. Support continuous growth in connectivity and digital enabled trade. In 2020, digital trade represented 25% of global trade9, with Europe accounting for over half of global exports of digitally delivered services in 202210. Digital trade influences the global economy and every company regardless of its activity and size, by allowing access to virtually limitless export markets with relatively low investment. Data flows underpin digital trade and are important to European…
…5. 11 DIGITALEUROPE, BUSINESSEUROPE, ERT and ACEA (2020), SCHREMS II, Impact Survey, Figure 2 4 Ibec Policy Submission 5. Maintain and respect key principles of GDPR such as the One-Stop-Shop (OSS) mechanism for organisations and individuals. As previously stated, it would be premature to change key principles. The benefits of the OSS are clear: it reduces the administrative burden for organizations and makes it simpler for individuals to exercise their rights. As the EDPB states: “The one-stop-shop helps individuals to stand up for their rights, no matter where they live in Europe”. • The OSS ensures a simpler and clearer process for individuals to exercise their privacy rights. Changes may complicate or delay the resolution of data subject complaints or requests. Ensuring that individuals can easily access their data rights is crucial, and we must preserve this ease of access. • The…
…an efficient and cost-effective regulatory framework to promote economic growth and competitiveness in Europe.