Trade and business associations · US
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 80 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
April 29, 2020 U.S. Chamber of Commerce Response to the European Commission on the Implementation of the General Data Protection Regulation The U.S. Chamber of Commerce welcomes the opportunity to provide the European Commission with comments on the implementation of the General Data Protection Regulation. The U.S. Chamber of Commerce (“Chamber”) is the world’s largest business federation, representing the interests of more than three million enterprises of all sizes and sectors. The Chamber is a longtime advocate for stronger commercial ties between the United States and the European Union. According to a recent Chamber study jointly commissioned with AmCham EU, the U.S.
United States and the European Union. According to a recent Chamber study jointly commissioned with AmCham EU, the U.S. and EU are jointly responsible for over one- third of global gross domestic product, and transatlantic trade and investment supports 16 million jobs on both sides of the Atlantic.1 The Chamber is also a leading business voice on digital economy policy, including on issues of data privacy, cybersecurity, digital trade, artificial intelligence, and e-commerce. In the U.S. and globally, we support sound policy frameworks that promote data protection, support economic growth, and foster innovation.2 Since its enactment, the General Data Protection Regulation (“GDPR” or “Regulation”) has reshaped how U.S. firms do business in or trade with the European Single Market.
(“GDPR” or “Regulation”) has reshaped how U.S. firms do business in or trade with the European Single Market. While the Regulation is proving beneficial in some respects, the past two years offer a wealth of information on how its implementation may be improved. First, the Chamber recommends that the European Commission (“Commission”) reinforce and broaden GDPR’s international data transfer regime, as persistent legal uncertainty is undermining these core elements of the Regulation. Second, closer cooperation between data protection authorities (“DPAs”) is needed to ensure consistent interpretation and efficient enforcement of GDPR across the single market. This includes strengthening and reinforcing the one-stop-shop (“OSS”) mechanism. Addressing these concerns will enable the Commission to improve both data protection 1 U.S.
(“OSS”) mechanism. Addressing these concerns will enable the Commission to improve both data protection 1 U.S. Chamber of Commerce & AmChamEU, The Transatlantic Economy 2020. 2 U.S. Chamber of Commerce, Data Privacy. Ref. Ares(2020)2299311 - 29/04/2020 and the EU’s economic competitiveness, including in the development and use of data- driven technologies such as artificial intelligence. The current COVID-19 pandemic highlights the importance of a practical approach to data protection. As policymakers and the business community prepare for economic recovery, regulatory pragmatism will continue to be necessary. Businesses are likely to suffer limited organizational capacity and significantly reduced financial resources for the foreseeable future. DPAs may need to issue new or revised guidance and provide regulatory forbearance, as businesses struggle to remain viable.
…may need to issue new or revised guidance and provide regulatory forbearance, as businesses struggle to remain viable. We encourage the Commission to integrate the lessons learned in the current crisis, along with the experiences of the past two years, into how GDPR is implemented in practice. The Chamber has outlined its recommendations below. International Transfers of Personal Data No business, regardless of size or sector, can operate, let alone export goods or services, without the ability to move personal data and access information across borders. As written, GDPR has a toolkit of legal mechanisms that organizations may use to engage in international data transfers, including adequacy decisions, standard contractual clauses (“SCCs”), binding corporate rules (“BCRs”), and codes of conduct and certifications.
…standard contractual clauses (“SCCs”), binding corporate rules (“BCRs”), and codes of conduct and certifications. More work, however, must be done to ensure that this toolkit functions in practice, including reinforcing those mechanisms subject to legal challenge and making full use of all the tools available under Chapter V of the Regulation. Without functioning data transfer tools, GDPR serves as a de facto requirement to localize EU personal data, an outcome with serious economic and trade ramifications, including for Europe’s ability to reach foreign markets. The EU-U.S. Privacy Shield The Chamber applauds the Commission’s commitment, alongside that of the U.S. Government, to uphold the EU-U.S. Privacy Shield framework.
…the Commission’s commitment, alongside that of the U.S. Government, to uphold the EU-U.S. Privacy Shield framework. We share Commission Vice President Věra Jourová’s assessment that the agreement is a “success story” for the nearly 5,300 organizations on both sides of the Atlantic that are certified.3 Over 70 percent of these organizations are small and medium-sized enterprises, making the Privacy Shield a notable example of inclusive digital commerce. Unfortunately, the Privacy Shield has come under threat by repeated legal challenges to non-commercial 3 European Commission, EU-U.S. Privacy Shield: Third Review Welcomes Progress While Identifying Steps for Improvement. aspects of the agreement, putting its future in doubt.4 The Chamber encourages the Commission to continue to defend the Privacy Shield as a vital bridge between the EU and its largest trade and investment partner.
…to continue to defend the Privacy Shield as a vital bridge between the EU and its largest trade and investment partner. Standard Contractual Clauses The Chamber is supportive of efforts by the Commission to update SCCs to reflect the growing complexity of data processing arrangements and to bring them in line with GDPR. We encourage the Commission to quickly conclude this work, while also grandfathering existing SCCs to minimize disruptions to business operations. The Chamber must also express its concern that SCCs are under legal challenge before the European Court of Justice in Data Protection Commissioner v Facebook Ireland, Maximillian Schrems (“Schrems II”).
…the European Court of Justice in Data Protection Commissioner v Facebook Ireland, Maximillian Schrems (“Schrems II”). A 2019 survey by the International Association of Privacy Professionals and EY found that SCCs are by far the most widely used international data transfer tool under GDPR.5 Invalidation by the Court will therefore have a grave impact on the ability of organizations—European and American—to transfer personal data out of the EU. In such a scenario, decisive action by the Commission and the European Data Protection Board (“EDPB”) will be necessary to swiftly put in place alternative data transfer arrangements and a grace period for companies to adapt. Adequacy Decisions The Chamber encourages the Commission to seek new adequacy decisions with third countries in order to facilitate cross-border data flows.
…the Commission to seek new adequacy decisions with third countries in order to facilitate cross-border data flows. We recommend an expedited adequacy decision for the United Kingdom, independent of the status of EU- UK trade talks, due to the unprecedented level of convergence between the EU and UK data protection regimes. We note that the UK transposed GDPR into its domestic law in 2018, under the Data Protection Act, and that the Information Commissioner’s Office was a leading member of both the EDPB and its predecessor, the Article 29 Working Party. Failure to grant such a decision quickly would have material negative commercial impacts on firms who today seamlessly transfer data across the Channel. 4 Data Protection Commissioner v Facebook Ireland, Maximillian Schrems; La Quadrature du Net and Others v Commission. 5 IAPP-EY Annual Governance Report, 2019.
Ireland, Maximillian Schrems; La Quadrature du Net and Others v Commission. 5 IAPP-EY Annual Governance Report, 2019. Guidance on Disruptions to International Data Flows The persistent uncertainty surrounding Privacy Shield, SCCs, and EU-UK data flows may necessitate that DPAs exercise regulatory forbearance in the future. We note that, following the invalidation of the Safe Harbor Agreement in 2015 by the European Court of Justice, the Article 29 Working Party provided a grace period for companies using the mechanism. In addition to providing a degree of certainty for the business community, this decision enabled the Commission to negotiate the Privacy Shield with the U.S. and subsequently issue an adequacy finding.
…enabled the Commission to negotiate the Privacy Shield with the U.S. and subsequently issue an adequacy finding. The Chamber recommends that the Commission work together with the EDPB to issue formal guidance on the use of grace periods in the event of any future disruptions to international data transfer flows. Binding Corporate Rules The efficacy of BCRs as data transfer tools is hampered by the formidable investment of time and resources needed for their approval. In its forthcoming report, the Commission should encourage DPAs to devote greater attention to approving BCRs and urge member states to designate additional resources for DPAs to complete this work.
19 → 12