Media Scope Group OÜ

Interesų grupė

Kategorija
Būstinė
Registruota
Deklaruotos metinės išlaidos
(pačios deklaruota)
Skaidrumo registras
488689550927-70
0
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Ką pateikė viešoms konsultacijoms

2024-01-30 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Please find attached the feedback for the Report on the General Data Protection Regulation.

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 3 p.

Feedback for the Report on the General Data Protection Regulation Tallinn, 30 January 2024 The General Data Protection Regulation (GDPR), a significant piece of legislation designed to protect personal data, has been in effect for several years. However, there are still areas that require further clarification and improvement to ensure its effective application. We would like to highlight the following key areas: Clarifying definitions and terminology One of the main areas of concern is the need for further clarification on the definition of personal data under Article 4 of the GDPR. Specifically, it should be specified under which conditions datasets containing personal data are considered anonymous.

Specifically, it should be specified under which conditions datasets containing personal data are considered anonymous. There is also ambiguity surrounding the extent to which anonymous data, which could potentially be supplemented with information when passed on to third parties, can be considered anonymous. Addressing information fatigue The information obligations under Articles 13 and 14 of the GDPR have led to an overload of information, which is neither requested nor acknowledged by the data subject. The lengthy and often confusing information provided in the form of data protection declarations does not lead to transparency for the data subject, as intended by the GDPR, but rather serves to fulfil a legal obligation on the part of the controller. Additional guidance on the interpretation of the Ref.

…to fulfil a legal obligation on the part of the controller. Additional guidance on the interpretation of the Ref. Ares(2024)691841 - 30/01/2024 2 information obligations is needed, and it should be clarified what information should be made immediately available to the data subject and whether additional information could be made available elsewhere. To prevent information fatigue, it is proposed that information relevant to data protection be clustered and standardised symbols be implemented as proposed in Article 12 (8) of the GDPR. Making the GDPR more SME-friendly Small and medium-sized enterprises (SMEs) in particular have difficulties fulfilling the extensive documentation requirements under the GDPR. A differentiation of the documentation obligations is therefore supported to reduce the burden for SMEs.

…the GDPR. A differentiation of the documentation obligations is therefore supported to reduce the burden for SMEs. With regard to the documentation requirements, it is recommended to focus more on the risk that the processing might pose to data subjects, in line with the risk-based approach of the GDPR. Providing clarity on data breaches Companies face uncertainties with regard to reporting personal data breaches. It remains unclear whether any further misconduct uncovered as part of the data breach notification can be used in the course of a subsequent investigation by the supervisory authority. While a comprehensive prohibition of use has been adopted to resolve the conflict between the reporting obligation under the GDPR and the freedom of self-incrimination, this point remains unclear at the European level.

…under the GDPR and the freedom of self-incrimination, this point remains unclear at the European level. It is necessary to clearly state that such information must not be used for subsequent investigations. Eliminating dark patterns and deceptive tactics Large companies, in their quest to collect and use this data, often resort to what are known as “dark patterns” and deceptive tactics. These are design strategies used in websites, operating systems and applications that trick users into sharing more personal data than they intend to, often without their explicit consent. Dark patterns exploit the gap between user understanding and system functionality, manipulating users into making decisions that benefit the company, often at the expense of the user’s privacy.

…users into making decisions that benefit the company, often at the expense of the user’s privacy. These tactics can take various forms, such as misleading wording, data collection opt-in by default, hidden information, and default settings that favor data sharing. One common example is the use of pre-checked boxes in online forms, which users may overlook, inadvertently giving consent to data collection and sharing. Another tactic is the use of complex language or excessive detail in privacy policies and terms of service, which can confuse users and lead them to agree without fully understanding the implications. 3 It is necessary to address the issue of dark patterns and deceptive tactics that are used with aim of misleading users to collect their data without their explicit consent.

…and deceptive tactics that are used with aim of misleading users to collect their data without their explicit consent. Eliminating pay-or-consent practices The pay-or-consent approach is a practice among large online platforms, particularly social media platforms and digital applications. Large online providers say that this model “offers” users a “choice” between using a service for free in exchange for their consent to data collection and targeted advertising or paying a subscription fee for an ad-free, privacy-enhanced experience. From a legal perspective, the pay-or-consent approach conflicts with the General Data Protection Regulation. The GDPR stipulates that consent must be freely given, informed, specific, and unambiguous. If users feel compelled to consent to data collection because they cannot afford the paid version, it could be argued that their consent was not freely given.

…collection because they cannot afford the paid version, it could be argued that their consent was not freely given. Furthermore, the GDPR includes the principle of data minimization, which states that only the necessary amount of data required to provide a service should be collected. The extensive data collection involved in the “free” version of the pay-or-consent model violates this principle. It is strongly recommended to strongly enforce the GDPR on large online providers who use this practice, conflicting the GDPR. Media Scope Group OÜ is registered under the number 488689550927-70 in the EU Transparency Register. www.mediascope.group | [email protected]

originalus šaltinis (PDF) ↗