Stiftung Ordnungspolitik - Centrum für Europäische Politik

CEP · Think tanks and research institutions · DE

Kategorija
Think tanks and research institutions
Būstinė
Freiburg DE
Registruota
2013-03-08
Deklaruotos metinės išlaidos
100 000–199 999 € (pačios deklaruota)
Svetainė
https://www.cep.eu
Skaidrumo registras
488753210783-18 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

20192

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 2 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Dear Sir or Madam, Cep thanks you for the opportunity to provide feedback on the application of the GDPR. Free of vested interests and party-politically neutral, the Centres for European Policy Network (https://www.cep.eu/) provides analysis and evaluation of European Union policy, aimed at supporting European integration and upholding the principles of a free-market economic system. Please find our contribution to the consultation in the attached document. In this statement, we would like to A. propose concepts how bureaucratic burdens for companies can be reduced for sensible and necessary documentation and reporting obligations which the GDPR imposes on companies (using the example of…

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 6 p.

Centrum für Europäische Politik FREIBURG | BERLIN Kaiser-Joseph-Straße 266 | D-79098 Freiburg +49 761 38693-0 [email protected] Centre for European Policy (cep) Statement as Part of the Call for evidence - Ares(2024)182158 on the application of the General Data Protection Regulation February 8th, 2024 Dear Sir or Madam, Cep thanks you for the opportunity to provide feedback on the application of the GDPR. Free of vested interests and party-politically neutral, the Centres for European Policy Network (https://www.cep.eu/) provides analysis and evaluation of European Union policy, aimed at supporting European integration and upholding the principles of a free-market economic system. In this statement, we would like to A.

…integration and upholding the principles of a free-market economic system. In this statement, we would like to A. propose concepts how bureaucratic burdens for companies can be reduced for sensible and necessary documentation and reporting obligations which the GDPR imposes on companies (using the example of Art. 30 and 33 of the GDPR), and, secondly, B. comment on the interaction between the GDPR and new initiatives (using the example of the Data Act). A. Concepts for reducing bureaucratic burdens for companies I. Background Bureaucratic obligations are increasingly perceived by companies as an economic obstacle. This is not surprising, as companies are – also under the GDPR – confronted with numerous bureaucratic obligations: reporting obligations, information obligations or documentation obligations are just a few of them.

…obligations: reporting obligations, information obligations or documentation obligations are just a few of them. Even if such obligations are a burden for companies, they are often sensible and necessary. Therefore, it is important to organise and implement the obligations in such a way that they burden companies as little as possible. This statement therefore describes how information and documentation obligations can be implemented by authorities in such a way that they place as little burden on companies as possible. Our statement is based on the findings of several empirical comparative studies carried out by the Centre for European Policy (cep) and Prognos AG on behalf of the German Family Business Foundation (Stiftung Familienunternehmen).

European Policy (cep) and Prognos AG on behalf of the German Family Business Foundation (Stiftung Familienunternehmen). The studies examine how European legislation was implemented in Austria, France, Germany and Italy and which bureaucratic burdens are associated with its implementation. In volume 4 of this Study which was published on 14 June 2023, we and our co-authors have analysed the burdens arising from Art. 30 and 33 of the General Data Protection Regulation (GDPR). More specifically, the study examines the regulatory density and economic costs of (1) the creation and maintenance of a record of processing activities (RPA) in accordance with Art. 30 of the GDPR and (2) the notification of personal data breaches to the competent supervisory authority in accordance with Art. 33 of the GDPR.

…notification of personal data breaches to the competent supervisory authority in accordance with Art. 33 of the GDPR. As part of the studies, a total of 177 companies and experts in the four Member States mentioned were surveyed to estimate the costs associated with the selected legal provisions. This makes it possible to derive evidence-based recommendations for reducing bureaucratic burdens. Ref. Ares(2024)976184 - 08/02/2024 Centrum für Europäische Politik FREIBURG | BERLIN Kaiser-Joseph-Straße 266 | D-79098 Freiburg +49 761 38693-0 [email protected] II. Main findings of our Study1: Among our main findings in the study ”Regulatory and financial burdens of EU legislation in four Member States – a comparative study, Vol. 4: Burdens arising from Art. 30 and 33 of the General Data Protection Regulation” are the following: 1.

…study, Vol. 4: Burdens arising from Art. 30 and 33 of the General Data Protection Regulation” are the following: 1. On the creation and maintenance of a record of processing activities (RPA) in accordance with Art. 30 of the GDPR • Since the information listed in Art. 30 of the GDPR must be provided for each “processing activity”, the volume of the RPA depends on the understanding of the notion of a “processing activity”. However, the term is not defined in the GDPR. While the Austrian and the Italian data protection authorities (DPAs) do not provide any relevant help here, it becomes clear from the guidance given by the French and the German2 DPAs that not every single processing operation must be included in the RPA, but a certain abstraction can be made. However, the appropriate level of abstraction is not entirely clear.

…in the RPA, but a certain abstraction can be made. However, the appropriate level of abstraction is not entirely clear. • Overall, the levels of guidance and help given on the websites of the national DPAs on how to draft an RPA differ significantly between the four Member States researched. While the Austrian DPA does not provide a template and gives only very little information on the duties in relation to the drafting of an RPA, the other authorities provide significantly more guidance and help. • As the GDPR lists the information to be included in the RPA without detailing it, the official templates provided by the national DPAs differ to a certain extent. For example, other than in Austria (where there is no official template at all) and in Italy, the German and French templates clearly list which exact contact details must be indicated.

…at all) and in Italy, the German and French templates clearly list which exact contact details must be indicated. Although a more comprehensive template seems to create a greater burden, it makes it clearer for the controller what level of granularity of information is required. • Some of the Member States researched request additional information to be included in the RPA, which can be regarded as gold plating; however, the extent of gold plating is marginal. • The bureaucratic burden with regard to the drafting of an RPA also depends on the availability and user-friendliness of the official templates provided by the competent DPAs. • The exemption for smaller enterprises with fewer than 250 employees from the obligation to maintain an RPA in Art. 30 (5) GDPR largely runs dry. As the counter-exceptions are wide, the exemption rarely applies.

…an RPA in Art. 30 (5) GDPR largely runs dry. As the counter-exceptions are wide, the exemption rarely applies. Based on the above, we issue the following recommendations: The bureaucratic burden under Art. 30 of the GDPR could be reduced by the provision of improved official templates for an RPA which meet the following criteria: • they are harmonised and translated into the respective national language, • they combine the advantages of existing templates of national DPAs, e.g. by 1 Regulatory and financial burdens of EU legislation in four Member States – a comparative study, Vol. 4: Burdens arising from Art. 30 and 33 of the General Data Protection Regulation, available at https://www.familienunternehmen.de/media/public/pdf/publikationen- studien/studien/Regulatory-and-financial-burdens-of-EU-legislation-in-four-Member-States_Vol4_Stiftung-Familienunternehmen.pdf.

/studien/Regulatory-and-financial-burdens-of-EU-legislation-in-four-Member-States_Vol4_Stiftung-Familienunternehmen.pdf. 2 Germany has a federal system of data protection supervision. It consists of the DPAs of the Federation (the “Bund”) and the 16 federal states (the “Länder”). As far as the data protection supervisory authorities of the federal states are the competent authority, this study is based on the templates and guidance provided by the Landesbeauftragter für Datenschutz und Informationsfreiheit (LfDI) Baden-Württemberg.

…and guidance provided by the Landesbeauftragter für Datenschutz und Informationsfreiheit (LfDI) Baden-Württemberg. Centrum für Europäische Politik FREIBURG | BERLIN Kaiser-Joseph-Straße 266 | D-79098 Freiburg +49 761 38693-0 [email protected] - being clearly structured, - being self-explanatory or containing direct links to sources where further information is available, - offering checkboxes or, preferably, drop-down menus at least for the most relevant information (like the template of the French DPA), • they provide more help for small and medium-sized enterprises on how to create a simplified RPA. 2. On the notification of personal data breaches to the competent supervisory authority in accordance with Art. 33 of the GDPR • According to Art.

…data breaches to the competent supervisory authority in accordance with Art. 33 of the GDPR • According to Art. 33 GDPR, the notification shall contain at least - a description of the nature of the personal data breach, - the name and contact details of the data protection officer or other contact point where more information can be obtained, - a description of the likely consequences of the personal data breach and - a description of the measures taken or proposed to be taken by the controller to address - the personal data breach. • In addition, France, Germany3 and Italy request some information that is not required by the GDPR. For instance, France and Italy ask, inter alia, for security measures taken before the data breach and the data breach’s estimated level of severity. We consider these requirements to be gold plating.

25 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Wirtschaftspolitik
Umweltpolitik
Energiepolitik
Verkehrspolitik
Finanzmarktregulierung
Telekommunikation und IT
Digitale Wirtschaft
Institutionelle Fragen
Euro-Zone