noyb - European Center for Digital Rights

noyb · Non-governmental organisations, platforms and networks and similar · AT

Kategorija
Non-governmental organisations, platforms and networks and similar
Būstinė
Vienna AT
Registruota
2021-05-11
Deklaruotos metinės išlaidos
452 000 € (pačios deklaruota)
Svetainė
http://www.noyb.eu
Skaidrumo registras
488900342587-15 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

2025420261

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 5 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.

Ką pateikė viešoms konsultacijoms

2023-03-24 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
…noyb strongly supports the initiative launched by the European Commission aimed at strengthening and improving the application and enforcement of the General Data Protection Regulation (GDPR). Please find the attached submission with: - Cover Letter - An Issues List - High-Level Concepts Paper - A Suggestion for a Regulation

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 41 p.

…noyb – European Center for Digital Rights Goldschlagstraße 172/4/3/2 1140 Vienna AUSTRIA noyb – European Center for Digital Rights | Goldschlagstr. 172/4/3/2, 1140 Vienna, AUSTRIA | ZVR N°: 1354838270 www.noyb.eu | General email: [email protected] | Legal communication: [email protected] | IBAN: AT21 2011 1837 8146 6600 Page 1 of 2 European Commission JUST.C.3 Rue Montoyer 59 1000 Bruxelles BELGIUM Vienna, 24 March 2023 noyb’s feedback to the European Commission Consultation noyb strongly supports the initiative launched by the European Commission aimed at strengthening and improving the application and enforcement of the General Data Protection Regulation (GDPR). Five years into the application of the GDPR, it becomes more and more obvious that the legislator was overly optimistic regarding national Supervisory Authorities (SAs) actively cooperating and enforcing European law.

…was overly optimistic regarding national Supervisory Authorities (SAs) actively cooperating and enforcing European law. noyb has a unique insight via more than 800 procedures that we are currently engaged with – many of which fall under the “One Stop Shop” (OSS) system. The vast majority of these cases are not decided as they are stuck between SAs, have not been handled properly, or were heavily delayed. Three Steps: Seventy Issues, Sixteen Concepts and One Draft Regulation The noyb team has identified about 70 issues that we have experienced first-hand in our daily operations. We have summarized these issues in the “issues” document provided. Based on these issues, we have developed 16 high level concepts that could provide the basis for any new Regulation on the cooperation procedures.

…developed 16 high level concepts that could provide the basis for any new Regulation on the cooperation procedures. As a third step, we have developed a draft procedural regulation, as a sample implementation of these concepts – we hope that this will offer a practical, “hands on” example of a possible Regulation. Issues Concepts Regulation Ref. Ares(2023)2161524 - 24/03/2023 Page 2 of 2 Focus in relevant issues In the following documents, noyb has avoided making lengthy submissions on matters that we consider to be obvious, such as the right of complainants to be heard as a party. We take the view that, despite a small number of SAs not agreeing with the law, there is a clear requirement under Article 41 of the Charter of Fundamental Rights (CFR) to grant such rights. Any new Regulation that would not comply with these and other minimum requirements would clearly violate Article 41 CFR.

…new Regulation that would not comply with these and other minimum requirements would clearly violate Article 41 CFR. We have, instead, focused on the elements where the European legislator has leeway to improve the procedures that citizens and business struggles with every day. We hope the attached submission is useful for the Commission, and we are available to answer any questions the Commission may have. Kind Regards, Max Schrems __________ Attached: 1) Table with Common Issues 2) High Level Concepts

Commission may have. Kind Regards, Max Schrems __________ Attached: 1) Table with Common Issues 2) High Level Concepts 3) Draft Procedural Regulation General topic Description of a specific problem under the general topic Ideal solution Article(s) involved (national, EU, or other) Reference to specific noyb cases References to EDPB documents / table Comments Proposed Solution Admissibility - Formal requirements: signature In some Member States, an electronic mail is enough for validly filing a complaint with a supervisory authority (SA), while in others, the lack of a written signature on paper leads to inadmissibility of the complaint. The procedural provision should mention the minimum formal conditions for filing a complaint with a SA. When met, the complaint should always be deemed admissible.

…minimum formal conditions for filing a complaint with a SA. When met, the complaint should always be deemed admissible. Article 77 GDPR EDPB Letter to the EU Commission on procedural aspects that could be harmonised at EU level ("EDPB wish list") : FN 16, referring to EDPB copntribution to the evaluation of the GDPR, page 10: national legislation in AT, BE, BG, IT, LV, NL, PL, SI, ES foresees formal admissibility requirements. On the other hand, no admissibility requirements are foreseen in CZ, DK, DE, whereas a discretionary power regarding the assessment of admissibility is exercised in LU. Concept 2 would ensure that the national law of the filing SA is relevant for any rules on the admissability of the law and other SAs may not review the admissability.

…the filing SA is relevant for any rules on the admissability of the law and other SAs may not review the admissability. Admissibility - Formal requirements: proof that the not- for-profit entity is certified Some SAs request additional documentation with regard to the representation of data subjects by not-for-profit organisations under Art. 80(1) GDPR. Not only a representation agreement is requested to be filed in the country's official language but also a proof that the specific organisation is allowed to represent data subjects. The procedural provision should mention the minimum formal conditions for the representation of data subjects. When met, the complaint should always be deemed admissible. Article 80(1) GDPR Poland in all C-037-... cases ("cookie banners") where the Polish DPA required addition proof or representation.

GDPR Poland in all C-037-... cases ("cookie banners") where the Polish DPA required addition proof or representation. See also Bulgaria asking, 2 years after the complaint, to have a representation agreement in Bulgarian signed before a public notary. Concept 2 would ensure that the national law of the filing SA is relevant for any rules on the admissability of the law and other SAs may not review the admissability. Admissibility - Substantive requirement: residency of the complainant or other link with the territory of the SA In some Member States, complaints are considered inadmissible if the complainant is not a resident in the Member State of the SA. Article 77 provides that data subjects have the right to lodge a complaint with a SA "in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement (...)".

…in the Member State of his or her habitual residence, place of work or place of the alleged infringement (...)". The words 'in particular' leaves room for interpretation and legal uncertainty. A complaint should always be deemed admissible by the SA of a Member State at least on the basis of the complainant's residence or place of work, or on the basis of the place where the infringement occurred, with the possibility for SAs to also accept complaints based on any other relevant circumstances. Article 77, 80 GDPR See internal EDPB document 6/2020 on preliminary steps to handle a complaint: admissibility and vetting of complaints The matter is already clear from the wording of the GDPR, but could be mentioned in recitals and futrther specified in the procedural regulation.

…from the wording of the GDPR, but could be mentioned in recitals and futrther specified in the procedural regulation. Admissibility - Substantive requirement: prior request to the controller Some SAs reject complaints where the data subject has not made a prior request to the controller in the context of the exercise of his or her rights under Article 15 to 22 of the GDPR. As a result, in some Member States, complaints are only admissible after (1) the data subject has provided a written request to the controller and (2) the 1-month period foreseen under Article 12(3) GDPR for the controller to answer has passed. When the issue is precisely that the data subject cannot identify the controller or contact the latter because of a lack of information, the SA should not be able to reject a complaint on the basis that a prior request has not been made.

…of information, the SA should not be able to reject a complaint on the basis that a prior request has not been made. Article 77 GDPR should clarify that the exercise by the data subjects of one of their rights under Article 15 to 22 is not a prerequisite for filing a complaint with an SA, or should clarify if and in which cases such a prior request must be made. Article 77, 80 GDPR Spanish Supreme Court n° 1039/2022 (https://gdprhub.eu/index.php?title=TS_- _1039/2022). EDPB document 6/2000 The GDPR does not seem to require an attempt to agree with a controller, but Concept 2 would allow to ensure that the national law of the filing SA is relevant for any rules on the admissability of the law and other SAs may not review the admissability, including such pre-conditions.

…rules on the admissability of the law and other SAs may not review the admissability, including such pre-conditions. Admissibility - Substantive requirement: identification of relevant legal grounds Some SAs refuse a complaint if the legal grounds for such a complaint are not identified. The provisions should prohibit to ask to specify legal grounds as the complainant might not be in a position to identify them and does not have the legal expertise to do so. Article 77, 80 GDPR see EDPB internal document 6/2000 and EDPB internal document 02/2021 (§57) (cf. the notion of 'substantiated complaint' should form a less higher threshold than some SAs expect from complainants. The formal threshold is not defined in the GDPR.

236 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
- Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
- COM (2023) 348: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679

Paminėjimai spaudoje

Straipsniai, kuriuose organizacijos pavadinimas paminėtas pažodžiui IR kurie liečia teisę ar reguliavimą. Vien paminėjimas nereiškia, kad straipsnis yra apie lobizmą.
2026-08-26 · noyb.eu · EN
As a state-approved Qualified Entity, noyb has therefore taken action to protect consumers from SCHUFA’s unrestrained data-hoarding and secrecy. Compliance with the GDPR is now to be restored in…
2026-08-26 · PPC Land · EN
As a state-approved qualified entity, noyb says it has therefore taken action itself. Max Schrems, chair of noyb, said the organisation is increasingly witnessing a breakdown of the public data…
2026-07-29 · Genbeta · ES
Lisa Steinfeld, asesora jurídica de Noyb, califica esta práctica como engañosa y advierte que miles de usuarios podrían haber recibido información incompleta, sin saber realmente qué datos se recogen…