Companies & groups · NO
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 77 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
Oslo, February 2023 EDPB wish list concerning further European harmonisation on procedural matters to increase effective enforcement - Vienna statement on enforcement cooperation Position paper Background In October 2022, the EDPB submitted a list of aspects in national procedural law that it wished to see harmonised at EU level to facilitate GDPR enforcement. The creation of this wishlist was stated as a key action in the EDPB’s Vienna statement on enforcement cooperation. The list was sent to the European Commission 10 October 2022. Schibsted is a family of digital consumer brands based in the Nordics with world-class Scandinavian media houses, leading classifieds marketplaces and investor in tech start-ups in the field of comparison sites and collaborative economies. We empower people in their daily lives and offer a variety of consumer choices across the Nordic market.
…economies. We empower people in their daily lives and offer a variety of consumer choices across the Nordic market. Schibsted supports a strong legal framework for data protection, and considers effective enforcement to be an important area of improvement to protect the integrity of citizens of the EU/EEA and to ensure a level playing field for entities processing personal data across the Union. In this position paper, Schibsted summarises the company’s perspective on the EDPB wish list. The need for additional regulation and problematic requests Overall, Schibsted does not necessarily see the need for the European Commission to address all the issues in the EDPB wish list as several of the issues seem to be of a nature that can already be solved by the DPAs through increasing the quality and level of collaboration.
…to be of a nature that can already be solved by the DPAs through increasing the quality and level of collaboration. If there is a common will and interest in increasing effective enforcement and collaboration, we assume that several of the topics raised by the EDPB can simply be solved in practice within the context of EDPB and practical collaboration between supervisory authorities. Examples of such topics are the proposals under item 5 in the wish list (for instance around information sharing between supervisory authorities).
…the proposals under item 5 in the wish list (for instance around information sharing between supervisory authorities). While several clarifications in the wish list is difficult to see that would have a material detrimental impact, the implications of the proposals might have negative effects and create unclarity around the supervisory authorities role as supervisory authority; ● On the status of the parties to the procedure and the complainants’ access to the procedure as party (section 1): Whatever the status of data subjects with regard to procedures before a DPA, it should be absolutely clear that DPAs are not courts of law. They should not seek to alleviate their obligation to conduct fair and independent investigations by relying heavily on arguments made by complainants and merely playing an adjudicating role between complainant and defendant (which is what a court would do).
…and merely playing an adjudicating role between complainant and defendant (which is what a court would do). 1 Ref. Ares(2023)1837711 - 14/03/2023 We are sceptical of providing individuals or organisations increased rights as parties in DPA proceedings. This might turn into a popularity contest, and apply pressure on DPAs to apply the law more strictly. DPAs shall interpret the law in concrete cases and use that law on the set of facts of the case, which they should be fully capable of doing as supervisory authorities. Strong voices on the complainant side, such as consumer organisations, could potentially lead to a less "objective" interpretation of the law and increase the enforcement action levels. While strong enforcement action may be both justified and reasonable, the level of enforcement should not be handled in the same way as monetary claims are in civil legal proceedings.
…the level of enforcement should not be handled in the same way as monetary claims are in civil legal proceedings. ● On harmonisation of procedural rules (section 2, 3.1, 3.2, 4.2 and 4.3): There is a movement in the EU to standardise procedural law generally, but it has definitely never been to this level of detail - that would be pretty exceptional. The EDPB appears to suggest here that it is the fragmentation of procedural aspects that causes non-uniform application of the GDPR. Non-uniform applications seem primarily to stem from differing guidance and positions from DPAs on the substantive content and interpretation of the GDPR, not from differing procedural rules.
…and positions from DPAs on the substantive content and interpretation of the GDPR, not from differing procedural rules. This is something that the EDPB itself is already tasked with harmonising and which it should be focusing on - in particular with a view to producing more balanced guidance that does not necessarily reflect the views of the most "purist" DPAs. Harmonisation and clarification of procedural aspects that are not covered by the wish list While it is understandable that the EDPB’s wish list focuses on the needs seen from the perspective of the supervisory authorities, it is important to bear in mind that supervisory authorities are not the only entities that are affected by procedural aspects and their inefficiencies and unclarities.
…are not the only entities that are affected by procedural aspects and their inefficiencies and unclarities. Procedural inefficiencies seen from the data controller perspective are not mentioned, but would nonetheless be relevant to consider should there be any additional legal instrument made to improve procedural aspects of GDPR enforcement. There are weaknesses in today's practices that are to the detriment of entities being under investigation. Examples of such practices are; ● DPAs using draft decisions (that have not been subject to feedback/corrections from the entity in question) as more or less “marketing” for the work of the DPA. This has an impact on the reputation of and the trust in the brands in question, regardless of whether the decision is legally effective.
…on the reputation of and the trust in the brands in question, regardless of whether the decision is legally effective. ● Authorities collecting user complaints without informing the data controller in question about the topics raised by individuals and thus not giving the controller the chance to provide feedback to the user or mitigating any shortcomings individuals have reacted on. This is both a poor user experience for EU citizens as customers and users, and removes the ability of data controllers to get information about shortcomings or concerns of the data subjects which data controllers would wish to mitigate. ● Unreasonably long case handling time after cases have been initiated by the supervisory authority is another important topic, which is briefly touched upon in the wish list, but not seen from the perspective of the entity under investigation and for non cross-border cases.
…in the wish list, but not seen from the perspective of the entity under investigation and for non cross-border cases. While legal entities under scrutiny by DPAs are given clear 2 and often short deadlines to provide submissions in ongoing cases, it may take months and sometimes years before any further communication from the supervisory authorities. Not only is this massively inefficient and difficult to deal with in practice, as cases can be complicated and require substantial efforts to provide details on. This also creates legal uncertainty, and could even be a blocker in developing current solutions while awaiting legal clarification or guidance. The above are but examples of concrete issues that should be addressed if improvement of procedural aspects would be considered by way of a legal instrument.
…issues that should be addressed if improvement of procedural aspects would be considered by way of a legal instrument. In addition to these procedural matters, we also see weaknesses in the application of GDPR in light of other fundamental interests or strategically and politically important topics. Firstly, we would like to point out the need to balance the fundamental right of personal data protection towards other fundamental interests and rights. While data protection is indeed a fundamental right, it will in several cases have to be balanced towards other fundamental rights and interests, such as freedom of expression, freedom of information and media pluralism. We would like to point out the risk of not having this balancing in mind when GDPR is applied.
…and media pluralism. We would like to point out the risk of not having this balancing in mind when GDPR is applied. GDPR already has room for taking such interests into consideration, but it is important that this is also done in practice both by data protection authorities and by the EDPB. Similarly, there are certain highly innovative areas for which personal data protection might constitute an unproportional limitation compared to other political and societal interests, such as the application of artificial intelligence and machine learning. While such areas clearly have a multitude of risks which need to be mitigated, it is important that limitations based on personal data protection legislation are based on risk and not as limiting the use of personal data by default.
16 → 12