Trade and business associations · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 66 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
December 2023 DOT Europe feedback on the Application of the GDPR 2024 DOT Europe welcomes the opportunity to provide our feedback on the evaluation of the application of the GDPR, scheduled for 2024. We believe this is a great opportunity to reflect on how the regulation has functioned and examine what has worked well, what has not and where there is room for improvement. Crucially, we would like to take this opportunity to offer recommendations on how the shortcomings of the GDPR can be addressed. We believe this can be done without the need to reopen the original text; most shortcomings identified are the result of interpretation and enforcement of the original wording, which has often focused on the letter and not the spirit of the law.
…and enforcement of the original wording, which has often focused on the letter and not the spirit of the law. Such narrow and “absolutist” interpretations of the GDPR have had unintended consequences including legal uncertainty, imbalance between consumers’ privacy rights and other rights and delayed decisions about business operations in the EU. Overall, the past years have seen an enormous amount of work from all stakeholders of society, including industry, towards the implementation of what is a monumental framework. This work continues today in what is an ever evolving and ongoing process of implementation and dialogue. It is thus crucial to review its operation carefully and objectively.
…ongoing process of implementation and dialogue. It is thus crucial to review its operation carefully and objectively. While DOT Europe and its members believe there are issues around implementation and interpretation that should be addressed, many can be resolved through further dialogue and guidance and without further legislation. Our contribution to the evaluation will cover the following topics: • What has worked well • Shortcomings of the GDPR • Recommendations on practical next steps What has worked well Overall, the framework has brought several benefits which have been allowed a number of years to unfold and be evaluated. The GDPR provides for a principles-based and solid legal basis, in turn, allowing for the protection of data whilst providing for a certain level of flexibility.
…solid legal basis, in turn, allowing for the protection of data whilst providing for a certain level of flexibility. Furthermore, the GDPR has generated greater awareness from consumers who clearly better understand their rights and appreciate what happens with their data. This key piece of legislation has also inspired a number of global privacy laws, thus resulting in more global convergence on shared data protection principles. More specifically, the regime provides for several beneficial provisions and considerations. Foremost amongst these is the One-Stop-Shop principle, a cornerstone and pillar of the GDPR with the intention of creating a single regulator for EU businesses and an efficient process for addressing cross-border complaints without the burden and cost of a company having to engage with 27 separate regulators.
…cross-border complaints without the burden and cost of a company having to engage with 27 separate regulators. The legislative intent was to create legal certainty for all parties involved and a system fully aligned with the needs and goals of the EU single market. It is thus important that this principle is not undermined in any way. Beyond this key principle, industry favourably recognises the following aspects of the framework which should be reinforced and protected. Ref. Ares(2024)958553 - 08/02/2024 December 2023 • The risk-based intention of the framework • The six legal bases and the flexibility they provide • The awareness that the regime has created amongst consumers of their rights • The GDPR acting as a blueprint worldwide resulting in a push towards global harmonisation • Positive intention to create a culture of constant improvement.
…resulting in a push towards global harmonisation • Positive intention to create a culture of constant improvement. • Lead to increasing levels of harmonisation. The above points are practical examples of the benefits of the framework and aspects that should be reinforced, safeguarded, or further harmonised within the EU Single Market. Shortcomings The GDPR was an ambitious piece of legislation that set several laudable goals. Outside of creating a regime that protects the privacy of EU citizens, the GDPR also sought to bring about a change in the long-term view of companies by creating a stable regulatory framework; and fostering a culture of innovation that would be based on the very requirements the legislation put in place.
…and fostering a culture of innovation that would be based on the very requirements the legislation put in place. DOT Europe believes that, while these goals are largely yet to be met, an overly strict, interpretation of the GDPR has resulted in the undermining of mechanisms that were supposed to provide certainty for data controllers and processors. Contrary to the original intention of the GDPR and co-legislators, these very interpretations have resulted in the framework not achieving its full potential when it comes to innovation, for example. 1. De-prioritisation of the risk-based approach In the experience of DOT Europe members, DPAs have adopted an absolutist approach in the interpretation and enforcement of the GDPR. The risk-based approach enshrined in the text of the Regulation as a key guiding principle has not been properly applied.
…risk-based approach enshrined in the text of the Regulation as a key guiding principle has not been properly applied. Instead, we have seen the right to the protection of personal data treated as an absolute, without any weighing against the legitimate interests of data controllers and others’ rights and interests. DPAs have adopted a zero-risk policy, which is not in alignment with the risk-based approach that implies proportionality. This has resulted in advice that is impractical or too focussed on theoretical issues, rather than working with stakeholders towards finding practical solutions to problems at hand. A good example of this absolute, rigid approach is the debate on anonymisation technologies. We have seen regulators go for a zero-identification risk, instead of a sufficiently low, negligible risk level.
We have seen regulators go for a zero-identification risk, instead of a sufficiently low, negligible risk level. Opting for zero identification risk significantly hampers innovation and the development of new technologies, such as AI training. This is despite practical experimentation showing that pseudonymous datasets with state-of-the-art technical and organisation measures can be privacy- and confidentiality-preserving, and thus free from adversarial attacks. It must be highlighted that the GDPR allows data processing without consent or other specific legal bases in principle only when data is anonymized. However, a strict adherence to the letter of the law could hinder the development of innovative techniques, alternative to anonymization, which can have the same end result for privacy.
…the development of innovative techniques, alternative to anonymization, which can have the same end result for privacy. Another instance where the attitudes of regulators have not kept up with developments, creating problems in the process, is the issue of international data transfer regimes. Legal interpretations no longer reflect the practical reality of data processing – the internet is global and data is no longer packaged up in a little box and shared from one place to another akin to a physical filing system. We December 2023 believe that the regulatory world might benefit from a shift in its focus towards controls to protect the data, rather than the prevention/limitation of transfer to both address existing concerns and not further limit the transfer of data.
…the prevention/limitation of transfer to both address existing concerns and not further limit the transfer of data. For example, several jurisdictions have worked on Global Cross- Border Privacy Rules to allow organisations to demonstrate compliance to internationally recognised data protection standards. Again, a rigid interpretation of the legal text that does not reflect reality on the ground risks fragmenting the global nature of digital services, threatening their seamless provision, and causing significant legal uncertainty for global businesses. Moreover, proposals for "immunity from the law" requirements and an embrace of data localization considerations across regulatory sectors are compounding an already impossible compliance conundrum. In reality, however, the GDPR does not intend to limit the free flow of personal data to the bare minimum.
…conundrum. In reality, however, the GDPR does not intend to limit the free flow of personal data to the bare minimum. On the contrary, it means creating the framework for facilitating data flows while protecting individual rights as part of the EU's progression towards a digital society. "Zero-risk" regulates away from the realities of a global digital economy and runs contrary to the intent of the GDPR's co-legislators to have a horizontal approach of the risk-based approach throughout the GDPR, including for data transfers. DOT Europe Recommendation: We suggest that DPAs need to have additional considerations in mind when working on decisions or guidance.
55 → 12
GDPR: procedural rules on cross-border enforcement; DOT Europe position With the General Data Protection (Regulation 2016/679, GDPR) approaching five years since its formal entry into force, DOT Europe welcomes the European Commission’s initiative to support the robust enforcement of the GDPR and believes that the time is right to consider the operation of this landmark regulation to see what worked well, what did not and what could work better as well as of course identifying why. Although aspects of the GDPR are still being clarified via EU jurisprudence and Supervisory Authority (SA) guidance and enforcement, one issue that has consistently suffered in its application is the one-stop-shop (OSS) mechanism, including dealing with cross-border cases. The OSS is one of the main achievements of the GDPR.
(OSS) mechanism, including dealing with cross-border cases. The OSS is one of the main achievements of the GDPR. It is worth recalling that the mechanism was introduced to enhance consistency in application, legal certainty and reduce the administrative burden for controllers and processors, while also resulting in significant added value for individuals in the EU, who could now benefit from central enforcement of the right to data protection. The implementation of the GDPR has, in practice, led to a less than ideal operation of the OSS mechanism. We believe the OSS has not achieved its full capacity, where resistance from certain SAs has contributed to complex procedures that do not deliver the legal certainty and mutual cooperation intended by the GDPR.
…to complex procedures that do not deliver the legal certainty and mutual cooperation intended by the GDPR. Against this backdrop, DOT Europe welcomes this targeted consultation but is troubled by the ongoing focus on enforcement as the primary measure of success of the GDPR. The legislators’ goal in adopting the GDPR was broad – to promote a high and harmonized level of the right to data protection across Member States; clarify legitimate uses of data; introduce more effective transparency and control for data subjects; and strengthen legal certainty for compliant organisations.
…more effective transparency and control for data subjects; and strengthen legal certainty for compliant organisations. Narrowly focusing SAs’ efforts on enforcement, in particular enforcement by means of administrative fines, risks detracting from other important regulatory objectives central to the EU data protection framework: upholding the accountability principle; enabling amicable resolution; and promoting compliance by issuing targeted and actionable guidance and enforcement actions not restricted to administrative fines. These are important tasks of SAs and the EDPB, and this consultation should take care to position enforcement action as one of the mechanisms through which the GDPR can achieve its policy goals rather than overshadow these other crucial regulatory activities.
…through which the GDPR can achieve its policy goals rather than overshadow these other crucial regulatory activities. Failure to strike this balance sets a concerning precedent for EU regulation more broadly, and this could chill investment and growth in the EU’s digital economy, while creating a process that does not efficiently and effectively meet EU policy goals. Our contribution will touch on the following aspects of the OSS mechanism: • Its significance for data subjects and organisations in the EU; • Taking unnecessary burdens off SAs; • Procedural deadlines; • Promoting confidentiality; • Streamlining how parties are heard during the process; and • The role of the EDPB and other related issues.
…how parties are heard during the process; and • The role of the EDPB and other related issues. OSS mechanism: its significance for data subjects and organisation in the EU The OSS mechanism is essential to the GDPR’s goal of providing a high common level of data protection for all data subjects in the EU. The centralised enforcement led by the LSA ensures that regulatory decisions are implemented across Member States, reducing fragmentation and uneven Ref. Ares(2023)2144346 - 24/03/2023 outcomes for organisations and businesses in the EU. The OSS mechanism, paired with the consistency mechanism, also provides clarity to data subjects as to the competent regulator and by ensuring a consistent and efficient application of data protection rules across the EU. The OSS mechanism is also particularly important for companies with pan-EU business operations.
…rules across the EU. The OSS mechanism is also particularly important for companies with pan-EU business operations. It provides operational efficiency, management of cost and legal certainty via one ‘lead’ SA being their single point of contact. Similarly, smaller companies established in one Member State and providing services across the EU benefit from the OSS provision as it significantly reduces the complexity of compliance for nascent businesses. Without this mechanism, they would be obliged to engage with multiple SAs, which would not be commercially viable. A well-functioning OSS mechanism has the potential to reduce red tape and confusion on the competency issue and to avoid conflicting approaches by SAs.
…has the potential to reduce red tape and confusion on the competency issue and to avoid conflicting approaches by SAs. DOT Europe observes that most SAs support and respect the OSS principle described in the GDPR and consider that a single establishment (acting as a controller / processor or an establishment of a controller / processor outside of the Union) triggers the OSS mechanism on the basis of article 56(1) GDPR. Certain SAs, however, seem to deviate from this mechanism and add further requirements for such establishments that go beyond what is included in the GDPR and relevant case law. DOT Europe recommends that the European Commission clarify that organisations that have a single establishment in the Union benefit from the OSS mechanism on the basis of Article 56(1) GDPR, without needing to meet further or heightened criteria which are not provided in the GDPR.
…basis of Article 56(1) GDPR, without needing to meet further or heightened criteria which are not provided in the GDPR. Another relevant issue that merits clarification is the GDPR provisions on local cases, which can undermine the lead SA concept. Despite the existence of the OSS mechanism under Article 56(1) GDPR, DOT Europe members have observed cases where other SAs approach organisations arguing that a case is considered “local” and, as such, they are empowered under Article 56(2) of the GDPR to investigate. This derogation from the OSS mechanism is often difficult for organisations to reconcile.
…of the GDPR to investigate. This derogation from the OSS mechanism is often difficult for organisations to reconcile. DOT Europe thus believes that more clarity is needed on the aspects of the relevant Article, which are underlined below: “By derogation from paragraph 1, each supervisory authority shall be competent to handle a complaint lodged with it or a possible infringement of this Regulation, if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State.” In addition, DOT Europe continues to maintain that the SA of an organisation’s main establishment should be the only competent authority for decision-making, including for managing complaints and deciding on appropriate sanctions.
…only competent authority for decision-making, including for managing complaints and deciding on appropriate sanctions. This SA should coordinate joint actions; be the main competent authority for decision-making; and have a leading role in any cooperation procedures with other SAs in relation to an organisation whose main establishment is within its competence. This is preferable to a model of co-competence, which would weaken the OSS mechanism and introduce more uncertainty, inefficiency, and costs in the procedure. The European Commission initiative should preserve and strengthen the OSS mechanism and not afford more powers to the wider SA community to review and comment on the factual findings, draft determinations and ultimate sanctions during the course of lead SA investigations.
…on the factual findings, draft determinations and ultimate sanctions during the course of lead SA investigations. Although the European Commission has noted that it wants to focus on administrative measures, such as introducing procedural deadlines, clarifying the position of complainants in the procedural steps and streamlining how parties are heard during the process, DOT Europe would invite policy makers to first reaffirm and strengthen the OSS mechanism which reinforces the European single market. Taking unnecessary burdens off SAs The consultation notes a lack of uniformity between SAs as to amicable resolution. DOT Europe invites the European Commission to recommend that all SAs adopt this process as a means of strengthening the accountability principle and ensuring that less complex data subject complaints are resolved quickly.
31 → 12