EuroISPA · Trade and business associations · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 9 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2026-06-02 | Communications Networks, Content and Technology | Exchange of views on copyright / private copying |
| 2025-11-18 | Communications Networks, Content and Technology | Monitoring and follow-up of the Commission Recommendation on combating online piracy of live events Main points |
| 2021-10-12 | Cabinet of Commissioner Ylva Johansson | Digital policies of DG Home |
| 2021-10-04 | Cabinet of Vice-President Věra Jourová | Digital policies |
| 2021-10-04 | Cabinet of Vice-President Věra Jourová | Digital policies |
| 2021-09-16 | Cabinet of Executive Vice-President Margrethe Vestager | Digital Services Act, NIS2, ePrivacy |
| 2020-02-19 | Cabinet of Commissioner Didier Reynders | Presentation general of activities of the Group |
| 2020-02-19 | Cabinet of Vice-President Věra Jourová | Digital Services Act |
| 2020-02-19 | Cabinet of Vice-President Věra Jourová | Digital Services Act |
…1 EUROISPA’S ANSWER TO THE CALL FOR EVIDENCE ON THE REPORT ON THE APPLICATION OF THE GDPR QUESTIONS 1. General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? Answer: Benefits: 1. Increased efficiency and harmonisation in cross-border cases: We appreciate the aim of the new proposal on GDPR procedural rules to streamline the handling of cross- border GDPR cases, ensuring more efficient and harmonised approaches across the EU. 2. Transparency and accountability: There has been a noticeable increase in organisational transparency regarding data collection and usage. 3. Awareness and control: Individuals have become more aware of their data protection rights and exercise greater control over their personal data. Challenges:
…become more aware of their data protection rights and exercise greater control over their personal data. Challenges: 1. Complexity and compliance costs: The complexity poses significant challenges, particularly for SMEs in understanding and complying with the requirements. In addition the compliance with the GDPR can be costly, especially for small and medium-sized organisations. 2. Exercise of data subject rights a. From the individuals’ perspective: please provide information on the exercise of the data subject rights listed below, including on possible challenges (e.g. delays in controllers/processors reply, clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.).
…clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.). From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). • Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) Ref.
…obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) Ref. Ares(2024)973400 - 08/02/2024 2 • Access to data (Article 15) • Rectification (Article 16) • Erasure (Article 17) • Data portability (Article 20) • Right to object (Article 21) • Meaningful explanation and human intervention in automated decision making (Article 22) Where possible please provide a quantification and information on the evolution of the exercise of these rights since the entry into application of the GDPR. b. Do you avail of / are you aware of tools or user-friendly procedures to facilitate the exercise of data subject rights? c. Do you have experience in contacting representatives of controllers or processors not established in the EU? d. Are there any particular challenges in relation to the exercise of data subject rights by children? Answer: a.
EU? d. Are there any particular challenges in relation to the exercise of data subject rights by children? Answer: a. Improve transparency to users: Need to simplify and/or standardise the information provided to European users to help them better navigate the information they need to make informed decisions and address any challenges. b. Online self-service tools and forms: These allow a more efficient management of requests, including verification that these requests only come from verified users. c. N/A d. Parents’ ability to exercise the rights of their children on their behalf, as GDPR data subjects, should be clarified as some uncertainties and complexities persist.
…children on their behalf, as GDPR data subjects, should be clarified as some uncertainties and complexities persist. 3. Application of the GDPR to SMEs a. What are the lessons learned from the application of the GDPR to SMEs? b. Have the guidance and tools provided by data protection authorities and the EDPB in recent years assisted SMEs in their application of the GDPR (see also the EDPB data protection guide for small business5)? c. What additional tools would be helpful to assist SMEs in their application of the GDPR? Answer: a. The complexity of the requirements (i.e., contracting obligations, data mapping, DPOs appointment, data portability aspects, etc.) have an impact on their ability to comply, also in a context where GDPR requirements are not the only ones to be taken into account (i.e., security measures, transparency obligations, etc.). b. Guidelines are helpful but do not…
…obligations, etc.). b. Guidelines are helpful but do not address the issue of complexity entirely. c. N/A 3 4. Use of representative actions under Article 80 GDPR a. From the controllers and processors’ perspective: are you aware of representative actions being filed against your organisation(s)? b. For civil society organisations: have you filed representative actions in any Member State (please specify: complaint to DPA or to court, claim for compensation; and the type of GDPR infringement) and if yes, what was your experience? Do you intend to take actions under the Representative Actions Directive6? Answer: a. The use of this article is expected to increase significantly, raising concerns in the possible misuse of this procedure. Therefore, protecting individuals’ rights should be the first purpose of the litigation. Giving more guidance and clarity on compensatory damages can help…
…on the same matter under Article 80 GDPR should be avoided through harmonisation of domestic procedures. b. N/A 5. Experience with Data Protection Authorities (DPAs) a. What is your experience in obtaining advice from DPAs? b. How are the guidelines adopted so far by the EDPB supporting the practical application of the GDPR? c. Are DPAs following up on each complaint submitted and providing information on the progress of the case? d. Are you aware of guidelines issued by national DPAs supplementing or conflicting with EDPB guidelines? (please explain) Answer: a. There has been reluctance from DPAs in providing guidance and advice especially on complex interpretation cases. The development of engagement procedures to obtain advice on key industry developments and related privacy issues with and from DPAs should be encouraged. b. EDPB guidelines should be more pragmatic to better reflect…
…procedure has improved in the last months, resulting in a more efficient, transparent and consistent approach. d. N/A 4 6. Experience with accountability and the risk-based approach a. What is your experience with the implementation of the principle of accountability? b. What is your experience with the scalability of obligations (e.g., appropriate technical and organisational measures to ensure the security of processing, Data Protection Impact Assessment for high risks, etc.)? Answer: a. The right to the protection of personal data is not an absolute right, nevertheless it has to be in balance with the legitimate interest of data controllers and others’ rights and interests which should be more clearly enshrined in the GDPR. b. DPAs have often adopted a zero-risk policy approach, while a risk-based approach should be a prerequisite for development and deployment of anonymisation…
…on the acceptance of a risk-based approach by DPAs may lead to less investments and developments in these fields. 7. Data protection officers (DPOs) a. What is your experience in dealing with DPOs? b. Are there enough skilled individuals to recruit as DPOs? c. Are DPOs provided with sufficient resources to carry out their tasks efficiently? d. Are there any issues affecting the ability of DPOs to carry out their tasks in an independent manner (e.g., additional responsibilities, insufficient seniority, etc.)? Answer: a. Disparity of DPOs practices across companies is being noticed; this is potentially due to limited guidance from DPAs as well as a role played inconsistently across the industry. b. The statutory requirements in Article 39 are quite broad, leading to difficulties in finding the individual with the appropriate skills. c. Resources dedicated to DPOs in order to cover the…
…by DPAs; moreover, it remains unclear what the consequences might be if controllers do not adhere to DPO advice. 8. Controller/processor relationship (Standard Contractual Clauses) a. Have you made use of Standard Contractual Clauses adopted by the Commission on controller/processor relationship7? b. If yes, please provide feedback on the Standard Contractual Clauses? 5 Answer: a. N/A b. N/A 9. International transfers a. For controllers and processors: Are you making use of the Standard Contractual Clauses for international transfers adopted by the Commission8? If yes, what is your experience with using these Clauses? b. For controllers and processors: Are you using other tools for international data transfers (e.g., Binding Corporate Rules, tailor-made contractual clauses, derogations)? If yes, what is your experience with using these tools? c.
Rules, tailor-made contractual clauses, derogations)? If yes, what is your experience with using these tools? c. Are there any countries, regional organisations, etc. with which the Commission should work in your view to facilitate safe data flows? Answer: a. Some of our members are; what they are experiencing is that the SCCs do not answer all the potential needs of a business coming from international transfers. Collaboration with global actors on best practices and interoperability is recommended. b. N/A c. Some concrete examples might be Australia, Indonesia, Singapore, South Africa. More generally, cross-border data flows are necessary for companies, European and international, to operate globally and to ensure a good level of services to their customers, wherever they are located.
19 → 12
April 2020 EuroISPA’s views on the implementation of the GDPR EuroISPA welcomes the introduction of the EU General Data Protection Regulation (GDPR) and considers it as a necessary piece of legislation. We believe a comprehensive analysis and assessment of the effectiveness of the GDPR remains premature as the legal framework still has to be supplemented by appropriate decision-making practices by supervisory authorities along with case- law. However, since the May 2018 entry into application of the GDPR, several questions from the point of view of EuroISPA have emerged. You can find below a summary of these views.
GDPR, several questions from the point of view of EuroISPA have emerged. You can find below a summary of these views. Cooperation and consistency mechanism between national data protection authorities (Chapter VII GDPR) The application of the GDPR must be uniform and proportionate In some cases, the GDPR has created difficulties for SMEs and non-commercial actors, with its strict rules coupled with high fines. Even though data protection rules should apply to everyone uniformly, particular attention should be paid to the resources of the respective actors involved and the proportionality of the measures applied, particularly when enforcing data protection law. It should also be noted that future evaluations should ensure the uniformity and proportionality of the fines imposed on actors deemed to have infringed the law, while upholding the independence of supervisory authorities.
…fines imposed on actors deemed to have infringed the law, while upholding the independence of supervisory authorities. If decisions by the supervisory authorities are considered as inconsistent and unpredictable, it would weaken the harmonising promise of the GDPR, to the detriment of data protection. We reiterate the importance of the One-Stop-Shop (OSS) mechanism The European Commission has explicitly confirmed that the OSS mechanism is necessary to pursue the EU’s single market objectives, and leads to estimated EUR 2.3 billion per year in savings. Furthermore, this has been confirmed by emerging case-law on the GDPR (e.g. Case C- 210/16 Wirtschaftsakademie Schleswig-Holstein GmbH and the Case Google LLC v CNIL).
…case-law on the GDPR (e.g. Case C- 210/16 Wirtschaftsakademie Schleswig-Holstein GmbH and the Case Google LLC v CNIL). However, we observe a worrying trend whereby national Data Protection Associations (DPAs) seek to exert jurisdiction on entities involved in such cross-border processing operations that do not have their place of main establishment in that Member State. It is concerning that certain DPAs are looking at novel ways of interpreting provisions in the GDPR, such as Article 58(5), to exert such jurisdictional claims. This goes against the heart of the GDPR regime of territorial competence and subsequent cooperation and consistency mechanism. By doing so, DPAs are going against the clear emphasis on consistency and cooperation between supervisory authorities and Member States throughout the Union, both in terms of application and enforcement.
…between supervisory authorities and Member States throughout the Union, both in terms of application and enforcement. We note that Article 51(2), obliges DPAs to "contribute to the consistent application of this Regulation throughout the Union”, including to “cooperate with each other and the Commission in accordance with Chapter VII”. It is also important to note that similar practices are detrimental to business certainty and investment in Europe. Therefore, we would welcome the European Commission affirming the rules and obligations of the OSS mechanism in its upcoming report. Ref. Ares(2020)2283221 - 29/04/2020 April 2020 Lack of harmonisation on data protection principles We remain concerned regarding the prevalence and use of so-called “opening clauses” for the adoption of diverging national legislation on specific topics. This creates a disparity of approaches.
…clauses” for the adoption of diverging national legislation on specific topics. This creates a disparity of approaches. In particular, this is the case for the age of consent, where Member States have adopted different provisions setting a different threshold in their jurisdiction. Such an approach is especially complicated for companies providing services in a plurality of Member States. Furthermore, some of the derogations from the GDPR or variations of the provisions of the GDPR codified in national data protection laws might go beyond what is permitted under the GDPR (e.g., limitations related to data subject rights; heirs exercising certain rights under the GDPR, specific national laws on digital will). Moreover, even where the GDPR is providing full harmonisation, some data protection authorities continue to take their own interpretation (e.g.
GDPR is providing full harmonisation, some data protection authorities continue to take their own interpretation (e.g. guidance on cookies, guidance on artificial intelligence (AI)). Role of the European Data Protection Board (EDPB) The role of the EDPB is essential - it must ensure that the harmonisation promise of the GDPR is kept and that DPAs approach issues in the same manner. In order for the EDPB to complete its tasks efficiently, its procedures and website should be made more transparent. This includes increased transparency on mandates, information on which DPAs are in charge of drafting guidance, structures of the working groups, timelines for adoption of documents, improvement of the website of the EDPB to make information more easily accessible, publication of all official correspondence, minutes and agendas of each meeting (whether plenary or working groups).
…publication of all official correspondence, minutes and agendas of each meeting (whether plenary or working groups). Such a level of transparency should also be required for each individual European DPA. International transfers of personal data to third countries (Chapter V GDPR) The importance of international transfers is acknowledged by the GDPR. In a world where digital services are internationalised, the ability for data to cross EU borders is essential. However, transfers with third countries, which will include the United Kingdom, remain strained for companies. Companies – and especially internationally active ones - urgently need more legal certainty. The Privacy Shield For transfers to the United States, the Privacy Shield constitutes a central mechanism for entities partaking in transatlantic commerce.
…the United States, the Privacy Shield constitutes a central mechanism for entities partaking in transatlantic commerce. Its importance should continue to be acknowledged and supported by both the EU Institutions and European DPAs. However, the system is regularly questioned and reviewed not only by political actors, but also through legal proceedings and lawsuits. Legal certainty cannot be securely established in this way. Businesses require reliable, sustainable and comprehensive rules for international data exchange with third countries. The GDPR report should highlight this point. Standard contractual clauses The EU standard contractual clauses (SCCs) constitute one of the most important mechanisms to achieve data transfers. However, these instruments do not reflect the reality of today’s international transfers.
…to achieve data transfers. However, these instruments do not reflect the reality of today’s international transfers. Although it is very common for a processor to use another organisation, SCCs do not cover the situations of transfers between data processors and sub-processors. Moreover, they are not April 2020 sufficiently flexible and cannot be modified easily to reflect the evolution of technologies and business models. Furthermore, such tools are also under scrutiny. We are concerned regarding the European Commission's review of SCCs in the context of law enforcement requests. Organisations cannot be put in a position where they will need to choose between breaching a legitimate law enforcement request (e.g. detailed disclosures to a DPA could be a criminal offense in certain countries) or the GDPR.
…enforcement request (e.g. detailed disclosures to a DPA could be a criminal offense in certain countries) or the GDPR. Binding Corporate Rules Binding Corporate Rules (BCRs) are commonly relied upon by companies for data transfers. DPAs should be sufficiently equipped to ensure that BCRs projects are reviewed and approved swiftly. It is unclear how organisations subject to the GDPR should deal with requests of UK law enforcement authorities after Brexit. It would be useful if regulators could issue guidance on how these data flows ought to be managed going forward to enable businesses to put plans in place prior to 31 December. Certifications Certification is an attractive option to enable cross-border data transfers since it provides a higher degree of compliance certainty that an audit can deliver and, if coupled with an ISO standard, is more globally scalable.
…of compliance certainty that an audit can deliver and, if coupled with an ISO standard, is more globally scalable. If more data protection regulations continue to emulate the GDPR, an ISO-based certification makes it much easier for other countries to reciprocate with the similar cross-border data transfer mechanism. It is also far more cost effective from the perspective of data controllers and processors. We encourage the European Commission to send a clear signal to the EDPB and the market at large about the necessity of a unified European Data Protection Seal. If this is not achievable via the EDPB, we encourage the European Commission to adopt the delegated and implementing act per Article 43. Other concerns Elements of the GDPR promote bureaucracy There is uncertainty among companies concerning the joint responsibility for data processing.
16 → 12