Internet Service Providers Austria

ISPA · Trade and business associations · AT

Kategorija
Trade and business associations
Būstinė
Wien AT
Registruota
2009-10-02
Deklaruotos metinės išlaidos
18 221 € (pačios deklaruota)
Svetainė
http://www.ispa.at
Skaidrumo registras
56028372438-43 ↗
0
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
ISPA - Internet Service Providers Austria welcomes the Commissions initiative to continue reporting on how the rules of the GDPR have been applied, 6 years after their entry into application and the opportunity to provide comments to the Report on the GDPR. ISPA Internet Service Providers Austria is a voluntary business representation and act as the voice of over 220 internet service providers from various fields all along the internet value chain in Austria. Moreover, the majority of ISPA members are SMEs, and as such,face novel challenges from any new requirements.

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 12 p.

EuropeanCommission Rue de la Loi 200 B-1040 Brussels Belgium 8th February 2024 ISPA AUSTRIA’S CONTRIBUTION TO THE REPORT ON THE GENERAL DATA PROTECTION REGULATION ISPA - Internet Service Providers Austria welcomes the Commission’s initiative to continue reporting on how the rules of the GDPR have been applied, 6 years after their entry into application and the opportunity to provide comments to the Report on the GDPR. 1. General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? The GDPR initially created awareness of prioritizing the protection of personal data and its guarantee. The protection of data and the rights of the individual has now been achieved.

…of personal data and its guarantee. The protection of data and the rights of the individual has now been achieved. As the importance of protecting personal data continues to increase, GDPR is a milestone for society and its development. The challenges include in particular: o different interpretation and enforcement of the GDPR in the member states/by national data protection authorities o different approaches by national legislators o responsible supervisory authorities are equipped with different human/financial resources in the individual member states o GDPR-compliant international transfers Ref.

…with different human/financial resources in the individual member states o GDPR-compliant international transfers Ref. Ares(2024)970750 - 08/02/2024 Priority issues that should be addressed are: o Harmonization of international transfers o uniform procedural rules when applying the GDPR o a uniform interpretation of the obligations under the GDPR In order to act in compliance with the GDPR, a significant investment of time and resources is required by introducing an appropriate information management and data protection system in the respective company. Difficulties in implementation arose particularly for small and medium-sized companies. It would therefore be desirable to simplify procedures in order to reduce the administrative burden.

It would therefore be desirable to simplify procedures in order to reduce the administrative burden. The preliminary check that entrepreneurs repeatedly demand (also with other European legal acts) to determine whether regulations can be technically implemented is also desired for the GDPR (compatibility with new technologies). Finally, it should not be left unmentioned that a general guide (in particular by the national data protection authority DSB ) that also contains current decisions and interpretation aids would be of immense benefit. This would be particularly important for SMEs that do not have their own legal department. 2. Exercise of data subject rights a. From the individuals’ perspective: please provide information on the exercise of the data subject rights listed below, including on possible challenges (e.g.

…provide information on the exercise of the data subject rights listed below, including on possible challenges (e.g. delays in controllers/processors reply, clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.). From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). The individual's perspective: In everyday life, data subjects are often overwhelmed by a large amount of information in connection with data protection notices (particularly through complex legal language).In practice, information about the processing of personal data raises more questions than it answers.

…legal language).In practice, information about the processing of personal data raises more questions than it answers. In addition, the information is not even read by those affected. It would therefore be desirable to provide more understandable information for the data subject about their rights and for data protection authorities to support innovation in how data subject rights can be exercised. Perspective of the controller and the processor: We have not received any reports of problems in this regard, but administration can be very time- consuming.

…processor: We have not received any reports of problems in this regard, but administration can be very time- consuming. • Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) The use of the EDPB guidelines for the provision of information in accordance with Articles 13 and 14 GDPR has apparently become established as a certain standard (standard for the information of customers/suppliers, website users, other data subjects who are "from outside" with the for the controllers interact). • Access to data (Article 15) The wording of Art 15 was not easy to interpret in practice, although recent ECJ rulings have provided clarity. However the long duration of the proceedings before the European Court of Justice represents an unsatisfactory situation and stands in the way of legally compliant application of the GDPR.

…of Justice represents an unsatisfactory situation and stands in the way of legally compliant application of the GDPR. • Rectification (Article 16) • Erasure (Article 17) In general the members have not reported any problems to us in connection with the data subject's right to cancellation. The right to erasure is generally recognised and implemented. However, in practice, the technical implementation of deleting data from backups may be complicated or not possible to comply with the principle of integrity. • Data portability (Article 20) The relationship between data portability under the GDPR and the Data Act could lead to misunderstandings in practice, which is why clarification in this regard would be desirable.

…the Data Act could lead to misunderstandings in practice, which is why clarification in this regard would be desirable. • Right to object (Article 21) • Meaningful explanation and human intervention in automated decision making (Article 22) Where possible please provide a quantification and information on the evolution of the exercise of these rights since the entry into application of the GDPR. b. Do you avail of / are you aware of tools or user-friendly procedures to facilitate the exercise of data subject rights? Yes. For example, the Austrian data protection authority provides templates and forms that the data subject can use to submit complaints. c. Do you have experience in contacting representatives of controllers or processors not established in the EU? d. Are there any particular challenges in relation to the exercise of data subject rights by children?

…in the EU? d. Are there any particular challenges in relation to the exercise of data subject rights by children? It can be problematic for telecommunications operators if the contract is concluded with an adult, but the mobile phone is then used by a child, for example. In this context, declarations of consent can pose a challenge.

…the mobile phone is then used by a child, for example. In this context, declarations of consent can pose a challenge. 3. Application of the GDPR to SMEs a. What are the lessons learned from the application of the GDPR to SMEs? Free advice on data protection issues for SMEs in particular by the national data protection authority would therefore be desirable. b. Have the guidance and tools provided by data protection authorities and the EDPB in recent years assisted SMEs in their application of the GDPR (see also the EDPB data protection guide for small business)? In some cases the guidelines are helpful. Public guidance is generally a welcomed support for SMEs to comply with the GDPR. Additional information and tools from national data protection authority could lead to a solution to the problem. c. What additional tools would be helpful to assist SMEs in their application of the GDPR?…

…using cookies and other obligations under the GDPR o Provision of checklists and more guidance by national authorities 4. Use of representative actions under Article 80 GDPR a. From the controllers and processors’ perspective: are you aware of representativeactions being filed against your organisation(s)? No. b. For civil society organisations: have you filed representative actions in any Member State (please specify: complaint to DPA or to court, claim for compensation; and the type of GDPR infringement) and if yes, what was your experience? Do you intend to take actions under the Representative Actions Directive? 5. Experience with Data Protection Authorities (DPAs) a. What is your experience in obtaining advice from DPAs? The Austrian data protection authority provides general information, but not individual advice.

26 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse
Proposal for a Regulation of the European Parliament and of the Council on European Production and Preservation Orders for electronic evidence in criminal matters
Proposal for a Regulation of the European Parliament and of the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications)
Entwurf der Durchführungsverordnung zur Transparenzberichterstattung im Rahmen des Gesetzes über Digitale Gesetze (DSA)
Weißbuch Europäischen Kommission „How to master Europe’s digital infrastructure needs?“