Companies & groups · US
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 14 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2026-05-28 | Communications Networks, Content and Technology | Glasswing project |
| 2026-04-23 | Communications Networks, Content and Technology | Exchange of views on the fight against online piracy |
| 2025-04-30 | Communications Networks, Content and Technology | Cybersecurity |
| 2025-03-18 | Cabinet of Commissioner Michael McGrath | Forthcoming Digital Fairness Act, protection of minors, data protection, simplification |
| 2025-03-11 | Cabinet of Commissioner Maroš Šefčovič | Global trade developments |
| 2025-03-11 | Cabinet of Commissioner Maroš Šefčovič | Global trade developments |
| 2025-01-23 | Cabinet of Executive Vice-President Henna Virkkunen | EU tech agenda |
| 2023-10-10 | Cabinet of Vice-President Věra Jourová | Connectivity, cyber-security, DSA, DMA |
| 2023-10-10 | Cabinet of Vice-President Věra Jourová | Connectivity, cyber-security, DSA, DMA |
| 2021-03-29 | Cabinet of Commissioner Thierry Breton | DSA |
| 2020-12-02 | Cabinet of Commissioner Thierry Breton | Roundtable with platforms on DSA and DMA |
| 2020-12-02 | Cabinet of Commissioner Thierry Breton | Roundtable with platforms on DSA and DMA |
| 2020-12-02 | Cabinet of Commissioner Thierry Breton | Roundtable with platforms on DSA and DMA |
| 2020-02-11 | Cabinet of Executive Vice-President Margrethe Vestager | Digital services act |
Response to the European Commission’s call for evidence on the application of the General Data Protection Regulation Cloudflare welcomes the opportunity to contribute to the European Commission’s call for evidence on the application of the General Data Protection Regulation (GDPR), based on our practical experience both as a controller and a processor of personal data since the GDPR became applicable six years ago. Introduction and background on Cloudflare Cloudflare is an Internet performance and security company that is on a mission to help build a better Internet. Our global network of over 310 Points of Presence (PoPs) in over 120 countries serves an average of 50 million HTTP requests per second.1 In the EU alone, we have 40+ PoPs in 25 Member States. Our current suite of services includes, among others, application services (e.g.
…we have 40+ PoPs in 25 Member States. Our current suite of services includes, among others, application services (e.g. DDoS protection, bot management) and Secure Access Service Edge (“SASE”) products, which offer our customers’ employees the ability to authenticate and securely connect to internal resources from anywhere, and provide better control over and visibility into the users, traffic, and data accessing a large network — vital capabilities for modern, globally distributed organizations. On balance, the GDPR has definitely moved the needle in the right direction for giving people more control over their personal data and in protecting their privacy. In a couple of key areas, however, we believe the way the GDPR has been applied to data flowing across the Internet has not helped and in fact may even jeopardize the protection of personal data.
…to data flowing across the Internet has not helped and in fact may even jeopardize the protection of personal data. The first area where we see this is with respect to cross-border data transfers. Location has become a proxy for privacy in the minds of many EU data protection regulators, and we think that is the wrong result. The second area is an overly broad interpretation of what constitutes “personal data” by some regulators with respect to Internet Protocol or “IP” addresses. We contend that IP addresses should not always be considered personal data, especially when the entities handling IP addresses have no ability on their own to tie those IP addresses to individuals. This is important because the ability to implement a number of industry-leading cybersecurity measures relies on the ability to gain threat intelligence from Internet traffic metadata, including IP addresses.
…measures relies on the ability to gain threat intelligence from Internet traffic metadata, including IP addresses. We provide further explanation of these two areas of concern below. 1 https://www.cloudflare.com/network/ Ref. Ares(2024)975379 - 08/02/2024 Location should not be a proxy for privacy After the “Schrems II” decision in 2020 by the Court of Justice of the European Union (CJEU),2 which invalidated the EU-US Privacy Shield, we saw many EU Data Protection Authorities (DPAs) double down on their view that European personal data simply could not be processed in the United States in a way that would be consistent with the GDPR. The EU’s recent approval of the EU-US Data Privacy Framework re-established adequacy for US entities that certify to the framework, so these cross-border data transfers are not currently an issue.
…for US entities that certify to the framework, so these cross-border data transfers are not currently an issue. But if the Data Privacy Framework were to be invalidated again, which is a possible scenario, then we could again find ourselves in a place where the GDPR is applied to mean that EU residents’ personal data cannot be processed in the US, therefore promoting what we believe is a misconception that data localization should be a proxy for data protection. In fact, the opposite is the case: our experience and recent research3 have shown that GDPR-induced data localization threatens an organization’s ability to achieve integrated management of cybersecurity risk and limits an entity’s ability to employ state-of-the-art cybersecurity measures that rely on cross-border data transfers to make them as effective as possible.
…state-of-the-art cybersecurity measures that rely on cross-border data transfers to make them as effective as possible. This directly clashes with the obligation Article 32 GDPR places on data controllers and processors to “develop appropriate technical and organizational measures to ensure a level of security appropriate to the risk”, “taking into account the state of the art”.
…measures to ensure a level of security appropriate to the risk”, “taking into account the state of the art”. In addition, data localization undermines information sharing within industry and with government agencies for cybersecurity purposes, which is generally recognized as vital to effective cybersecurity.4 Applying data transfer rules to IP addresses makes it harder to effectively protect personal data and could lead to fragmentation of the Internet One particularly problematic application of GDPR in this context is the treatment of IP addresses as personal data, making them subject to data transfer restrictions under the GDPR. As the Internet is a global network, Internet traffic – which necessarily contains IP addresses – will often cross national borders.
…is a global network, Internet traffic – which necessarily contains IP addresses – will often cross national borders. IP addresses are also part of important metadata used for cybersecurity purposes: advanced machine learning/predictive AI techniques that look at IP addresses to protect against DDoS attacks, prevent risks from malicious bots, or otherwise guard against personal data breaches, will draw on attack patterns and threat intelligence from around the world to the benefit of EU entities and residents. If the Data Privacy Framework were to be invalidated as the EU-US Privacy Shield was in the Schrems II decision, then we could find ourselves in a place where the GDPR is applied to mean that IP addresses ostensibly linked to EU residents cannot be processed in the US, or potentially not even leave the EU.
IP addresses ostensibly linked to EU residents cannot be processed in the US, or potentially not even leave the EU. If this were the case, then providers would have to start developing Europe-only networks to ensure IP addresses never cross jurisdictional boundaries. 4 https://www.enisa.europa.eu/topics/national-cyber-security-strategies/information-sharing 3 Swire, Peter and Kennedy-Mayo, DeBrae and Bagley, Andrew and Modak, Avani and Krasser, Sven and Bausewein, Christoph, Risks to Cybersecurity from Data Localization, Organized by Techniques, Tactics, and Procedures (2023). 2 Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems. 2 A world where IP addresses are always treated as personal data and subject to the GDPR’s data transfer rules could therefore come perilously close to requiring a walled-off European Internet.
…to the GDPR’s data transfer rules could therefore come perilously close to requiring a walled-off European Internet. This would not only seriously hamper the deployment of a number of critical cybersecurity measures necessary for keeping personal data safe and private, it likely would cut the EU off from any number of global marketplaces, information exchanges, and social media platforms. A possible solution would be to consider that IP addresses are not always “personal data” subject to the GDPR. In 2016 – even before the GDPR took effect – the CJEU established the view in Breyer v. Bundesrepublik Deutschland5 that dynamic IP addresses constituted personal data only if the processing entity could link them to an individual.
…that dynamic IP addresses constituted personal data only if the processing entity could link them to an individual. Unfortunately, many EU DPAs applied the decision as if dynamic IP addresses were always personal data under the GDPR, without considering whether an entity actually has a way to tie the IP address to a real person.6 Keeping privacy in focus As demonstrated above, a misguided application of the GDPR that places privacy protections above all other considerations – even appropriate security measures – can actually cause unintended harm to data protection. If taken too far, this approach would not only negatively impact cybersecurity and data protection, but could even put into question the functioning of the global Internet infrastructure as a whole, which depends on cross-border data flows.
…question the functioning of the global Internet infrastructure as a whole, which depends on cross-border data flows. In order to prevent this, without necessarily having to re-open the GDPR again at this moment, we would like to propose the following: First, the Commission could encourage the EDPB to adopt guidelines for DPAs, clarifying that IP addresses should not be considered personal data when they cannot be linked by an entity to a real person. This would follow the relative approach adopted by the CJEU in the Breyer case, as described above. The pending CJEU decision in SRB v EDPS7 could provide some further helpful clarification in this regard. Second, the European Commission and the EDPB should clarify that the GDPR’s application should be considered with the cybersecurity benefits of data processing in mind.
14 → 12