DT · Companies & groups · DE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 103 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
…1 Status: January 2020 Opinion of Deutsche Telekom AG concerning the evaluation and review of the General Data Protection Regulation by the EU Commission pursuant to Article 97 GDPR The General Data Protection Regulation has created a good basis for data processing in the non-public area in the European Union, based on a set of uniform rules. Experience so far has shown, however, that the intended harmonization and the intended "level playing field" are at risk. This is why, based on the experiences of Deutsche Telekom Group, some amendments to the Regulation (I) and improvements in the consistent application of the existing rules (II) are required. I) Need for regulatory action
…and improvements in the consistent application of the existing rules (II) are required. I) Need for regulatory action 1) Consistency mechanism is not used – no consistent application of the Regulation Request: The consistency mechanism has to be obligatory in respect of any matter of general application or producing effects in more than one Member State. The urgency procedure referred to in Article 66 GDPR must be used more often. Actual situation: Unclear legal definitions are interpreted differently by different supervisory authorities (e.g., data portability, scope of right of access, etc.). This is contrary to the harmonization objective of the General Data Protection Regulation.
…of right of access, etc.). This is contrary to the harmonization objective of the General Data Protection Regulation. National data protection supervisory authorities sometimes issue instructions without making clear whether these are permanent or whether they should be handled in the consistency mechanism and then canceled. Problem: The failure to take the consistency mechanism into consideration leads to legal uncertainty for both industry and citizens. Moreover, the different interpretation has a considerable financial impact because business models and processes cannot be implemented uniformly across Europe.
…a considerable financial impact because business models and processes cannot be implemented uniformly across Europe. Solution: Article 64 (2) GDPR is worded as follows: "Any supervisory authority, the Chair of the Board or the Commission may request within a reasonable period that any matter of general application or producing effects in more than one Member State be examined by the Board with a view to obtaining an opinion, in particular where a competent supervisory authority does not comply with the obligations for mutual assistance in accordance with Article 61 or for joint operations in accordance with Article 62." In addition, the urgency procedure as laid down in Article 66 GDPR should be applied more often. Ref. Ares(2020)2272609 - 28/04/2020 2 Status: January 2020
…laid down in Article 66 GDPR should be applied more often. Ref. Ares(2020)2272609 - 28/04/2020 2 Status: January 2020 2) Company-specific divergent interpretation, depending on where the company is established – standardized enforcement Request: The consistency mechanism must be obligatory for the evaluation of similar business models operated by different companies established in different Member States. Actual situation: In terms of enforcing compliance with the GDPR, supervisory authorities are not strictly required to use the consistency mechanism laid down in Article 63 GDPR et seq., even if it is a matter of general application or producing effects in more than one Member State.
…63 GDPR et seq., even if it is a matter of general application or producing effects in more than one Member State. Problem: It is possible for national supervisory authorities to make decisions regarding the enforcement of compliance with the GDPR in the area of their competence, which differ from decisions made in other Member States on similar matters. This applies above all to different companies of the same sector in different Member States (e.g., internet service provider X is treated differently in country A from internet service provider Y in country B). This puts the harmonization objective of the General Data Protection Regulation at risk and results in considerable legal uncertainty for both industry and citizens.
Data Protection Regulation at risk and results in considerable legal uncertainty for both industry and citizens. Different decisions may have a considerable impact on the cost-effectiveness of business models and could therefore also compromise the intended "level playing field." Solution: Article 64 (2) GDPR is worded as follows: "Any supervisory authority, the Chair of the Board or the Commission may request within a reasonable period that any matter of general application or producing effects in more than one Member State be examined by the Board with a view to obtaining an opinion, in particular where a competent supervisory authority does not comply with the obligations for mutual assistance in accordance with Article 61 or for joint operations in accordance with Article 62."
…obligations for mutual assistance in accordance with Article 61 or for joint operations in accordance with Article 62." 3) Scope of the right of access under Article 15 GDPR – handover of documents Request: Clarification that Article 15 GDPR refers only to the information specified in Article 15 GDPR and that data subjects do not have the right to request copies of documents on which that information is based. Actual situation: In some cases data subjects not only ask for information on and copies of their personal data, but also request copies of the original documents on which these data are based. Problem: This raises the question of distinction between this right and other rights, such as per Article 20 GDPR and rights to request the handover of documents under public law, criminal law, civil law, and labor law in particular. Article 15 GDPR must not become an across-the-board right…
…in recital 63: "That right does not include the handover of copies of original documents." 3 Status: January 2020 4) Scope of the right to data portability, Article 20 Request: Clarification that the right to data portability does not include data generated automatically by the service when it is used by the data subject (e.g., log data, traffic or location data). Actual situation: Article 20 GDPR gives the data subject the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used, and machine-readable format. Problem: In guidelines issued by supervisory authorities the term "provided" is very broadly interpreted. According to such guidelines, the term also includes data generated when a service is performed in an IT system or, for instance, in the network technology of a telecommunications network.
…a service is performed in an IT system or, for instance, in the network technology of a telecommunications network. Although these data are required in order to operate a telecommunications network, they are not actually provided by the data subject. While it would take the service provider a considerable amount of time and effort to hand over such data to the data subject, they would be of no benefit to the latter if, for instance, he or she wanted to change providers. Moreover, this broad interpretation loses sight of the fact that the legislator has deliberately decided to use the term "provided" by the data subject. In the legislative process, the legislator expressly decided not to extend the right of data portability to all processed personal data, regardless of whether they were provided by the data subject or not.
…data portability to all processed personal data, regardless of whether they were provided by the data subject or not. The starting point was to enable the data transfer of the "history" from one social network to another. Solution: Insert the following sentence after the first sentence in recital 68: "Data that are created automatically when a service is used and that are by-products of using that service (e.g., log files, traffic or location data) are not considered data provided by the data subject." 5) Notification of a personal data breaches Request: Limitation of notifiable personal data breaches by introducing clear materiality thresholds.
…data breaches Request: Limitation of notifiable personal data breaches by introducing clear materiality thresholds. Actual situation: As a result of the changed legal definition of a data privacy incident, increasing sensitivity among employees in the companies, and the new framework for sanctions available under the GDPR, the number of reported data breaches has increased. The notification obligation is only not applicable in cases where the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Problem: The application of the undefined legal term "risk" results in considerable legal uncertainty. To avoid mistakes that may incur penalties, all incidents are reported if in doubt, regardless of the risk potentially associated with a personal data breach.
23 → 12