SRIW · Trade and business associations · DE
European Commission report on the General Data Protection Regulation Feedback to the initiative “Report on the application of the General Data Protection Regulation”, pursuant to Article 97 of the GDPR April 2020 Ref. Ares(2020)2299425 - 29/04/2020 1 / 11 About SRIW e.V. & SCOPE Europe sprl Self-Regulation Information Economy (German: Selbstregulierung Informationswirtschaft e.V. – short: SRIW) is a Berlin-based non-profit-organization that fosters and promotes data and consumer protec- tion through self- and co-regulation. SRIW is also a monitoring body for data protection codes of con- duct in Germany since 2011 and, yet, has successfully implemented and enforced two codes of con- duct in the field of data protection. It further serves as a platform for the development, implementa- tion, enforcement, and evaluation of various codes of conduct.
…serves as a platform for the development, implementa- tion, enforcement, and evaluation of various codes of conduct. SRIW has also actively contributed to the work of the Community of Practice for better self- and co-regulation during its mandate. SCOPE Europe sprl / bvba (SCOPE Europe) is a subsidiary of SRIW. Located in Brussels, it aims to continue and complement the portfolio of SRIW in Europe and strives to become an accredited mon- itoring body under the European General Data Protection Regulation, pursuant to Article 41 GDPR. SCOPE Europe gathered expertise in levelling industry and data subject needs and interests to credi- ble but also rigorous provisions and controls. SCOPE Europe also acts as monitoring body for the EU Data Protection Code of Conduct for Cloud Service Providers1 and is engaged in other GDPR code of conduct initiatives.
Protection Code of Conduct for Cloud Service Providers1 and is engaged in other GDPR code of conduct initiatives. SRIW and SCOPE Europe (the authors) appreciate the opportunity to share our perspectives for the report on the application of the General Data Protection Regulation and, based on our experience, the following comments are made. 1 https://eucoc.cloud/en/home/ Selbstregulierung Informationswirtschaft e.V. Albrechtstraße 10 B 10117 Berlin, Gemany https://sriw.de +49 (0)30 30878099-0 [email protected] Amtsgericht Berlin Charlottenburg Registernummer: VR 30983 B USt-Nummer: DE301407624 Deutsche Bank AG IBAN DE33 1007 0000 0550 0590 00 Chairman of the Executive Board Dr. Claus-Dieter Ulmer Managing Director Jörn Wittmann SCOPE Europe b.v.b.a/s.p.r.l.
…00 Chairman of the Executive Board Dr. Claus-Dieter Ulmer Managing Director Jörn Wittmann SCOPE Europe b.v.b.a/s.p.r.l. Rue de la Science 14 1040 Brussels, Belgium https://scope-europe.eu/ +32 2 609 5319 [email protected] Company Register: 0671.468.741 VAT: BE 0671.468.741. ING Belgium IBAN BE14 3631 6553 4883 SWIFT / BIC: BBRUBEBB Managing Director Jörn Wittmann Feedback to the initiative “Report on the application of the General Data Protection Regulation”, pursuant to Article 97 of the GDPR 2 / 11 Table of Contents About SRIW e.V. & SCOPE Europe sprl ...................................................................................................... 1 1 International transfers of personal data to non-EU countries .........................................................
…transfers of personal data to non-EU countries ......................................................... 3 1.1 Enhancing legal certainty for third country transfers ............................................................... 3 1.2 Robust oversight with codes of conduct ................................................................................... 4 2 Codes of Conduct & Monitoring Bodies ............................................................................................ 4 2.1 Codes of Conduct ....................................................................................................................... 5 2.1.1 Procedural aspects .............................................................................................................
…aspects ............................................................................................................. 5 2.1.2 General validity ................................................................................................................... 6 2.2 Monitoring Body .......................................................................................................................... 6 2.2.1 Mandatory obligation of monitoring and accessibility for SMEs ..................................... 6 2.2.2 Supervisory Authorities’ competences related to the accreditation procedure ............. 7 2.2.3 Art. 41.6 (non-applicability for public authorities and bodies)......................................... 8 3 Conclusion .......................................................................................................................................
........................................................................................................................ 10 Feedback to the initiative “Report on the application of the General Data Protection Regulation”, pursuant to Article 97 of the GDPR 3 / 11 1 International transfers of personal data to non-EU countries The free flow of data across borders is a cornerstone of the globalized world economy. The GDPR contributes for the necessity of movement of personal data globally, by introducing transfer mecha- nisms of personal data to third countries or international organisations in Chapter V GDPR. In the following, our feedback addresses two of these mechanisms: standard data protection clauses and codes of conduct.
…the following, our feedback addresses two of these mechanisms: standard data protection clauses and codes of conduct. 1.1 Enhancing legal certainty for third country transfers The standard contractual clauses for third country transfers introduced under the Directive 95/46/EC have not been updated to GDPR yet and are still in use, while currently under investigation by the European Court of Justice (ECJ) in the so-called “Schrems II” case. An update of the clauses by intro- ducing standard data protection clauses pursuant to Art. 46.2 (c) GDPR would create much needed legal certainty for organisations that rely on pan-European data flows.
…to Art. 46.2 (c) GDPR would create much needed legal certainty for organisations that rely on pan-European data flows. In particular, clauses address- ing the needs of processor-to-processor relationships are needed and currently missing, which is why SRIW/SCOPE Europe formed a consortium of different European and international companies from different sectors to develop key concepts that are necessary and worth considering for the overhaul of the clauses2. For instance, a key benefit for the implementation of standard data protection clauses should be a high-level of comprehensibility and accuracy, while avoiding redundancies or conflicts with other mandatory components for legally processing personal data, such as the Data Processing Agreement according to Art. 28 GDPR or the relevant technical and organizational measures.
…such as the Data Processing Agreement according to Art. 28 GDPR or the relevant technical and organizational measures. It is also important to note that the definitions of the current set of clauses as introduced under the Directive of data importer/exporter do not take into account a possible re-transfer of personal data into the EU by a sub-processor – which is a common scenario in today’s processing activities of global enterprises. Due to the high impact and complexity of this matter, the authors would appreciate the continuous dialogue between the European Commission and industries during the revision of the standard con- tractual clauses. As GDPR slightly modified the applicable terms, a consequent reference of standard contractual clauses (Art. 28 GDPR) as standardised processing agreements and standard data pro- tection clauses (Art.
…clauses (Art. 28 GDPR) as standardised processing agreements and standard data pro- tection clauses (Art. 46 GDPR) as safeguard for third country transfers would be appreciated. 2 The work of this industry consortium is available to the public to share perspectives on innovative concepts for standard data protection clauses in a processor-to-processor environment: https://scope-europe.eu/en/pro- jects/standard-data-protection-clauses/ Feedback to the initiative “Report on the application of the General Data Protection Regulation”, pursuant to Article 97 of the GDPR 4 / 11 1.2 Robust oversight with codes of conduct Besides the mentioned standard data protection clauses, approved codes of conduct pursuant to Art. 46.2 (e) in conjunction with Art. 40 GDPR can be a crucial, robust but innovation-friendly transfer mechanism.
…to Art. 46.2 (e) in conjunction with Art. 40 GDPR can be a crucial, robust but innovation-friendly transfer mechanism. Codes of conduct can be developed by industries themselves, making it possible to in- troduce modern business practices and giving the flexibility of incorporating state-of-the-art technical and organizational measures while meeting all legal requirements as set out in Chapter V GDPR. One key advantage of codes of conduct is their thorough approval and oversight system: To achieve facili- tated proof of GDPR compliance and become a safeguard for third country transfers, a code of con- duct must be confirmed by the European Data Protection Board (EDPB) to provide appropriate safe- guards and can be declared generally valid by the European Commission.
44 → 12
European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation Joint Comments by SCOPE Europe and Selbstregulierung Informationswirtschaft March 2023 Ref. Ares(2023)2159800 - 24/03/2023 European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 1 | 10 Publishers Selbstregulierung Informationswirtschaft e.V. Großbeerenstraße 88 10963 BERLIN https://sriw.de [email protected] Associations‘ Register at: Amtsgericht Berlin Charlottenburg Register Number: VR 30983 B VAT: DE301407624 Deutsche Bank AG IBAN: DE33 1007 0000 0550 0590 00 Managing Director Frank Ingenrieth Chair of the Board Dr.
Bank AG IBAN: DE33 1007 0000 0550 0590 00 Managing Director Frank Ingenrieth Chair of the Board Dr. Claus-Dieter Ulmer SCOPE Europe srl Rue de la Science 14 1040 BRUSSELS https://scope-europe.eu [email protected] Company Register: 0671.468.741 VAT: BE 0671.468.741 ING Belgium IBAN BE14 3631 6553 4883 SWIFT / BIC: BBRUBEBB Managing Director Gabriela Mercuri European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 2 | 10 Table of Contents 1 Key Messages ........................................................................................................................ 3 1.1 It is strongly recommended to extend the understanding of enforcement by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission.
…by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission. 3 1.2 It is strongly recommended to review the procedural requirements in receiving a Code of Conduct’s approval and a Monitoring Body’s accreditation. .................................................................................... 3 1.3 In regards of third country transfers, a general validity by implementing act is required. It is strongly recommended to ensure that procedural efforts will be streamlined preventing any unreasonable delays in operationalizing such projects. ................................................................................................. 3 2 About the Authors (Short) .......................................................................................................
Authors (Short) ....................................................................................................... 4 3 Introduction ........................................................................................................................... 5 4 Complementary enforcement tools .......................................................................................... 5 4.1 Sector-Specific Particularization; collecting good and widely adopted practises .................................. 5 4.2 Inherent enforcement and remediation next to authoritative actions ................................................... 6 4.2.1 General Oversight ............................................................................................................................
........................................................................................................................ 6 4.2.2 Additional Oversight and Complaint Channel ................................................................................. 6 4.2.3 Enabling focus of resources and continuous expert’s exchange .................................................. 7 5 Streamlining of procedures under Article 40 and 41 GDPR ........................................................ 7 5.1 Competent data protection authorities for transnational Codes of Conduct, streamline of procedural elements .................................................................................................................................................... 7 5.2 Periods of authoritative actions and potentially prohibitive administrative fees ...................................
…of authoritative actions and potentially prohibitive administrative fees ................................... 8 5.2.1 Periods of processing requests ....................................................................................................... 8 5.2.2 Potentially prohibitive administrative fees ...................................................................................... 8 5.3 Accreditation requirements for Monitoring Bodies .................................................................................. 9 5.4 General validity mechanism for Codes of Conduct as tools for transfers ..............................................
…validity mechanism for Codes of Conduct as tools for transfers .............................................. 9 European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 3 | 10 1 Key Messages 1.1 It is strongly recommended to extend the understanding of enforcement by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission. ■ Codes of Conduct strongly support harmonization across Europe, by allowing for particulariz- ing ambiguous interpretations in sector-specific manners. ■ The enforcement of Codes of Conduct complements the public actions via data protection supervisory authorities and may significantly increase GDPR compliant yet practical imple- mentations.
…data protection supervisory authorities and may significantly increase GDPR compliant yet practical imple- mentations. ■ Compulsory oversight by independent Monitoring Bodies allows for additional robust enforce- ment. ■ Required continuous communication between Monitoring Bodies and data protection super- visory authorities may establish exchange of first-hand experiences, fostering consistent, ro- bust yet practical application of the law. 1.2 It is strongly recommended to review the procedural requirements in receiving a Code of Conduct’s approval and a Monitoring Body’s accreditation. ■ Generally, the legal framework and EDPB’s guidelines are considered suitable, if applied con- sistently.
■ Generally, the legal framework and EDPB’s guidelines are considered suitable, if applied con- sistently. ■ Specifically for transnational Codes of Conduct, harmonized interpretation is appreciated, be- cause projects suffer delays, e.g., by means of consistently and mutually determining the com- petent data protection supervisory authorities. ■ Periods as indicated by GDPR are not yet met in practice. So, it is recommended to adapt such periods to more realistic timelines and to clarify that in case data protection supervisory authorities cannot unanimously determine undisputable conflicts with GDPR, Codes of Con- duct shall be deemed in accordance with GDPR. ■ It is recommended to limit deviations in regards of the accreditation criteria for Monitoring Bodies to the minimum needed, e.g., by different administrative member state laws.
…criteria for Monitoring Bodies to the minimum needed, e.g., by different administrative member state laws. Any ma- terial deviation creates unnecessary obstacles to Monitoring Bodies, which seek to provide their services in several member states, limiting the scalability of their services, which is a key element in ensuring that adherence to Codes of Conduct remains accessible to micro, small and medium sized enterprises. 1.3 In regards of third country transfers, a general validity by implementing act is required. It is strongly recommended to ensure that procedural efforts will be streamlined pre- venting any unreasonable delays in operationalizing such projects. ■ Safeguarding third country transfers is one of the key elements subject to legal, political and operational discussions.
…third country transfers is one of the key elements subject to legal, political and operational discussions. ■ Codes of Conduct may act as a safeguard provide that, next to the formalities to be met for transnational Codes of Conduct in any case, general validity will be granted. ■ Considering the procedural steps of deciding on an implementing act, it is strongly recom- mended to allow for a material assessment by the European Commission and the EDPB in parallel. European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 4 | 10 2 About the Authors (Short) Selbstregulierung Informationswirtschaft e.V. (SRIW) is a non-profit association supporting the self-regulation of the information economy.
…e.V. (SRIW) is a non-profit association supporting the self-regulation of the information economy. It acts as a think tank to discuss and debate key issues in digital policy and provides an umbrella organisation supporting credible and effective self- and co-regulation of the information economy. SCOPE Europe srl (SCOPE Europe) is a subsidiary of SRIW. Located in Brussels, it continues and complement the portfolio of SRIW in Europe. SCOPE Europe gathered expertise in levelling industry and data subject needs and interests to credible but also rigorous provisions and controls. SCOPE Europe has been the first accredited Monitoring Body under the European General Data Protection Regulation (GDPR) since May 2021 related to a transnational Code of Conduct, i.e., EU Data Protection Code of Conduct for Cloud Service Providers.
37 → 12
Report on the General Data Protection Regulation Comments and Responses by Selbstregulierung Informationswirtschaft Call for Evidence by the European Commission February 2024 Ref. Ares(2024)976051 - 08/02/2024 Report on the General Data Protection Regulation 1 | 38 Herausgeber Selbstregulierung Informationswirtschaft e.V. Großbeerenstraße 88 10963 Berlin https://sriw.de +49 (0)30 30878099-0 [email protected] Amtsgericht Berlin Charlottenburg Registernummer: VR 30983 B USt-Nummer: DE301407624 Deutsche Bank AG IBAN: DE33 1007 0000 0550 0590 00 Vorstandsvorsitz Dr. Oliver Draf Geschäftsführer Frank Ingenrieth Report on the General Data Protection Regulation 2 | 38 Table of Contents 1. Executive Summary ................................................................................................................................................. 4 1.1.
…4 1.1. General Remarks and Harmonization of GDPR ............................................................................................................... 4 1.2. Codes of Conduct and GDPR Compliance ....................................................................................................................... 4 1.3. Approval of Codes of Conduct .......................................................................................................................................... 5 1.4. Monitoring Bodies and Accreditation ............................................................................................................................... 5 1.5. International Data Transfers ............................................................................................................................................. 6 1.6.
…6 1.6. Cross-Regulatory Compliance ........................................................................................................................................... 6 1.7. Data Subject Rights .......................................................................................................................................................... 6 1.8. Impact on mSME ............................................................................................................................................................... 6 1.9. Impact on Research and Development ............................................................................................................................ 7 2. Introduction .............................................................................................................................................................. 8
…8 3. About the authors .................................................................................................................................................... 9 4. Question 2.a General Comments – What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? ...................................................................................................................................................................... 11 5. Question 3.a Exercise of data subject rights – From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g.
…information on the compliance with the data subject rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). ........................................................................................................................................................ 13 5.1. Question 3.a.1 Exercise of data subject rights – Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) ........................................................................................................................... 13 5.1.1. Codes of Conduct as means to particularize interpretation and practical implementation ....................................................... 13 5.1.2.
…interpretation and practical implementation ....................................................... 13 5.1.2. Elements of ambiguity which should either be clarified within GDPR or amplified as suitable and legitimate approaches if enclosed within Codes of Conduct .................................................................................................................................................................. 14 5.2. Question 3.a.2 Exercise of data subject rights – Right to object (Article 21) .............................................................. 16
…of data subject rights – Right to object (Article 21) .............................................................. 16 6. Question 4.a to c Application of the GDPR to SMEs – What are the lessons learned from the application of the GDPR to SMEs? Have the guidance and tools provided by data protection authorities and the EDPB in recent years assisted SMEs in their application of the GDPR (see also the EDPB data protection guide for small business)? What additional tools would be helpful to assist SMEs in their application of the GDPR? ............ 18 7. Question 5.a to c Experience with Data Protection Authorities (DPAs) – What is your experience in obtaining advice from DPAs? How are the guidelines adopted so far by the EDPB supporting the practical application of the GDPR? Are you aware of guidelines issued by national DPAs supplementing or conflicting with EDPB guidelines?
…of the GDPR? Are you aware of guidelines issued by national DPAs supplementing or conflicting with EDPB guidelines? (please explain) ...................................................................................................................... 18 7.1. Establishing Guidelines and more effective stakeholder involvement......................................................................... 18 7.2. Considering Codes of Conduct as effective alternative to guidelines .......................................................................... 18 7.3. Experience with Guidelines in the sphere of Article 40 and Article 41 ........................................................................ 19 7.3.1.
…sphere of Article 40 and Article 41 ........................................................................ 19 7.3.1. General Findings ............................................................................................................................................................................ 19 7.3.2. Article 40 ........................................................................................................................................................................................ 20 7.3.3. Article 41 ........................................................................................................................................................................................ 21
…21 8. Question 6.b Experience with accountability and risk-based approach – What is your experience with the scalability of obligations (e.g., appropriate technical and organisational measures to ensure the security of processing, Data Protection Impact Assessment for high risks, etc.)? .................................................................. 22 Report on the General Data Protection Regulation 3 | 38
…22 Report on the General Data Protection Regulation 3 | 38 9. Question 7.a and b Controller / processor relationship (SCC) – Have you made use of Standard Contractual Clauses adopted by the Commission on controller/processor relationship? If yes, please provide feedback on the Standard Contractual Clauses? ...................................................................................................... 22 9.1. Streamlining Terminology and Scope of SCC vs SDPC .................................................................................................. 22 9.2. Remaining uncertainty due to annexes of SCC ............................................................................................................. 23 9.3. Empasis on multitude of suitable safeguards ............................................................................................................... 23
............................................................................................................... 23 10. Question 8.b International transfers – For controllers and processors: Are you using other tools for international data transfers (e.g., Binding Corporate Rules, tailor-made contractual clauses, derogations)? If yes, what is your experience with using these tools? Are there any countries, regional organisations, etc. with which the Commission should work in your view to facilitate safe data flows? ................................................... 24 10.1. General Remarks ............................................................................................................................................................ 24 10.2. Details on different requirements for Codes of Conduct and Certifications…
157 → 12