AMICE · Trade and business associations · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 10 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2025-03-04 | Cabinet of Commissioner Maria Luís Albuquerque | Exchange with AMICE on regulatory developments |
| 2025-03-04 | Cabinet of Commissioner Maria Luís Albuquerque | Exchange with AMICE on regulatory developments |
| 2020-11-30 | Cabinet of Commissioner Mairead Mcguinness | Pre-Recorded closing address. Insurance regulation, sustainability and risk management. |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
| 2020-05-28 | Cabinet of Executive Vice-President Valdis Dombrovskis | COVID-19 relief measures |
Association of Mutual Insurers and Insurance Cooperatives in Europe aisbl | www.amice-eu.org Rue du Trône 98/14 | B-1050 Brussels | T : +32 2 503 38 78 | [email protected] | @AMICE_Mutuals February 2024 AMICE contribution to the Commission report on the evaluation of the General Data Protection Regulation (GDPR) Preliminary remarks AMICE, the Association of Mutual Insurers and Insurance Cooperatives in Europe, welcomes the opportunity to provide input to the European Commission for the next evaluation of the General Data Protection Regulation (EU) 2016/679 (hereinafter, "GDPR") foreseen in 2024. As a preliminary remark, AMICE aims to uphold the GDPR as an important standard for privacy protection.
…in 2024. As a preliminary remark, AMICE aims to uphold the GDPR as an important standard for privacy protection. The GDPR has delivered a fundamental change in how data controllers and data processors handle personal data and at the same time gave European citizens expansive rights as to how their data are collected, used and stored, increasing control over their personal information. Going forward, while Europe’s competitiveness will increasingly depend on the ability of companies to analyse and leverage data, and several new laws – such as the Data Act and the AI Act – become fully applicable, the GDPR will continue to represent one of the most important regulatory frameworks. For this reason, we think that it is of utmost importance to discuss and analyse the impact of GDPR and possible ways to improve it.
…we think that it is of utmost importance to discuss and analyse the impact of GDPR and possible ways to improve it. From a market perspective, any relevant regulation should be clear, and proportionate, and encourage a level playing field for competition. The financial sector, particularly the insurance industry, stands as one of the most data-intensive fields globally. Insurance companies collect and store an extensive array of personal and financial information about their clients. This data is crucial for underwriting risks, setting policy prices, and processing claims. Consequently, to safeguard customer data effectively and ensure compliance with the GDPR requirements, insurance companies have dedicated significant resources to the implementation of GDPR processes.
GDPR requirements, insurance companies have dedicated significant resources to the implementation of GDPR processes. However, the past five years have shown that data protection in Europe is a dynamic area and that the inherent complexity of such a high-level and horizontal regulation has sometimes triggered unintended consequences in specific sectors. Therefore, in its evaluation the European Commission should carefully review the extent to which the application of the GDPR is indirectly hampering the use of certain technologies and – in the interests of technological neutrality – deliver solutions for how innovation can truly thrive. Our data economy must be able to provide protection for our citizens while still permitting businesses to realise the full potential for making great technological forward leaps.
…citizens while still permitting businesses to realise the full potential for making great technological forward leaps. As the digital landscape evolves, so too should the regulatory framework guiding it, ensuring it remains adaptable and responsive to the needs of all stakeholders involved. This includes fostering an environment where startups and established companies alike can innovate responsibly, without being unduly constrained by compliance burdens that may stifle growth or deter the adoption of new technologies. Such an environment would not only support economic growth and competitiveness but also enhance consumer trust and security in the digital age.
…not only support economic growth and competitiveness but also enhance consumer trust and security in the digital age. The Commission's role in facilitating dialogue between technology leaders, policymakers, and consumer advocates is crucial in shaping policies that are both forward-thinking and grounded in the reality of technological capabilities and societal expectations. Ref. Ares(2024)974884 - 08/02/2024 2 Considering the above, AMICE calls on the European Commission to address the following issues when evaluating the GDPR: I. The need to add a specific legal basis at EU level for the processing of special categories of data (hereinafter, “special category data”, as identified by Article 9 of GDPR) for the conclusion and performance of insurance contracts. II. The impact of the GDPR on AI and more broadly on innovation. I.
…conclusion and performance of insurance contracts. II. The impact of the GDPR on AI and more broadly on innovation. I. The need for a legal basis for health data processing for the performance of a contract AMICE recognizes that the intent of Article 9 of GDPR was to grant data subjects with greater protection in relation to their special category data, by listing the possible legal basis for the relevant data processing and by enabling data subjects to autonomously manage their special categories of personal data on the basis of their consent. However, with specific respect to the (re)insurance sector, we would like to point out that this approach creates a potential conflict between the requirement of consent, on the one hand, and contract law principles, on the other, according to which both parties are generally obliged to fulfill their respective duties in the form and time agreed.
…according to which both parties are generally obliged to fulfill their respective duties in the form and time agreed. Indeed, to perform (re)insurance contracts, (re)insurance companies acting as data controllers have to balance the need for consent to process health data during the claim settlement procedure with the general principle of fulfilling contractual obligations, which require the company to settle the claim. Thus doing, data controllers may incur a number of operational problems and compliance issues. Article 9(2)(a) of GDPR: assessing the genuine and free choice to give consent in the (re)insurance sector The GDPR prohibits the processing of special category data unless the data controller can rely on one of the exemptions listed under Article 9(2).
…of special category data unless the data controller can rely on one of the exemptions listed under Article 9(2). However, unlike Article 6 of GDPR, the conditions under Article 9 do not include the case for which the processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract. As a direct consequence, considering that none of the legal basis listed in Article 9(2) from (b) to (j) can legitimate the processing of special category data for (re)insurance companies, for a data processing to be lawful, (re)insurance companies acting as data controllers need to rely on another legal basis.
…a data processing to be lawful, (re)insurance companies acting as data controllers need to rely on another legal basis. According to the current formulation of Article 9(2) of GDPR, consent seems to represent the only lawful basis for special category data processing that is carried out by a (re)insurance company. Such an approach is endorsed by the European Data Protection Board (“EDPB”) in its “Guidelines 05/2020 on consent under Regulation 2016/679”, which explicitly states that: "Data controllers and Member States dealing with this situation should consider the specific exceptions in Article 9(2)(b) to (j). Should none of the exceptions (b) to (j) apply, obtaining explicit consent in accordance with the conditions for valid consent in the GDPR remains the only possible lawful exception for processing such data”.
…with the conditions for valid consent in the GDPR remains the only possible lawful exception for processing such data”. Given the above, the processing of special category data for the performance of a contract in the insurance sector is at odds with the GDPR consent requirements as outlined below: − consent is “[…] any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she signifies, by a statement or by a clear affirmative action, his or her agreement to the processing of personal data relating to him or her” (Article 4(11) GDPR); − “[...] consent should not be considered freely given if the data subject does not have a genuine or free choice or is unable to refuse or withdraw consent without detriment” (Recital 42); − "in assessing whether consent is freely given, the utmost account shall be taken of the fact that, inter alia, the…
…to the processing of personal data which is not necessary for the performance of that contract” (Article 7 (4)). At the same time, the processing of special category data based on consent can only be carried out with the application of the exception in Article 7(4) of GDPR, although in its Guidelines 5/2020 on consent the EDPB underlines that since the wording of Article 7(4) is not absolute, there could be a very limited number of cases where this conditionality would not render consent invalid. In the (re)insurance sector, the processing of special category data relating to the policyholders is essential in certain (re)insurance contracts and/or in specific phases of the contractual relationship to provide insurance-related services.
33 → 12