Sky Group

SKY · Companies & groups · GB

Kategorija
Companies & groups
Būstinė
Isleworth, Middlesex GB
Registruota
2012-03-01
Deklaruotos metinės išlaidos
400 000–499 999 € (pačios deklaruota)
Svetainė
https://www.skygroup.sky/
Skaidrumo registras
62536168216-12 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

201512020420214202332025720262

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 21 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2026-02-25Mobility and Transport…eSAF Group wished to present their policy priorities for eSAF industry development
2026-02-25Mobility and Transport…eSAF Group wished to present their policy priorities for eSAF industry development
2025-09-04Cabinet of Executive Vice-President Henna VirkkunenRoundtable with representatives of the media industry
2025-09-04Cabinet of Executive Vice-President Henna VirkkunenRoundtable with representatives of the media industry
2025-05-22Communications Networks, Content and TechnologyUpcoming Digital Networks Act
2025-02-18Cabinet of Executive Vice-President Stéphane SéjournéGeo-blocking AI Piracy
2025-02-18Cabinet of Executive Vice-President Stéphane SéjournéGeo-blocking AI Piracy
2025-01-24Cabinet of Commissioner Michael McGrathExchange of views on media related policies, including the European Media Freedom Act (EMFA) and consumer protection
2025-01-24Cabinet of Commissioner Michael McGrathExchange of views on media related policies, including the European Media Freedom Act (EMFA) and consumer protection
2023-05-02Cabinet of Commissioner Thierry BretonCopyright
2023-04-25Cabinet of Commissioner Mairead McguinnessIntroductory Meeting
2023-01-18Cabinet of Executive Vice-President Margrethe VestagerTelecommunication
2021-10-28Cabinet of Commissioner Thierry BretonItalian situation regarding co-investment pursuant to EECC
2021-10-28Cabinet of Commissioner Thierry BretonItalian situation regarding co-investment pursuant to EECC
2021-10-28Cabinet of Commissioner Thierry BretonItalian situation regarding co-investment pursuant to EECC
2021-10-28Cabinet of Commissioner Thierry BretonItalian situation regarding co-investment pursuant to EECC
2020-02-05Cabinet of President Ursula von der LeyenAudiovisual media
2020-02-04Cabinet of Commissioner Thierry BretonExchange on audio-visual and media policy
2020-02-04Cabinet of Executive Vice-President Margrethe VestagerDigital policy
2020-02-04Cabinet of Executive Vice-President Frans TimmermansSustainability, Plastics and the Green Deal
2015-05-12Communications Networks, Content and TechnologyDigital Single Market

Ką pateikė viešoms konsultacijoms

2020-04-29 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Please see attached PDF document for our response. Thank you

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 2 p.

We are writing in response to your public consultation on the application of the GDPR as regards international transfers of personal data to third countries and the cooperation and consistency mechanism between national data protection authorities. With 24 million customers across seven countries, Sky is Europe’s leading media and entertainment company and is proud to be part of the Comcast group. Our 32,000 employees help connect our customers to the very best entertainment, sports, news, arts and to our own local, original content. We would like to take this opportunity to highlight a number of challenges and opportunities for improvement in relation to the existing law and guidance on international transfers of personal data: 1. We consider that the Standard Contractual Clauses (SCCs) should be revised, updated and simplified (e.g.

…data: 1. We consider that the Standard Contractual Clauses (SCCs) should be revised, updated and simplified (e.g. specific formal requirements removed) to reflect the changes in data protection law and practice since their issue, and that alternative options for international transfers should be explored and made available to organisations. We have set out our key points on this topic below: a. The most notable change since the publication of the SCCs is clearly the introduction of the GDPR, the requirements of which often overlap and conflict with language contained in the SCCs. Although there are a number of examples, this is best illustrated by the controller-processor SCCs, which contain an imperfect replica of many of the provisions which organisations are already required to have in place today under Article 28 GDPR.

…of many of the provisions which organisations are already required to have in place today under Article 28 GDPR. As neither an Article 28-compliant contract nor the controller-processor SCCs alone are sufficient for an organisation to discharge its obligations for a transfer to a non-EEA processor, the result will typically be a set of data protection clauses which annex the SCCs, creating the potential for confusion and inconsistencies within the agreement about the provisions and standard of protections which apply. We would highlight that this unsatisfactory outcome is nevertheless often the best currently available; the frequent alternative is that an organisation attempts to produce its own hybrid Article 28 / SCC agreement, often with a resulting document meeting neither set of requirements.

…produce its own hybrid Article 28 / SCC agreement, often with a resulting document meeting neither set of requirements. Furthermore, if the SCCs were recast as a set of principles or minimum standards (consistent with Article 28) this would help avoid contractual duplication and allow parties to cover the necessary protections within a broader commercial contract. b. The years since the SCCs were last reviewed have seen a vast increase in cases where an EEA processor transfers data to a non-EEA sub-processor. The obvious options available to legitimise such a transfer, such as entering the sub-processor’s name onto SCCs between the (possibly both EEA-based) controller and processor, are unwieldy, administratively burdensome, and do not provide sufficient certainty and transparency about the protections which are in place.

…burdensome, and do not provide sufficient certainty and transparency about the protections which are in place. As such, we would ask that the Commission considers issuing EU processor – non-EU processor SCCs. c. As the Commission is undoubtedly aware, there is a tremendous amount of uncertainty amongst EU and global organisations about whether the SCCs will continue to remain valid following the challenges posed to their existence by various legal actions across Europe. We would urge the EDPB to publish a statement setting out contingencies and a plan of action in the event that the SCCs are invalidated or deemed to provide an insufficient level of protection. Ref. Ares(2020)2291765 - 29/04/2020 2.

SCCs are invalidated or deemed to provide an insufficient level of protection. Ref. Ares(2020)2291765 - 29/04/2020 2. The UK ICO’s guidance on international transfers1 takes an organisation-level, rather than a national-level, approach to what constitutes a “restricted transfer” requiring appropriate safeguards under the GDPR. Under the ICO’s guidance, an international transfer is “restricted” only if “you are sending personal data, or making it accessible, to a receiver to which the GDPR does not apply”. We understand the latter part of this sentence to refer to whether an organisation is caught by either the establishment or targeting criteria under Article 3 GDPR. As such, this guidance means that no safeguards would be required where an EEA organisation is transferring data to a non-EEA established organisation which is caught by the targeting criterion in Article 3(2) GDPR.

…to a non-EEA established organisation which is caught by the targeting criterion in Article 3(2) GDPR. This approach makes sense in light of the extra-territorial scope of the GDPR, as it recognises that the personal data involved never strays outside the protections of the GDPR and additional safeguards would therefore be duplicative and unnecessary. However, this contrasts starkly with the approach mandated by Article 44 GDPR, which instead is concerned with transfers to a ‘third country’. As such, compliance with Article 44 GDPR requires the implementation of appropriate safeguards where a country’s data protection regime is not deemed adequate, even where the non-EEA organisation receiving the data is already subject to (and compliant with) the GDPR.

…adequate, even where the non-EEA organisation receiving the data is already subject to (and compliant with) the GDPR. We would ask the Commission to publish guidance clarifying that the approach endorsed by the UK ICO on this point is acceptable, as this is a significant point of confusion and confirming this interpretation would liberalise international transfers in circumstances where the extra-territorial scope of the GDPR meant that the data and the data subject’s rights are already adequately protected. This would recognise the steps taken by non- EEA organisations to comply with the GDPR and significantly reduce the administrative burden on organisations (both EEA-based and otherwise) who have taken a proactive role to GDPR compliance, while maintaining the need for adequate safeguards in circumstances where the GDPR’s protections do not already exist. 3.

…maintaining the need for adequate safeguards in circumstances where the GDPR’s protections do not already exist. 3. We would appreciate clarity on how an international transfer can be legitimised in scenarios where an EEA-based processor is transferring personal data to a non-EEA-based controller. Page 12 of the EDPB’s Guidelines 3/2018 on the territorial scope of the GDPR make clear that a processor in such a scenario will still be within the scope of the GDPR by virtue of Article 3(1) GDPR, and therefore subject to the prohibition on international transfers without appropriate safeguards in Article 44 GDPR.

…and therefore subject to the prohibition on international transfers without appropriate safeguards in Article 44 GDPR. As there are no “EEA processor to non-EEA controller” SCCs, there appears to be no readily available or “off the shelf” solution in circumstances where data is being transferred to a third country not subject to an adequacy decision or possessing its own bespoke transfer mechanism (e.g. Privacy Shield). Aside from the limited exceptions available under Article 49 GDPR, the only obvious option, therefore, would be for an organisation to submit a set of data protection clauses to a supervisory authority for approval, which would impose such a significant administrative burden on both supervisory authorities and organisations as to be unworkable.

…impose such a significant administrative burden on both supervisory authorities and organisations as to be unworkable. Therefore, we would welcome meaningful guidance or additional transfer mechanisms addressing the transfer of personal data in these circumstances. We would highlight that this point would become a critical compliance gap without an easy solution for many organisations across the UK were the Brexit transition period to expire before agreement on adequacy is reached. 1 https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation- gdpr/international-transfers/

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Media Freedom Act, Digital Networks Act, Anti-Piracy, Digital Fairness Act, Democracy Shield, DSA, DMA, Copyright, Audiovisual Media, Electronic Communications, AI, E-Commerce, IPR Enforcement, Culture, Competition, Consumer rights, Privacy, Sustainability.