AFS · Trade and business associations · BE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 25 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
Deadline for submission: 8 February 2024 Introduction: In 2018, the General Data Protection Regulation (GDPR) became a compliance milestone for anyone who processes EU citizens’ personal data. While it has provided a harmonised standard for almost 500 million citizens, it has also been especially challenging for startups, who inherently have fewer resources than more established players. The GDPR is a response to the evolving landscape of digital economies and societies, addressing both their opportunities and challenges. This regulatory framework brought about a substantial transformation in the conceptualisation of privacy. It has not only standardised and streamlined rules but it also has empowered citizens with increased control over their data through the establishment of a comprehensive set of easily enforceable rights.
…with increased control over their data through the establishment of a comprehensive set of easily enforceable rights. Beyond specific provisions, the GDPR catalysed a cultural shift, embedding the conscientious handling of personal data as a fundamental aspect of business practices. Due to the 'Brussels effect,' the impact of the GDPR has extended to third countries that are adopting it as a model for crafting comparable legislation. In the last six years, the startup ecosystem has made strides to ensure they are compliant with the existing framework. Ensuring regulatory stability in this space is paramount for startups. Complying with existing rules: Almost 6 years after the entry into the application of the EU data protection framework, startups have dedicated large amounts of resources to catching up with the law.
…of the EU data protection framework, startups have dedicated large amounts of resources to catching up with the law. Despite daunting challenges for smaller players, such as complex, burdensome, and expensive regulatory requirements, entrepreneurs have dedicated time and money to ensuring their competitiveness in this space. Regulatory stability: According to a working paper from the University of Oxford, GDPR compliance has imposed substantial costs, especially for startups. The study shows the detrimental impact of the law on the startup ecosystem, as entrepreneurs startups have been facing reduced profits and lower sales since its implementation. Notably, small businesses in the information technology sector seem to bear a disproportionate burden, experiencing losses approximately double those of their larger counterparts.
…seem to bear a disproportionate burden, experiencing losses approximately double those of their larger counterparts. This is concerning given that innovation and competition, particularly from startups, are often expected to challenge established players. A paper from the Centre for Economic Policy Research (CEPR) emphasises that GDPR implementation has inadvertently raised entry barriers, fostering higher market concentration in web technologies. This consolidation has led to Ref. Ares(2024)913845 - 07/02/2024 reduced competition and, as corroborated by a survey conducted in 2022, contributed to the depletion of consumer surplus. For that reason, any reopening or review of GDPR will most likely create yet another legal and cost barrier for startups, who have already dedicated enormous amounts of resources to comply.
…yet another legal and cost barrier for startups, who have already dedicated enormous amounts of resources to comply. Regulatory stability is essential to create an environment that innovators can trust to create and disrupt existing trends. Given the regulatory avalanche of the last EU mandate, entrepreneurs are asking policymakers to provide a regulatory umbrella they can rely upon and build on. As the upcoming EU legislature should be about consolidating existing frameworks rather than creating new unnecessary ones, policymakers should choose regulatory stability over legislative tsunamis.
…rather than creating new unnecessary ones, policymakers should choose regulatory stability over legislative tsunamis. How to make the existing framework easier for entrepreneurs: Policymakers have a variety of tools that would support startups with the existing regulation implementation while safeguarding regulatory stability: ● Further harmonisation of the existing framework in the EU and beyond: Startups have global ambitions from day one, they shouldn’t have to scale up 27 times, much less 195 times. Ensuring common frameworks across borders should be policymakers’ first priority: startups should devote their resources to innovating, not legal compliance. Reducing the complexity and the cost of compliance by having a unified set of standards simplifies the legal landscape, allowing startup entrepreneurs expand their reach and focus on their core business activities.
…the legal landscape, allowing startup entrepreneurs expand their reach and focus on their core business activities. For the same reasons, having a clear point of contact is key for startups and their compliance. In this regard, the GDPR’s one-stop-shop principle ensures regulatory consistency and legal certainty for organisations operating across the EU. Any degradation of this principle would introduce inconsistency, making it more challenging for organisations to predict and meet their compliance obligations which might lead to a competitive disadvantage for Europe. ● Funding R&D initiatives for better data protection solutions: Facilitating innovation through the funding of research and development initiatives on data protection technologies is key for the startup ecosystem.
…the funding of research and development initiatives on data protection technologies is key for the startup ecosystem. As R&D projects can for instance lead to the creation of sophisticated risk assessment tools that help startups identify and mitigate potential risks to data security and privacy (risk assessments being a key component of GDPR compliance), they could also develop advanced encryption techniques, secure data storage solutions, and other AI-driven tools for monitoring and detecting potential breaches. ● Provide more guidance and clarity for innovators on their rights and responsibilities: More than established players, startups, and scale-ups need to be guided along their path for innovation to better understand their data protection rights and responsibilities.
…to be guided along their path for innovation to better understand their data protection rights and responsibilities. Considering their very limited resources, startup entrepreneurs often find themselves in a situation where they want to comply but have to decipher overly complex legalistic jargon before they can even start innovating. Helping these innovators comply with the GDPR has to be made easier by properly informing them about every step of the compliance process, with clear and understandable explanations. Also, generally raising awareness on the GDPR complexities would eventually not only spur ethical innovation, but it would also improve citizens' trust in EU privacy regulations.