GDV · Trade and business associations · DE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 74 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
Seite 1 von 18 QUESTIONS TO GDPR MULTISTAKEHODLER EXPERT GROUP FOR COMMISSION 2024 REPORT ON THE APPLICATION OF THE GDPR Answers of the German Insurance Association (GDV) QUESTIONS 1. General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? The German insurance industry welcomes the opportunity to provide input to the European Commission for the evaluation of the General Data Protection Regulation (GDPR). Insurance companies have always been handling personal data in a responsible way. The German Insurance Association already had a Code of Conduct approved by the data protection authorities under the German Federal Data Protection Act, according to which numerous requirements for data processing created by the GDPR already applied.
Data Protection Act, according to which numerous requirements for data processing created by the GDPR already applied. Insurers started implementing the GDPR at an early stage and did it thoroughly. Since the General Data Protection Regulation (GDPR) came into force, data processing in companies has changed massively. Processes are becoming more and more digitalized. The EU Commission has recognized the importance of data for the competitiveness of the European economy and has initiated numerous legislative projects to improve data exchange, such as the Data Act, the European Health Data Space and the Financial Data Access Regulation. Most of these new laws are supposed to leave the GDPR unaffected. However, this leads to major challenges in the application of these laws.
…are supposed to leave the GDPR unaffected. However, this leads to major challenges in the application of these laws. Further on, the EDPB's guidelines often give the provisions of the GDPR a much narrower understanding, which ultimately becomes an obstacle to digitalization due to the interpretation of the national data protection authorities. A uniform European understanding of the GDPR, operational guidance and recommendations that guarantee compliance while of practical nature would be very useful. In light of the foregoing, the evaluation should take into account the following points: • The prohibition of fully automated case-by-case decisions (Art. 22 GDPR) with its too narrow exceptions no longer does justice to digitalization in mass business – such as that of insurers. It should be replaced by rules on transparency and verifiability.
…in mass business – such as that of insurers. It should be replaced by rules on transparency and verifiability. At the very least, the restrictive interpretation of the exceptions by data protection authorities should be abandoned and further exceptions should be created for the settlement of third-party claims. • With regard to the transfer of data to third countries (Art. 44 et seq. GDPR), it should be possible to take technical and organizational measures on a risk-based basis. • The requirements for binding corporate rules (BCRs) and consents to data transfers to third countries should be limited to what is required by law. • There is considerable legal uncertainty as to when data is sufficiently anonymized, especially since the EDPB has not yet issued the guidance announced in this regard. Ref.
…is sufficiently anonymized, especially since the EDPB has not yet issued the guidance announced in this regard. Ref. Ares(2024)966572 - 08/02/2024 Seite 2 von 18 The requirements for the anonymization of personal data must be defined and must be clear and easy to comply with. • There needs to be a clear legal basis for the use of personal data for the development and testing of IT applications, products, systems and analytical models. • For the processing of health data in the insurance sector exist individual regulations in many member states that are not coordinated with each other. A Europe-wide uniform legal basis would increase legal certainty and create a level playing field for insurers and reinsurers in Europe. 2. Exercise of data subject rights a.
…certainty and create a level playing field for insurers and reinsurers in Europe. 2. Exercise of data subject rights a. From the individuals’ perspective: please provide information on the exercise of the data subject rights listed below, including on possible challenges (e.g. delays in controllers/processors reply, clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.). From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). Requests of data subjects are mainly concerned with the access to data.
…identification of data subjects, etc.). Requests of data subjects are mainly concerned with the access to data. The biggest challenge in this area has been mapping the “life cycle” and the location of the personal data in different systems and business processes and identifying data processors to whom the data was transferred. Meeting the deadline for responding to data subjects’ requests is also challenging for the following reasons: • the number of requests received has increased, • sometimes the complexity of the request makes it challenging to meet the deadline, • the consolidation of all data that need to be provided in case of right to access requests can be time-consuming, • consequently, more human resources need to be allocated for responding to such requests.
…can be time-consuming, • consequently, more human resources need to be allocated for responding to such requests. • Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) Information and access rights are important instruments for enforcing data protection. However, high bureaucratic requirements have the opposite effect. The application of the GDPR showed early on that extensive information obligations under Art. 13, 14 GDPR do not meet the needs of business partners and lead to unnecessary burdens for data subjects and companies. Examples: → In business communication and business correspondence, business partners and their employees do not expect any data protection information.
…and business correspondence, business partners and their employees do not expect any data protection information. Seite 3 von 18 → During the initial telephone contact with customers and claimants, the "reading out" of the data protection information and even the notice are usually perceived as an annoying delay. The layered approach introduced by the EDPB in the Transparency Guidelines under Regulation 2016/679 (WP 260 rev.01, para. 35f) provides only a slight relief, as the information to be provided at the first level is still extensive. Proposals of the German insurance industry: → To avoid unnecessary bureaucracy and the flooding of data subjects with information, the information provided for in Art. 13, 14 GDPR should only be kept electronically for business partners and their employees in the B2B sector and (should) only be transmitted on request.
…electronically for business partners and their employees in the B2B sector and (should) only be transmitted on request. → In other business transactions, the necessity, manner, scope and timing of proactive provision of information should be based on the context of the data processing with a risk-based approach. If no information is typically expected under the circumstances, the information should not be proactive, but should also be kept electronically and should only have to be sent on request. • Access to data (Article 15) The application of the right of access has increased significantly since the GDPR came into force. For insurers, providing information about all stored data involves a vast amount of time and effort because extensive documents have to be reviewed. Automated extraction of personal data from contract documents and claims files is not yet technically possible.
Automated extraction of personal data from contract documents and claims files is not yet technically possible. In most companies, there are several people involved in fulfilling the information requirements on a daily basis. It is becoming more common for dissatisfied customers with the insurer's performance to request information about all stored data in order to harass or pressure the insurer into giving in to a legal dispute. Former employees who are in a dispute with their employers often ask for all e-mails they wrote during the time of their employment and all notices in which they are mentioned. In addition, requests in the context of litigation on other matters cause significant additional expense for controllers. A first decision by the ECJ in case C 307/22 was pronounced as of October 26, 2023. The ruling shows that the interpretation of the provisions in Art.
…case C 307/22 was pronounced as of October 26, 2023. The ruling shows that the interpretation of the provisions in Art. 15 of the GDPR leads to very far-reaching decisions that result in significant burdens for data controllers. The EDPB is also of the opinion that the right to access is not excessive if it is intended to enforce further claims against the controllers. Companies have also observed that lawyers representing natural persons in the context of a lawsuit against insurance companies, or companies that want to evaluate customer data, request information about all data stored about the person. Often, the persons represented are not even aware of this.
82 → 12
Comment of the German Insurance Association (GDV) on the evaluation of the General Data Protection Regulation (EU) 2016/679 (GDPR) Gesamtverband der Deutschen Versicherungswirtschaft e. V. German Insurance Association Wilhelmstraße 43 / 43 G, 10117 Berlin P.O. Box 08 02 64, 10002 Berlin Phone: +49 30 2020-5290 Fax: +49 30 2020-6290 51, rue Montoyer B - 1000 Brussels Phone: +32 2 28247-30 Fax: +32 2 28247-39 ID Number 6437280268-55 Contact: Data Protection/ Fundamental Issues E-mail: [email protected] www.gdv.de Ref. Ares(2020)2284938 - 29/04/2020 Page 2 / 20 Executive Summary The upcoming evaluation of the General Data Protection Regulation (GDPR) should be used to identify inadequacies in data protec- tion law and to facilitate Europe’s transition to digitalisation.
…be used to identify inadequacies in data protec- tion law and to facilitate Europe’s transition to digitalisation. Even though changing the text of the Regulation might yet be too early, any provisions of the GDPR which apparently lead to excessive bu- reaucracy or impede progress should be identified in the near future. Harmonisation of data protection law across the EU would be desira- ble; however, national derogations should not be withdrawn prematurely. It should rather be reviewed whether the existing na- tional exemptions might be useful for the application of the GDPR and whether they can be integrated into the GDPR the next time the Regulation is being amended. The EU Commission should examine in detail the impacts of the GDPR on digitalisation and the resulting need for making amend- ments as soon as possible and propose respective amendments to the GDPR.
…and the resulting need for making amend- ments as soon as possible and propose respective amendments to the GDPR. The EU Commission should propose that any interpretations which are not covered by the GDPR are removed from the Guidelines of the European Data Protection Board (EDPB). It may also be bene- ficial to establish an expert panel composed of representatives from the industry, academia and research communities to assist the EDPB and consult the data protection authorities with regard to im- plementing practical provisions (see section 5, p.
…and consult the data protection authorities with regard to im- plementing practical provisions (see section 5, p. 19 et seq.) The German insurance industry has identified some weaknesses of the Regulation in the following areas, in particular: A clear legal basis for data processing in the insurance industry is missing, including an EU-wide regulation on when the processing of data con- cerning health which is necessary for insurance purposes shall be allowed (Art. 9 GDPR, see section 2.a), p. 5 et seq.) a clear legal basis for the processing of personal data relat- ing to criminal offences in the insurance business (Art. 10 GDPR, see section 2.b), p. 6 et seq.) clear rules on joint controllership (Art. 26 GDPR, see sec- tion 2.c), p. 7 et seq.) legal certainty with regard to the transfer of data to third countries (Art. 46 GDPR, see section 2.d), p. 8 et seq.).
…certainty with regard to the transfer of data to third countries (Art. 46 GDPR, see section 2.d), p. 8 et seq.). Page 3 / 20 The EU Commission should examine in detail the impacts of the GDPR on digitalisation as soon as possible. The following is required: practical provisions on fully automated decision-making and profiling. Automated decision-making that does not rely on the use of self-learning systems should be exempted from a general ban in this context (Art. 22 GDPR, see section 3.a), p. 9 et seq.). with regard to big data, AI and blockchain solutions, facilitat- ing the processing of pseudonymised data (see section 3.b), p. 13), examining the application of the data protection principles (Art. 5 GDPR, see section 3.c) and d), p. 13 et seq.), and implementing practical solutions for data storage (Art. 17 GDPR, see section 3.e), p. 14 et seq.).
…p. 13 et seq.), and implementing practical solutions for data storage (Art. 17 GDPR, see section 3.e), p. 14 et seq.). with regard to cloud solutions, facilitating the monitoring of processors (Art. 28 GDPR, see section 3.f), p. 15) The evaluation of the GDPR should be used to eliminate unneces- sary bureaucracy. The following is required: limitation of the obligation to provide information and the right of access to a reasonable level based on the context (Art. 13 to 15 GDPR, see section 4.a) and b), p. 15 et seq.) risk-based limitation of the obligation to provide notification of data breaches (Art. 33 GDPR, see section 4.c) p. 17) promoting codes of conduct through practical, unbureau- cratic provisions, in particular by not requiring the establish- ment of a monitoring body (Art. 40 GDPR, see section 4.d), p. 17 et seq.) Page 4 / 20 1.
…not requiring the establish- ment of a monitoring body (Art. 40 GDPR, see section 4.d), p. 17 et seq.) Page 4 / 20 1. Preliminary remarks Pursuant to Article 97 of the GDPR, the EU Commission shall submit a report on the evaluation and review of Regulation (EU) 2016/679 (GDPR) to the European Parliament and to the Council by 25 May 2020. The EU General Data Protection Regulation has only recently been im- plemented. Many companies have invested substantial financial and hu- man resources in implementing the new law. We therefore agree with the EU Commission that it is necessary to gain further experience with the application of the GDPR. Nonetheless, the evaluation of the General Data Protection Regulation (GDPR) should be used as an occasion to identify inadequacies in da- ta protection law and to facilitate Europe’s transition to digitalisa- tion.
…occasion to identify inadequacies in da- ta protection law and to facilitate Europe’s transition to digitalisa- tion. Any provisions which apparently lead to excessive bureaucracy or impede progress should be identified in the near future. The GDPR has been drafted in a technology-neutral way. Numerous de- velopments which are emerging today, however, have not been on the radar of the European legislator then. Since the date the GDPR has come into effect, an increasing number of business processes are carried out digitally. Big data solutions, the Internet of Things, AI applications, blockchain and cloud solutions are used in almost all industries. The EU Commission should examine in detail the impacts of the GDPR on digitalisation and the resulting need for making amendments as soon as possible to promote innovation and technological development across Europe.
…need for making amendments as soon as possible to promote innovation and technological development across Europe. In principle, harmonising data protection law across Europe seems rea- sonable. A very cautious approach, however, should be taken when it comes to withdrawing national derogations. For instance, the German legislator has used the opening clauses of the Regulation in a very pru- dent manner. National law specifies the circumstances under which the processing of certain data shall be allowed as well as exemptions, which makes the application of the GDPR much easier in Germany. There is probably a similar need for specification in other EU Member States as well. It should therefore be examined whether national provisions can be integrated into the GDPR. The issues which, in the view of the German insurance industry, should be reviewed in the near future are listed below.
The issues which, in the view of the German insurance industry, should be reviewed in the near future are listed below. As a result, amendments Page 5 / 20 might have to be made on the Regulation level. In many cases, however, even an adjustment of the Guidelines of the European Data Protection Board would be helpful. 2. Creating legal certainty for the insurance business In principle, the legal bases of the GDPR seem appropriate for carrying out insurance business. Increased legal certainty, however, is required in the following areas. a) Clear legal basis for the processing of data concerning health for the purpose of entering into and performance of insurance con- tracts (Art. 9 GDPR) The processing of data concerning health for insurance purposes is based on very different legal bases in the EU Member States.
…of data concerning health for insurance purposes is based on very different legal bases in the EU Member States. Some countries have national provisions in place which specify the circumstances under which the processing of health-related data for the purpose of entering into and performance of an insurance contract shall be allowed. In other coun- tries, at least with regard to the performance of contracts, Article 9(2)(f) GDPR is used as legal basis. There are also countries in which the pro- cessing solely relies on consent. The different legal frameworks signifi- cantly impede cross-border data transfer, in particular in the reinsurance business.
…legal frameworks signifi- cantly impede cross-border data transfer, in particular in the reinsurance business. Example: A direct insurer located in a Member State which has a national legal provision in place that specifies the circumstances under which the processing of health-related data shall be allowed does not require the consent of the data subject to collect and process data concerning health for a life insurance. If a reinsurer working for the direct insurer is located in a Member State which does not have a respective national provision in place, however, it is not al- lowed to accept or process the data without the consent of the da- ta subject. The reinsurer, however, does not have any direct con- tact with the data subject, which makes it difficult to obtain the consent. Furthermore, in these cases, many data subjects are usually not willing to give their consent.
52 → 12