American Express Corporation

Companies & groups · GB

Kategorija
Companies & groups
Būstinė
London GB
Registruota
2015-01-14
Deklaruotos metinės išlaidos
100 000–199 999 € (pačios deklaruota)
Svetainė
http://www.americanexpress.com
Skaidrumo registras
671547715580-60 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

202022023320252

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 7 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2025-09-17Financial Stability, Financial Services and Capital Markets UnionDevelopments in the EU financial services landscape
2025-04-22Cabinet of Executive Vice-President Henna VirkkunenExchange of views on online financial scams and online fraud
2023-03-28Cabinet of Commissioner Mairead McguinnessRound-Table on Digital Euro (with EVP Dombrovskis and DG FISMA)
2023-03-28Cabinet of Commissioner Mairead McguinnessRound-Table on Digital Euro (with EVP Dombrovskis and DG FISMA)
2023-03-28Cabinet of Commissioner Mairead McguinnessRound-Table on Digital Euro (with EVP Dombrovskis and DG FISMA)
2020-08-27Communications Networks, Content and TechnologyPatronage vouchers
2020-06-19Communications Networks, Content and TechnologyImpact of COVID-19 (virtual)

Ką pateikė viešoms konsultacijoms

2020-04-29 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
American Express is pleased to have the opportunity to provide comments for the upcoming European Commission report on the application of the General Data Protection Regulation (GDPR). American Express has welcomed the entry into force of the GDPR which has brought a necessary alignment between national data protection legislations across Europe and has overall increased the protection of our customers. Data protection and information security are long-standing priorities for American Express and our existing robust data protection program was enhanced to meet the additional requirements introduced by the GDPR. In the implementation of these new requirements, American Express has however…

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 6 p.

…1 American Express comments for the European Commission upcoming report on the application of the GDPR INTRODUCTION American Express is pleased to have the opportunity to provide comments for the upcoming European Commission report on the application of the General Data Protection Regulation (GDPR). American Express has welcomed the entry into force of the GDPR which has brought a necessary alignment between national data protection legislations across Europe and has overall increased the protection of our customers. Data protection and information security are long-standing priorities for American Express and our existing robust data protection program was enhanced to meet the additional requirements introduced by the GDPR. In the implementation of these new requirements, American Express has however faced some challenges.

…by the GDPR. In the implementation of these new requirements, American Express has however faced some challenges. Our comments will focus on (I) general issues in the application of the GDPR (II) the international transfer of personal data to third countries; and (III) the cooperation and consistency mechanism between national data protection authorities. I. GENERAL ISSUES IN THE APPLICATION OF THE GDPR Member states derogations and lack of harmonization American Express has welcomed the harmonization of the data protection framework brought by the GDPR across the EEA. As a global corporation, American Express has however sometimes experienced challenges in consistently implementing some aspects of the GDPR across the EEA due to the different approaches taken by the national legislators and local data protection authorities.

…the EEA due to the different approaches taken by the national legislators and local data protection authorities. The Regulation is enforced by dozens of national regulators who apply differing legal and cultural interpretations to key areas of the law and the broad leeway given to Member states to regulate certain areas has indeed generated some uncertainty. We have, for instance, noticed some divergences regarding: • The legal basis to process personal data, including attempts to limit the scope of legitimate interest and contractual necessity in favor of consent (e.g., the approach followed by the Italian data protection authority in favor of consent as the legal basis to be used for direct Ref.

…followed by the Italian data protection authority in favor of consent as the legal basis to be used for direct Ref. Ares(2020)2298498 - 29/04/2020 2 marketing activities or the approach taken by the Dutch data protection authority to deny the possibility to rely on legitimate interest for marketing activities); • Attitudes to “risk” and “high risk”, leading to differing guidance on DPIA and data breach notification; • Conditions for the processing of special categories of data, leading to conflicting guidance from national regulators (for example, on responding to the Covid-19 crisis). In practice, the above disparities lead to diverging assessments by market of common processes in our business, such as marketing practices, call recording and credit risk decisions.

…by market of common processes in our business, such as marketing practices, call recording and credit risk decisions. Data protection roles (data controller / data processor) A clear definition of the data protection roles is essential as such roles determine the parties’ responsibilities. Although defined by the GDPR and addressed by some data protection authorities’ guidance, the application of the concepts of “data controller” and “data processor” sometimes encounters practical difficulties. An updated guidance of the EDPB would be welcome, including additional practical examples and enhanced criteria to help companies determine the data protection roles of the parties with more certainty. Interplay between the GDPR and the PSD2 The interplay between the GDPR and the PSD2 raises uncertainty.

…more certainty. Interplay between the GDPR and the PSD2 The interplay between the GDPR and the PSD2 raises uncertainty. The most obvious example is the different meaning of consent under the PSD2 and under the GDPR but there are other aspects that should also be clarified. More specifically, there is insufficient clarity on the activities included in the definitions of AISP and PISP. In particular, it would be helpful to have more clarity on the activities that can relate or derive from open banking services (from a data protection perspective, this would enable American Express to understand whether these related activities can be processed based on the performance of a contract as a GDPR lawful basis). A more precise definition of these services including examples and criteria are therefore welcome.

GDPR lawful basis). A more precise definition of these services including examples and criteria are therefore welcome. In addition, clearer guidance is needed on the possible use of the data originally collected for AIS and PIS services for secondary purposes; and on the possibility to further process such data based on legal bases other than consent. 3 There is also a need for explicit guidance on the GDPR permissible processing of personal data during or as a result of the provision of PSD2 services (e.g., after receiving data from a licensed Payment Initiation Service Provider (PISP) or Account Information Service Provider (AISP)). And, finally, American Express also seeks more clarity on the data protection roles of the different actors involved within the Open Banking ecosystem under the PSD2.

…clarity on the data protection roles of the different actors involved within the Open Banking ecosystem under the PSD2. Data Subjects’ rights American Express believes that the right to data portability needs aligned guidance from data protection authorities, particularly on the intersection with open banking and whether sharing personal data to applications via APIs meets portability requirements. American Express also believes that the right to data portability needs aligned guidance at European level in the context of the monetization of data and more particularly in cases where companies acting as intermediaries are exercising the right to data portability on data subjects’ behalf to enrich their own database. By doing so, data subjects are trading away their fundamental right to control their data.

…enrich their own database. By doing so, data subjects are trading away their fundamental right to control their data. We recognize that the Italian data protection authority is further analyzing this issue to provide more guidance on the activities of these intermediaries. However, a coordinated European position and clear guidance on whether such practices are permissible is welcome, notably regarding the merchantability' of the data, the exercise of the right to data portability by delegated powers and the possible duplication of the databases subject to the portability. Personal data breach There is a need for alinement between data protection authorities regarding personal data breach.

Personal data breach There is a need for alinement between data protection authorities regarding personal data breach. For instance, some data protection authorities have issued differing requirements and guidance regarding what constitutes a notifiable personal data breach and have developed their own models for determining the severity of a breach (such as the CNIL). In addition, some data protection authorities do not wish to receive notices for small incidents. We believe that these elements should be unified across the Member States. We also believe that the 72 hours requirement for notification in cases of risk to the data subject is arbitrary and does not add the protection of individuals.

…for notification in cases of risk to the data subject is arbitrary and does not add the protection of individuals. Complying with the timeline is significantly hampered by the lack of a common intake process by supervisory authorities: each one has a different form, asking for different information in a different language. American Express suggests that notification be limited to systematic failings and “high risk” cases to ensure prioritisation of controllers and data protection authorities’ resources, while maintaining the obligation to keep records of all data breaches. 4 Another proposition would be to follow an approach similar to the European Banking Authority (EBA) Guidelines regarding major incident reporting under PSD2. The data breach notification under GDPR could be aligned with the EBA methodology by, for instance, using similar criteria (i.e.

…breach notification under GDPR could be aligned with the EBA methodology by, for instance, using similar criteria (i.e. similar decision tree for assessing major - high risk – incidents; or non- major - lower risk - incidents). Territorial scope of the GDPR Although the European Data Protection Board (EDPB) has issued guidance on this subject, some additional clarification would be welcome as respect to the application of the targeting criterion and more specifically regarding the “monitoring of data subjects’ behavior” to determine what specific activities constitute monitoring under Article 3(2)(b) of the GDPR. GDPR application in the online space American Express believes that the effective implementation of GDPR in the online space is hindered by the continued absence of a corresponding e-Privacy Regulation.

19 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Regulation (EU) No 260/2012 establishing technical and business requirements for credit transfers and direct debits in euro; Regulation (EU) 2024/886 as regards instant credit transfers in euro; Regulation (EU) 2021/1230 on cross-border payments in the Union; Payment Services Regulation; Payment Services Directive 3; Regulation on the establishment of the digital euro; Regulation on the provision of digital euro services by payment services providers incorporated in Member States whose currency is not the euro; Financial Data Access Regulation; Digital Operational Resilience Act; Markets in Crypto-Assets Regulation; Digital Markets Act; Consumer Credit Directive 2; General Data Protection Regulation; Data Act; Data Governance Act; Artificial Intelligence Act; NIS 2 Directive; Cyber Resilience Act; Cyber Solidarity Act