Association for Competitive Technology

ACT · Trade and business associations · BE

Kategorija
Trade and business associations
Būstinė
Brussels BE
Registruota
2010-07-16
Deklaruotos metinės išlaidos
50 000–99 999 € (pačios deklaruota)
Svetainė
http://actonline.org/eu
Skaidrumo registras
72029513877-54 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

20203202232025720266

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 19 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2026-02-25CompetitionExchange of views on merger control framework in the EU
2026-02-25Communications Networks, Content and TechnologyExchange of views on Future networks policies
2026-02-25Cabinet of Commissioner Michael McGrathExchange of views on the forthcoming 28th regime and Digital Fairness Act
2026-02-25Cabinet of Executive Vice-President Henna VirkkunenApp Association activities and EU tech competitiveness agenda
2026-02-25Cabinet of Executive Vice-President Teresa Ribera RodríguezThe European digital landscape, the Digital Markets Act (DMA), the Review of Technology Transfer Block Exemption Regulation (TTBER) and Guidelines, and the AI Act.
2026-02-25Cabinet of Executive Vice-President Teresa Ribera RodríguezThe European digital landscape, the Digital Markets Act (DMA), the Review of Technology Transfer Block Exemption Regulation (TTBER) and Guidelines, and the AI Act.
2025-06-04Cabinet of Executive Vice-President Roxana MînzatuIntroductory meeting by Jason Culloty-CEO, Skillsvista
2025-06-04Cabinet of Executive Vice-President Roxana MînzatuIntroductory meeting by Jason Culloty-CEO, Skillsvista
2025-03-26Internal Market, Industry, Entrepreneurship and SMEsACT came to discuss their views on how the EU should improve the business environment for start- and scale ups
2025-03-26Cabinet of Commissioner Valdis DombrovskisEU implementation and simplification agenda and digital innovation in the EU
2025-03-26Cabinet of Commissioner Ekaterina ZaharievaThe state of the current regulations and the barriers for App developers and SMEs in Europe
2025-03-25Internal Market, Industry, Entrepreneurship and SMEsDiscussion on the scalability of Single Market and the regulatory challenges faced by EU startups
2025-03-25Cabinet of Executive Vice-President Henna VirkkunenExchange of views on ACT activities, EU innovation agenda, EU digital rules and the upcoming28th regime.
2022-09-08Cabinet of Executive Vice-President Margrethe VestagerDigital policies.
2022-09-08Cabinet of Executive Vice-President Margrethe VestagerRegulation for Mobile Phones, Cordless Phones and Tablets
2022-04-21Cabinet of Executive Vice-President Valdis DombrovskisWTO Matters
2020-10-06Cabinet of Executive Vice-President Margrethe VestagerTo discuss the Digital Markets Act.
2020-06-12Cabinet of Commissioner Thierry BretonDigital services Act
2020-02-17Cabinet of Executive Vice-President Margrethe VestagerPlatform policy

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
ACT | The App Association (App Association) is grateful for the opportunity to contribute insights to the European Commission (EC) regarding our members experiences with implementing the General Data Protection Regulation (GDPR). Please find our full response attached as a pdf.
2023-03-20 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
Please see attached the feedback of ACT | The App Association to this call for evidence on further specifying the procedural rules relating to the enforcement of the General Data Protection Regulation.
2022-02-14 · VAT in the Digital Age ↗ originalus šaltinis
Please find attached comments of ACT | The App Association (Transparency Reg. # 7202951387754) on the European Commission’s call for evidence for an impact assessment: Value-added tax in the digital age.
2020-04-28 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Please see the file attached for ACT | The App Association's feedback.

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
VAT in the Digital Age · 4 p.

ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] 14 February 2022 Comments of ACT | The App Association (Transparency Reg. # 72029513877-54) Rue de la Loi 23 B-1000 Brussels to The European Commission’s Directorate-General for Taxation and Customs Union (Unit C1) on its Call for evidence for an impact assessment: Value-added tax in the digital age Ref.

…and Customs Union (Unit C1) on its Call for evidence for an impact assessment: Value-added tax in the digital age Ref. Ares(2022)1350568 - 22/02/2022 ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] ACT | The App Association feedback to the European Commission’s call for evidence for an impact assessment: Value-added tax in the digital age I/ Introduction and Statement of Interest ACT | The App Association submits feedback to the European Commission’s (EC) Directorate- General for Taxation and Customs Union (DG TAXUD) in response to its call for evidence for an impact assessment regarding the value-added tax in the digital age. The App Association appreciates DG TAXUD’s efforts to make Europe fit for the digital age and its commitment to a modern, stable, and sustainable tax framework across the European Union.

…for the digital age and its commitment to a modern, stable, and sustainable tax framework across the European Union. The App Association represents thousands of small software application development companies and technology firms. Our members create the software apps used on mobile devices and in enterprise systems around the globe. The ecosystem the App Association represents—which we call the app economy—provided more than €187 billion in revenue in the European Union and supported up to 1.7 million jobs across the European economy in 2019, adding 0.4 per cent to the EU’s GDP. Alongside the world’s rapid embrace of mobile technology, our members create innovative solutions that power the internet of things (IoT) across all modalities and segments of the economy.

…create innovative solutions that power the internet of things (IoT) across all modalities and segments of the economy. Our member companies are small technology and app development companies, many of them ‘micro-multinationals’ which makes cross-border taxation an essential issue for their growth and job creation. II/ The call for evidence for an impact assessment: Value-added tax in the digital age We agree with the Commission on the importance of fair and efficient taxation, especially considering the COVID-19 pandemic and transitions like digitalisation, globalisation, climate change, and ageing populations. Small businesses like our members face a diverse array of challenges when entering new markets, including tax policies. Although the global digital economy holds great promise for App Association members, trade barriers continue to impede investment in Europe and European exports.

…great promise for App Association members, trade barriers continue to impede investment in Europe and European exports. The laws, regulations, policies, or practices that protect domestic goods and services from foreign competition reflect these trade barriers and artificially stimulate exports of certain domestic goods and services or fail to provide adequate and effective protection of intellectual property rights. We agree that the VAT system has become increasingly complex and burdensome for businesses. Therefore, we support the Commission’s ambition to harmonise the current patchwork of VAT frameworks across the EU and with key trading partners. We fully support the Commission’s objective of combating VAT fraud and ensuring tax equality and neutrality.

…partners. We fully support the Commission’s objective of combating VAT fraud and ensuring tax equality and neutrality. Making compliance with VAT rules easier for EU businesses, particularly those working in the digital economy and those carrying out cross-border trade will be help companies of all sizes as well as prevent regulatory failure and market fragmentation. Further, we believe the use of technology can be beneficial in reducing administrative burdens and related costs for businesses, and we encourage the Commission to examine how it can increase such use of technology. Simplifying and modernising VAT reporting obligations and moving to a single VAT registration in the EU could be hugely beneficial especially for small businesses.

…and moving to a single VAT registration in the EU could be hugely beneficial especially for small businesses. As ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] several of the Member States are introducing different digital reporting obligations, we agree with the Commission that uncoordinated reporting obligations create substantial new compliance burdens for businesses operating in different Member States, which hurts small businesses in particular. Further, such actions increase the risk of fragmentation, hindering the operation of the single market. We thus support the Commission’s policy option to examine the introduction of partial (cross-border transactions only) or fully harmonised (covering domestic and cross-border transactions) digital reporting requirements, including e-invoicing.

…harmonised (covering domestic and cross-border transactions) digital reporting requirements, including e-invoicing. However, we urge the Commission to refrain from introducing any data storage obligations that will require taxpayers to record transactional data using a pre-determined format and provide information only upon request. Such obligations present trade barriers which only increases the barriers small businesses like our members face when entering new markets. A single VAT registration in the EU in combination with the newly introduced OSS (one-stop-shop) would enable businesses to avoid multiple VAT registrations in the EU for all cross-border transactions, including supplies with installation and e-mobility.

VAT registrations in the EU for all cross-border transactions, including supplies with installation and e-mobility. We, therefore, support the extension of the OSS to include not yet covered business-to-customer supplies, combine the OSS with simplification measures for intra-EU business-to-business supplies and improve the import one-stop-shop by eliminating the EUR 150 threshold and making use of the import-OSS mandatory. In considering an update to the VAT rules for the platform economy, the Commission states that VAT rules are ill-equipped to deal with challenges of the platform economy, i.e. they fail to ensure the fair taxation of online and traditional economic transactions.

…of the platform economy, i.e. they fail to ensure the fair taxation of online and traditional economic transactions. While we strongly encourage the Commission to ensure Member States take a uniform approach to the application of the VAT rules regarding the provider, nature of services, place of supply, and reporting in the light of the divergent and evolving business models, we urge the Commission to refrain from including any unilateral action items related to digital tax proposals. Digital taxes represent one of the most concerning forms of trade barriers that will fracture the digital economy and undermine the EC’s DSM vision.

…the most concerning forms of trade barriers that will fracture the digital economy and undermine the EC’s DSM vision. Additionally, we encourage the Commission to call on the Member States to refrain from unilateral digital tax legislation and to align with the Organization for Economic Cooperation and Development’s (OECD) multilateral consensus approach to digital taxation.1 The negative effects of unilateral action on the EU’s part are significant and include the fragmentation of the global economy and the threat it poses to the progress of multilateral and collaborative work that is a key aspect of the global economy. We prefer the policy option of clarifying existing VAT rules to ensure a more uniform approach to these new business models over considering whether platforms could play an active role in the collection of VAT.

…to these new business models over considering whether platforms could play an active role in the collection of VAT. While we acknowledge that the digital economy and new business models create challenges for tax administrations and international taxation may need some changes due to the rise of the digital economy, we believe the Commission must also carefully consider the impact of any unilateral actions it may take. 1 https://www.oecd.org/tax/international-community-strikes-a-ground-breaking-tax-deal-for-the-digital- age.htm ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] III/ Conclusion The App Association agrees that VAT frameworks may require some changes to fit the future economy.

14 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 6 p.

…29 April 2020 Comments of ACT | The App Association to The European Commission’s Directorate-General for Justice on its Roadmap for a Report on the Application of the General Data Protection Regulation (GDPR) Ref. Ares(2020)2275681 - 28/04/2020 I. Introduction and Statement of Interest ACT | The App Association (The App Association) appreciates the opportunity to provide input to the European Commission (EC) regarding our members’ experiences with implementing the General Data Protection Regulation (GDPR). We are committed to ensuring European leadership in privacy policy and support the EC’s timely evaluation of the function, implementation, oversight, and enforcement of the GDPR.

…policy and support the EC’s timely evaluation of the function, implementation, oversight, and enforcement of the GDPR. We submit the following comments in response to the EC’s request for input on its report about the GDPR’s effectiveness with a specific emphasis on international transfer of personal data and cooperation between national data protection authorities. The App Association represents more than 5,000 app makers and connected device companies across the European Union (EU) and around the globe that use mobile technologies to produce innovative solutions that drive the dynamic €830 billion app ecosystem, providing millions of jobs across the EU. Alongside the global adoption of mobile technologies, our members lead in developing innovative hardware and software solutions that power the growth of the internet of things (IoT) across modalities and segments of the economy.

…solutions that power the growth of the internet of things (IoT) across modalities and segments of the economy. The global nature of the digital economy has enabled our members to serve customers and enterprises located across the EU as well as the rest of the world. The App Association serves as a leading resource in the privacy space for thought leadership and education within our small business technology developer community. We work to keep our members informed and engaged on the latest policy and legal developments, and we also translate those developments into practical and useable guidance to ease the burden of compliance for them.1 II. Views of the App Association on the General Data Protection Regulation After Two Years Based on two years of our and our members’ GDPR implementation and compliance efforts, the App Association provides the following feedback to the EC.

…our members’ GDPR implementation and compliance efforts, the App Association provides the following feedback to the EC. The App Association is committed to advancing proactive approaches to ensure end-user privacy. In the context of the GDPR, App Association members appreciate that the European privacy regulation is cross-sectoral and uses a single set of rules to govern data protection rights and liberties for EU consumers. Further, GDPR has influenced other key markets, in both the developed and developing world, that are crafting new privacy policy frameworks. The App Association continues to seek the development of comprehensive cross-sectoral privacy frameworks in other markets that include EU trading partners, such as the United States. The App Association and its members are supportive of strong privacy standards and share the EC’s goals in further refining the GDPR.

…and its members are supportive of strong privacy standards and share the EC’s goals in further refining the GDPR. In the leadup to, and since, the GDPR’s effective date, the App Association’s members undertook and continue 1 See, e.g., ACT | The App Association, General Data Protection Regulation Guide (May 2018), available at https://actonline.org/wp-content/uploads/ACT_GDPR-Guide_interactive.pdf. to take significant (and often costly) steps to comply with the GDPR per Data Protection Authorities’ (DPAs) domestic requirements. For small and medium size enterprises (SMEs), compliance is especially complex because each data processing activity requires a different response from the company including on the various internal levels including HR, legal, research and development as well as in external interaction with customers.

…internal levels including HR, legal, research and development as well as in external interaction with customers. Our members worked to exceed the GDPR’s baseline requirements to respond to consumer expectations and market competition by utilizing cutting-edge privacy-by-design approaches from the earliest phases of product development and the most advanced tools and methods available, such as differential privacy techniques.2 Complying with GDPR has given some of our members a competitive advantage over competitors who are not compliant, and has allowed for a thorough review of organization and a streamlining processes throughout the company. However, many of our members provide services for larger companies who often try to impose their obligations (such as controller and processor obligations) on the SME.

…larger companies who often try to impose their obligations (such as controller and processor obligations) on the SME. Such behaviour by larger companies forces small entities to implement unnecessarily high levels of compliance that are not required for their business. While we agree with the EC and the enforcing DPAs on the goals of the GDPR, the App Association’s small business members continue to face challenges when it comes to GDPR compliance with the law. Small businesses – like our members – represent approximately 98 percent of all EU firms3 and must play a more significant role as the EC makes adaptations or amendments to its privacy management strategies, particularly with respect to GDPR.

…as the EC makes adaptations or amendments to its privacy management strategies, particularly with respect to GDPR. We strongly encourage the EC to remain mindful of the fact that large companies often dedicate large budgets to creating and maintaining privacy control processes and can hire staff and consultants to mitigate privacy risks. Conversely, small enterprises do not have unlimited resources to contribute to compliance costs. For many App Association members, the role of chief privacy officer may be one of five (or more) functions carried out by a single employee who might have to spend a considerable amount of additional time on GDPR compliance and monitoring. Therefore, we commend the EC for reviewing the GDPR at this critical two-year juncture.

GDPR compliance and monitoring. Therefore, we commend the EC for reviewing the GDPR at this critical two-year juncture. Commercial privacy is not a static concept, and the App Association agrees that products and services should be designed to respect user privacy. Notwithstanding, this can only be accomplished through an ongoing dialogue with users that accounts for changing contexts and expectations. As a result, the EC should make allowances for these evolving circumstances through changes to the GDPR and DPAs. Further, we urge the EC to be mindful of emerging technologies that represent future opportunities for privacy leadership. For example, the EC should consider artificial/augmented intelligence (AI) when it evaluates the GDPR’s current data processing requirements.

…consider artificial/augmented intelligence (AI) when it evaluates the GDPR’s current data processing requirements. AI is a constantly evolving constellation of technologies that enable computers to simulate elements of human thinking, which entails a range of approaches and technologies, such as Machine Learning (ML) and deep learning. 2 Differential Privacy, HARVARD UNIVERSITY PRIVACY TOOLS PROJECT, https://privacytools.seas.harvard.edu/differential-privacy (last visited 22 April 2020). 3 How many people work in small enterprises?, EUROSTAT, https://ec.europa.eu/eurostat/web/products-eurostat-news/-/WDN-20180627-1 (last updated 27 June 2018). These technologies have algorithms based on the way neurons and synapses in the brain change due to exposure to new inputs, allowing independent or assisted decision making.

…and synapses in the brain change due to exposure to new inputs, allowing independent or assisted decision making. AI-driven algorithmic decision tools and predictive analytics have, and will continue to have, substantial direct and indirect effects on Europeans. Specifically, AI is used to detect financial and identity theft and to protect the communications networks upon which Europeans rely against cybersecurity threats. Moving forward, across use cases and sectors, AI has considerable potential to improve European consumers’ lives through faster and better-informed decision making, enabled by cutting-edge distributed cloud computing. In the healthcare context, treatments and patient outcomes stand poised to improve disease prevention and conditions, in addition to efficiently and effectively treating diseases through automated analysis of x-rays and other medical imaging.

…to efficiently and effectively treating diseases through automated analysis of x-rays and other medical imaging. Moreover, it is estimated that AI technological breakthroughs will represent a €116 billion market by 2025.4 However, if regulations such as the GDPR lack flexibility with respect to data processing requirements, they will stand in the way of responsible and transparent development of AI tools with great societal benefit. Small business-targeted efforts by the EC, European Data Protection Board (EDPB), and DPAs to date are helpful, but much more needs to be done to support small businesses complying with broad regulations such as the GDPR. The App Association is committed to advancing innovation in privacy engineering throughout our community through direct member education, public-private partnerships, and other means.

22 → 12

originalus šaltinis (PDF) ↗

Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 5 p.

ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] 20 March 2023 Feedback of ACT | The App Association (Transparency Reg. # 72029513877-54) Rue de la Loi 23 1000 Brussels to the European Commission on its Call for Evidence on further specifying procedural rules relating to the enforcement of the General Data Protection Regulation Ref.

…on further specifying procedural rules relating to the enforcement of the General Data Protection Regulation Ref. Ares(2023)2007511 - 20/03/2023 ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] ACT | The App Association response to the European Commission’s call for evidence on further specifying procedural rules relating to the enforcement of the General Data Protection Regulation I/ Introduction and statement of interest ACT | The App Association (hereafter ‘App Association’) submits feedback to the European Commission’s call for evidence for an initiative (without an impact assessment) for a regulation regarding the procedural rules on enforcement of the General Data Protection Regulation (GDPR).

…for a regulation regarding the procedural rules on enforcement of the General Data Protection Regulation (GDPR). The App Association is an international not-for-profit trade association located in Brussels, Belgium, that represents small and medium-sized application developers and connected device companies located across the European Union (EU) and around the globe. We are committed to European leadership in innovation, as well as supporting competition and growth in the Digital Single Market (DSM). The App Association dedicates itself to creating an economic and regulatory environment in which small and medium digital players can thrive. Today, the ecosystem the App Association represents—which we call the app economy—is valued at approximately €830 billion globally and is responsible for more than one million jobs across the Member States of the EU.

€830 billion globally and is responsible for more than one million jobs across the Member States of the EU. Alongside the world’s rapid embrace of mobile technology, our members have been developing innovative hardware and software solutions that power the growth of the internet of things (IoT) across modalities and segments of the economy. The App Association’s members include many EU-based innovators who develop mobile technology products in both established and emerging markets, and how they can use and share data affects how their products function and how consumers engage with those products and services. Our members handle and work with data daily, so they are directly affected by European data governance, including enforcement of the GDPR.

…and work with data daily, so they are directly affected by European data governance, including enforcement of the GDPR. SMEs take privacy and consumer complaints seriously and want to handle them with the appropriate care, but the diverging approaches across the EU can make that more difficult. Further harmonisation of the procedural rules will enable our members and other SMEs to better plan for handling complaints appropriately. We support the Commission’s goal of streamlining cooperation between national data protection authorities (DPAs) in cross-border cases. Many of our member companies offer their services and have customers in various Member States, and further harmonisation of the administrative procedures of national DPAs will ensure consistent application of the GDPR and, therefore, benefit all stakeholders subject to it.

…of national DPAs will ensure consistent application of the GDPR and, therefore, benefit all stakeholders subject to it. II/ Political context, problem definition, and subsidiarity check The App Association welcomes the Commission taking initiative to address some of the issues it identified in its report on the application of the GDPR, namely the list of procedures of national DPAs in cross-border enforcement cases the European Data Protection Board submitted to the ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] Commission in October 2022. We agree with the Commission that improving cooperation between national DPAs will support robust enforcement of the GDPR and give businesses a higher level of legal certainty of what to expect in cross-border cases.

…enforcement of the GDPR and give businesses a higher level of legal certainty of what to expect in cross-border cases. The European Data Protection Board (EDPB) has found that national DPAs follow diverging approaches when it comes to complaint handling, the form of complaints, the duration of proceedings, businesses’ right to be heard during the proceedings, and when they can be heard, as well as the involvement of the complainant and progress communications. These divergences are not in the spirit of the GDPR and can create an environment that’s hard to navigate especially for smaller businesses that are subject to GDPR. Further, when multiple DPAs are involved because of a cross-border scenario, they do not always reach a consensus.

Further, when multiple DPAs are involved because of a cross-border scenario, they do not always reach a consensus. While the GDPR’s dispute resolution mechanism (Article 65) accounts for those situations, we agree with the Commission that clarifying existing steps and spelling out additional ones for cooperation will help to speed up investigations and the resolution of disagreements. Such improvements would benefit both data subjects and businesses and ensure a smoother functioning of GDPR. Additionally, we believe this measure will help to increase public trust in a digital society where citizens’ data is adequately protected in all situations.

…will help to increase public trust in a digital society where citizens’ data is adequately protected in all situations. We agree with the Commission’s assessment that Article 16 of the Treaty on the Functioning of the European Union (TFEU) provides a sound legal basis for this initiative, as it enables the European Parliament and the Council to make rules for the protection of individuals in the context of personal data processing and the free movement of such data. Since the proposal relates to cross-border cases and applies to DPAs in multiple Member States as well as the EDPB, it makes sense for the EU institutions to act, rather than a single Member State. III/ Aims of the initiative and how it plans to achieve them The App Associations supports the Commission’s aim of improving cooperation between DPAs by harmonizing procedural aspects in cross-border cases when enforcing the GDPR.

…of improving cooperation between DPAs by harmonizing procedural aspects in cross-border cases when enforcing the GDPR. Articles 60 and 65 of the GDPR currently lack explicit procedural deadlines for cooperation between DPAs in cross-border cases, and we believe the proposed policy option to specify such deadlines is sufficient to address this issue. Further guidance for DPAs on information-sharing between the investigating and concerned DPAs as well as developing additional tools that promote cooperation throughout the investigative process will likely have a positive impact on the overall streamlining of procedural enforcement rules. Concerning parties involved in a procedure, it will be helpful to clarify the positions of each party (complaints and parties under investigation) in each step of the procedure, as the Commission proposes.

…of each party (complaints and parties under investigation) in each step of the procedure, as the Commission proposes. Complainants should have the possibility to voice their views, and parties under ACT | The App Association | Rue de la Loi 23, 1000 Brussels | www.actonline.org | [email protected] investigation should have an opportunity to be heard in all cross-border cases, no matter which DPAs are involved. As for the likely effects of this initiative, we fully agree with the Commission that harmonising procedural rules’ key aspects for cross-border cases will overall benefit all stakeholders, including DPAs, complainants, the parties under investigation, as well as public confidence in the GDPR.

…stakeholders, including DPAs, complainants, the parties under investigation, as well as public confidence in the GDPR. Specifically for the small businesses the App Association represents, long investigation procedures can be particularly burdensome, and they often struggle with the patchwork of procedural rights like differences in the right to be heard and access the file. Improving cooperation between DPA will help to shorten investigations and, thus, reduce that burden on businesses of all sizes. Additionally, having the same expectation for procedural rights in all cross- border cases will improve legal certainty and protect the right to good administration for parties under investigation, as the Commission rightly states.

16 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 5 p.

ACT | The App Association | Rue de la Loi 23, 1040 Brussels | www.actonline.org | [email protected] Call for evidence - Report on the General Data Protection Regulation (GDPR) ACT | The App Association 8 February 2024 ACT | The App Association provides the following feedback to the public consultation opened by the European Commission on the Report 2024 on the application of the General Data Protection Regulation (GDPR). The feedback is based on the questionnaire sent to members of the GDPR multi-stakeholder expert group in September 2023. 1. General comments What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed?

…in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? ACT | The App Association (App Association) is grateful for the opportunity to contribute insights to the European Commission (EC) regarding our members’ experiences with implementing the General Data Protection Regulation (GDPR). We remain committed to fostering European leadership in privacy policy, and we support the EC’s evaluation of the GDPR’s function, implementation, oversight, and enforcement. We welcome the cross-sectoral nature of the GDPR, utilising a unified set of rules to govern data protection rights for EU data subjects. We particularly appreciate the principle-based approach embedded in the GDPR, being technology-neutral.

…data subjects. We particularly appreciate the principle-based approach embedded in the GDPR, being technology-neutral. This provides flexibility and adaptability and ensures that the framework withstands the test of time, allowing it to evolve seamlessly with advancements in technology while consistently upholding robust privacy standards across various sectors. The App Association serves as a key resource for thought leadership and education within the small business technology developer community, particularly in the realm of privacy. We are dedicated to keeping our members informed of the latest policy and legal developments, translating complex regulations into practical guidance to facilitate compliance and alleviate burdens for our members. The implementation of GDPR rules has posed notable challenges for our small and medium-sized entity (SME) members.

The implementation of GDPR rules has posed notable challenges for our small and medium-sized entity (SME) members. The adjustment process required considerable effort and investment, particularly for micro-organisations and startups within our community. For SMEs, compliance was complex because each data processing activity requires a different response from the company, including on the various internal levels including human resources, legal, research and development, as well as in external interaction with customers. This process remains burdensome and costly for SMEs. 2.

…development, as well as in external interaction with customers. This process remains burdensome and costly for SMEs. 2. Exercise of data subject rights From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g., manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). • Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) The App Association asserts that obligations should be as simple and accessible as possible for SMEs. For example, information obligations should not be disproportionate and a publicly available and understandable policy published on an app or a website should be enough. Ref.

…and a publicly available and understandable policy published on an app or a website should be enough. Ref. Ares(2024)974101 - 08/02/2024 ACT | The App Association | Rue de la Loi 23, 1040 Brussels | www.actonline.org | [email protected] • Access to data (Article 15) • Rectification (Article 16) • Erasure (Article 17) • Data portability (Article 20) • Right to object (Article 21) • Meaningful explanation and human intervention in automated decision-making (Article 22) b. Do you avail of / are you aware of tools or user-friendly procedures to facilitate the exercise of data subject rights? c. Do you have experience in contacting representatives of controllers or processors not established in the EU? d. Are there any particular challenges in relation to the exercise of data subject rights by children? 3. Application of the GDPR to SMEs a.

…challenges in relation to the exercise of data subject rights by children? 3. Application of the GDPR to SMEs a. What are the lessons learned from the application of the GDPR to SMEs? b. Have the guidance and tools provided by data protection authorities and the EDPB in recent years assisted SMEs in their application of the GDPR? c. What additional tools would be helpful to assist SMEs in their application of the GDPR? To comply with GDPR obligations, SMEs undertake often costly measures. Compliance for SMEs, such as our members, has been particularly challenging, as it involves developing various privacy-by-design approaches from the earliest stages of product development and the most advanced tools and methods available. We urge the Commission to acknowledge that large companies have greater resources for privacy compliance, while small enterprises face limitations.

…that large companies have greater resources for privacy compliance, while small enterprises face limitations. Many of our members lack dedicated privacy staff and must allocate additional time and resources to GDPR compliance. Complying with GDPR has given some of our members a competitive benefit and has allowed for a thorough review of organisation and streamlining processes throughout the company. However, many of our members provide services for larger companies who often try to impose their obligations (such as controller and processor obligations) on the SME. Such behaviour by larger companies forces small entities to implement unnecessarily high levels of compliance that are not required for their business. We are disappointed in the lack of strong and uniform enforcement of the GDPR, years after its adoption.

We are disappointed in the lack of strong and uniform enforcement of the GDPR, years after its adoption. The additional costs and burdens related to GDPR compliance can lead to anticompetitive effects between GDPR-compliant SMEs and GDPR non- compliant companies, as the latter would have the opportunity to invest those resources in other ways, which may provide more efficient competition advantages. We believe that strong and uniform enforcement is a crucial aspect of successful regulation. Therefore, we request the European Commission to take measures to ensure a stronger uniform enforcement of the GDPR. The App Association welcomes the guidance tools provided by data protection authorities and the European Data Protection Board (EPDB), which are important and useful resources for SMEs.

…authorities and the European Data Protection Board (EPDB), which are important and useful resources for SMEs. Any additional tools—easy to use for SMEs—translated into different European languages would be welcome. Those tools could take the form of risk assessment tools, templates, and checklists for IT security. 4. Use of representative actions under Article 80 GDPR From the controllers and processors’ perspective: are you aware of representative actions being filed against your organization? ACT | The App Association | Rue de la Loi 23, 1040 Brussels | www.actonline.org | [email protected] 5. Experience with Data Protection Authorities (DPAs) a) What is your experience in obtaining advice from DPAs? b) How are the guidelines adopted so far by the EDPB supporting the practical application of the GDPR?

…from DPAs? b) How are the guidelines adopted so far by the EDPB supporting the practical application of the GDPR? c) Are DPAs following up on each complaint submitted and providing information on the progress of the case? d) Are you aware of guidelines issued by national DPAs supplementing or conflicting with EDPB guidelines? (please explain) There is a pressing need for improved alignment and coordination among DPAs across the EU. Currently, the varying degrees of national GDPR implementation and divergent interpretations of the Regulation poses challenges for small businesses, especially concerning the appointment of Data Protection Officers (DPOs) and international data transfers. The App Association advocates for enhanced coordination among DPAs to harmonise policies and address inconsistencies, ensuring consistent compliance and reduced burdens for SMEs.

DPAs to harmonise policies and address inconsistencies, ensuring consistent compliance and reduced burdens for SMEs. With limited resources, App Association members rely on the guidance provided by the European Commission, EDPB, and DPAs to support them with compliance. The App Association calls on the EDPB to develop more guidance on the EU level—and at the national level—to adequately address unclear rules, limits, and liabilities. Clear and coherent guidelines applicable all over Europe and in a similar way in each country should be developed; This point is of particular importance for our members. Guidelines should be as accessible and easy to use as possible as SMEs do not always have access to lawyers and full legal department services.

24 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

The App Association has an interest in the activities in all European institutions – commission, parliament and council – and their impact on the EU-based, and global, small- and medium-sized entity (SME) innovator community and the digital economy.
Interests include:
 Artificial Intelligence
 Digital Single Market Strategy
 EU Communications Regulatory Framework
 Cross-border Data Flows
 Preventing Online Piracy & Cybercrime
 eHealth
 Data Protection
 Data Security
 Intellectual Property Rights
 Internet of Things
 Network Security & Interoperability
 Taxation