BSA · Trade and business associations · US
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 21 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
Brussels, February 2024 Avenue des Arts 44 www.bsa.org 1040 Brussels EU Register of Interest Representatives 75039383277-48 Belgium BSA | The Software Alliance’s Response to the European Commission’s Call for Evidence on the Second Application Report of the EU General Data Protection Regulation BSA | The Software Alliance (“BSA”),1 the leading advocate for the global enterprise software industry, welcomes the opportunity to provide input for the second report of application of the EU General Data Protection Regulation (GDPR). The business-to-business (B2B) software industry is at the forefront of the development of cutting-edge innovation, including cloud computing, privacy and security solutions, data analytics, and artificial intelligence (AI).
…including cloud computing, privacy and security solutions, data analytics, and artificial intelligence (AI). Our member companies’ software-enabled technologies increasingly rely on data and, in some cases, personal data, to function and provide insights to our customers to enable their businesses. As a result, the protection of personal data is an important priority for BSA members, and we recognize that it is a key part of building customer trust.
…data is an important priority for BSA members, and we recognize that it is a key part of building customer trust. As the European Commission conducts its second evaluation, it is important to assess if the GDPR continues to achieve its goal of effectively harmonizing data protection laws throughout the EU and beyond for two reasons: first, so that consumers know and trust what privacy controls they have, regardless of where they are; and second, so that businesses know what their obligations are, which not only improves the EU single market but also advances trust, digital transformation and innovation in Europe. Benefits of GDPR Application Within EU and EEA countries2, the GDPR has brought valuable harmonization of applicable rules and increased transparency of data handlers’ responsibilities.
…has brought valuable harmonization of applicable rules and increased transparency of data handlers’ responsibilities. Since May 2018, the GDPR has raised general public awareness of privacy and focused the attention of organizations, including non-profits and SMEs, that were not necessarily accustomed to dealing with data protection requirements. It has also given Data Protection Authorities (DPAs) the tools to monitor and enforce compliance, including requirements for international data transfers. The GDPR has adopted a risk-based and technology-neutral approach to data protection requirements, which allows organizations to ensure compliance while adapting their practices and safeguards to the 1 BSA | The Software Alliance (www.bsa.org) is the leading advocate for the global software industry before governments and in the international marketplace.
…is the leading advocate for the global software industry before governments and in the international marketplace. Its members are among the world’s most innovative companies, creating software solutions that spark the economy and improve modern life. With headquarters in Washington, DC, and operations in more than 30 countries, BSA pioneers compliance programs that promote legal software use and advocates for public policies that foster technology innovation and drive growth in the digital economy.
…use and advocates for public policies that foster technology innovation and drive growth in the digital economy. BSA’s members include: Adobe, Alteryx, Asana, Atlassian, Autodesk, Bentley Systems, Box, Cisco, Cloudflare, CNC/Mastercam, Databricks, DocuSign, Dropbox, Elastic, Graphisoft, Hubspot, IBM, Informatica, Kyndryl, MathWorks, Microsoft, Okta, Oracle, Palo Alto Networks, PagerDuty, Prokon, Rubrik, Salesforce, SAP, ServiceNow, Shopify Inc., Siemens Industry Software Inc., Splunk, Trend Micro, Trimble Solutions Corporation, TriNet, Twilio, Workday, Zendesk, and Zoom Video Communications, Inc. 2 References to the EU in the submission are to be read to also mean EEA countries. Ref.
Video Communications, Inc. 2 References to the EU in the submission are to be read to also mean EEA countries. Ref. Ares(2024)963091 - 08/02/2024 Page 2 of 14 Avenue des Arts 44 www.bsa.org 1040 Brussels EU Register of Interest Representatives 75039383277-48 Belgium most-suited approach given their business model, activity and risk profile. The GDPR’s principle of accountability has raised awareness among companies on the importance of evidence based GDPR compliance. It has streamlined the unification of privacy operations across industries, providing greater insight into where personal information is collected, used, and accessed. The GDPR not only helped organizations (especially, smaller companies) to better understand processing activities within their entities and better manage data flows, but also improved the regulatory readiness of the industry.
…within their entities and better manage data flows, but also improved the regulatory readiness of the industry. The GDPR has become a global point of reference at a time when many countries are developing or updating their privacy laws and regulations, based on standards pioneered in the GDPR. Very importantly, the GDPR enshrined free movement of personal data as a crucial pillar of the EU acquis, supporting digitalization and streamlining data processing, thus facilitating the digital transformation of the economy. The overarching goals of the GDPR – to provide high levels of data protection and to ensure free movement of data – are continuously essential to privacy laws worldwide. The principles that underpin the GDPR have been foundational to privacy legislation for decades and across economies.
The principles that underpin the GDPR have been foundational to privacy legislation for decades and across economies. Offering these principles to all customers globally helps foster trust and transparency and contributes to reaching global convergence across privacy frameworks. BSA welcomes the leading role that the European Commission is taking on the global scene to support the emergence of “modern data protection regimes […] designed to afford individuals a high level of protection while facilitating data flows in a way that maximizes economic opportunity and consumer interests3.” The EU has a critical role to play to encourage international privacy best practices and interoperability of privacy systems.
…has a critical role to play to encourage international privacy best practices and interoperability of privacy systems. Challenges of GDPR Application BSA concurs with the European Data Protection Board (EDPB)4 that it is premature to revise the legislative text of the GDPR at this point in time (less than 6 years after its entry into force) and welcomes continued discussion with BSA members to enhance the practical application of the GDPR. BSA offers its feedback based on our member companies’ practical experience of GDPR implementation and highlights areas that could benefit from further attention from the European Commission, the European Data Protection Board and national data protection authorities. Priority issues to be addressed in the second GDPR application report include: I.
…national data protection authorities. Priority issues to be addressed in the second GDPR application report include: I. Consistency mechanism should be improved to reduce fragmentation in the Member States and advance harmonization. II. International data transfers toolbox should be strengthened to support global data flows. III. Contractual and business relationships in a B2B environment should be addressed to further advance digital transformation and ensure smooth application of risk- based approach. IV. The GDPR and other data related legislation should be coherent to help foster innovation and new technologies.
IV. The GDPR and other data related legislation should be coherent to help foster innovation and new technologies. 3 https://eeas.europa.eu/delegations/india/53963/node/53963_zh- hans?Consumers_to_the_Ministry_of_Electronics_and_Information_Technology_%28MeitY%29= 4 Contribution of the EDPB to the report on the application of the GDPR under Article 97: edpb_contributiongdprevaluation_20231212_en.pdf (europa.eu) Page 3 of 14 Avenue des Arts 44 www.bsa.org 1040 Brussels EU Register of Interest Representatives 75039383277-48 Belgium I. Consistency mechanism should be improved to reduce fragmentation in the Member States and advance harmonization. The consistency mechanism has been an important improvement introduced first in the Directive 95/46 and then further developed in the GDPR.
79 → 12
Brussels, April 2020 Avenue des Arts 44 P +32 (0)2 274 13 10 1040 Brussels W bsa.org Belgium EU Register of Interest Representatives 75039383277-48 BSA | The Software Alliance’s feedback on the implementation of the EU General Data Protection Regulation. BSA | The Software Alliance (“BSA”),1 the leading advocate for the global software industry, welcomes the opportunity to provide feedback on the EU General Data Protection Regulation (GDPR). The business-to-business (B2B) software industry is at the forefront of the development of cutting-edge innovation, including cloud computing, privacy and security solutions, data analytics, and artificial intelligence. Our member companies’ software-enabled technologies increasingly rely on data and, in some cases, personal data, to function and provide insights to our customers to enable their businesses.
…data and, in some cases, personal data, to function and provide insights to our customers to enable their businesses. As a result, the protection of personal data is an important priority for BSA members, and we recognize that it is a key part of building customer trust. As the Commission conducts its evaluation, it is important to assess if the GDPR is working as intended to successfully harmonize data protection laws throughout the EU and beyond for two reasons: first, so that consumers know and trust what privacy controls they have, regardless of where they are; and second, so that businesses know what their obligations are, which improves the EU single market. Within EU and EEA countries2, the GDPR has brought valuable harmonization of applicable rules and increased transparency of data handlers’ responsibilities.
…has brought valuable harmonization of applicable rules and increased transparency of data handlers’ responsibilities. It has raised general public awareness of privacy and focused the attention of organizations, including non-profits and SMEs, that were not necessarily accustomed to dealing with data protection requirements. It has also given Data Protection Authorities (DPAs) the tools to effectively monitor and enforce compliance, including requirements for international data transfers. The GDPR has adopted a risk-based and technology-neutral approach to data protection requirements, which allows organizations to ensure compliance while adapting their practices and safeguards to the most-suited approach given their business model, activity and risk profile. It also importantly enshrines free movement of personal data as an important pillar of the EU acquis.
…and risk profile. It also importantly enshrines free movement of personal data as an important pillar of the EU acquis. The GDPR has become a global point of reference at a time when many countries are developing or updating their privacy laws and regulations, emulated by the GDPR. The overarching goal of the GDPR – 1 BSA | The Software Alliance (www.bsa.org) is the leading advocate for the global software industry before governments and in the international marketplace. Its members are among the world’s most innovative companies, creating software solutions that spark the economy and improve modern life. With headquarters in Washington, DC, and operations in more than 30 countries, BSA pioneers compliance programs that promote legal software use and advocates for public policies that foster technology innovation and drive growth in the digital economy.
…use and advocates for public policies that foster technology innovation and drive growth in the digital economy. BSA’s members include: Adobe, Akamai, Atlassian, Autodesk, Bentley Systems, Box, Cadence, Cloudflare, CNC/Mastercam, IBM, Informatica, Intel, Intuit, MathWorks, McAfee, Microsoft, Okta, Oracle, PTC, Salesforce, ServiceNow, Siemens Industry Software Inc., Sitecore, Slack, Splunk, Trend Micro, Trimble Solutions Corporation, Twilio, and Workday. 2 References to EU in the submission are to be read to also mean EEA countries. Ref. Ares(2020)2292955 - 29/04/2020 Avenue des Arts 44 P +32 (0)2 274 13 10 1040 Brussels W bsa.org Belgium EU Register of Interest Representatives 75039383277-48 to provide high levels of privacy protection – is essential to privacy laws worldwide.
Representatives 75039383277-48 to provide high levels of privacy protection – is essential to privacy laws worldwide. The principles that underpin the GDPR have been foundational to privacy legislation for decades and across economies. Offering these principles to all customers globally helps foster trust and transparency and contributes to reaching global convergence across privacy frameworks. BSA welcomes the leading role that the European Commission is taking on the global scene to support the emergence of “modern data protection regimes […] designed to afford individuals a high level of protection while facilitating data flows in a way that maximizes economic opportunity and consumer interests3.” The EU has a critical role to play to encourage international privacy best practices and interoperability of privacy systems.
…has a critical role to play to encourage international privacy best practices and interoperability of privacy systems. BSA offers this feedback based on member companies’ practical experience of GDPR implementation and highlights areas that could benefit from further attention from the European Commission and DPAs. BSA concurs with the European Data Protection Board (EDPB)4 that it is premature to revise the legislative text at this point in time and welcomes continued discussion with its members to further improve the GDPR in practice. COVID-19 test case The difficult times stemming from the COVID-19 pandemic are challenging our societies in unprecedented ways.
…test case The difficult times stemming from the COVID-19 pandemic are challenging our societies in unprecedented ways. They are also testing the GDPR against unpredictable yet very real situations and have highlighted among others the high-level of adoption of software technologies across economies and communities, including technologies that facilitate the ability of companies and employees to work remotely and technologies that enable contract tracing applications that are currently being developed.
…to work remotely and technologies that enable contract tracing applications that are currently being developed. BSA members are taking responsible action to address the COVID-19 crisis in an number of ways, including by providing free access to their services; advice and help regarding remote work; helping track and disseminate information on the spread of the virus; supporting medical research efforts and the production of personal protective equipment; preventing the spread of malicious campaigns including email spam, malware, and ransomware; and partnering with governments to keep people safe.5 Some of these activities require by nature processing of sensitive personal data, including in the employment context. This triggers the application of additional GDPR provisions, to which Member States can add specific conditions under Article 89.
…the application of additional GDPR provisions, to which Member States can add specific conditions under Article 89. This situation has highlighted the need for a harmonized approach to data protection, as companies and public authorities use data in connection with urgent efforts to combat the pandemic and to adapt to pandemic remediation measures. For example, the narrow interpretation adopted by some DPAs to limit legal grounds for processing of sensitive data to explicit consent creates uncertainty for companies seeking to use data to help address these dramatic circumstances (including, at the very least, to ensure the safety of their employees) while continuing to abide by the necessary requirements for sensitive data processing.
…the safety of their employees) while continuing to abide by the necessary requirements for sensitive data processing. In this context, clarity and harmonization are paramount, and it is important to clarify that public interest and legitimate interest could serve as legal basis for processing of sensitive data. 3 https://eeas.europa.eu/delegations/india/53963/node/53963_zh- hans?Consumers_to_the_Ministry_of_Electronics_and_Information_Technology_%28MeitY%29= 4 EDPB “Contribution of the EDPB to the evaluation of the GDPR under Article 97” 5 https://www.bsa.org/covid19 Avenue des Arts 44 P +32 (0)2 274 13 10 1040 Brussels W bsa.org Belgium EU Register of Interest Representatives 75039383277-48 Consistency mechanism & European Data Protection Board The consistency mechanism has been an important improvement introduced by the GDPR over the Directive 95/46.
Board The consistency mechanism has been an important improvement introduced by the GDPR over the Directive 95/46. The EDPB should play an important role to ensure that the GDPR is interpreted and enforced in a harmonized manner across Member States, that individuals benefit from a coherent application of subjects rights and redress mechanisms, and that reversely, companies have the guidance they need to reach compliance while being able to tailor their compliance programs to their specific situation and needs. Nevertheless, BSA is concerned that some DPAs are not fully committed to the consistency mechanism and still seek to assert their own jurisdiction, approaching GDPR compliance and enforcement differently.
37 → 12