SCOPE Europe (Self and Co-Regulation for an Optimized Policy Environment in Europe)

SCOPE Europe · Think tanks and research institutions · BE

Kategorija
Think tanks and research institutions
Būstinė
Brussels BE
Registruota
2017-11-24
Deklaruotos metinės išlaidos
50 000–99 999 € (pačios deklaruota)
Svetainė
https://scope-europe.eu
Skaidrumo registras
751925529087-67 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

20201

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 1 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
SCOPE Europe highly appreciates the opportunity to contribute to this call for feedback and remains available and eager to continuously support the European Commission's efforts regarding GDPR implementation. Against this background, please find our response here enclosed.
2023-03-24 · Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation ↗ originalus šaltinis
Please, find the detailed joint-feedback as attachment. Following the key messages: 1. It is strongly recommended to extend the understanding of enforcement by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission. Codes of Conduct strongly support harmonization across Europe, by allowing for particularizing ambiguous interpretations in sector-specific manners. The enforcement of Codes of Conduct complements the public actions via data protection supervisory authorities and may significantly increase GDPR compliant yet practical implementations. Compulsory oversight by independent Monitoring Bodies allows for additional robust enforcement.…

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation · 12 p.

European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation Joint Comments by SCOPE Europe and Selbstregulierung Informationswirtschaft March 2023 Ref. Ares(2023)2159348 - 24/03/2023 European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 1 | 10 Publishers Selbstregulierung Informationswirtschaft e.V. Großbeerenstraße 88 10963 BERLIN https://sriw.de [email protected] Associations‘ Register at: Amtsgericht Berlin Charlottenburg Register Number: VR 30983 B VAT: DE301407624 Deutsche Bank AG IBAN: DE33 1007 0000 0550 0590 00 Managing Director Frank Ingenrieth Chair of the Board Dr.

Bank AG IBAN: DE33 1007 0000 0550 0590 00 Managing Director Frank Ingenrieth Chair of the Board Dr. Claus-Dieter Ulmer SCOPE Europe srl Rue de la Science 14 1040 BRUSSELS https://scope-europe.eu [email protected] Company Register: 0671.468.741 VAT: BE 0671.468.741 ING Belgium IBAN BE14 3631 6553 4883 SWIFT / BIC: BBRUBEBB Managing Director Gabriela Mercuri European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 2 | 10 Table of Contents 1 Key Messages ........................................................................................................................ 3 1.1 It is strongly recommended to extend the understanding of enforcement by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission.

…by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission. 3 1.2 It is strongly recommended to review the procedural requirements in receiving a Code of Conduct’s approval and a Monitoring Body’s accreditation. .................................................................................... 3 1.3 In regards of third country transfers, a general validity by implementing act is required. It is strongly recommended to ensure that procedural efforts will be streamlined preventing any unreasonable delays in operationalizing such projects. ................................................................................................. 3 2 About the Authors (Short) .......................................................................................................

Authors (Short) ....................................................................................................... 4 3 Introduction ........................................................................................................................... 5 4 Complementary enforcement tools .......................................................................................... 5 4.1 Sector-Specific Particularization; collecting good and widely adopted practises .................................. 5 4.2 Inherent enforcement and remediation next to authoritative actions ................................................... 6 4.2.1 General Oversight ............................................................................................................................

........................................................................................................................ 6 4.2.2 Additional Oversight and Complaint Channel ................................................................................. 6 4.2.3 Enabling focus of resources and continuous expert’s exchange .................................................. 7 5 Streamlining of procedures under Article 40 and 41 GDPR ........................................................ 7 5.1 Competent data protection authorities for transnational Codes of Conduct, streamline of procedural elements .................................................................................................................................................... 7 5.2 Periods of authoritative actions and potentially prohibitive administrative fees ...................................

…of authoritative actions and potentially prohibitive administrative fees ................................... 8 5.2.1 Periods of processing requests ....................................................................................................... 8 5.2.2 Potentially prohibitive administrative fees ...................................................................................... 8 5.3 Accreditation requirements for Monitoring Bodies .................................................................................. 9 5.4 General validity mechanism for Codes of Conduct as tools for transfers ..............................................

…validity mechanism for Codes of Conduct as tools for transfers .............................................. 9 European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 3 | 10 1 Key Messages 1.1 It is strongly recommended to extend the understanding of enforcement by integrating complementing tools, such as Codes of Conduct, into the evaluation by the European Commission. ■ Codes of Conduct strongly support harmonization across Europe, by allowing for particulariz- ing ambiguous interpretations in sector-specific manners. ■ The enforcement of Codes of Conduct complements the public actions via data protection supervisory authorities and may significantly increase GDPR compliant yet practical imple- mentations.

…data protection supervisory authorities and may significantly increase GDPR compliant yet practical imple- mentations. ■ Compulsory oversight by independent Monitoring Bodies allows for additional robust enforce- ment. ■ Required continuous communication between Monitoring Bodies and data protection super- visory authorities may establish exchange of first-hand experiences, fostering consistent, ro- bust yet practical application of the law. 1.2 It is strongly recommended to review the procedural requirements in receiving a Code of Conduct’s approval and a Monitoring Body’s accreditation. ■ Generally, the legal framework and EDPB’s guidelines are considered suitable, if applied con- sistently.

■ Generally, the legal framework and EDPB’s guidelines are considered suitable, if applied con- sistently. ■ Specifically for transnational Codes of Conduct, harmonized interpretation is appreciated, be- cause projects suffer delays, e.g., by means of consistently and mutually determining the com- petent data protection supervisory authorities. ■ Periods as indicated by GDPR are not yet met in practice. So, it is recommended to adapt such periods to more realistic timelines and to clarify that in case data protection supervisory authorities cannot unanimously determine undisputable conflicts with GDPR, Codes of Con- duct shall be deemed in accordance with GDPR. ■ It is recommended to limit deviations in regards of the accreditation criteria for Monitoring Bodies to the minimum needed, e.g., by different administrative member state laws.

…criteria for Monitoring Bodies to the minimum needed, e.g., by different administrative member state laws. Any ma- terial deviation creates unnecessary obstacles to Monitoring Bodies, which seek to provide their services in several member states, limiting the scalability of their services, which is a key element in ensuring that adherence to Codes of Conduct remains accessible to micro, small and medium sized enterprises. 1.3 In regards of third country transfers, a general validity by implementing act is required. It is strongly recommended to ensure that procedural efforts will be streamlined pre- venting any unreasonable delays in operationalizing such projects. ■ Safeguarding third country transfers is one of the key elements subject to legal, political and operational discussions.

…third country transfers is one of the key elements subject to legal, political and operational discussions. ■ Codes of Conduct may act as a safeguard provide that, next to the formalities to be met for transnational Codes of Conduct in any case, general validity will be granted. ■ Considering the procedural steps of deciding on an implementing act, it is strongly recom- mended to allow for a material assessment by the European Commission and the EDPB in parallel. European Commission’s Initiative: Further specifying procedural rules relating to the enforcement of the General Data Protection Regulation 4 | 10 2 About the Authors (Short) Selbstregulierung Informationswirtschaft e.V. (SRIW) is a non-profit association supporting the self-regulation of the information economy.

…e.V. (SRIW) is a non-profit association supporting the self-regulation of the information economy. It acts as a think tank to discuss and debate key issues in digital policy and provides an umbrella organisation supporting credible and effective self- and co-regulation of the information economy. SCOPE Europe srl (SCOPE Europe) is a subsidiary of SRIW. Located in Brussels, it continues and complement the portfolio of SRIW in Europe. SCOPE Europe gathered expertise in levelling industry and data subject needs and interests to credible but also rigorous provisions and controls. SCOPE Europe has been the first accredited Monitoring Body under the European General Data Protection Regulation (GDPR) since May 2021 related to a transnational Code of Conduct, i.e., EU Data Protection Code of Conduct for Cloud Service Providers.

37 → 12

originalus šaltinis (PDF) ↗

Report on the application of the General Data Protection Regulation · 9 p.

February 2024 Call for Evidence by the European Commis- sion on GDPR SCOPE Europe’s Response Ref. Ares(2024)975849 - 08/02/2024 SCOPE Europe srl Rue de la Science 37 1040 BRUSSELS https://scope-europe.eu [email protected] Managing Director Gabriela Mercuri Company Register: 0671.468.741 VAT: BE 0671.468.741 ING Belgium IBAN BE14 3631 6553 4883 SWIFT / BIC: BBRUBEBB 1 | 8 1 About SCOPE Europe .......................................................................................................................... 2 2 Introduction ......................................................................................................................................... 2 3 SCOPE Europe’s Response ................................................................................................................

................................................................................................................ 3 3.1 Question 1: General Comments ........................................................................................................ 3 a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed?3 3.2 Question 3: Application of the GDPR to SMEs .................................................................................. 4 c. What additional tools would be helpful to assist SMEs in their application of the GDPR? . 4 3.3 Question 12: Codes of Conduct......................................................................................................... 5 a. Do you consider that adequate use is made of codes of conduct?

…5 a. Do you consider that adequate use is made of codes of conduct? ...................................... 5 b. Have you encountered challenges in the development of codes of conduct, or in their approval process? ................................................................................................................................. 6 c. What supports would assist you in developing codes of conduct? ....................................... 7 Call for Evidence by the European Commission on GDPR 2 | 7 1 About SCOPE Europe SCOPE Europe is a Brussels-based organization specialized in the development and implementation of industry-driven standards, such as codes of conduct, with a focus on the data economy. SCOPE Europe was founded in 2017 as a subsidiary of the German non-profit-organization SRIW e.V. (Selbstregulierung Informationswirtschaft).

…in 2017 as a subsidiary of the German non-profit-organization SRIW e.V. (Selbstregulierung Informationswirtschaft). In May 2021, SCOPE Europe became the first accred- ited Monitoring Body under the European General Data Protection Regulation (GDPR), pursuant Art. 41, for a transnational code of conduct and, in 2023, received its second accreditation, this time to monitor a national code of conduct in the Netherlands. With a long track record of addressing regulatory challenges posed by the digital economy – notably for data processing technologies –, SCOPE Europe has largely contributed to the shaping of co-regu- latory mechanisms and the setting of effective privacy standards across the European Union (EU).

…shaping of co-regu- latory mechanisms and the setting of effective privacy standards across the European Union (EU). In this regard, SCOPE Europe was also one of the leading stakeholders responsible for the development of the first EU-wide operational data protection standard under the GDPR, namely, the EU Cloud Code of Conduct. 2 Introduction With years of experience in the field of designing and monitoring GDPR compliance tools, SCOPE Europe has developed a unique expertise when it comes to identifying and assessing core issues in this sphere. In this context, SCOPE Europe highly appreciates the opportunity to contribute to this call for feedback of the European Commission (the Commission).

…highly appreciates the opportunity to contribute to this call for feedback of the European Commission (the Commission). As SCOPE Europe, we strongly believe in the importance of establishing such communication chan- nels to enable meaningful inputs by stakeholders dealing with the materialization of GDPR require- ments on a daily basis. Therefore, we are eager to contribute to the evaluation and subsequent efforts for an appropriate application of the GDPR throughout the EU. Considering our field of activity, SCOPE Europe will solely provide responses to the questions that fall under our area of expertise. Finally, with this feedback, SCOPE Europe aims to continuously foster GDPR compliance and, ultimately, an effective and fair European digital transition. Call for Evidence by the European Commission on GDPR 3 | 7 3 SCOPE Europe’s Response 3.1 Question 1: General Comments a.

…for Evidence by the European Commission on GDPR 3 | 7 3 SCOPE Europe’s Response 3.1 Question 1: General Comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? Since becoming applicable, GDPR has significantly transformed the way personal data is handled within and beyond the EU. Such impact is evident once observing subsequent global regulatory de- velopments in the field as well as the dissemination and acute specialization of privacy-related func- tions across our job markets. The substantial shift of GDPR in terms of enforcement – once compared to its predecessor –, has promptly propelled businesses to either establish or sophisticate their prac- tices and often seek to build a privacy-friendly culture.

…businesses to either establish or sophisticate their prac- tices and often seek to build a privacy-friendly culture. Without undermining how previous regulatory efforts have paved the way for the establishment of solid data protection practices, it is safe to say that GDPR’s strong incentives had a crucial role in promoting a more consistent and substantial step towards the recognition and adequate protection of data subjects’ rights. Moreover, this important upswing in the data protection trajectory is partic- ularly relevant if we consider how this is still a relatively new topic which is constantly affected by complex and fast-paced technical developments. With that being said, given the multiple asymmetries across and within different Member States – as well as across and within sectors of our economy –, the impact of GDPR has been far from homoge- nous.

States – as well as across and within sectors of our economy –, the impact of GDPR has been far from homoge- nous. Therefore, once analysing our path since May 2018, we believe that in order to optimize GDPR implementation in the coming years, the following priorities should be pursued: Harmonization of legal interpretation and im- plementation Increase Transparency and Public Aware- ness Enable Foreseeability and Legal Certainty Enhance Consistency in the Application of the Risk-Based Approach Considering the challenges to concretize these priorities and the mechanisms we have at our disposal to enhance GDPR’s proper implementation and enforcement, we would like to emphasize the role of codes of conduct (pursuant Article 40 GDPR).

…implementation and enforcement, we would like to emphasize the role of codes of conduct (pursuant Article 40 GDPR). When it comes to these tools, SCOPE Europe can Call for Evidence by the European Commission on GDPR 4 | 7 provide first-hand insights on their day-to-day impact and, consequently, on their potential to support the achievement of the abovementioned goals. As products of what we believe to be a suitable and coherent legal framework established by GDPR, codes of conduct – especially those at the transnational level – have the power to: Harmonize legal interpretation and application not solely across a given industry, but also among different Member States and data protection authorities. This is particularly true for codes that are required to go through the European Data Protection Board (EDPB).

This is particularly true for codes that are required to go through the European Data Protection Board (EDPB). Translate complex actions and provisions into clear statements of compliance, which fosters transparency, accountability, and reduces information asymmetries. Support the materialization of accurate risk-based approaches - e.g. by the drafting of appro- priate provisions and the establishment of a monitoring scheme that suits particular pro- cessing contexts. Promote mutual understanding between data protection authorities and the industry. This is specially helpful when dealing with highly complex technologies that entail significant risks and require remarkably well-designed and specific technical and organizational measures.

…that entail significant risks and require remarkably well-designed and specific technical and organizational measures. Provide a suitable framework and the necessary legal certainty to enable SMEs to safely op- erate while fully leveraging the advantages of our data economy. Considering the capacity to enable harmonization, accountability, transparency and trust, SCOPE Eu- rope believes that, up until now, these tools are still underutilized. Against this background, we are pleased to contribute to this consultation by sharing our practical experience with the development and implementation of codes of conduct and hope that, with this feedback, we can meaningfully support their dissemination and proper application. 3.2 Question 3: Application of the GDPR to SMEs c. What additional tools would be helpful to assist SMEs in their application of the GDPR?

26 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

GDPR, Privacy, International Data Flows, Data Act, Data Governance Act, EU Artificial Intelligence Act, Digital Decade Policy Programme 2030, Digital Rights and Principles, EU Cloud Rulebook, EU Standardisation Strategy, European Data Strategy, Digital Services Act, Digital Markets Act, European Cybersecurity Certification Scheme for Cloud Services.