SP ČR · Trade and business associations · CZ
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 35 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
PHONE (+420) 225 279 111 | E-MAIL [email protected] WEB WWW.SPCR.CZ | ADDRESS FREYOVA 948/11, 190 00 PRAGUE 9, CZECH REPUBLIC THE CONFEDERATION OF INDUSTRY OF THE CZECH REPUBLIC HAVE SIGNED UP TO THE EU TRANSPARENCY REGISTER AND THE ASSOCIATED CODE OF CONDUCT. REGISTER IDENTIFICATION NUMBER: 785320514128-81. MEMBER OF Positive impact of GDPR: 1. Streamlining privacy operations: GDPR has required us to unify our operating model, providing greater insight into where personal information (PI) is collected, used, and accessed. 2. Regulatory readiness: Creating privacy-related internal standards and consistency has enabled the business to respond to various kinds of regulatory changes with greater speed and accuracy.
…consistency has enabled the business to respond to various kinds of regulatory changes with greater speed and accuracy. 3. Insights into PI processing and data usage: GDPR required business, as well as customer businesses, to understand which processing activities exist within the entity, as well as their owners, data categories and data flows. 4. Greater awareness of the importance of trust and transparency: GDPR raised general awareness among customers on the importance of trust and transparency in the digitalized world, e.g., in terms of communication, business processes, and the broader societal debate around privacy and data protection. Overall, GDPR was a catalyst for the digitization and streamlining of data processing, and contributed to facilitate the digital transformation of the economy as such. Issues with/negative impact of GDPR:
…and contributed to facilitate the digital transformation of the economy as such. Issues with/negative impact of GDPR: 1. Lack of harmonization: A harmonized privacy regime across Europe is not always applicable due to the different and sometimes conflicting views of local authorities. We need for better coordination between centralized bodies (such as the EDPB) and local authorities. 2. Privacy by Design is not always easy to implement, especially in the data transfer regime, as most provisions (Transfer Impact Assessments, the EU SCC 4-models-mechanism) imply a case-by-case assessment, which makes automation and a risk-based approach implementation very difficult.
…imply a case-by-case assessment, which makes automation and a risk-based approach implementation very difficult. 3. Challenges to the Risk-Based Approach (RBA), due to gaps between the RBA as a core principle of GDPR (5(2), 24 and 35) and how its interpretation (by EDPB) changed following the Schrems II judgement, challenging its applicability when it comes to Chapter V (ie interpreting Schrems II and GDPR to say that the RBA no longer applies to data transfers under Chapter V).
V (ie interpreting Schrems II and GDPR to say that the RBA no longer applies to data transfers under Chapter V). 4. Balance of interests: in a series of judgements, the CJEU has substantially raised the bar for controllers to comply with a data subject access request. It would be helpful if regulators can seek a reasonable balance and also give attention to the impact that data access requests can have on controllers and their organizations, recognizing limits to what may be reasonably expected from a controller. For example: a. Over the past years, data subject requests have been massively weaponized by lawyers (representing disgruntled employees). b. Another concern is the impact on confidentiality rights, especially in an employment context and the conflict with privacy rights in the context of the "Barbulescu vs Romenia" case (European Courts of Human Rights), the Convention for the…
Rights), the Convention for the Protection of Human Rights and Fundamental Freedoms and the GDPR Data Subject Rights. 5. GDPR sets the bar too high when it comes to data sharing and the secondary use of public available information. The principles for secondary use should also apply to the scraping of publicly available data. In its current approach, the original purpose and the secondary purpose must be set by the same controller. Thus, publicly available data may not be re-used by a different controller. GDPR Ref. Ares(2024)887846 - 06/02/2024 should recognize that individuals have made a lot of data available in the public domain and that a secondary use might well be compatible with the original purpose (even if set out by different controllers). Suggestions for improvement:
…well be compatible with the original purpose (even if set out by different controllers). Suggestions for improvement: 1. Expand and speed-up adequacy decisions, considering their impact on digital trade between the EU and the relevant third country. 2. Ensure a coherent approach by regulators across the EU (i.e., more stringent guidance as opposed to country-specific recommendations), as well as quicker turnaround times and properly staffed Data Protection Authorities. 3. Ensure coherence with other data-related legislation, aligning rules and enforcement for personal and non-personal data to provide more legal clarity for controllers and processors. For example, mixed data sets (with personal and non-personal data) are treated as personal data under GDPR, while non-personal data sets are subject to other data transfer rules as per the EU Data Act.
…personal data under GDPR, while non-personal data sets are subject to other data transfer rules as per the EU Data Act. 4. Special Categories of Data: Regulators could help controllers (e.g., employers driving Diversity and Inclusion programs or organizations training AI systems improving accuracy and fairness) in clarifying best practices for a lawful processing of special categories of data. 5. Anonymization: As the most privacy enhancing technology, it should not be regarded as a processing activity that needs a legal basis, as it removes the possibility to identify a data subject. If the regulator still considers anonymization as a processing activity, it should at least be covered by "legitimate interest" (as anonymization is per se in the interest of the data subject).
…should at least be covered by "legitimate interest" (as anonymization is per se in the interest of the data subject). More detailed commentary on individual topics Exercise of data subject rights The GDPR grants data subjects expansive rights in the areas of data access and portability. Developing the systems to comply with these rights is not only costly but comes with counterbalancing risks and may strain the bounds of what is technically feasible. For instance, providing “all instances” of personal data may lead to an overwhelming “data-dump” of repetitive low risk data that customers cannot comprehend and “porting” such data may in fact engender Data Security risk.
…low risk data that customers cannot comprehend and “porting” such data may in fact engender Data Security risk. The lack of practical guidance on resolving these tensions from the EDPB and DPA’s, as well as detail on what is actually expected with respect to controls under the Accountability Principle (and understanding of how such expectations may change over time), makes it hard for companies to reasonably anticipate or plan for compliance while bearing a disproportionate risk of turnover penalties should their good-faith solutions be deemed insufficient. The sanction is particularly disproportionate where there is no substantive privacy harm to the data subject and considering unintended circumstances where such rights have been invoked (e.g., as a discovery tool in employment litigation).
…unintended circumstances where such rights have been invoked (e.g., as a discovery tool in employment litigation). Beyond that, it would be appropriate to explicitly include in the GDPR a condition for refusal of the data subject's request in cases where the reason for the request is to use the requested information for the subsequent filing of a criminal complaint / civil lawsuit against the data controller, i.e., in practice, there may be self-incrimination of the controller. Alternatively, it would be appropriate to at least charge a fee for such a data subject request. Experience with Data Protection Authorities DPAs are often unwilling to provide tailored guidance which is needed given the horizontal and principles- based nature of the GDPR based on professed resourcing constraints.
…is needed given the horizontal and principles- based nature of the GDPR based on professed resourcing constraints. This is likely due to DPAs being overburdened with a large number of technical breach notifications and formal complaint-handling rather than prioritising their activities based on risks and harms to individuals and focusing their regulatory resources on proactive engagement with organisations and thought leadership activities. The EDPB should create a framework for data controllers to voluntarily reach out to DPAs in good faith, and the DPAs should play a more proactive role in engaging with other regulators to clarify their areas of competence to avoid conflicting rulings. Member States must also ensure that DPA’s are appropriately resourced.
25 → 12