FEBIS · Trade and business associations · DE
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 1 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2026-06-23 | Financial Stability, Financial Services and Capital Markets Union | Exchange of views on FEBIS activities |
…www.febis.org Federation of Business Information Services Föderation für Wirtschaftsinformationsdienste e.V. FEBIS Comments on the GDPR questionnaire – February 2024 FEBIS members are business information providers whose core business model is to provide creditworthiness assessments, credit scores and business information reports on businesses for businesses. Contrary to credit rating, credit scores are done on all businesses’ population of a country, using data management and processing, statistical analysis and analysis technologies owned by business information providers. The raw data used is composed of part of public and open data made available for re-use (e.g.
…information providers. The raw data used is composed of part of public and open data made available for re-use (e.g. part of business registers data) – cf the directive 2019/1024 and its implementing regulation 2023/138 but also a lot of value-added data managed by business information providers under proprietary databases and technologies. Credit scores and business information reports are then used by credit managers or by other businesses when assessing their trade counterparts, making trade credit decisions, doing compliance checks, and fulfilling Know-Your-Customer obligations inter alia. Important to say, business information and credit scoring providers are not financial institutions or financial providers as they do not lend money; they provide data solutions helping the assessment for lending and trade credit decisions to be made. QUESTIONS General comments a.
…data solutions helping the assessment for lending and trade credit decisions to be made. QUESTIONS General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? Sole traders’ data fall into the definition of natural persons’ data, though they refer to the carrying out of a business activity. Therefore, it should be evaluated if and how GDPR should be applicable to these kind of data and subjects. A clearer view is needed on the level of application of GDPR on sole traders data; we recommend an approach based on the capacity under which sole traders interact.
…of GDPR on sole traders data; we recommend an approach based on the capacity under which sole traders interact. Sole traders should encompass all businesses with data available from a public register, be it the trade register but also the craftsmen register or the business register, and the legal form of the business should not matter. Indeed, as driven by the EC definition, a business should be anyone acting in his trade, business or profession, as opposed to a consumer which is anyone acting outside his trade, business or profession. Both citizens and businesses need to have a clear view on the applicable laws and regulations and the way they interact, and at the moment many businesses find the coordination between all relevant EU laws difficult.
…the way they interact, and at the moment many businesses find the coordination between all relevant EU laws difficult. One example could be again the definition of enterprise which in the Data Act comprise both natural and legal persons acting in business capacity. FEBIS recommends that this definition of an enterprise should be replicated in all EU regulations and laws thus enabling to differentiate between private/natural persons and businesses Ref. Ares(2024)963811 - 08/02/2024 www.febis.org Federation of Business Information Services Föderation für Wirtschaftsinformationsdienste e.V. whatever the legal business form is (sole traders and associations included).
…für Wirtschaftsinformationsdienste e.V. whatever the legal business form is (sole traders and associations included). In providing business information services, one of the purposes pursued is compliance with AML laws and regulations, which also implies the processing of data falling under the definition of article 10; differently from article 9, this kind of processing is also left to the authorization of Member States’ laws (not always adopted or adequately defined, causing uncertainty in the application of the relevant discipline). In our opinion there’s a major discrepancy between articles 9 and 10, which leads to a different treatment of data related to criminal convictions and offences, that cannot be processed occurring the same kind of exemptions set forth in article 9.
…convictions and offences, that cannot be processed occurring the same kind of exemptions set forth in article 9. We suggest a rethinking of this approach, maybe by introducing some exemptions in article 10, as it has been done in article 9, especially in relation to data retrieved from the so-said bad press, also in consideration of the availability of such information on the public sources. 2. Exercise of data subject rights a. From the individuals’ perspective: please provide information on the exercise of the data subject rights listed below, including on possible challenges (e.g. delays in controllers/processors reply, clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.).
…clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.). From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.).
(e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). • Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) • Access to data (Article 15) • Rectification (Article 16) • Erasure (Article 17) • Data portability (Article 20) • Right to object (Article 21) • Meaningful explanation and human intervention in automated decision making (Article 22) It would be important to better assess the division of duties between data controllers and data processors, as there may be multiple data holders in various economic chain management who may not all have the same interaction possibilities with the final user, and the first-party data holder should be the one responsible for data management.
…with the final user, and the first-party data holder should be the one responsible for data management. It also seems important to see the links that may exist between article 22 and the balancing test and with the national/sectoral legislation that may have different interpretations. Furthermore, there are some divergences of both definitions and principles with other legislation such as the discrepancies with ratings/scoring legislation, artificial intelligence and GDPR especially on the human intervention/non- www.febis.org Federation of Business Information Services Föderation für Wirtschaftsinformationsdienste e.V. intervention contradicting requirements that may exist between article 22 of the GDPR and the Credit Ratings Regulation.
…contradicting requirements that may exist between article 22 of the GDPR and the Credit Ratings Regulation. We would like to understand the Commission’s view regarding this matter, also in the light of the recent CJEU decision , since we are encountering interpretation and application difficulties. Moreover, especially regarding the right of access, we have experienced the receival of a large number of instrumental requests coming from subjects that provide this kind of service, also in connection with other consulting services and/or support to indebted clients; we think that the category of subject which could be delegated to make such requests should be more strictly and accurately defined, exclusively in order to protect data subjects’ rights.
…such requests should be more strictly and accurately defined, exclusively in order to protect data subjects’ rights. Where possible please provide a quantification and information on the evolution of the exercise of these rights since the entry into application of the GDPR. b. Do you avail of / are you aware of tools or user-friendly procedures to facilitate the exercise of data subject rights? c. Do you have experience in contacting representatives of controllers or processors not established in the EU? d. Are there any particular challenges in relation to the exercise of data subject rights by children?
26 → 12