IV · Trade and business associations · AT
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 103 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
…1 FEEDBACK ON THE REPORT ON THE GENERAL DATA PROTECTION REGULATION BY THE FEDERATION OF AUSTRIAN INDUSTRIES The Federation of Austrian Industries (IV) is the voluntary and independent organisation representing the interests of Austrian industry and its associated sectors. It represents the interests of its more than 5,000 members from the manufacturing sector, the banking industry, infrastructure and industry-related services in the Austrian states, to the Austrian government and in Europe. IV members represent more than 80% of Austria’s domestic manufacturing companies. 1. General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? Overall, the GDPR has achieved a major improvement in the protection of personal data and the rights of individuals.
Overall, the GDPR has achieved a major improvement in the protection of personal data and the rights of individuals. Times have changed and personal data is of increased importance as well as more endangered than ever before. The GDPR is therefore - even in a global context - an achievement for society and its development. The GDPR has become a global privacy standard as can be seen by other states worldwide adopting the principles of the GDPR in their local privacy laws (e. g. Brazilian Data Protection Law (LGPD), Swiss Federal Data Protection Act, different U.S. State Privacy Laws). Nevertheless, due to the progressiveness of the GDPR there are challenges especially regarding international transfers of personal data while upholding the data protection standards of the GDPR and the effective and efficient exercise of data subject rights.
…upholding the data protection standards of the GDPR and the effective and efficient exercise of data subject rights. On the level of the European Union there is also the challenge of different approaches, interpretations, and enforcement of the GDPR by the local Data Protection Authorities and national courts. Further complexity is introduced due to different approaches of the national legislators when it comes down to making use of the opening clauses in the GDPR. An additional layer of complexity is also introduced since not all responsible supervisory authorities are equipped with comparable personal and financial resources.
…since not all responsible supervisory authorities are equipped with comparable personal and financial resources. Priority issues that should be addressed by the European Commission and the Parliament are amongst others: • International transfers that should be harmonized to strengthen the European Union and the European Economic Area and its global competitiveness, • a unified approach to procedural aspects of the GDPR and • a uniform interpretation of obligations of the GDPR. It has to be stated that the GDPR and compliance therewith resulted in a substantial amount of time and resources (including financial resources) to be dedicated to the project of Ref. Ares(2024)881743 - 06/02/2024 2 implementing an adequate information management and privacy system in the respective companies.
- 06/02/2024 2 implementing an adequate information management and privacy system in the respective companies. Especially small and medium sized enterprises had difficulties to implement the necessary procedures in their organization. It therefore remains necessary to cut red tape and tackle administrative burdens. One of many important issues should be the compatibility of GDPR with new technologies and the material scope of GDPR; regarding the latter, a similar approach like in the UK’s recent data protection reform would be desirable: “personal data” should be limited to those data that enable the identification of a natural person only at the time of the processing. This is an attempt to provide a more pragmatic and application-safe solution for the increasingly difficult distinction between personal, pseudonymized, and anonymous data in practice.
…solution for the increasingly difficult distinction between personal, pseudonymized, and anonymous data in practice. Furthermore, the fact that companies belonging to the same group and subject to the same internal regulations have to be treated like third-party companies means an additional effort that does not increase data protection level. The currently valid provisions on data protection lack a group privilege in particular. It is not discernible why both customer and employee personal data, in the case of their processing within the meaning of the GDPR, an entry in the register of procedures to be kept, including the necessary information and actions, such as in particular the conclusion of an order processing agreement, should be protective or expedient, as long as the data are not transferred to third parties outside the group for processing or otherwise.
…or expedient, as long as the data are not transferred to third parties outside the group for processing or otherwise. Also, the legal term processing without restriction can be interpreted very broadly and, if strictly interpreted, every MS Excel sheet with employee names, which by nature is stored electronically, can already constitute data processing within the meaning of the GDPR and make the associated legal requirements necessary. This is not feasible in practice. In particular, the two circumstances mentioned above cause a significant internal effort, which makes neither the national company nor the company group in Europe appear more attractive or competitive.
…effort, which makes neither the national company nor the company group in Europe appear more attractive or competitive. (It should be noted that it is not data protection per se, but rather the associated internal effort in connection with the internal processing of customer and employee data of a Group company that is seen as excessive.) Public authorities are very often not interested in the GDPR (e.g., if they are doing a procurement that involves data processing), which very often puts the contracting party in a non-GDPR compliant situation because the authority is not interested to sign a DPA. Often these are those authorities that are exempt from sanctions. On the other hand, we see authorities including localization requirements in their tender documents that data must not leave a specific country, which we see as unlawful discrimination against non-local bidders.
…that data must not leave a specific country, which we see as unlawful discrimination against non-local bidders. Another challenge that has been brought up were international transfers where processors based in Europe try to circumvent their obligations to conclude Model 3 clauses with their sub-processors and argue that European controllers are in most cases direct contractual partners of their sub-processors. 3 A general guideline, which contains also recent decisions and interpretation aids, would be very useful. 2. Exercise of data subject rights a. From the individuals’ perspective: please provide information on the exercise of the data subject rights listed below, including on possible challenges (e.g. delays in controllers/processors reply, clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.).
…clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures, etc.). From the controllers and processors’ perspective: please provide information on the compliance with the data subject rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulty meeting deadlines, identification of data subjects, etc.). Individual’s perspective: The aim of Articles 12 to 14 GDPR is to provide the data subject with transparent and comprehensive information regarding the processing of their personal data.
…the data subject with transparent and comprehensive information regarding the processing of their personal data. In daily life data subjects are overwhelmed with the amount of provided information in privacy notices which in most cases are written in a rather complex legal language containing information about processing of personal data that in practice does not even occur to the described extent and leads to more questions than answers. Most data subjects are not aware of their rights under the GDPR and therefore do not exercise them. If data subjects exercise their rights the provided answers especially regarding Article 15 are rather complex and not easy to understand. Controllers and processors’ perspective: There is a noticeable difference regarding the amount of received data subject right requests depending on the business area in which the controller or processor is active.
…of received data subject right requests depending on the business area in which the controller or processor is active. Due to the possibility of a high amount of automatization of data subject right requests, some controllers receive requests which are sent out in bulk to multiple controllers. Data subjects provide insufficient information regarding their identity and/or request and therefore the controller must access third party platforms by registering and providing corporate information to potentially receive further information regarding the request. The main challenge for the controller is the cooperation of the data subject so that the controller can easily dispel any doubt about the identity of the data subject (if any) and doesn’t need to spend additional resources due to the lack of clarity of the request.
57 → 12
INDUSTRIELLENVEREINIGUNG ̵ SCHWARZENBERGPLATZ 4 ̵ 1031 WIEN ̵ T+43 1 711 35-0 ̵ F DW 2910 ̵ MAIL. [email protected] ̵ WWW.IV.AT ZVR. 806801248 ̵ LIVR-N. 00160 ̵ EU-TRANSPARENZREGISTER NR. 89093924456-06 BANK. UNICREDIT ̵ BANK AUSTRIA ̵ IBAN. AT 82 1100 0006 6301 8000 ̵ BIC. BK AUATWW Federation of Austrian Industries Feedback concerning the evaluation and review of the General Data Protection Regulation by the EU Commission pursuant to Article 97 GDPR As the voluntary and independent representation of the Austrian industry and its related sectors, the Federation of Austrian Industries (Industriellenvereinigung – IV) promotes an attractive business location boasting competitive framework conditions so companies and employees can work successfully in Austria and Europe.
…boasting competitive framework conditions so companies and employees can work successfully in Austria and Europe. A federal organisation, nine regional groups and the Brussels office represent the issues of its currently more than 4,400 members in the manufacturing sector, banking and insurance as well as infrastructure and industry-oriented services in Austria and Europe. Information security and data protection must be guaranteed in the European market and respective European regulation should always ensure international competitiveness. The GDPR should therefore create a strong basis with the utmost legal certainty. The IV welcomes the opportunity to provide input to the report on the evaluation and review of the General Data Protection Regulation (GDPR). I.
…to provide input to the report on the evaluation and review of the General Data Protection Regulation (GDPR). I. General remarks Despite the goal to harmonize existing national legislation, the EU GDPR still leaves too much space for contradicting national laws. This is especially difficult to handle for groups of companies with partly decentralized decision-making structures and thus negatively influences the proper design and legal embodiment in accordance with the GDPR and the respective local laws of controller/controller and controller/processor relationships with further strong impact on other GDPR-requirements (e.g. diverging regulations regarding DPIA on national level). As the GDPR leaves many questions unanswered, advice and setting definitions via guidelines is especially important.
As the GDPR leaves many questions unanswered, advice and setting definitions via guidelines is especially important. The European Data Protection Board (EDPB) should therefore take a more active role in publishing guidelines in order to develop a uniform European understanding of data protection. It would be helpful if the European Data Protection Board reacted to new technological developments and innovations and provided recommendations on how to deal with them (e.g. Clouds, AI, Guidelines for technical and organizational changes). Ref. Ares(2020)2299572 - 29/04/2020 2 II. Special remarks – need for action a. Art 6 – Lawfulness of processing In practice there are many uncertainties when it comes to define which legal basis should apply to the processing activity. Sometimes several legal bases could apply. Clarifying guidelines with comprehensive examples are missing in this regard.
…several legal bases could apply. Clarifying guidelines with comprehensive examples are missing in this regard. Hence additional guidelines with comprehensive examples by the EDPB would be helpful. b. Art 6/ recital 48 – group of undertakings Controllers that are part of a group of undertakings or institutions affiliated to a central body may have a legitimate interest in transmitting personal data within the group of undertakings for internal administrative purposes, including the processing of clients' or employees' personal data. The general principles for the transfer of personal data, within a group of undertakings, to an undertaking located in a third country remain unaffected (recital 48). In addition to this, improving effectiveness of processes and services is also a legitimate interest of undertakings for transmitting personal data of clients or employees.
…and services is also a legitimate interest of undertakings for transmitting personal data of clients or employees. The definition of “legitimate interest” should therefore be extended to cover more than administrative purposes, eg. effectiveness of processes and services should be included. c. Art 5 – Period of data storage regarding future legal claims The principle of data minimisation in practice often contravenes the companies interest of keeping (some) data e.g. in cases of future warranty or product liability claims. If most data was deleted due to the principle of data minimisation, companies wouldn’t be able to defend themselves. The processing of data for the purpose of enforcement or defense of legal claims should be given greater consideration as legitimate interests pursuant to Art 6 (1) lit f. d.
…defense of legal claims should be given greater consideration as legitimate interests pursuant to Art 6 (1) lit f. d. Art 12 – Proof of the data subjects identity The controller shall provide information (on action taken) on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary. In times of increasing cybercrime such as email frauds, companies cannot be careful enough. Due to security reasons and the protection of personal data the proof of identity is therefore essential when dealing with the data subjects rights such as the right of access.
…the proof of identity is therefore essential when dealing with the data subjects rights such as the right of access. There is no reasonable doubt on the identity of the data subject, if the data subject has submitted information, that is either known only to the data subject and the controller or is not publicly available and the controller is able to identify the data subject based on the provided information. 3 When asking for proof of identity however there is remaining doubt about when the above-mentioned period of one month starts. It should be clarified that the period should start at the point at which there is no reasonable doubt about the identity of the data subject. e. Art 15 – Obligation of professional secrecy Art 14 includes a list of exceptions.
…the identity of the data subject. e. Art 15 – Obligation of professional secrecy Art 14 includes a list of exceptions. Information must not be provided for instance where personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy. Art 15 however misses a corresponding list of exceptions. This differentiation is inexplicable, as Art 15 is principally congruent with Art 14 regarding content. The exception of professional secrecy should therefore also be included in Art 15. f. Art 25 – Data Protection by Design and by Default The definition of Data Privacy by Default is not clear; especially the comparison to Data Privacy by Design leaves room for questions about what the difference between these two definitions exactly is.
…to Data Privacy by Design leaves room for questions about what the difference between these two definitions exactly is. A clearer differentiation between “Design” and “Default” would be helpful. g. Art 26 – Joint controllers The processing of data as joint controllers is regulated merely in general terms and could therefore be specified. Art 26 especially lacks - a detailed definition of „joint controllers“. It is sometimes difficult to distinguish it from a processor or separate controllers. - a specification which information they have to obtain. - a specification what should be part of the information about the joint controller arrangement given to data subjects. h. Art 35 – Data Protection Impact Assessment (DPIA) In practice there are some uncertainties how comprehensive a DPIA should be.
– Data Protection Impact Assessment (DPIA) In practice there are some uncertainties how comprehensive a DPIA should be. Clarifying guidelines with comprehensive examples, especially for processes that are applicable to many companies (e.g. video surveillance systems), are therefore considered necessary. i. Art 45ff – Transfers of personal data to third countries or international organisations Re Art 45 (adequacy decision): The possibility to assess the adequacy of the level of protection as an instrument to regulate data transfers is not being used by the Commission up to the possible substantial extent. Far too few countries, among these some of non-major relevance for personal data transfers (e.g. Faroe Islands), have 4 been declared having a similar data protection level. Stepping up of efforts for negotiations, evaluations, etc.
…have 4 been declared having a similar data protection level. Stepping up of efforts for negotiations, evaluations, etc. to include countries of major global relevance for personal data transfers is needed. The commission should also issue an adequacy decision for the UK to ensure that ongoing transfers can continue without additional safeguards. Re Art 46ff (appropriate safeguards): In practice, standard contractual clauses often are the only feasible safeguard for international data transfers. Hence, the standard contractual clauses should be revised and updated. Furthermore, the Commission should adopt further sets of standard contractual clauses. In particular, it should adopt a set of standard contractual clauses for data transfers from processors in the EU to sub-processors established outside the EU or EEA.
16 → 12