EFAMRO

Interesų grupė

Kategorija
Būstinė
Registruota
Deklaruotos metinės išlaidos
(pačios deklaruota)
Skaidrumo registras
90847842431-88
0
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Ką pateikė viešoms konsultacijoms

2020-04-21 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Market, social and opinion research plays a key role in helping businesses and other constituencies better understand consumers, customers and citizens in developing goods and services and is essential for economic efficiency, innovation and progress. Social and opinion research is widely used by public bodies to understand citizens’ preferences and measure key performance indicators, for example the Eurobarometer surveys carried out by the European Commission, and government studies used for improving educational, healthcare and police services. Research in itself does not seek to change or influence opinions or behaviour. Unlike direct marketing, advertising or other commercial…

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 9 p.

Camilla Ravazzolo - Head of Policy and Standards EFAMRO www.efamro.eu A Response to the EC’s Roadmap Report on the General Data Protection Regulation Ref. Ares(2020)2158315 - 21/04/2020 Position Paper EFAMRO, EphMRA and BHBIA Position Paper A Response to the EC’s Roadmap Report on the General Data Protection Regulation This paper is submitted on behalf of: • EFAMRO1, the European Federation of Associations of Market Research Organisations. Founded in 1992, EFAMRO represents the interests of market, social and opinion research in Europe. Its members are national trade associations for research businesses. • EphMRA2 the European Pharmaceutical Market Research Association, develops and improves standards and techniques for global market research in the field of health and healthcare, supports its members in their international activities to create transparency to the general benefit.

…and healthcare, supports its members in their international activities to create transparency to the general benefit. • BHBIA3, the British Healthcare Business Intelligence Association, is an industry association representing companies involved in healthcare market research and data analytics in the UK. It is a long established and association and almost all pharmaceutical, medical device and biotech companies and business intelligence agencies with a UK base, are members. 1www.efamro.eu EU transparency Register ID Number : 90847842431-88 2 www.ephmra.org 3 www.bhbia.org.uk Background information about market and social research Market, social and opinion research plays a key role in helping businesses and other constituencies better understand consumers, customers and citizens in developing goods and services and is essential for economic efficiency, innovation and progress.

…and citizens in developing goods and services and is essential for economic efficiency, innovation and progress. Social and opinion research is widely used by public bodies to understand citizens’ preferences and measure key performance indicators, for example the Eurobarometer surveys carried out by the European Commission, and government studies used for improving educational, healthcare and police services. Research in itself does not seek to change or influence opinions or behaviour. Unlike direct marketing, advertising or other commercial communications, it does not seek to promote the aims or ideals of those who conduct or commission it. While research is used by marketers to test their products or messages, it is not a commercial communication.

…it. While research is used by marketers to test their products or messages, it is not a commercial communication. EFAMRO, EphMRA and BHBIA are pleased to contribute to the European Commission’s (Commission) 2020 evaluation and review of the General Data Protection Regulation (GDPR). This position paper is based on the feedback of our members on their experience with the application and implementation of the GDPR. EFAMRO, EphMRA and BHBIA members have a long-standing tradition in promoting, developing, supporting and regulating standards and innovation in the realm of privacy and data protection via the associations’ Codes of Conduct and accompanying guidelines which underpin membership of the EFAMRO member associations.

…associations’ Codes of Conduct and accompanying guidelines which underpin membership of the EFAMRO member associations. 1. Evaluate and review the application and functioning of the GDPR in its entirety by carrying out an extensive consultation process of society at large and analyse the practical implications of the regulation. No matter the extent of EC’s evaluation and review, EFAMRO, EphMRA and BHBIA strongly believe that this should be taken as valuable opportunity to gather business and civil society’s practical experience with the implementation of the GDPR. As correctly pointed out by the Council of the European Union (Council), the Commission should evaluate and review the application and functioning of the GDPR beyond what is specifically mentioned in article 97 by also considering the experiences and input of relevant stakeholders. This will help to ensure that the evaluation…

…and input of relevant stakeholders. This will help to ensure that the evaluation is as comprehensive as possible4. 2. International Transfers a. Review and update Standard Contractual Clauses and adopt new EU processor to non-EU or EEA processor clauses With only 13 adequacy decisions in place, businesses need to refer to other tools listed in Chapter V. Standard contractual clauses for data transfers to third countries have not been updated since they were originally adopted. The Commission should urgently review and revise the standard contractual clauses and consider the needs of controllers and processors with the addition of new clauses to cover EU processor to non-EU or EEA processor data transfers, following up the Article 29 Working Party Working document 01/2014 on Draft Ad hoc contractual clauses “EU data processor to non-EU sub-processor". 4 Council position and findings on…

Regulation (GDPR) – Adoption 14994/1/19 REV 1 https://data.consilium.europa.eu/doc/document/ST-14994-2019-REV-1/en/pdf 3. Codes of Conduct The different sectorial experiences in devising sector Codes has demonstrated that there is some degree of uncertainty left regarding Codes of Conduct by sectors and the same Data Protection Authorities that should be in charge of adopting them5. Even greater uncertainty rests on how to use sector Codes in the framework of international transfers. The Commission should clarify the practical and technical implications of Art. 46(2 – e) an approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects’ rights.

…or processor in the third country to apply the appropriate safeguards, including as regards data subjects’ rights. The EC should also take this occasion to clarify other important aspects of Codes of Conduct and in particular: • Is it possible and admissible to have more than one approved Code of Conduct in a given sector? • Is it possible and admissible for a single controller or processor to adhere to more than one Code of Conduct, including Codes applicable to different sectors? If so, how are potentially conflicting sector Code requirements resolved? By the European Data Protection Board (EDPB)? • What is the binding mechanism of a Code of Conduct to processor who is not party to it? • Can the Commission clarify Art 40.9 and how “implementing acts” will be adopted and with which effect? • How will the interaction between national and transnational Codes be managed?

…will be adopted and with which effect? • How will the interaction between national and transnational Codes be managed? • In case of supervisory authority imposing fine on a Code’s subscriber, what could be the consequences and liabilities for the Code holders? 5 Preparation of the Council position on the evaluation and review of the General Data Protection Regulation (GDPR) - Comments from Member States https://data.consilium.europa.eu/doc/document/ST-12756-2019- REV-1/en/pdf 4. Harmonization and digital single market The GDPR is directly applicable in all Member States but it also leaves a margin for national legislators to maintain or introduce more specific provisions to adapt the application of certain rules. This national margin has resulted in a fragmented legal landscape for some of the GDPR provisions.

…of certain rules. This national margin has resulted in a fragmented legal landscape for some of the GDPR provisions. In turn, the non-uniform application of the GDPR across member states can create obstacles to cross border operations even intra EU. In particular: • Age of consent of a child: the possibility to choose different age limits as provided by Article 8 has given rise to legal uncertainty concerning the applicable law among the Member States in situations where the national laws of two Member States are applicable to a single processing activity. o For instance, to give consent, a child has to be 13 years old in Sweden, 14 years old in Bulgaria and Spain; and 16 in Hungary and the Netherlands. In the other countries, maturity is required6.

…years old in Bulgaria and Spain; and 16 in Hungary and the Netherlands. In the other countries, maturity is required6. • Lawfulness of processing: the possibility for Member States to introduce more specific provisions for when processing is necessary for the performance of a task carried out in the public interest Article 6 1-e and 2, may lead to a rather relaxed approach on the Governments’ side. o See UK Data Protection Act 20187 “democratic engagement” is listed as an example of processing activities that can be undertaken lawfully in the public interest and consider the extent of this when it comes to special categories of data.

…undertaken lawfully in the public interest and consider the extent of this when it comes to special categories of data. o See Irish Data Protection Act 20198 Section 39 A specified person may, in the course of that person’s electoral activities in the State, use the personal data of a data subject for the purpose of communicating in writing (including by way of newsletter or circular) with the data subject. Moreover, the section goes on to state that: ‘Communicating in accordance with subsection (1) shall, for the purposes of Article 6(1)(e), be considered to be the performance of a task carried out in the public interest’.

21 → 12

originalus šaltinis (PDF) ↗