L'Afep · Trade and business associations · FR
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 134 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
RGPD - Coordination autorités nationales – Contribution Afep 1 Rationaliser la coopération entre autorités nationales chargées de la protection des données personnelles Appel à contribution de la Commission européenne – Réponse de l’Afep La DG Justice de la Commission a ouvert fin février un appel à contribution pour rationaliser la coopération entre les autorités nationales chargées de la protection des données lors de l'application du Règlement général sur la protection des données (RGPD) dans les cas transfrontaliers. Dans ce cadre, elle souhaite recueillir des commentaires sur les divergences apparues dans les approches suivies par ces autorités nationales de contrôle depuis l'entrée en application du règlement en mai 2018 (traitement des réclamations, formulaires pour celles-ci, durée des procédures ou droit à être entendu).
…en mai 2018 (traitement des réclamations, formulaires pour celles-ci, durée des procédures ou droit à être entendu). La participation des plaignants au cours de la procédure, y compris la fourniture d’informations sur l’état d’avancement de l’enquête, est également un thème sur lequel la Commission attend des réponses. L’Afep remercie la Commission de cette initiative qui appelle plusieurs commentaires. En tant qu’acteurs économiques européens et internationaux, les grandes entreprises françaises représentées par l’Afep soulignent d’abord leurs difficultés lorsqu’elles sont confrontées à de multiples autorités nationales de contrôle et préconisent diverses modifications. Elles proposent ensuite des orientations pratiques destinées à contribuer aux améliorations recherchées par la Commission en matière d’enquête.
…des orientations pratiques destinées à contribuer aux améliorations recherchées par la Commission en matière d’enquête. A/ Les difficultés des entreprises européennes confrontées à la multiplicité d’avis émanant des autorités de contrôle en Europe Les entreprises membres de l’Afep sont attachées au respect du RGPD qui fonde un cadre structurant pour la protection des données personnelles en Europe, source d’exemplarité également dans le reste du monde. Cependant, si les entreprises ont à cœur de promouvoir ces hautes exigences au sein de l’ensemble de leurs structures, elles déplorent les divergences d’approche ou d’interprétation de ce texte fondateur parmi les autorités nationales de contrôle (« ANC »), y compris au travers de textes présentés comme éclairant ou accompagnant les acteurs économiques. 1.
ANC »), y compris au travers de textes présentés comme éclairant ou accompagnant les acteurs économiques. 1. Les DPO et les avis/guides des ANC Les ANC publient des textes normatifs (avis, guides…) sans aucune coordination entre elles, segmentant ainsi la mise en œuvre du règlement de 2016 censé harmoniser les pratiques autant des ANC que des parties prenantes (responsables de traitement ou sous-traitants). Les rédactions de ces textes sont propres à chaque Etat membre pour respecter – à juste titre - les législations nationales dans toutes leurs spécificités. Elles ne prennent cependant pas en compte leurs implications concrètes pour un acteur économique possédant des filiales au sein de plusieurs Etats membres.
…leurs implications concrètes pour un acteur économique possédant des filiales au sein de plusieurs Etats membres. Celui-ci se trouve alors confronté à une mise en œuvre complexe d’un texte d’une ANC, élaboré à l’aune d’une législation spécifique, ayant des conséquences directes sur le respect d’autres dispositions nationales. Ref. Ares(2023)2149187 - 24/03/2023 RGPD - Coordination autorités nationales – Contribution Afep 2 Cette confrontation normative induit de réelles difficultés pratiques de mise en œuvre, doublées de coûts divers (consultations extérieures, temps consacré à la pédagogie auprès des équipes en interne déroutées par des contraintes inconnues localement, etc.).
…temps consacré à la pédagogie auprès des équipes en interne déroutées par des contraintes inconnues localement, etc.). En outre, des questions juridiques très concrètes se posent pour les acteurs européens, telle que la possibilité pour une ANC d’un Etat membre X de les sanctionner pour avoir mis en œuvre, sur son territoire, les recommandations d’une ANC d’un autre Etat membre Y. Face à ces difficultés, les entreprises proposent la mise en place d’un système de reconnaissance mutuelle lorsque, dans le cadre de recommandations/lignes directrices, une autorité interprète une disposition du RGPD à l’exclusion de l’application concomitante de toute disposition spécifique de droit national. L’entreprise pourrait bénéficier d’un délai de grâce dans l’attente que le cas soit remonté au CEPD dans le cadre de la mise en œuvre du mécanisme de cohérence.
…de grâce dans l’attente que le cas soit remonté au CEPD dans le cadre de la mise en œuvre du mécanisme de cohérence. Ainsi, la prise en considération de cette incohérence ne porterait pas préjudice aux entreprises concernées mais inciterait les autorités à régler dans les plus brefs délais ce point ou à se concerter en amont. 2. Les DPO et leurs relations avec les ANC a) Publication de textes normatifs Les acteurs économiques souhaitent que les ANC se concertent entre elles via le CEPD pour produire des outils d’accompagnement normatifs cohérents et communs afin de faciliter la mise en œuvre de leurs recommandations. A titre d’exemple, le guide pour le recrutement “Les fondamentaux en matière de protection des données personnelles et questions-réponses”, récemment publié par l’ANC française (la CNIL), soulève des difficultés de mise en œuvre immédiate pour les acteurs économiques.
…publié par l’ANC française (la CNIL), soulève des difficultés de mise en œuvre immédiate pour les acteurs économiques. En l’espèce, les distorsions d’interprétation portent sur la durée de conservation des données relatives à une candidature. En Allemagne, celles-ci ne peuvent être conservées que 6 mois, alors qu’en France elles peuvent l’être pendant 2 ans. Comment un recruteur s’adapte-t-il face à un marché du travail unifié qui permet des candidatures au sein du marché unique soumis à des normes différentes ? Comment déploie-t-il efficacement un logiciel RH mutualisé au sein d’un même groupe de sociétés implantées au sein de différents Etats membres de l’UE ? b) Interprétation du RGPD Au-delà des productions textuelles normatives déterminées sans concertation, les ANC continuent à avoir des interprétations variables du RGPD lui -même.
…normatives déterminées sans concertation, les ANC continuent à avoir des interprétations variables du RGPD lui -même. Ainsi, à titre d’exemple, la notification d’une faille de sécurité ne répond pas aux mêmes critères en Allemagne et en France : - L’approche relative à la notion d’incidence sur le droit des personnes concernées conduit certains acteurs économiques à avoir dû notifier de telles failles en Allemagne 410 fois en un an quand, en France, seules 12 notifications ont été requises ; - Une faille de sécurité notifiée à la CNIL concernait 450 entités de la maison mère réparties au sein de nombreux Etats membres.
…de sécurité notifiée à la CNIL concernait 450 entités de la maison mère réparties au sein de nombreux Etats membres. Alors qu’elle était désignée chef de file, la CNIL a considéré que chaque responsable de traitement devait notifier auprès de chaque ANC locale dont dépendait chaque entité ; - Le point de départ du délai de 72 heures appliqué aux notifications est lui-même sujet à des interprétations qui peuvent diverger selon les pays. RGPD - Coordination autorités nationales – Contribution Afep 3 Pour éviter cette déperdition d’énergie coûteuse et cette lourdeur administrative inutile, les acteurs économiques préconisent la mise en place d’un système de mandat.
…et cette lourdeur administrative inutile, les acteurs économiques préconisent la mise en place d’un système de mandat. Celui-ci conduirait à établir auprès de l’ANC liée à l’établissement principal une notification unique d’un seul responsable de traitement « pour le compte de » l’ensemble des entités concernées et préserverait la responsabilité juridique des entités concernées. B/ Les entreprises proposent différentes améliorations/facilitations tant pour les ANC que pour les parties prenantes dans le domaine des enquêtes Les acteurs économiques européens remercient la Commission d’aborder la possibilité d’améliorer la cohérence des procédures dans le domaine des enquêtes susceptibles d’être ouvertes par des ANC.
…la cohérence des procédures dans le domaine des enquêtes susceptibles d’être ouvertes par des ANC. Les entreprises adhèrent aux objectifs destinés à fournir des outils à ces autorités afin de promouvoir la coopération à un stade précoce du processus d’enquête et à clarifier la position des plaignants dans les différentes étapes de la procédure.
18 → 12
…1 Contribution to the Commission's consultation in view of its 2024 report on the application of the GDPR February 2024 1. General comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the implementation of the GDPR since May 2018? Are there any priority issues that need to be addressed? The GDPR has undoubtedly increased consumer confidence in the protection of their personal data and helped businesses to better organise their governance and processes for handling this data. As a result, companies have invested heavily in GDPR compliance. Moreover, the GDPR has also become an international benchmark, encouraging other countries to adopt similar regulations.
…the GDPR has also become an international benchmark, encouraging other countries to adopt similar regulations. However, AFEP companies deplore the fact that personal data protection authorities (hereinafter "DPAs") are reluctant not to implement the risk-based approach on which the GDPR is based. In this respect, they observe that DPAs have a particularly restrictive approach, applying the GDPR to the letter and even adopting a position of maximum protection of personal data without consideration for the day-to-day business life and economic models of companies. Nevertheless, the right to protection of personal data is not absolute: the GDPR recalls the principle of proportionality, which requires this protection to be weighed against all other fundamental rights, in particular freedom of enterprise.
…which requires this protection to be weighed against all other fundamental rights, in particular freedom of enterprise. AFEP therefore considers that companies are faced with an overly rigid and systematic interpretation of the texts. For their part, individuals have a detailed knowledge of the extensive interpretation given by DPAs to the protection of their personal data. In this context, companies are seeing an increase in litigation, often brought by privacy actors on questions of principle without any material issue at stake or any infringement of the fundamental rights and freedoms of individuals. This approach creates ongoing legal uncertainty for businesses, exacerbated by the lack of a harmonised approach at European level. Such an approach also constitutes a disincentive for businesses to innovate and create value with data, particularly through artificial intelligence.
…a disincentive for businesses to innovate and create value with data, particularly through artificial intelligence. While creating legal distortions that are hardly conducive to business, the approach adopted by the Italian DPA on ChatGPT is an illustration of Europe's appetite for new technologies, and jeopardises the attractiveness of the European economy. Ref. Ares(2024)968088 - 08/02/2024 2 GDPR evaluation – 2024 report – February 2024 Refocusing the assessment of DPAs on this risk-based approach is therefore a priority for AFEP in order to free companies from constraints that are disproportionate to the issues at stake, and to enable them to seize the opportunities offered by the development of new technologies based on the processing of personal and non-personal data. 2. Exercise of data subject rights a.
…of new technologies based on the processing of personal and non-personal data. 2. Exercise of data subject rights a. From the individuals’ perspectives: please provide information on the exercise of the data subjects' rights listed below, including on possible challenges (e.g. delays in controllers/processors reply, clarity of information, procedures for exercise of rights, restrictions on the basis of legislative measures). etc.). NA From the controllers and processors’ perspective: please provide information on compliance with the data subjects rights listed below, including on possible challenges (e.g. manifestly unfounded or excessive requests, difficulties in meeting deadlines, identification of data subjects, etc.). As mentioned above, businesses are continually investing time and resources in developing and maintaining their compliance with the GDPR.
…businesses are continually investing time and resources in developing and maintaining their compliance with the GDPR. However, they are facing difficulties in implementing the rights of data subjects. For example, companies do not have a DPA-validated solution for checking the identity of the person requesting a right and limiting the risk of unauthorised access to data. The use of an identity card could be a solution, but the DPAs refuse this solution, deeming it too intrusive. Companies are therefore awaiting clarification on this point. In addition, companies are faced with a growing number of civil court proceedings resulting from the instrumentalisation of the rights of data subjects, supported by law firms specialising in this area, for questions of principle with no material issue at stake.
…subjects, supported by law firms specialising in this area, for questions of principle with no material issue at stake. Indeed, despite the measures taken by companies, and often for reasons of unintentional technical problems, non-compliance may persist despite the goodwill of the companies concerned. In a digital economy, the possible consequences of non-compliance for the individuals concerned remain limited (receipt of a commercial e-mail or unwanted advertising). However, some courts deal with these cases without taking any account of the principle of proportionality, and the plaintiff can thus obtain substantial compensation without any objective justification. This diverted use of the GDPR has already been identified in the Commission's previous report of June 2020 on the application of the GDPR, without the matter having been referred to the supervisory authorities.
June 2020 on the application of the GDPR, without the matter having been referred to the supervisory authorities. • Information obligations, including the type and level of detail of the information to be provided (Articles 12 to 14) NA 3 GDPR evaluation – 2024 report – February 2024 • Access to data (Article 15) AFEP member companies note that the scope of the right of access is not clearly defined. Companies cannot assume by default that all data must be provided to the person making the request, particularly when the data has been pseudonymised and has very little to do with the rights and freedoms of the data subject. In addition, some supervisory authorities appear to be extending the scope of access requests.
…of the data subject. In addition, some supervisory authorities appear to be extending the scope of access requests. For example, the French DPA states that when an employee makes a request for access to emails, the employer should provide "the content of the emails" and not the personal data contained in the email. This position goes beyond the provisions of the GDPR. These requests entail a substantial workload for the companies, with a significant cost, while the gains for the applicants are particularly limited. Certain specific requests raise other notable difficulties and demonstrate the instrumentalisation of the right of access. Many of the people concerned (customers, employees, etc.) exercise their right of access not to check the accuracy of the data processed but to obtain documents which, for the most part, will be used to support a pre-litigation action.
…the data processed but to obtain documents which, for the most part, will be used to support a pre-litigation action. This is also apparent from the wording of access requests, which aim to obtain copies or duplicates of "documents" rather than copies of data. AFEP companies have observed increasing requests from employees for access to their personal data on the basis of the GDPR. These requests relate in particular to emails, of which the employees are neither the author nor the recipient, but which mention their identity or elements likely to identify them. They are almost systematically part of pre-litigation cases with the employer. Case law tends to adopt a broad if not incoherent view of employees' right of access, even though such requests must be assessed in the light of the principle of proportionality.
…right of access, even though such requests must be assessed in the light of the principle of proportionality. Companies are therefore faced with the difficulty of having to provide copies of emails containing purely internal information, which is necessary for their business and sometimes strategic for them. AFEP member companies therefore draw the Commission's attention to the fact that the rights and freedoms of third parties - both natural and legal persons - should also be taken into account when assessing such a request, including the business secrets and intellectual property of the companies concerned in a balanced approach to the essential principles of the GDPR, reconciling freedom and proportionality.
…concerned in a balanced approach to the essential principles of the GDPR, reconciling freedom and proportionality. • Rectification (Article 16) NA • Erasure (Article 17) AFEP member companies note that personal data for which the data subject exercises his/her right to erasure/right to object or withdraws consent could also be used to train an algorithmic/AI model. The limits of these rights should therefore be interpreted in the light of current technological developments and the low risk for data subjects, in order to encourage innovation. 4 GDPR evaluation – 2024 report – February 2024 • Data portability (Article 20) Companies may receive mass requests for access and portability from private bodies (e.g. brokers) on the basis of a mandate signed electronically by the data subjects.
35 → 12
Association française des entreprises privées French Association of Large Companies POSITION – April 2020 www.afep.com Transparency Register identification number: 953933297-85 Public consultation on the roadmap by the European Commission on the GDPR application report ANSWER FROM AFEP (FRENCH ASSOCIATION OF LARGE COMPANIES) The European Commission launched until April 29 a public consultation on its roadmap for the report on the application of the general data protection regulation (GDPR), which will be made public by 25 May 2020. This report intends to identify potential problems in the application of the GDPR, in particular as regards the issue of international transfer of personal data to third countries and existing adequacy decisions (Chapter V) as well as the cooperation and consistency mechanism between national data protection authorities (Chapter VII).
V) as well as the cooperation and consistency mechanism between national data protection authorities (Chapter VII). French companies substantially ask for: • an evolution of the approach on data transfer towards more liberalisation, given the growing convergence of personal data protection regimes; • being able, in any case, to rely more on adequacy decisions rather than using by default alternative instruments (binding corporate rules and above all standard data protection clauses) and therefore for an increase in the number of adequacy decisions and the acceleration of their adoption procedures; • to do this, a clarification of the criteria on which the European Commission takes adequacy decisions, with a priority notably given to the countries with which free trade agreements are negotiated and the countries with the closest legal architecture; • strengthening reciprocity in data…
…of this regulation; • greater harmonisation of practices and interpretations; • an update of certain provisions. 1. ON CHAPTER V Large companies carry out numerous transfers of personal data to third countries based on Chapter V of the GDPR, of which they appreciate the principle of extra-territoriality. However, the reality of these exchanges outside the EU leads them to underline the need for the European Commission to correct various shortcomings or inaccuracies during the preparation of its future report. Some of these corrections are related to adequacy decisions (art 45) and standard contractual clauses ( "SCC" - art 46), which are major tools in companies daily- life for both the practical circulation of these data flows and the related legal responsibility ("accountability").
…for both the practical circulation of these data flows and the related legal responsibility ("accountability"). • Current limits in the use of data transfer tools to third countries Companies have learned to use solutions such as adequacy decisions like the “Privacy Shield” or the instruments provided for in articles 46 and 47 of the GDPR (in particular the company rules binding or standard data protection clauses) as data transfer tools to third countries. However, they believe that, given the increase in transfer volumes linked to the development of digital technology and industrial applications (Internet of Things), they should be able to have access to more global, more efficient and better-articulated solutions.
…of Things), they should be able to have access to more global, more efficient and better-articulated solutions. • Revision of the overall architecture of the mechanism for the transfer of personal data in the light of the convergence of legal data protection systems The EU approach to data protection has been widely documented and an increasing number of third countries are setting up personal data protection regimes whose principles are converging with those of the EU, including within the United States (cf. legislation adopted by the State of California). Ref.
…with those of the EU, including within the United States (cf. legislation adopted by the State of California). Ref. Ares(2020)2297775 - 29/04/2020 Association française des entreprises privées French Association of Large Companies POSITION – April 2020 www.afep.com Transparency Register identification number: 953933297-85 This dynamic should lead to a new approach to the transfer of data to third countries, with the basic principle being the free transfer of personal data to third countries when their legal system guarantees an equivalent level of data protection, subject to public-policy exception. This new approach does not necessarily mean questioning the principle of adequacy decisions but could lead to their easier adoption and to the EU adopting blacklists of countries to which the transfers would be prohibited and/or restricted.
…adoption and to the EU adopting blacklists of countries to which the transfers would be prohibited and/or restricted. This approach would also facilitate the conclusion of data provisions in free trade agreements since most third countries accept the standard adopted in the Transatlantic Partnership Agreement, which recognizes the principle of free transfer of non-personal and personal data, subject to limits related to public-policy objectives in data protection. • More numerous and prioritized adequacy decisions In any case, companies would rather rely on adequacy decisions than on binding corporate rules or standard data protection clauses, even if they recognize that the adequacy regime must sometimes be combined with them (especially in the case of the Privacy Shield).
…recognize that the adequacy regime must sometimes be combined with them (especially in the case of the Privacy Shield). It is therefore important to increase the number of adequacy decisions and, to do so, to establish priorities without renouncing the imperative of an equivalent level of protection. Firstly, companies stress the importance of adopting adequacy decisions quickly for third countries with which the volumes of material and digital trade are significant (Australia, Brazil, Great Britain, India). They welcome the approach followed with Japan, which has been to combine the negotiations of the Economic Partnership Agreement with the process of adopting twin adequacy decisions.
…to combine the negotiations of the Economic Partnership Agreement with the process of adopting twin adequacy decisions. On a secondary basis, one solution could be to accelerate and/or simplify the adoption of an adequacy decision with countries which present not only an equivalent level of protection but also fairly close legal architectures, with in particular a decisive role granted to independent data protection authorities. An adequacy decision with the United Kingdom must therefore be the main priority: it is both a leading economic partner and a country whose legal data protection system, even after its withdrawal from the EU, is modelled on that of the GDPR.
…a country whose legal data protection system, even after its withdrawal from the EU, is modelled on that of the GDPR. • Better consideration of the reciprocity of transfers of personal data Companies are committed to ensuring the level of protection provided by the GDPR in their transfers to third countries but also wish to be able to transfer personal data from third countries. However, this reciprocal liberalisation continues to come up against some protectionism of personal and non-personal data. The process to obtain twin adequacy decisions with Japan is an important step towards this goal of reciprocity.
…data. The process to obtain twin adequacy decisions with Japan is an important step towards this goal of reciprocity. Two elements could further strengthen the reciprocity requirement: (1) On the one hand, the approximation of the EU position with those of its main trading partners on trade agreements’ provisions on personal data, which would make it possible to demand in return the same degree of openness in data transfers to the EU; (2) In any case, to include reciprocity as an explicit and mandatory criterion for adopting an adequacy decision. This clarification would constitute a leverage effect on our partners.
…criterion for adopting an adequacy decision. This clarification would constitute a leverage effect on our partners. • Need to make adequacy decisions even more efficient As data transfers to third countries require adequate levels of protection defined by the European Commission, companies deplore the fact that tools as essential as the “Privacy Shield” are not fully deployed and, therefore, would like additional clarifications aiming both already existing decisions (future revisions) and coming ones: Association française des entreprises privées French Association of Large Companies POSITION – April 2020 www.afep.com Transparency Register identification number: 953933297-85 - the operating methods of the authorities of third countries: they have the reputation of enforcing the GDPR and assurances in this regard must be better considered by the European Commission; - the obligations to…
22 → 12
The voice of large French companies 25 rue d’Astorg 75008 Paris • 23 rue de la Science 1040 Bruxelles lafep.org 1 9 February 2026 POSITION – COMMISSION PUBLIC CONSULTATION EU rules on administrative cooperation in the field of taxation – recast The successive amendments to the Directive on Administrative Cooperation in the field of taxation (DAC) have resulted in an increasingly complex framework, imposing a significant compliance burden on businesses. This burden is particularly heavy in a context where the global tax landscape is undergoing a profound transformation following the introduction of the global minimum tax, now fully implemented within the EU.
…a profound transformation following the introduction of the global minimum tax, now fully implemented within the EU. In light of this paradigm shift in international taxation, L’Afep, the Association of large French companies, welcomes this public consultation as it is timely and appropriate to reassess the necessity, relevance and effectiveness of the various DAC provisions. Moreover, in the current context of global economic and geopolitical instability, enhancing the coherence of the EU tax framework is essential to foster a more business-friendly and competitive environment within the Union. The following comments provide an overview of proposed solutions for each DAC amendment, with the objective of simplifying and clarifying reporting obligations and introducing targeted improvements to enhance the overall functioning of the DAC framework.
…reporting obligations and introducing targeted improvements to enhance the overall functioning of the DAC framework. We insist that all work must be carried out with simplification of the current provisions as the sole objective and should not include new provisions (e.g.: inclusion of the failed proposal to tackle the misuse of shell entities or a new attempt at harmonising sanctions). To this end, the business must be consulted to avoid any side effects or decisions that could lead to further uncertainties, especially since other simplifications are currently being studied in the Tax Omnibus directive and are being encouraged by the business community (abolishing all withholding taxes within the EU, reform of the ATAD Directive, etc.). Ref.
…by the business community (abolishing all withholding taxes within the EU, reform of the ATAD Directive, etc.). Ref. Ares(2026)1435331 - 09/02/2026 The voice of large French companies 25 rue d’Astorg 75008 Paris • 23 rue de la Science 1040 Bruxelles lafep.org 2 DAC 1 • Reassessing the relevance of certain categories of income Some categories of income currently subject to reporting obligations no longer appear relevant. For example, the inclusion of life insurance products does not seem justified, as the information collected is not used for any identifiable purpose. It therefore appears necessary to assess whether the collection of information serves a clearly identified and effective objective. Where this is not the case—as illustrated by life insurance products—we recommend withdrawing the corresponding reporting obligation. DAC 6
…case—as illustrated by life insurance products—we recommend withdrawing the corresponding reporting obligation. DAC 6 1) As a principal claim • Removing the reporting obligation The proposal to repeal DAC 6 reporting obligations is based on several factors: (i) the relatively low number of reports filed; (ii) the significant development of information exchange mechanisms; (iii) the obsolescence of certain arrangements covered by DAC 6; (iv) the mobilisation of substantial internal resources for reporting that does not generate meaningful risk detection; and (v) persistent interpretation issues between jurisdictions for the same cross-border transactions.
…risk detection; and (v) persistent interpretation issues between jurisdictions for the same cross-border transactions. 2) In the alternative • Reducing the number of hallmarks DAC 6 includes a large number of hallmarks, some of which are either redundant or no longer relevant to the prevention of tax evasion. Reducing and refocusing the hallmarks on arrangements that present a genuine risk of aggressive tax planning would significantly ease the reporting burden. Two categories of hallmarks could be reconsidered:
…tax planning would significantly ease the reporting burden. Two categories of hallmarks could be reconsidered: 1) Hallmarks that have become obsolete and should be removed, including: - Hallmark A.1 – Confidentiality clause, especially regarding its limited application and the contractual implication during negotiations with companies from third countries; - Hallmark C.1 – ▪ C.1.a – Beneficiary of deductible cross-border payments not resident for tax purposes in any jurisdiction, ▪ C.1.b.i – the beneficiary is resident for tax purposes in a jurisdiction that does not levy corporation tax or levies corporation tax at a rate of zero or close to zero, The voice of large French companies 25 rue d’Astorg 75008 Paris • 23 rue de la Science 1040 Bruxelles lafep.org 3 ▪ C.1. b) ii – Beneficiary of deductible cross-border payments not resident for tax purposes in any ‘cooperative jurisdiction’,…
D.1 – Infringement of reporting obligations under the automatic exchange of financial account information. 2) Hallmarks that are excessively complex and difficult to apply consistently, such as: - Hallmark B.1 – Acquisition of a loss-making company with a view to utilising its losses; - Hallmark B.2 – Conversion of income into other types of income or capital/gifts; - Hallmark B.3 – Circular transactions resulting in a carousel of funds; - Hallmark C.4 – Significant difference in the amount considered payable in return for the transferred assets. • Excluding specific situations from reporting obligations Many standardised arrangements—such as common banking products, routine market transactions or regulated savings schemes—may technically fall within the scope of DAC 6, despite presenting no material tax risk.
…or regulated savings schemes—may technically fall within the scope of DAC 6, despite presenting no material tax risk. Explicitly excluding such arrangements would substantially reduce the administrative burden for both businesses and intermediaries. In this regard, Germany’s proposal to establish a “white list” of non-reportable transactions is a particularly constructive approach. In addition, reporting obligations should not apply to arrangements designed by advisers but not implemented by businesses. Requiring advisers to report all potential restructuring scenarios— many of which are never executed—creates a disproportionate burden and a risk of unwarranted stigmatisation. Reporting is currently triggered too early in the decision-making process, while penalties are excessively severe.
Reporting is currently triggered too early in the decision-making process, while penalties are excessively severe. • Consulting businesses if reporting obligations are maintained For French companies, the implementation of DAC 6 has proven particularly challenging. As internal processes are now established, further clarification or modification of DAC 6 provisions risks adding new layers of complexity. Should DAC 6 be maintained, any changes should be carefully designed in consultation with businesses to avoid disrupting existing compliance frameworks. • Capping penalties (for harmonisation purposes) Although enforcement remains within Member States’ competence, introducing a maximum level of penalties under DAC 6 would help limit disparities and prevent disproportionate sanctions.
…a maximum level of penalties under DAC 6 would help limit disparities and prevent disproportionate sanctions. Current penalties vary widely, ranging from €250,000 in Luxembourg to €1.03 million in the Netherlands and €2.35 million in Poland. The voice of large French companies 25 rue d’Astorg 75008 Paris • 23 rue de la Science 1040 Bruxelles lafep.org 4 DAC 7 Greater alignment between DAC 7 and other EU legislation would be beneficial. • Addressing overlaps between DAC 7 and the VAT Directive (ViDA) Clarifying the interaction between DAC 7 and the VAT framework would avoid duplicate reporting and significantly reduce the compliance burden for digital platform operators.
…would avoid duplicate reporting and significantly reduce the compliance burden for digital platform operators. • Addressing overlaps with other sector-specific regulations Certain businesses—such as those engaged in short-term rentals—are subject to multiple reporting obligations under sector-specific regulations in addition to DAC 7. Identifying and resolving these overlaps would contribute to simplification and improved efficiency. About L’Afep L’Afep, founded in 1987, brings together 117 of France's largest companies. Among the 60 largest European companies, one-third are members of L’Afep. Its mission is to contribute to the emergence of an environment conducive to economic development and to represent the interests of large French companies to public decision-makers in Paris and Brussels. Transparency register identification number: 953933297-85