Associazione Italiana per l’Information and Communication Technology

Anitec-Assinform · Trade and business associations · IT

Kategorija
Trade and business associations
Būstinė
Milano IT
Registruota
2023-09-18
Deklaruotos metinės išlaidos
50 000–99 999 € (pačios deklaruota)
Svetainė
anitec-assinform.it
Skaidrumo registras
964146751045-46 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
0
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

2025420262

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 6 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2026-02-26Cabinet of Executive Vice-President Henna VirkkunenApply and Simplification
2026-02-26Cabinet of Executive Vice-President Henna VirkkunenApply and Simplification
2025-02-11Communications Networks, Content and TechnologyOpening Session: DSA roundtable discussions on online advertising (Article 46 DSA)
2025-02-11Communications Networks, Content and TechnologyOpening Session: DSA roundtable discussions on online advertising (Article 46 DSA)
2025-02-11Communications Networks, Content and TechnologyOpening Session: DSA roundtable discussions on online advertising (Article 46 DSA)
2025-02-11Communications Networks, Content and TechnologyOpening Session: DSA roundtable discussions on online advertising (Article 46 DSA)

Ką pateikė viešoms konsultacijoms

2026-09-08 · Implementing rules on registering in and reporting to the register of producers ↗ originalus šaltinis
Anitec-Assinform supports the European Commissions objective of establishing a harmonised EU framework for producer registration and reporting under Regulation (EU) 2025/40. Key priorities: Harmonisation: ensure common registration, reporting, packaging categories and data requirements across Member States, limiting national divergences. Administrative simplification: allow PROs and authorised third parties to submit registration and reporting information on behalf of producers, avoiding duplication. Single registration: enable producers to register once per Member State and reuse data already available in existing EPR registers. Digitalisation & interoperability: develop automated and…
2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
The GDPR has had a significant impact on the way organisations collect, use and store personal data. It has improved transparency and accountability, and increased awareness. We thank for the opportunity to have our say on the impact of this regulation. please find herewith our input on the questionnaire.

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 30 p.

Associazione Italiana per l’Inform ation and Com m unication Technology (ICT) M ilano, Via San M aurilio 21, 20123 Telefono 02 0063281 segreteria@ anitec-assinform .it – anitec-assinform @ pec.it – w w w .anitec-assinform .it P.IVA: 10053550967 C.F.: 10053550967 Written Input GDPR Multistakeholder Expert Group Questionnaire February 8th, 2024 Ref. Ares(2024)973296 - 08/02/2024 1 Questions 1) General Comments a. What is your overall assessment (benefits/challenges, increase in trust and awareness, etc.) of the application of the GDPR since May 2018? Are there priority issues to be addressed? 1) Answer – High Level a. Concept of Personal Data and Anonymisation: The concept of anonymizing data should not require a guarantee of absolute or zero identification risks, but rather require reducing it to a sufficiently low, negligible level based on contextual factors.

…risks, but rather require reducing it to a sufficiently low, negligible level based on contextual factors. Assessing if the risk of identifiability has been reduced to such level, should be a context‐specific exercise. b. Concept of Special Categories of Data: Art. 9 should pertain solely to data processed with the intent to reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union memberships, health status, or sex life or sexual orientation, as well as genetic or biometric data processed for the purpose of uniquely identifying an individual. Further it should be clarified that “revealing” does not mean the existence of any theoretical possibility of identifying a sensitive trait. c. Joint Controllership: Art.

…c. Joint Controllership: Art. 26 should provide clarity on the delineation of the joint controllership concept and therefore ensure legal certainty. Art. 26 requires joint controllers to determine both the means and purposes of processing. It should be clarified that the act of determining in the sense of Art. 26 requires the ability to have actual and decisive influence on a processing activity to establish joint controllership. The applicability of the one‐stop‐shop to joint controllership should be confirmed and clarified. d. Legal basis ‐ CN/LI/Consent: The GDPR allows for a range of legal bases under which data can be processed. The rules of GDPR should be clear on the fact there is no hierarchy between these legal bases, and none should be considered better or more legitimate than any other.

…there is no hierarchy between these legal bases, and none should be considered better or more legitimate than any other. The GDPR should not interfere with the bona fide interpretations of a contract, and be clearer on the fact that privacy and data protection are not absolute rights but must be weighed against other fundamental rights and, respectively, multiple interests. e. Article 82 GDPR ‐ the right to compensation for non‐material damage: A clear threshold for non‐material damage should be established in the context of individual and collective redress claims for data protection violations determining that mere annoyance, general unease or concern, or unsubstantiated claims of loss cannot meet this threshold. A clear threshold should bring certainty as to what comprises compensable harm under the GDPR. f.

A clear threshold should bring certainty as to what comprises compensable harm under the GDPR. f. Article 83 GDPR ‐ Unclear framework with respect to the calculation of admin fines: The GDPR should provide common and clear standards for the calculation of administrative fines, which ensure the proportionality of sanctions (rather than 2 deterrence), guarantee consistency with the concepts and scope established in the GDPR (instead of importing the EU Competition Law concept of “undertaking”) and not incentivise investigations based on turnover (but rather based on given risks). 1) Answer – Detailed 1. Concept of Personal Data and Anonymisation: GDPR should be edited to clarify that anonymising data does not mean reducing the risk of identifying an individual to absolute, or near, zero.

…o clarify that anonymising data does not mean reducing the risk of identifying an individual to absolute, or near, zero. Instead, it should mean reducing that risk to a sufficiently low, negligible level, given the context of data processing. It should clarify that assessing whether the risk of identifiability has been reduced to such a level is a highly fact‐specific exercise. That assessment should take into account, among other things, the nature of the data, the nature of the processing, any technical measures (such as PETs) that have been applied, and any non‐technical measures (such as access controls, storing data on‐device, and contractual restrictions) that have been put in place. Recital 26 states that GDPR does not apply to anonymous data, data that does not relate to an identified or identifiable natural person.

…s that GDPR does not apply to anonymous data, data that does not relate to an identified or identifiable natural person. But there is significant uncertainty concerning exactly what this means and how the risk of identifiability should be assessed. Some have interpreted Recital 26, EDPB guidance, and court decisions to mean that data is anonymous only if it has been treated such that the risk of identifying an individual is nearly zero. Such an absolutist approach fails to recognise that it is possible to reduce the risk of identifiability to sufficiently low levels that mean, in practice, an individual is extremely unlikely to be identified. It also fails to recognise that a given dataset might be personal data in one data processing context, but anonymous in another. The effect of this absolutist approach is to actually discourage investment and innovation in technologies like PETs.

The effect of this absolutist approach is to actually discourage investment and innovation in technologies like PETs. Because developing these technologies can be extremely costly, organisations need incentives to do so. A valuable incentive would be the confidence that, if an organisation applied PETs and other measures, their data would be deemed anonymous. But the uncertainty in GDPR precludes this confidence. Some other jurisdictions have already moved away from an absolutist approach, adopting instead a more pragmatic approach that incentivizes innovation. The most prominent is the UK ICO, which issued draft guidance clarifying what anonymisation means in a way that generally aligns with our position.

K ICO, which issued draft guidance clarifying what anonymisation means in a way that generally aligns with our position. As part of their data protection reform, UK has also proposed to rephrase the definition of personal data to only cover such data that is identifiable by a reasonable means of the controller or processor at the time of the processing. We support a similar approach to be taken for EU GDPR 2. Concept of Special Categories of Data: Art. 9 should be edited to apply only to data processed in order to reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health status, or sex life or sexual orientation, as well as genetic or biometric data processed for the purpose of uniquely identifying an individual.

…exual orientation, as well as genetic or biometric data processed for the purpose of uniquely identifying an individual. Alternatively, GDPR’s recitals should be edited to clarify that “revealing” does not mean the existence of any mere theoretical possibility—no matter how low—of identifying—directly or indirectly—a sensitive trait 3 listed. Instead, “revealing” should be interpreted as the existence of a reasonable likelihood, given contextual, fact‐specific factors, of such identification, and the controller’s intention to determine such a sensitive trait.

…tual, fact‐specific factors, of such identification, and the controller’s intention to determine such a sensitive trait. For example, if a user visits a breast cancer website, the fact of this visit should not be automatically protected under Article 9 as SCD because that user could have visited the website for donation purposes or because they are interested in learning more about breast cancer on behalf of a friend or family member; it does not necessarily indicate anything about their health which should be protected under Article 9. Until recently, the common understanding of Art. 9 was that a data point was SCD only if it directly indicated one of the listed sensitive traits about an individual. Recent CJEU decisions have called that common understanding into question.

Recent CJEU decisions have called that common understanding into question. They seem to imply that any data point could be SCD if it is theoretically possible to derive a sensitive trait from it (also in combination with other data). This novel interpretation creates extreme risks because, taken to its logical conclusion, it means that virtually every data point is SCD. Nearly any data point about someone could be combined with a plethora of other information about them to potentially, in theory, reveal something sensitive about them. This focus on merely theoretical sensitivity also conflicts the goals of Art. 9 ‐ to protect fundamental rights and freedoms, including by preventing discrimination. What is responsive to that goal is limiting how a data point is used— preventing its use to single out individuals because of sensitive traits—not merely what a data point is.

111 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

Anitec-Assinform targets any proposal referred to the development of ICT production and supply chain, digital skills, digital transformation and Digital single market. In particular: Digital skills, Digitization of territories, Digital health, Cloud, Blockchain & IA, environment, copyright, market surveillance.
dossiers of interest: AI Act, Copyright directive, DSA, DMA, Nis2, CRA, ESPR, PPWR Green claims, CSRD, CS3D, Battery regulation, Data act, metaverse, P2B, EPDP directive, Fair share, accessibility act, Vat in the digital age chips act, RSGP Smei Csam external power supplies, Digital Fairness Act, the MFF, AI Factories, and any similar initiative.