Interesų grupė
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 3 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2020-07-15 | Cabinet of Executive Vice-President Margrethe Vestager | To discuss White Paper on Artificial Intelligence |
| 2020-01-22 | Cabinet of Executive Vice-President Margrethe Vestager | Artificial intelligence |
| 2019-12-19 | Cabinet of Executive Vice-President Margrethe Vestager | Presentation of CIPL EU AI white paper |
…1 Centre for Information Policy Leadership’s Response to the EU Commission Consultation on the Evaluation of the GDPR The Centre for Information Policy Leadership (CIPL)1 submits this response (the Paper) as input for the EU Commission’s upcoming Report on the GDPR. This Paper builds and expands on CIPL’s 2019 report “GDPR One Year In: Practitioners Take Stock of the Benefits and Challenges”,2 which summarised the benefits, challenges and unfulfilled promises of the GDPR for organisations. I.
…and Challenges”,2 which summarised the benefits, challenges and unfulfilled promises of the GDPR for organisations. I. Companies continue to derive benefits from the GDPR CIPL confirms that in 2020, the GDPR continues to act as a driver of benefits for organisations by: Turning data protection into a mainstream business issue, beyond just legal and compliance; Creating momentum and focus on data protection, providing businesses with the opportunity to level-set their practices with other organisations and enabling a shift in organisational approaches to data protection through the implementation of comprehensive privacy compliance programmes; Aligning data protection with organisations’ digital transformation, data strategy and data-driven innovation, and instilling good data hygiene and governance, thereby enabling organisations to use data responsibly; Forcing organisations to…
…bottom line, by creating a positive return on investment from accountable practices and making data protection a strategic business driver and market differentiator;3 and Making it easier to engage in international business by encouraging organisations to address data protection globally across all business lines, products, services and locations and setting a global baseline for data protection law that serves as a reference for other countries and enables economic efficiency.4 Ref.
…for data protection law that serves as a reference for other countries and enables economic efficiency.4 Ref. Ares(2020)2264396 - 28/04/2020 2 II. Addressing the challenges and promises of the GDPR While the tangible benefits of the GDPR are still evident in 2020, unfortunately, so are the challenges and unfulfilled promises already highlighted by CIPL in 2019. Yet, organisations continue to invest significant resources into GDPR compliance while technology continues to evolve and to create tensions with legal norms. In addition, the COVID-19 crisis has also put into sharp focus the need for progressive GDPR interpretation while confirming the enormous potential of data in helping address this worldwide crisis. This ever-changing environment and the promises of beneficial data uses call for a shift in the approach to leverage the GDPR provisions to their fullest extent going forward.
…data uses call for a shift in the approach to leverage the GDPR provisions to their fullest extent going forward. CIPL considers that because of GDPR’s principle-based, outcome-based and risk-based approach, it constitutes a solid foundation for building effective protection and trust for individuals while enabling the digital economy, including at time of crises. This Paper does not advocate for a formal review of the GDPR at this stage, as CIPL believes that the current challenges with the application of the GDPR can be resolved by the Commission, the EDPB and data protection authorities (DPAs) using the existing institutional and regulatory mechanisms and their wide interpretative powers. CIPL believes it useful to consider the current challenges of the GDPR beyond the limited points in Article 97(2) GDPR.
CIPL believes it useful to consider the current challenges of the GDPR beyond the limited points in Article 97(2) GDPR. Consequently, we group CIPL’s evaluation and recommendations in four categories: 1. Short-term actions to make GPDR implementation more efficient, including on Article 97(2) topics; 2. Improvements to the EDPB and DPA collaboration and engagement; 3. Progressive interpretation of some of the GDPR’s key substantive requirements; and 4. Long-term positioning of the GDPR in the broader digital landscape. 1. Short-Term Actions to Make the Functioning of the GDPR More Efficient 1.1 International Transfer Tools (Article 97(2) topic) Some organisations report that due to the legal uncertainty associated with data transfer tools, controller- processor relationships try to increasingly exclude cross-border data flows in order to be compliant.
…controller- processor relationships try to increasingly exclude cross-border data flows in order to be compliant. This, in effect means more data localisation and less free flow of data. Due to the importance of international data transfers in digital economies, CIPL reiterates the urgent need to have operational and flexible international data transfer mechanisms including: Updated GDPR-compliant SCCs.
…need to have operational and flexible international data transfer mechanisms including: Updated GDPR-compliant SCCs. Importantly, CIPL disagrees with the EDPB that this should include SCCs for transfers back from EU processors to non-EU controllers;5 Acknowledgement of the importance and robustness of the Privacy Shield as well as adoption of further adequacy decisions; 3 More Binding Corporate Rules (BCRs) reviewed by the DPAs and approved by the EDPB6 for controllers, processors and entities engaged in a joint economic activity; and EU-wide certifications and codes of conduct that can work both as accountability tools and cross- border transfer mechanisms.7 Considerate guidance should also be provided on how organisations should manage requests of law enforcement authorities, including in the UK, post Brexit.
…provided on how organisations should manage requests of law enforcement authorities, including in the UK, post Brexit. Organisations cannot be put in a position where they have to choose between complying with a law enforcement request or complying with the GDPR provisions. Summary of CIPL Recommendations: The EU Commission and the EDPB should provide a complete transfer toolkit to organisations to enable data transfers. 1.2 Cooperation, Consistency and One-Stop-Shop (Article 97(2) topic) Smooth cooperation between DPAs and proper functioning of the consistency mechanism are essential to the harmonised implementation of the GDPR both in terms of substantive law and enforcement. It is also intended to benefit organisations that should, through the One-Stop-Shop (OSS) mechanism, work with a single-lead DPA through their main establishment for all their cross-border data processing.
…mechanism, work with a single-lead DPA through their main establishment for all their cross-border data processing. It appears however that this framework does not always function optimally and sometimes creates more bureaucracy than consistent and effective data protection. First, the concept of “main establishment” may sometimes be ill-adapted to the realities of complex cross- border organisations that may have multiple decision-making centres located in several Member States, or in a combination of Member States and third countries. (This situation is expected to increase after Brexit). In this case, there is neither a satisfactory way to designate a main establishment nor a possibility to appoint a representative. The EDPB should consider this complexity to enable organisations to identify their lead authority more easily.
The EDPB should consider this complexity to enable organisations to identify their lead authority more easily. Second, CIPL considers that the OSS is more than just a way to allocate enforcement cases between DPAs. It should also enable organisations to interact with a single regulatory interlocutor in the EU for all cross- border EU data protection-related matters in line with Article 56(6) of the GDPR.8 This is all the more relevant in the context of the COVID-19 crisis where organisations need to react quickly and DPAs may want to avoid being overwhelmed with requests that they may not be able to address in a timely fashion.
…and DPAs may want to avoid being overwhelmed with requests that they may not be able to address in a timely fashion. Just like in the case of notifying the breaches in multiple Member States to the single-lead DPA, there should be an official clarification that companies can abide by the national guidance of their lead authority for all their cross-border EU matters and operations.9 This should be the case even in situations where proximity to individuals may matter, such as for instance if a breach on a cross-border processing impacts individuals in a country different from the country where the controller’s main establishment is located and where the lead DPA will be notified of the breach.
129 → 12