A Modern European Data Protection Framework Safeguarding Privacy in a Connected World

Similar documents
A Modern European Data Protection Framework. Bruno Gencarelli DG JUSTICE and CONSUMERS

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Presentation to IAPP November 18, EU Data Protection. Monday 18 November 13

EU Data Protection Law - Current State and Future Perspectives

Data Protection Bill, House of Lords second reading Information Commissioner s briefing

Free and Fair elections GUIDANCE DOCUMENT. Commission guidance on the application of Union data protection law in the electoral context

Opinion 6/2015. A further step towards comprehensive EU data protection

LEGAL BASIS OBJECTIVES ACHIEVEMENTS

A Legal Overview of the Data Protection Act By: Mrs D. Madhub Data Protection Commissioner

Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679

REGULATION (EU) 2016/679 General Data Protection Regulation

GDPR. EU General Data Protection Regulation. ebook Version 1.2

Data protection and privacy aspects of cross-border access to electronic evidence

TECHNOLOGY AND DATA PRIVACY. Investigative Powers of the Data Protection Commissioner. by Peter Bolger, Jeanne Kelly

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,7November /1/13 REV1. InterinstitutionalFile: 2012/0011(COD) LIMITE

EUROPEAN PARLIAMENT Committee on the Internal Market and Consumer Protection

Regulation 1/2003: a modernised application of EC competition rules

GDPR: Belgium sets up new Data Protection Authority

Council of the European Union Brussels, 13 April 2015 (OR. en)

Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection

Implementation of GDPR and control mechanisms of data protection institutions in Germany

ARTICLE 29 DATA PROTECTION WORKING PARTY

Introduction to the Environmental Crime Directive 2008/99/EC

EDPS Opinion on the proposal for a recast of Brussels IIa Regulation

Interinstitutional File: 2012/0011 (COD)

Proposal for a COUNCIL DECISION

The Law of EC State Aid, Seminar organised by the Centre of European Law at King s College and the European State Aid Law Institute (EStALI)

New Directives on Public Procurement. Dr. Manfred Kraff, Deputy Director-General DG Budget, European Commission Portorož - Slovenia, 23rd April 2015

LEGAL BASIS OBJECTIVES ACHIEVEMENTS

Bitkom views on EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)

Information Notice. Information Notice. Reference: ComReg 17/49

ARTICLE 29 DATA PROTECTION WORKING PARTY

Consultation on the General Data Protection Regulation: CAP s evaluation of responses

European Economic and Social Committee OPINION. of the

16 March Purpose & Introduction

Antitrust: Commission introduces settlement procedure for cartels frequently asked questions (see also IP/08/1056)

DATA PROTECTION LAWS OF THE WORLD. Ireland

Comments on DG Competition s Guidance on procedures of the Hearing Officers in proceedings relating to Articles 101 and 102 TFEU *

Speech by Phil Hogan, Commissioner for Agriculture and Rural Development at the Extraordinary Meeting of COMAGRI, Strasbourg 18 January 2016

General Data Protection Regulation

36 Congress of the FIDH. Lisbon, 19 April Migration Forum. "EU Migration policy"

LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 12 February /13 Interinstitutional File: 2010/0210 (COD) LIMITE MIGR 15 SOC 96 CODEC 308

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Questionnaire. On the patent system in Europe

The legal framework and guidance on data protection under the. Cross-border ehealth Information Services (CBeHIS) T6.2 JAseHN draft v.2 (20.10.

Why is the Commission proposing to introduce a settlement procedure? Does the settlement procedure imply negotiations?

COMMISSION DELEGATED REGULATION (EU) /... of

EXECUTIVE SUMMARY. 3 P a g e

Statutes for the Groningen Declaration network. Chapter I: definitions, name, seat, legal status and objective

Amended proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

EVIDENCE ON THE DATA PROTECTION BILL. For the House of Commons Public Bill Committee by Open Rights Group and Chris Pounder

Study JLS/C4/2005/04 THE USE OF PUBLIC DOCUMENTS IN THE EU

COUNCIL OF THE EUROPEAN UNION. Brussels, 17 October /13 Interinstitutional File: 2012/0066 (COD) CODEC 2207 ENV 895 ENT 266 PE 440

ARTICLE 29 Data Protection Working Party

Official Journal of the European Union L 329/5

Self-Assessment of Agreements Under Article 81 EC: Is There a Need for More Commission Guidance?

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,

This document is meant purely as a documentation tool and the institutions do not assume any liability for its contents

Comment to the Guidelines on Consent under Regulation 2016/679 by Article 29 Working Party

REPORT FROM THE COMMISSION. 27th ANNUAL REPORT ON MONITORING THE APPLICATION OF EU LAW (2009) SEC(2010) 1143 SEC(2010) 1144

DATA PROTECTION LAWS OF THE WORLD. Romania

Question 1: Do you have any suggestions for further improving citizen's access to

on the Commission Communication on Internet Policy and Governance - Europe`s role in shaping the future of Internet Governance

Introduction to the Environmental Crime Directive 2008/99/EC

Law Enforcement processing (Part 3 of the DPA 2018)

RENEWING DATA PROTECTION CONVENTION 108: THE COE S GDPR LITE INITIATIVES

Data Protection Bill, House of Commons Second Reading Information Commissioner s briefing

STATUTORY INSTRUMENT 2002 NO THE ELECTRONIC COMMERCE (EC DIRECTIVE) REGULATIONS Statutory Instruments No. 2013

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE AND CONSUMERS

CONCORD Response to the Communication on the proposed Joint Declaration on the EU Development Policy CONCORD Policy Working Group September 2005

(Non-legislative acts) REGULATIONS

Privacy and Protection of Personal Data in the EU Transfers of Personal Data to third Countries

Spring Conference of the European Data Protection Authorities, Cyprus May 2007 DECLARATION

The European Union General Data Protection Regulation (GDPR) Barmak Nassirian, Federal Director Thursday, February 22, 2018

Historical Development of the EU Legislation on Equal Access to Goods and Services. Introduction of a relevant legal basis the Treaty of Amsterdam

An overview of EC Regulation 1/2003 as the new implementing regulation for the rules on competition laid down in Articles 81 and 82 of the EC Treaty

We appreciate your feedback

THE PERSONAL DATA PROTECTION BILL, 2018: A SUMMARY

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Case C-397/03 P. Archer Daniels Midland Co. and Archer Daniels Midland Ingredients Ltd v Commission of the European Communities

Vår dato Deres dato Vår saksbehandter:

COMMISSION OF THE EUROPEAN COMMUNITIES. Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Annex - Summary of GDPR derogations in the Data Protection Bill

Executive summary. We will continue to pursue any actions still outstanding at the time of writing. Regulatory action taken to date:

(Non-legislative acts) REGULATIONS

Glossary. account where we post news about TTIP. requiring all US. judges a disputed issue outside a court

Is information about legal entities personal data? No. The DPA only applies to information about individuals as opposed to legal entities.

COMMISSION OF THE EUROPEAN COMMUNITIES COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT

COMMUNICATION FROM THE COMMISSION. On the global approach to transfers of Passenger Name Record (PNR) data to third countries

Official Journal of the European Union. (Legislative acts) REGULATIONS

SUMMARY OF THE IMPACT ASSESSMENT

Internet Policy and Governance Europe's Role in Shaping the Future of the Internet

Amended proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. laying down standards for the reception of asylum seekers.

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Children and Young People (Information Sharing) (Scotland) Bill. Response to the call for evidence. Alistair Sloan

***I DRAFT REPORT. EN United in diversity EN 2012/0010(COD)

Having regard to the Treaty on the Functioning of the European Union, and in particular points (a) and (b) of Article 79(2) thereof,

Dr. Hielke Hijmans Special Advisor European Data Protection Supervisor

Recent Developments in EU Public Law. Scottish Public Law Group Annual Summer Conference 9 June 2014

Speech by Michel Barnier at the 28th Congress of the International Federation for European Law (FIDE)

Transcription:

A Modern European Data Protection Framework Safeguarding Privacy in a Connected World DG JUSTICE and CONSUMERS

The Data Protection Reform Package Ø "General" Data Protection Regulation (GDPR) Ø Directive in the field of police and criminal justice cooperation (Police Directive) 2012: Proposals 2016: Adoption 2018: Application

Why a new European framework for Data Protection? Technology developments and globalisation: addressing the challenges and seizing the opportunities of the digital economy, the trust deficit Constitutionalisation of the fundamental right to data protection (Lisbon Treaty) Fragmentation of legislative framework (different transposition of Directive 95/46/EC into national laws)

Main objectives and major changes RULES FIT FOR THE DIGITAL SINGLE MARKET (a harmonised and simplified framework) One single set of rules, "one-stop-shop" mechanism, cutting red tape PUTTING INDIVIDUALS IN CONTROL OF THEIR DATA (an updated set of rights and obligations) Enhancing transparency, clarifying the conditions for consent, notification of data breaches, right to data portability, right to be forgotten, risk-based approach A MODERN DATA PROTECTION GOVERNANCE Stronger national DPAs, consistency mechanism for crossborder cases, establishment of a European Data Protection Board to ensure consistent application of the Regulation, credible sanctions

A harmonised and simplified framework One single set of data protection rules for the EU (Regulation) One interlocutor and one interpretation (one-stopshop and consistency mechanism) Creating a level playing field (territorial scope) Cutting red tape (abolishment of most prior notification and authorisation requirement), including as regards international transfers 5

Updating rights and obligations Stronger rights, clearer obligations, more trust Evolution rather than revolution: basic architecture and core principles are maintained Putting individuals in better control of their data (e.g. consent to be given by clear affirmative action, clarification of conditions for compatible further processing, better information about data processing) including through the introduction of new rights (e.g. right to portability) and obligations (e.g. data breach notification) 6 Obligations graduated in function of the nature and potential risks of processing operations (risk-based approach)

A MODERN GOVERNANCE SYSTEM Better equipped DPAs and better cooperation amongst them (e.g. joint investigations) A new decision-making process for cross-border cases (the consistency mechanism) The creation of the European Data Protection Board (guidance and dispute settlement) Credible and proportionate sanctions (2/4% of global turnover in light of nature, duration, gravity etc. of the violation) 7

THE TRANSITION PERIOD AND BEYOND GDPR will apply from 25 May 2018 Preparing a compliance-ready/friendly environment: We need to use this time well to get everybody, i.e. Member States, DPAs, citizens and companies to prepare for the new rules. The Commission will work closely with the Member States, data protection authorities and other stakeholders to ensure a uniform application of the rules. We will also run awareness-raising campaigns so that citizens know their new rights (Commissioner V. Jourová) Aligning other legislative instruments (eprivacy Directive, Regulation 45/2001 ) Close dialogue with Member States on national implementation Central role of DPAs (Art. 29 W/EDPB), see Art. 29 WP 2016 Action Plan (guidelines on notion of high risk, DPO, right to portability, calculation of fines ) Commission s implementing and delegated acts Market-driven instruments: codes of conduct, certification mechanisms, data protection seals etc. A stakeholders process was launched in July 2016

THANK YOU VERY MUCH FOR YOUR ATTENTION!