2015年-CEPS欧洲政策研究中心_Online_Personal_Data_Processing_and_EU_Data_Protection_Reform_97页_2mb
报告摘要
Summary of "ONLINE PERSONAL DATA PROCESSING AND EU DATA PROTECTION REFORM" Report
Core Content
This report, authored by Kristina Irion and Giacomo Luchetta, is a product of the CEPS Digital Forum's Task Force on Online Personal Data Processing and EU Data Protection Reform. It analyses the challenges of data protection in the context of the evolving information economy and provides policy recommendations for modernising EU data protection regulations. The report is structured to examine the current state of data protection, the economic implications, and the need for a more integrated and effective regulatory approach.
Main Viewpoints
- Data Protection as a Fundamental Right: The EU treats data protection as a fundamental right, rooted in both national constitutions and EU primary law. It is seen as a key enabler of trust in the digital economy.
- Need for Reform: The 1995 data protection Directive is outdated and fails to address the complexities of the modern digital environment. Reform is necessary to align with current technological and economic realities.
- Fragmentation and Scalability Issues: Current EU data protection rules are fragmented, particularly due to the e-Privacy Directive, and need to be consolidated for a unified regulatory framework.
- Meta-governance Approach: The report advocates for a meta-governance approach that involves cooperation between EU institutions and member states, integrating legal, technological, cultural, and economic measures.
- Balancing Interests: Data protection must balance the interests of individuals, businesses, and the broader information society, ensuring that privacy is protected without stifling innovation and economic growth.
Key Information
1. The Emerging Information Economy
- The information economy is driven by the processing of personal data, which is increasingly seen as a critical input resource.
- The volume of global data transactions is growing rapidly, with an annual increase of 45%, and the EU is projected to gain €1 trillion annually by 2020 from this economy.
- Personal data is often referred to as the "new oil" of the information economy, highlighting its economic value.
- Online businesses generate revenue through user data, including advertising, personalisation, and data sharing.
2. EU Data Protection Regulation
- The EU's data protection framework is based on the principle of protecting fundamental rights to privacy and data protection.
- The 1995 Data Protection Directive is insufficient for the current digital landscape.
- The e-Privacy Directive and other legal instruments govern personal data processing, but there is a need for greater clarity and unification.
- National supervisory authorities and the European Data Protection Board (EDPB) play a crucial role in enforcing data protection laws.
3. Economic Implications
- Data protection creates compliance costs, which can be significant for large companies.
- The European Commission estimates that the current framework imposes an administrative burden of €5.3 billion on EU companies.
- Reducing fragmentation could save up to €1.6 billion in compliance costs.
- The economic value of personal data is high, but its use must be balanced with privacy concerns.
4. Policy Recommendations
- Clarify Regulatory Scope: The new general data protection Regulation (GDPR) should be technologically neutral, but the relationship with the e-Privacy Directive and other national laws must be further defined.
- Consolidate Rules: EU data protection rules should be unified to avoid fragmentation, especially for online services.
- Strengthen Risk-Based Regulation: Emphasise risk-based regulation, information assurance, and consumer protection.
- Clarify Consent and Legitimate Interest: Ensure that consent is clear and not bundled with unrelated services, and define the scope of "legitimate interest" for legal certainty.
- Implement Right to be Forgotten and Data Portability: These rights should be clearly defined and applied without conflicting with freedom of expression.
- Enable Technological Compliance: Use automated systems to manage compliance and express consent, reducing administrative burdens.
- Promote Positive Incentives: Encourage the use of privacy-compliant technologies and support compliance schemes, especially for SMEs.
- One-Stop-Shop Mechanism: Ensure the one-stop-shop model is fully implemented without undermining the role of national DPAs.
- Reflexive Governance: Strengthen the capacity of DPAs and the EDPB to define enforcement priorities and manage compliance effectively.
- Sanctions and Compliance: Allow DPAs to consider commitments made by controllers when imposing fines, and reinstate DPO designations for exempted SMEs.
- Transparency Measures: Require member states to establish public repositories of legal data processing obligations.
Conclusion
The report underscores the importance of modernising data protection regulation to reflect the realities of the digital age. It calls for a comprehensive, unified, and flexible regulatory approach that supports both the information economy and individual privacy rights. The proposed policy recommendations aim to improve transparency, reduce compliance costs, and foster trust in the digital environment.
试读结束,高清完整版pdf/doc/ppt,请点下载