Insights into the future of data protection enforcement: Regulatory strategies of European Data Protection Authorities for 2021-2022”.

Insights into the future of data protection enforcement: Regulatory strategies of European Data Protection Authorities for 2021-2022”.

The Future of Privacy Forum has released a report that brings “Insights into the future of data protection enforcement: Regulatory strategies of European Data Protection Authorities for 2021-2022” .

The European Data Protection Authorities (DPAs) are arguably the most powerful data protection and privacy regulators in the world, having been granted by the European Union’s General Data Protection Regulation (GDPR) broad powers and competences, in addition to independence. With GDPR enforcement?visibly ramping up ?in the past year, it is important to get insight into the key enforcement areas targeted by regulators, as well as understanding what are those complex or sensitive personal processing activities where DPAs plan to provide compliance guidelines or to shape public policy.

Last year, FPF released a report called?New Decade, New Priorities: A summary of twelve European Data Protection Authorities’ strategic and operational plans for 2020 and beyond . It outlined EU DPAs’ regulatory priorities for 2020 and the ensuing years, based on the documents of a strategic nature released by such authorities in the first half of last year. Since then, most DPAs have published their 2020 annual reports, as well as novel short or long-term strategies. These shed light on the areas to which DPAs are likely to devote significant regulatory efforts and resources, with a broad scope: guidance, awareness-raising, corrective measures, and enforcement actions.

We have compiled and analyzed these novel strategic documents, describing where different DPA strategies have touchpoints and noteworthy particularities. The report contains?links to and translated summaries of 15 DPAs’ strategic documents?from DPAs in France (FR ), Portugal (PT ), Belgium (BE ), Norway (NO ), Sweden (SE ), Ireland (IE ), Bulgaria (BG ), Denmark (DK ), Finland (FI ), Latvia (LV ), Lithuania (LT ), Luxembourg (LU ) and Germany (Bavaria ). The analysis also includes documents published by the European Data Protection Board (EDPB ) and the European Data Protection Supervisor (EDPS ). These documents complement or replace the ones that were included in our 2020 report.

No alt text provided for this image


Some of our main conclusions include:?

  • DPAs tend to rely on a?risk-based approach?when using their investigative and corrective powers, promising to focus on areas that have the potentially most negative impacts on data subjects.
  • DPAs seem to be on a trend to modernize their regulatory approach, several of them proposing?sandboxes?(e.g., the CNIL and the Norwegian DPA), and pushing for more self-regulation, like the adoption of Codes of Conduct.
  • DPAs also plan on dedicating efforts to make GDPR compliance work in practice on a large scale by targeting the empowerment of?DPOs?and by adopting tailored guidance for?SMEs;
  • Regulators seem to be responding to recent CJEU case law on?online tracking?and?international data transfers?by planning to ramp up their enforcement action in these areas.?
  • DPAs seem committed to tackling the privacy and data protection risks posed by the uptake of?AI/ML?technologies across society, in a sign that the AI Regulation proposed by the European Commission will merely complement protections that are already in place for individual rights. The Bulgarian DPA will focus on ensuring?facial recognition and profiling?techniques comply with legal standards, while the EDPS promises to develop?oversight, audit and assessment capabilities?for such technologies.
  • The protection of personal data of children is identified as a near term priority by a majority of DPAs, with plans for both guidance and enforcement actions being announced (9 of the 15 regulators included children data as a priority).?
  • The EDPB will continue to work for a consistent application of privacy and data protection instruments across the EU, by issue guidance on key concepts (e.g.,?data subjects’ rights, legitimate interests, scientific research, children’s data) and on data protection compliance aspects of new technologies (e.g.?blockchain,?PETs, AI/ML, Digital Identity, IoT and payment methods)
  • DPAs across the bloc also seem to be aligned with the European Commission’s and the French Government’s plan to achieve a?European “digital sovereignty”?in the new decade. As such, enhanced enforcement of data protection rules against large foreign tech players may be expected.

Download the full report below:

This post first appeared on the FPF blog . Credit to FPF EU Policy Fellow Sebasti?o Barros Vale who led this work, with senior staff Dr. Rob Van Eijk and Dr. Gabriela Zanfir-Fortuna .

Next Training Class:

Understanding Digital Data Flows: Biometrics – Head to Toe –?September 29, 2021. Sign up here.


This is great. Thank you!

回复
Manuj Aggarwal

Top Voice in AI | CIO at TetraNoodle | Proven & Personalized Business Growth With AI | AI keynote speaker | 4x patents in AI/ML | 2x author | Travel lover ??

3 年

Data protection enforcement is gaining increasing momentum in Europe - drawing significant attention recently due to the increased focus of the EU Data Protection. We live in an era where a person’s identity is stolen in less than 60 seconds, their personal information printed out and sold to get their money, or where they can be subject to having all of their social media activities captured and displayed on screen for others to see. In short, we are at a point where we now must also consider data protection and data control laws and regulations as these policies and strategies become more important in the world today. Jules Polonetsky Thanks for sharing.

回复
Clarisse Girot

Acting Head of Division on Data Flows, Governance and Privacy at OECD

3 年

Great report!

Maureen Wixon (Relationship Building)

Family Therapist, Specialist Gender, Culture, Life Enhancing Skills for Women, Relationships, Mindfulness, Author. Relationships and Well-being. #SelfCare #Relationships #Communication #Mental Health

3 年

Thank you Jules for highlighting the essential for data protection. ??????

要查看或添加评论,请登录

社区洞察

其他会员也浏览了