BETA

Activities of Nicola DANTI related to 2020/0340(COD)

Plenary speeches (1)

Data Governance Act (debate)
2022/04/06
Dossiers: 2020/0340(COD)

Shadow reports (1)

REPORT on the proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
2021/07/22
Committee: ITRE
Dossiers: 2020/0340(COD)
Documents: PDF(1 MB) DOC(471 KB)
Authors: [{'name': 'Angelika NIEBLER', 'mepid': 4289}]

Amendments (51)

Amendment 113 #
Proposal for a regulation
Recital 2
(2) Over the last few years, digital technologies have transformed the economy and society, affecting all sectors of activity and daily life. Data is at the centre of this transformation: data-driven innovation will bring enormous benefits for citizens, for example through improved personalised medicine, new mobility, and its contribution to the European Green Deal23 . The data economy has to be built in a way to enable companies, especially micro, small and medium sized enterprises (SMEs) to thrive, ensuring data access neutrality, portability and interoperability. In its Data Strategy24 , the Commission described the vision of a common European data space, a Single Market for data in which data could be used irrespective of its physical location of storage in the Union in compliance with applicable law, which can be pivotal for the rapid development of Artificial Intelligence technologies. It also called for the free and safe flow of data with third countries, subject to exceptions and restrictions for public security, public order and other legitimate public policy objectives of the European Union, in line with international obligations. In order to turn that vision into reality, it proposes to establish domain- specific common European data spaces, as the concrete arrangements in which data sharing and data pooling can happen. As foreseen in that strategy, such common European data spaces can cover areas such as health, mobility, manufacturing, financial services, energy, or agriculture or thematic areas, such as the European green deal or European data spaces for public administration or skills. _________________ 23Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions on the European Green Deal. Brussels, 11.12.2019. (COM(2019) 640 final) 24 COM (2020) 66 final.
2021/04/28
Committee: ITRE
Amendment 130 #
Proposal for a regulation
Recital 4
(4) Action at Union level is necessary in order to address the barriers to a well- functioning data-driven economy and to create a. A Union-wide governance framework for data accessshould have the objective of building trust among individuals and companies for data access, control, sharing, use and re-use, in particular regarding the re-use of certain types of data held by the public sector, the provision of services by data sharing providers to business users and to data subjects, as well as the collection and processing of data made available for altruistic purposes by natural and legal persons.
2021/04/28
Committee: ITRE
Amendment 147 #
Proposal for a regulation
Recital 10
(10) Prohibited exclusive agreements and other practices or arrangements between data holders and data re-userpertaining to the re-use of data held by public sector bodies which do not expressly grant exclusive rights but which can reasonably be expected to restrict the availability of data for re-use that have been concluded or have been already in place before the entry into force of this Regulation should not be renewed after the expiration of their term. In the case of indefinite or longer-term agreements, they should be terminated within three years from the date of entry into force of this Regulation.
2021/04/28
Committee: ITRE
Amendment 153 #
Proposal for a regulation
Recital 11
(11) Conditions for re-use of protected data that apply to public sector bodies competent under national law to allow re- use, and which should be without prejudice to rights or obligations concerning access to such data, should be laid down. Those conditions should be non-discriminatory, proportionate and, objectively justified, while not restricting and in line with competition law. In particular, public sector bodies allowing re- use should have in place the technical means necessary to ensure the protection of rights and interests of third parties. Conditions attached to the re-use of data should be limited to what is necessary to preserve the rights and interests of others in the data and the integrity of the information technology and communication systems of the public sector bodies. Public sector bodies should apply conditions which best serve the interests of the re-user without leading to a disproportionate effort for the public sector. Depending on the case at hand, before its transmission, personal data should be fully anonymised, so as to definitively not allow the identification of the data subjects, or data containing commercially confidential information modified in such a way that no confidential information is disclosed. Where provision of anonymised or modified data would not respond to the needs of the re-user, on- premise or remote re-use of the data within a secure processing environment could be permitted. Data analyses in such secure processing environments should be supervised by the public sector body, so as to protect the rights and interests of others. In particular, personal data should only be transmitted for re-use to a third party where a legal basis allows such transmission. The public sector body could make the use of such secure processing environment conditional on the signature by the re-user of a confidentiality agreement that prohibits the disclosure of any information that jeopardises the rights and interests of third parties that the re-user may have acquired despite the safeguards put in place. The public sector bodies, where relevant, should facilitate the re-use of data on the basis of consent of data subjects or permissions of legal persons on the re-use of data pertaining to them through adequate technical means. In this respect, the public sector body should support potential re-users in seeking such consent by establishing technical mechanisms that permit transmitting requests for consent from re-users, where practically feasible. No contact information should be given that allows re-users to contact data subjects or companies directly.
2021/04/28
Committee: ITRE
Amendment 180 #
Proposal for a regulation
Recital 19
(19) In order to build trust in re-use mechanisms, it may be necessary to attach stricter conditions for certain types of non- personal data that have been identified as highly sensitive by a specific Union act, as regards the transfer to third countries, if such transfer could jeopardise public policy objectives, in line with international commitments. For example, in the health domain, certain datasets held by actors in the public health system, such as public hospitals, could be identified as highly sensitive health data. In order to ensure harmonised practices across the Union, such types of highly sensitive non-personal public data should be defined by Union law, for example in the context of the European Health Data Space or other sectoral legislation. The conditions attached to the transfer of such data to third countries should be laid down in delegated acts. Conditions should be proportionate, non-discriminatory and necessary to protect legitimate public policy objectives identified, such as the protection of public health, public order, safety, the environment, public morals, consumer protection, privacy and personal data protection. The conditions should correspond to the risks identified in relation to the sensitivity of such data, including in terms of the risk of the re- identification of individuals. These conditions could include terms applicable for the transfer or technical arrangements, such as the requirement of using a secure processing environment, limitations as regards the re-use of data in third-countries or categories of persons which are entitled to transfer such data to third countries or who can access the data in the third country. In exceptional cases they could also include restrictions on transfer of the data to third countries to protect the public interest.
2021/04/28
Committee: ITRE
Amendment 184 #
Proposal for a regulation
Recital 20
(20) Public sector bodies should be able to charge fees for the re-use of data but. Such fees should be reasonable, transparent, published online and non-discriminatory. Public sector bodies should also be able to decide to make the data available at lower or no cost, for example for certain categories of re-uses such as non- commercial re-use, or re-use by micro, small and medium-sized enterprises, so as to incentivise such re-use in order to stimulate research and innovation and support companies that are an important source of innovation and typically find it more difficult to collect relevant data themselves, in line with State aid rules. Such fees should be reasonable, transparent, published online and non- discriminatory. The list of categories of re- users for which discounted or no fees apply should be made public together with the criteria used to establish such list, in line with State aid rules and competition law.
2021/04/28
Committee: ITRE
Amendment 200 #
Proposal for a regulation
Recital 24
(24) Data cooperatives seek to strengthen the position of individuals in making informed choices before consenting to data use, influencing the terms and conditions of data user organisations attached to data use or potentially solving disputes between members of a group on how data can be used when such data pertain to several data subjects within that group. In this context it is important to acknowledge that the rights under Regulation (EU) 2016/679 can only be exercised by each individual and cannot be conferred or delegated to a data cooperative. Data cooperatives could also provide a useful means for one-person companies, micro, small and medium-sized enterprises that in terms of knowledge of data sharing, are often comparable to individuals. Upon request and informed consent of their associated members, cooperatives - which detain the data of their members for the realisation of their economic, social and cultural purposes - should be identifiable as "data cooperatives".
2021/04/28
Committee: ITRE
Amendment 205 #
Proposal for a regulation
Recital 25
(25) In order to increase trust in such data sharing services, in particular related to the use of data and the compliance with the conditions imposed by data holders, it is necessary to create a Union-level regulatory framework, which would set out highly harmonised requirements related to the trustworthy provision of such data sharing services. This will contribute to ensuring that data holders and data users have better control over the access to and use of their data, in accordance with Union law. Both in situations where data sharing occurs in a business-to-business context and where it occurs in a business-to- consumer context, data sharing providers should offer a novel, ‘European’ way of data governance, by providing a separation in the data economy between data provision, intermediation and use, which is at the core of increasing such trust among data holders, be they individuals or companies. Providers of data sharing services may also make available specific technical infrastructure for the interconnection of data holders and data users.
2021/04/28
Committee: ITRE
Amendment 238 #
Proposal for a regulation
Recital 37
(37) This Regulation is without prejudice to the establishment, organisation and functioning of entities that seek to engage in data altruism pursuant to national law. It builds on national law requirements to operate lawfully in a Member State as a not-for-profit organisation. Entities which meet the requirements in this Regulation should be able to use the title of ‘Data Altruism Organisations recognised in the Union’. The entity should use a EU dedicated logo or QR code linking to the European register of recognised data altruism organisations, both online and offline. The logo shall have the objective of providing a coherent visual identity to European Union data altruism organisations and contribute to increase trust for data subjects and legal entities. The logo must be created and displayed with rules established in a separate implementing act.
2021/04/28
Committee: ITRE
Amendment 250 #
Proposal for a regulation
Recital 40
(40) In order to successfully implement the data governance framework, a European Data Innovation Board should be established, in the form of an expert group. The Board should consist of representatives of the Member States, the Commission and representatives of relevant data spaces and specific sectors (such as health, agriculture, transport and statistics), the EU SME Envoy or a representative appointed by the network of SME envoys and representatives of relevant Agencies. The European Data Protection Board should be invited to appoint a representative to the European Data Innovation Board. Representatives of national, trans-national or Common European data spaces, businesses, researchers and civil society should be invited regularly to participate in the work of the Board. The Board should meet in different configurations, depending on the subjects to be discussed.
2021/04/28
Committee: ITRE
Amendment 298 #
Proposal for a regulation
Article 2 – paragraph 1 – point 2 a (new)
(2 a) ‘personal data’ means any information relating to a data subject as defined in point (1) of Article 4 of Regulation (EU) 2016/679;
2021/04/28
Committee: ITRE
Amendment 299 #
Proposal for a regulation
Article 2 – paragraph 1 – point 2 b (new)
(2 b) 'data subject' means an identified or identifiable natural person as referred to in point (1) of Article 4 of Regulation (EU) 2016/679;
2021/04/28
Committee: ITRE
Amendment 329 #
Proposal for a regulation
Article 2 – paragraph 1 – point 10 a (new)
(10 a) 'data cooperative' means an organisation supporting its members, who are data subjects or one-person companies, micro, small and medium- sized enterprises, in making informed choices before consenting to data processing, or in negotiating terms and conditions for data processing and data sharing;
2021/04/28
Committee: ITRE
Amendment 331 #
Proposal for a regulation
Article 2 – paragraph 1 – point 10 b (new)
(10 b) 'purposes of general interest' means purposes established by national law and national competent authorities including and not limited to healthcare, official statistics, improving the provision of public services, supporting research;
2021/04/28
Committee: ITRE
Amendment 361 #
Proposal for a regulation
Article 5 – paragraph 1
(1) Public sector bodies which are (1) competent under national law to grant or refuse access for the re-use of one or more of the categories of data referred to in Article 3 (1) shall make publicly available the conditions for allowing such re-use and the procedure to request the re-use. In that task, they may be assisted by the competent bodies referred to in Article 7 (1).
2021/04/28
Committee: ITRE
Amendment 366 #
Proposal for a regulation
Article 5 – paragraph 2
(2) Conditions for re-use shall be non- discriminatory, proportionate and objectively justified with regard to categories of data and purposes of re-use and the nature of the data for which re-use is allowed. These conditions shall not be used to restrictbe in line with competition law.
2021/04/28
Committee: ITRE
Amendment 370 #
Proposal for a regulation
Article 5 – paragraph 3
(3) Public sector bodies may impose an obligation to re-use only pre-viously processed data where such pre-processing, performed by the public sector itself, aims to anonymize or pseudonymise personal data or delete commercially confidential information, including trade secrets. or content protected by Intellectual Property Rights;
2021/04/28
Committee: ITRE
Amendment 386 #
Proposal for a regulation
Article 5 – paragraph 5
(5) The public sector bodies shall impose conditions that preserve the integrity of the functioning of the technical systems of the secure processing environment used, including high level cybersecurity standards. The public sector body shall be able to verify any results of processing of data undertaken by the re- user and reserve the right to prohibit the use of results that contain information jeopardising the rights and interests of third parties.
2021/04/28
Committee: ITRE
Amendment 398 #
Proposal for a regulation
Article 5 – paragraph 9 – introductory part
(9) TWhen justified by the volume of cases concerning the re-use of data in specific third countries, the Commission may adopt implementing acts declaring that the legal, supervisory and enforcement arrangements of a third country:
2021/04/28
Committee: ITRE
Amendment 410 #
Proposal for a regulation
Article 5 – paragraph 11
(11) Where specific Union acts adopted in accordance with a legislative procedure establish that certain non-personal data categories held by public sector bodies shall be deemed to be highly sensitive for the purposes of this Article, the Commission shall be empowered to adopt delegated acts in accordance with Article 28 supplementing this Regulation by laying down special conditions applicable for transfers to third-countries. The conditions for the transfer to third-countries shall be based on the nature of data categories identified in the Union act and on the grounds for deeming them highly sensitive, non-discriminatory and limited to what is necessary to achieve the public policy objectives identified in the Union law act, such as safety and public health, as well as risks of re-identification of anonymized data for data subjects, in accordance with the Union’s international obligations. They may include terms applicable for the transfer or technical arrangements in this regard, limitations as regards the re-use of data in third-countries or categories of persons which are entitled to transfer such data to third countries or, in exceptional cases, restrictions as regards transfers to third- countriesshall be non-discriminatory, proportionate and limited to what is necessary to achieve the public policy objectives identified in the Union law act.
2021/04/28
Committee: ITRE
Amendment 417 #
Proposal for a regulation
Article 5 – paragraph 13
(13) Where the re-user intends to transfer non-personal data to a third country, the public sector body shall inform the data holder about the transfer of data to that third country and the purpose of such transfer.
2021/04/28
Committee: ITRE
Amendment 422 #
Proposal for a regulation
Article 6 – paragraph 2
(2) Any fees shall be non- discriminatory, proportionate and objectively justified and shall not restrictbe in line with competition law.
2021/04/28
Committee: ITRE
Amendment 429 #
Proposal for a regulation
Article 6 – paragraph 4
(4) Where they apply fees, public sector bodies shall take measures to incentivise the re-use of the categories of data referred to in Article 3 (1) for non- commercial purposes and bythe re-use by micro and small and medium-sized enterprises in line with State aid rules.
2021/04/28
Committee: ITRE
Amendment 430 #
Proposal for a regulation
Article 6 – paragraph 4 a (new)
(4 a) Public sector bodies may set up a list of categories of re-users for which data is made available at reduced or no cost, which shall be published together with the criteria used to establish such list and which shall have the objective to foster a wider re-use of the categories of data referred to in Article 3(1) and accessibility by a wider range of re-users, in line with State aid rules and competition law;
2021/04/28
Committee: ITRE
Amendment 437 #
Proposal for a regulation
Article 7 – paragraph 2 – point b
(b) providing technical support in the application of tested techniques ensuring data processing in a manner that preserves privacy of the information contained in the data for which re-use is allowed, including techniques for pseudonymisation, anonymisation, generalisation, suppression and randomisation of personal data and the deletion of commercially confidential information, including trade secrets or content protected by Intellectual Property Rights;
2021/04/28
Committee: ITRE
Amendment 456 #
Proposal for a regulation
Article 8 – paragraph 3
(3) Requests for the re-use of the categories of data referred to in Article 3 (1) shall be granted or refused by the competent public sector bodies or the competent bodies referred to in Article 7 (1) within a reasonable timethe shortest delay, and in any case within two months from the date of the request.
2021/04/28
Committee: ITRE
Amendment 462 #
Proposal for a regulation
Article 9 – paragraph 1 – point c
(c) services of data cooperatives, that is to say services supporting data subjects or one-person companies or micro, small and medium-sized enterprises, who are members of the cooperative or who confer the power to the cooperative to negotiate terms and conditions for data processing before they consent, in making informed choices before consenting to data processing, and allowing for mechanisms to exchange views on data processing purposes and conditions that would best represent the interests of data subjects or legal persons.
2021/04/28
Committee: ITRE
Amendment 477 #
Proposal for a regulation
Article 10 – paragraph 4
(4) Upon notification, the provider of data sharing services may start the activity subject to the conditions laid down in this Chapter.deleted
2021/04/28
Committee: ITRE
Amendment 486 #
Proposal for a regulation
Article 10 – paragraph 7
(7) At the request of the provider, tThe competent authority shall, within one week, issue a standardised declaration, confirming that the provider has submitted the notification referred to in paragraph 4 and that the notification meets fully the requirements outlined in paragraph 6.
2021/04/28
Committee: ITRE
Amendment 487 #
Proposal for a regulation
Article 10 – paragraph 7 a (new)
(7 a) Upon reception of the standardised declaration, the provider of data sharing services may start the activity subject to the conditions laid down in this Chapter.
2021/04/28
Committee: ITRE
Amendment 503 #
Proposal for a regulation
Article 11 – paragraph 1 – point 2
(2) the metadata collected from the provision of the data sharing service may be used only for the development of that service and should be made available to the data holders upon request;
2021/04/28
Committee: ITRE
Amendment 512 #
Proposal for a regulation
Article 11 – paragraph 1 – point 5
(5) the provider shall have procedures in place to prevent and monitor potential fraudulent or abusive practices in relation to access to data from parties seeking access through their services;
2021/04/28
Committee: ITRE
Amendment 514 #
Proposal for a regulation
Article 11 – paragraph 1 – point 6
(6) the provider shall ensure a reasonable continuity of provision of its services and, in the case of services which ensure storage of data, shall have sufficient guarantees in place that allow data holders and data users to obtain access to and to retrieve their data in case of insolvency of the provider;
2021/04/28
Committee: ITRE
Amendment 521 #
Proposal for a regulation
Article 11 – paragraph 1 – point 8
(8) the provider shall take measures to ensure a high level of security, including cybersecurity standards, for the storage and transmission of non-personal data;
2021/04/28
Committee: ITRE
Amendment 536 #
Proposal for a regulation
Article 12 – paragraph 3
(3) The designated competent authorities, the data protection authorities, the national competition authorities, the authorities in charge of cybersecurity, and other relevant sectorial authorities shall build up a strong cooperation and exchange the information which is necessary for the exercise of their tasks in relation to data sharing providers.
2021/04/28
Committee: ITRE
Amendment 539 #
Proposal for a regulation
Article 13 – paragraph 3
(3) Where the competent authority finds that a provider of data sharing services does not comply with one or more of the requirements laid down in Article 10 or 11, it shall notify that provider of those findings and give it the opportunity to state its views, within a reasonable time limitthe shortest delay.
2021/04/28
Committee: ITRE
Amendment 564 #
Proposal for a regulation
Article 15 – paragraph 3
(3) An entity registered in the register in accordance with Article 16 may refer to itself as a ‘data altruism organisation recognised in the Union’ in its written and spoken communication. The entity shall use a EU dedicated logo or QR code linking to the European register of recognised data altruism organisations, both online and offline. The logo shall have the objective of providing a coherent visual identity to European Union data altruism organisations and contribute to increase trust for data subjects and legal entities. The logo must be created and displayed with rules established in a separate implementing act in accordance with the procedure referred to in Article 29.
2021/04/28
Committee: ITRE
Amendment 594 #
Proposal for a regulation
Article 17 – paragraph 6
(6) The information referred to in paragraph 4, points (a), (b), (f), (g), and (h) shall be published in the national public register of recognised data altruism organisations.
2021/04/28
Committee: ITRE
Amendment 597 #
Proposal for a regulation
Article 17 – paragraph 7
(7) Any entity entered in the public register of recognised data altruism organisations shall submit any changes of the information provided pursuant to paragraph 4 to the competent authority within 14 calendar days from the day on which the change takes place.
2021/04/28
Committee: ITRE
Amendment 607 #
Proposal for a regulation
Article 19 – paragraph 1 – introductory part
(1) Any entity entered in the register of recognised data altruism organisations shall inform data holderssubjects and legal entities in a clear and easy-to-understand manner:
2021/04/28
Committee: ITRE
Amendment 612 #
Proposal for a regulation
Article 19 – paragraph 1 – point a
(a) about the purposes of general interest for which it permits the processing of their data by a data user in an easy-to- understand manner;
2021/04/28
Committee: ITRE
Amendment 615 #
Proposal for a regulation
Article 19 – paragraph 1 – point b
(b) about any processingthe purposes of general interest for which it permits any processing of their data by a data user outside the Union.
2021/04/28
Committee: ITRE
Amendment 670 #
Proposal for a regulation
Article 26 – paragraph 1
(1) The Commission shall establish a European Data Innovation Board (“the Board”) in the form of an Expert Group, consisting of the representatives of competent authorities of all the Member States, the European Data Protection Board, the Commission, relevant data spacethe EU SME Envoy or a representative appointed by the network of SME envoys and other representatives of relevant Agencies or competent authorities in specific sectors.
2021/04/28
Committee: ITRE
Amendment 677 #
Proposal for a regulation
Article 26 – paragraph 2
(2) Stakeholders and relevant third parties may, including representatives of national, trans-national or Common European data spaces, businesses, researchers, civil society shall be invited regularly to attend meetings of the Board and to participate in its work.
2021/04/28
Committee: ITRE
Amendment 684 #
Proposal for a regulation
Article 26 – paragraph 3
(3) The Commission shall chair the meetings of the Board which may be conducted in different configurations, depending on the subjects to be discussed.
2021/04/28
Committee: ITRE
Amendment 692 #
Proposal for a regulation
Article 27 – paragraph 1 – point b
(b) to advise and assist the Commission in developing a consistent practice of the competent authorities in the application of requirements applicable to data sharing providers and data altruism organisations;
2021/04/28
Committee: ITRE
Amendment 699 #
Proposal for a regulation
Article 27 – paragraph 1 – point d
(d) to assist the Commission in addressing fragmentation of the data economy in the single market by enhancing the interoperability of data as well as data sharing services between different sectors and domains, building on existing European, international or national standards, inter alia with the aim of encouraging the creation of Common European data spaces;
2021/04/28
Committee: ITRE
Amendment 703 #
Proposal for a regulation
Article 27 – paragraph 1 – point d a (new)
(d a) To advise the Member States and the Commission on the possibility to set harmonised conditions allowing for re- use of data referred to in Article 3 (1) held by public sector bodies across the single market;
2021/04/28
Committee: ITRE
Amendment 713 #
Proposal for a regulation
Article 27 – paragraph 1 – point e a (new)
(e a) to advise the Commission in the decision of adopting implementing acts referred to in article 5 (9);
2021/04/28
Committee: ITRE
Amendment 714 #
Proposal for a regulation
Article 27 – paragraph 1 – point e b (new)
(e b) to assist the Commission in the discussions conducted at bilateral, plurilateral or multilateral level with third countries aimed at improving the regulatory environment for non-personal data, including standardisation, at global level;
2021/04/28
Committee: ITRE
Amendment 737 #
Proposal for a regulation
Article 32 – paragraph 1
By [fourtwo years after the data of application of this Regulation], the Commission shall carry out an evaluation of this Regulation, and submit a report on its main findings to the European Parliament and to the Council as well as to the European Economic and Social Committee. Member States shall provide the Commission with the information necessary for the preparation of that report.
2021/04/28
Committee: ITRE