BETA

40 Amendments of Lucy ANDERSON related to 2017/0228(COD)

Amendment 41 #
Proposal for a regulation
Recital 1
(1) The digitisation of the economy is accelerating. Information and Communications Technology (ICT) is no longer a specific sector but the foundation of all modern innovative economic systems and societies. Electronic data is at the centre of those systems and can generate great value when analysed or combined with services and products. At the same time, cybersecurity represents one of the major threats to our societies. Securing network and information systems in the European Union is essential for the further development of the online economy, as well as for ensuring that there is trust in the digital economy as a whole. Consequently, this Regulation and the ENISA Regulation [2017/0225(COD)] need to be fully consistent with one another.
2018/04/09
Committee: IMCO
Amendment 46 #
Proposal for a regulation
Recital 3
(3) The freedom of establishment and the freedom to provide services under the Treaty on the Functioning of the European Union apply to data storage or other processing services. However, the provision of those services is hampered or sometimes prevented by certain national or federal requirements to locate data in a specific territory.
2018/04/09
Committee: IMCO
Amendment 53 #
Proposal for a regulation
Recital 4
(4) Such obstacles to the free movement of data storage or other processing services and to the right of establishment of data storage or other processing providers originate from requirements in the national or federal laws of Member States to locate data in a specific geographical area or territory for the purpose of storage or other processing. Other rules or administrative practices have an equivalent effect by imposing specific requirements which make it more difficult to store or otherwise process data outside a specific geographical area or territory within the Union, such as requirements to use technological facilities that are certified or approved within a specific Member State. Legal uncertainty as to the extent of legitimate and illegitimate data localisation requirements further limits the choices available to market players and to the public sector regarding the location of data storage or other processing.
2018/04/09
Committee: IMCO
Amendment 58 #
Proposal for a regulation
Recital 6
(6) For reasons of legal certainty and the need for a level playing field within the Union, a single set of rules for all market participants is a key element for the functioning of the internal market. IConsidering that the free movement of data is a fundamental element for the realization of the Digital Single Market and in order to remove obstacles to trade and distortions of competition resulting from divergences between national laws and to prevent the emergence of further likely obstacles to trade and significant distortions of competition, it is therefore necessary to adopt uniform rules applicable in all Member States.
2018/04/09
Committee: IMCO
Amendment 59 #
Proposal for a regulation
Recital 7
(7) In order to create a framework for the free movement of non-personal data in the Union and the foundation for developing the data economy and enhancing the competitiveness of European industry in compliance with European data protection rules, it is necessary to lay down a clear, comprehensive and predictable legal framework for storage or other processing of data other than personal data in the internal market. A principle-based approach providing for cooperation among Member States as well as self-regulation should ensure that the framework is flexible so that it can take into account the evolving needs of users, providers and national authorities in the Union. In order to avoid the risk of overlaps with existing mechanisms and hence to avoid higher burdens both for Member States and businesses, detailed technical rules should not be established.
2018/04/09
Committee: IMCO
Amendment 65 #
Proposal for a regulation
Recital 9
(9) The legal framework on the protection of natural persons with regard to the processing of personal data, in particular Regulation (EU) 2016/67930, and Directive (EU) 2016/68031 and Directive 2002/58/EC32s well as the legal framework on the respect for private life and the protection of personal data in electronic communications, in particular Directive 2002/58/EC32 to be repealed by new regulation 2017/003 (COD)32a should not be affected by this Regulation. _________________ 30 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). 31 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89). 32 Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37). 32aRegulation of the European Parliament and the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC.
2018/04/09
Committee: IMCO
Amendment 68 #
Proposal for a regulation
Recital 9 a (new)
(9a) This Regulation should not apply to the storage or other processing of electronic data in the case of any intermixture of non-personal data and personal data, or in the case of any combination of non-personal data that could lead to personal data or to identify a person.
2018/04/09
Committee: IMCO
Amendment 72 #
Proposal for a regulation
Recital 10
(10) Under Regulation (EU) 2016/679, Member States may neither restrict nor prohibit the free movement of personal data within the Union for reasons connected with the protection of natural persons with regard to the processing of personal data. This Regulation establishes the same principle of free movement within the Union for non-personal data except when a restriction or a prohibition would be justified for security reasons. Regulation (EU) 2016/679 and this Regulation provide a coherent set of rules that cater for free movement of different types of data. In the case of mixed data sets, Regulation (EU) 2016/679 should apply to the personal data part of the set, and this Regulation should apply to the non-personal data part of the set. Where non-personal and personal data are inextricably linked, this Regulation should not prejudice the application of Regulation (EU) 2016/679. The protection of the privacy of natural and legal persons as well as the protection of the processing of personal data, in particular Regulation (EU) 2016/679, Directive (EU) 2016/680 and Directive 2002/58/EC shall not be affected by this. Furthermore, this Regulation does not impose an obligation to store the different types of data separately.
2018/04/09
Committee: IMCO
Amendment 74 #
Proposal for a regulation
Recital 10
(10) Under Regulation (EU) 2016/679, Member States may neither restrict nor prohibit the free movement of personal data within the Union for reasons connected with the protection of natural persons with regard to the processing of personal data. This Regulation establishes the same principle of free movement within the Union for non-personal data except when a restriction or a prohibition would be justified for security reasons. Regulation 2016/679 and this Regulation regulate respectively personal and non- personal data. In the case of closely linked mixed data, which cannot be separated either technically or economically, this Regulation should as a whole, without prejudice to Regulation 2016/679. In those cases where a set of mixed data includes personal data that may directly affect the protection of physical persons, and put at stake the fundamental rights and freedoms thereof, Regulation 2016/679 will apply.
2018/04/09
Committee: IMCO
Amendment 78 #
Proposal for a regulation
Recital 10 a (new)
(10a) Whereas data that is neither personal nor non-personal does not exist by definition, new technological advancements in big data analytics have opened up for the possibility to turn anonymised non-personal data into personal data by comparing and aggregating large quantities of non- personal data. In this case, the line between personal data and non-personal data is not fixed but rather depends upon technological developments and new uses of technologies. In these instances, where non-personal data has become personalised, the data should be treated as such and the provisions laid down in Regulation (EU) 2016/679 should apply accordingly.
2018/04/09
Committee: IMCO
Amendment 82 #
Proposal for a regulation
Recital 10 b (new)
(10b) The growing availability of Internet of Things (IoT) and the development of machine learning and Artificial Intelligence (AI) goes hand in hand with the proliferation of devices that collect non-personal data. These new technologies are already used in farm productivity, translation, manufacturing robots and navigation systems among others. However, data collected within certain industries could contain both personal and non-personal data and should be treated under the Regulation (EU) 2016/679 and this regulation respectively.
2018/04/09
Committee: IMCO
Amendment 83 #
Proposal for a regulation
Recital 10 c (new)
(10c) The Commission should provide clear and easily accessible guidelines on the legal treatment of mixed data sets in order for especially SMEs to handle the interaction between this Regulation and Regulation (EU) 2016/679.
2018/04/09
Committee: IMCO
Amendment 85 #
(11) This Regulation should apply to electronic data storage or other processing in the broadest sense, encompassing the usage of all types of IT systems, whether located on the premises of the user or outsourced to a data storage or other processing service provider. It should cover data processing of different levels of intensity, from data storage (Infrastructure-as-a-Service (IaaS)) to the processing of data on platforms (Platform- as-a-Service (PaaS)) or in applications (Software-as-a-Service (SaaS)). These different services should be within the scope of this Regulation, unless data storage or other processing is merely ancillary to a service of a different type, such as providing an online marketplace intermediating between service providers and consumers or business users.
2018/04/09
Committee: IMCO
Amendment 88 #
Proposal for a regulation
Recital 12
(12) Data localisation requirements represent a clear barrier to the free provision of data storage or other processing services across the Union and to the internal market. As such, they should be banned unless they are justified based on the grounds of public security, as defined by Union law, in particular Article 52 of the Treaty on the Functioning of the European Union, and satisfy the principle of proportionality enshrined in Article 5 of the Treaty on European Union. Regardless of this data storage or other processing of authorities and political bodies of national or federal governments and parliaments should be always considered to be justified for grounds of public security. In order to give effect to the principle of free flow of non-personal data across borders, to ensure the swift removal of existing data localisation requirements and to enable for operational reasons storage or other processing of data in multiple locations across the EU, and since this Regulation provides for measures to ensure data availability for regulatory control purposes, Member States should not be able to invoke justifications other than public security.
2018/04/09
Committee: IMCO
Amendment 91 #
Proposal for a regulation
Recital 12
(12) Data localisation requirements represent a clear barrier to the free provision of data storage or other processing services across the Union and to the internal market. As such, they should be banned unless they are justified based on thimperative grounds of public security, as defined by Union law, in particular Article 52 of the Treaty on the Functioning of the European Union, and satisfy the principle of proportionality enshrined in Article 5 of the Treaty on European Union. In order to give effect to the principle of free flow of non-personal data across borders, to ensure the swift removal of existing data localisation requirements and to enable for operational reasons storage or other processing of data in multiple locations across the EU, and since this Regulation provides for measures to ensure data availability for regulatory control purposes, Member States should not be able to invoke justifications other than public security.
2018/04/09
Committee: IMCO
Amendment 93 #
Proposal for a regulation
Recital 12 a (new)
(12a) The concept of ‘public security’, is understood within the meaning of Article 52 of the TFEU and as interpreted by the European Court of Justice. The concept of ‘public security’ covers both the internal and external security of a Member State. Public security presupposes the existence of a genuine and sufficiently serious threat affecting one of the fundamental interests of society, such as a threat to the functioning of institutions and essential public services and the survival of the population, as well as by risk of a serious disturbance to foreign relations or the peaceful coexistence of nations, or a risk of military interest.
2018/04/09
Committee: IMCO
Amendment 94 #
(12a) The concept of “public security” within the meaning of Article 52 of the TFEU, encompasses the internal and external security of Member States. As established by the case law of the CJEU, the concept of imperative grounds of public security involves not only the existence of impairment of public safety, but also that such impairment presents a particularly high level of seriousness.
2018/04/09
Committee: IMCO
Amendment 102 #
Proposal for a regulation
Recital 14
(14) Moreover, in order to eliminate potential existing barriers, during a transitional period of 12 months, Member States should carry out a review of existing national or federal data localisation requirements and notify to the Commission, together with a justification, any data localisation requirement that they consider being in compliance with this Regulation. These notifications should enable the Commission to assess the compliance of any remaining data localisation requirements.
2018/04/09
Committee: IMCO
Amendment 105 #
Proposal for a regulation
Recital 16
(16) Data localisation requirements are frequently underpinned by a lack of trust in cross-border data storage or other processing, deriving from the presumed unavailability of data for the purposes of the competent authorities of the Member States, such as for inspection and audit for regulatory or supervisory control. Therefore, this Regulation should clearly establish that it does not affect the powers of competent authorities to request and receive access to data in accordance with Union or national law, and that access to data by competent authorities may not be refused on the basis that the data is stored or otherwise processed in another Member State, neither by the provider according to Art. 3 No. 4, nor by the professional user according to Art. 3 No. 8, nor by any authority of the other Member State with the exception of Art. 7 of this regulation.
2018/04/09
Committee: IMCO
Amendment 114 #
Proposal for a regulation
Recital 21
(21) In order to take full advantage of the competitive environment, professional users should be able to make informed choices and easily compare the individual components of various data storage or other processing services offered in the internal market, including as to the contractual conditions of porting data upon the termination of a contract. In order to align with the innovation potential of the market and to take into account the experience and expertise of the providers and professional users of data storage or other processing services, the detailed information and operational requirements for data porting should be defined by market players through self-regulation, encouraged and facilitated by the Commission, in the form of Union codes of conduct which may entail model contract terms. Nonetheless, if such codes of conduct are not put in place and effectively implemented within a reasonable period of time, the Commission should review the situation. based on Commission non- binding guidelines, in the form of Union codes of conduct which may entail model contract terms. When drafting the guidelines, the Commission may take into account “Cloud Service Level Agreement Standardisation Guidelines” and the activities performed within the Cloud Stakeholders’ Platform initiative. The Commission shall ensure that all relevant stakeholders, including small and medium enterprises and start-ups are consulted in the process. Nonetheless, if such codes of conduct are not put in place and effectively implemented or do not sufficiently meet the objectives of the proposed Regulation, the Commission should review the situation within two years after the entry into force of this Regulation and introduce, if appropriate, a statutory right to data portability.
2018/04/09
Committee: IMCO
Amendment 116 #
Proposal for a regulation
Recital 21
(21) In order to take full advantage of the competitive environment, professional users should be able to make informed choices and easily compare the individual components of various data storage or other processing services offered in the internal market, including as to the contractual conditions of porting data upon the termination of a contract. In order to align with the innovation potential of the market and to take into account the experience and expertise of the providers and professional users of data storage or other processing services, the detailed information and operational requirements for data porting should be defined by market players through self-regulation, encouraged and facilitated by the Commission, in the form of Union codes of conductimplementing acts which may entail model contract terms. Nonetheless, if such codes of conduct are not put in place and effectively implemented within a reasonable period of time, the Commission should review the situation.
2018/04/09
Committee: IMCO
Amendment 124 #
Proposal for a regulation
Recital 26
(26) Security requirements set at national or federal level should be necessary and proportionate to the risks posed to the security of data storage or other processing in the area in scope of the national law in which these requirements are set.
2018/04/09
Committee: IMCO
Amendment 128 #
Proposal for a regulation
Recital 28
(28) The Commission should periodically review this Regulation, in particular with a view to determining the need for modifications in the light of technological or market developments, especially with regards to the development of artificial intelligence, machine learning, Internet of Things, big data analysis among others.
2018/04/09
Committee: IMCO
Amendment 131 #
Proposal for a regulation
Recital 28 a (new)
(28 a) The legal framework of public procurement, especially with regard to environmental, social and labour aspects of public procurement, in particular Directive (EU) 2014/241a should not be affected by this Regulation. _________________ 1aDirective 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC.
2018/04/09
Committee: IMCO
Amendment 141 #
Proposal for a regulation
Article 2 – paragraph 1 a (new)
1a. This Regulation shall not apply to the storage or other processing of electronic data in the case of any intermixture of non-personal data and personal data, or in the case of any combination of non-personal data that can lead to personal data or to identify a person.
2018/04/09
Committee: IMCO
Amendment 142 #
Proposal for a regulation
Article 2 – paragraph 1 a (new)
1a. In the case of mixed data sets, this Regulation shall apply to the non- personal data part of the set. Where personal and non-personal data are inextricably linked, this Regulation shall apply without prejudice to Regulation (EU) 2016/679.
2018/04/09
Committee: IMCO
Amendment 150 #
Proposal for a regulation
Article 3 – paragraph 1 – point 1 a (new)
1a. ‘mixed data set’ means a data set composed of both personal and non- personal data.
2018/04/09
Committee: IMCO
Amendment 173 #
Proposal for a regulation
Article 4 – paragraph 4
4. Member States shall makeprovide the public with the details of any data localisation requirements applicable in their territory publicly availablevia an online via a single information point which they shall keep up-to-date.
2018/04/09
Committee: IMCO
Amendment 177 #
Proposal for a regulation
Article 5 – paragraph 1
1. This Regulation shall not affect the powers ofprevent competent authorities tofrom requesting and receiveing access to data for the performance of their official duties in accordance with Union or national law. Access to data by competent authorities may not be refused on the basis that the data is stored or otherwise processed in another Member State.
2018/04/09
Committee: IMCO
Amendment 178 #
Proposal for a regulation
Article 5 – paragraph 2
2. Where a competent authority has exhausted all applicable means to obtain access to the datadoes not receive access to the data after having contacted the provider of the data storage or processing service, it may request the assistance of a competent authority in another Member State in accordance with the procedure laid down in Article 7, and the requested competent authority shall provide assistance in accordance with the procedure laid down in Article 7, unless it would be contrary to the public order of the requested Member State.
2018/04/09
Committee: IMCO
Amendment 192 #
Proposal for a regulation
Article 6 – paragraph 1 – introductory part
1. The Commission shall encourage and facilitate the development of self- regulatory codes of conduct at Union level, in order to define guidelines on best practices inmay adopt implementing acts in order to specify requirements to facilitatinge the switching of providers and to ensure that they provide professional users with sufficiently detailed, clear and transparent information before a contract for data storage and processing is concluded, as regards the following issues:
2018/04/09
Committee: IMCO
Amendment 193 #
Proposal for a regulation
Article 6 – paragraph 1 – introductory part
1. The Commission shall encourage and facilitateprepare non-binding guidelines on the development of self- regulatory codes of conduct at Union level, in order to define guidelines oncluding best practices in facilitating the switching of providers and to ensure that they provide professional users with sufficiently detailed, clear and transparent information before a contract for data storage and processing is concluded, as regards the following issues:
2018/04/09
Committee: IMCO
Amendment 203 #
Proposal for a regulation
Article 6 – paragraph 1 a (new)
1a. The Commission shall ensure that the codes of conduct are developed in close cooperation with all relevant stakeholders, including associations of small and medium-sized enterprises and start-ups, users and providers of cloud services.
2018/04/09
Committee: IMCO
Amendment 209 #
Proposal for a regulation
Article 6 – paragraph 3
3. The Commission shall review the development and effective implementation of such codes of conduct and the effective provision of information by providers no later than two years after the start of application of this Regulation.deleted
2018/04/09
Committee: IMCO
Amendment 212 #
Proposal for a regulation
Article 6 – paragraph 3
3. The Commission shall reviewsubmit a report to the European Parliament and to the Council on the development and effective implementation of such codes of conduct and the effective provision of information by providers no later than two years after the start of application of this Regulation. The report shall be accompanied, if appropriate, by legislative proposals.
2018/04/09
Committee: IMCO
Amendment 216 #
Proposal for a regulation
Article 7 – paragraph 4 – subparagraph 1 (new)
The authority shall only refuse the request if: (a) it is not competent for the subject- matter of the request or for the measures it is requested to execute; or (b) compliance with the request would infringe this Regulation or Union or Member State law to which the requested authority receiving the request is subject.
2018/04/09
Committee: IMCO
Amendment 218 #
Proposal for a regulation
Article 9 – paragraph 1
1. No later than [53 years after the date mentioned in Article 10(2)], the Commission shall carry out a review of this Regulation and present a report on the main findings to the European Parliament, the Council and the European Economic and Social Committee. The Commission shall review the implementation of this Regulation in particular in respect of:
2018/04/09
Committee: IMCO
Amendment 223 #
Proposal for a regulation
Article 9 – paragraph 1 – point a (new)
(a) The application of this Regulation to mixed data sets especially taking into account the development of new technologies such as Internet of Things, artificial intelligence, big data analysis and the process of deanonymising data.
2018/04/09
Committee: IMCO
Amendment 226 #
Proposal for a regulation
Article 9 – paragraph 1 – point b (new)
(b) The use of the public security exception by Member States as defined in Article 4(1).
2018/04/09
Committee: IMCO
Amendment 229 #
Proposal for a regulation
Article 9 – paragraph 2 a (new)
2a. By 6 months after the date of publication of this Regulation the Commission shall provide guidelines on the legal treatment of mixed data sets and the interaction between this Regulation and Regulation (EU) 2016/679.
2018/04/09
Committee: IMCO