New EU Regulation on the Free Flow on Non-Personal Data
Total Page:16
File Type:pdf, Size:1020Kb
New EU regulation on the free flow of non- personal data May 2019 New EU regulation on the free flow of non-personal data Document Summary Document Item Current Value Document Name New EU regulation on the free flow of non-personal data Document Date May 2019 Document Version 1.0 Document Issue Document Status Draft Document Description This information package has been developed to inform GS1 stakeholders on a new European regulation with potential impact on the GS1 community. For more information please contact our Public Policy Director for Europe, Francesca Poggiali. Contributors Name Organisation Francesca Poggiali GS1 Public Policy Director for Europe Log of Changes Release Date of Change Changed By Summary of Change Disclaimer GS1®, under its IP Policy, seeks to avoid uncertainty regarding intellectual property claims by requiring the participants in the Work Group that developed this GS1 Document Name GS1 Document Type to agree to grant to GS1 members a royalty-free licence or a RAND licence to Necessary Claims, as that term is defined in the GS1 IP Policy. Furthermore, attention is drawn to the possibility that an implementation of one or more features of this Specification may be the subject of a patent or other intellectual property right that does not involve a Necessary Claim. Any such patent or other intellectual property right is not subject to the licencing obligations of GS1. Moreover, the agreement to grant licences provided under the GS1 IP Policy does not include IP rights and any claims of third parties who were not participants in the Work Group. Accordingly, GS1 recommends that any organization developing an implementation designed to be in conformance with this Specification should determine whether there are any patents that may encompass a specific implementation that the organisation is developing in compliance with the Specification and whether a licence under a patent or other intellectual property right is needed. Such a determination of a need for licencing should be made in view of the details of the specific system designed by the organisation in consultation with their own patent counsel. THIS DOCUMENT IS PROVIDED “AS IS” WITH NO WARRANTIES WHATSOEVER, INCLUDING ANY WARRANTY OF MERCHANTABILITY, NONINFRINGMENT, FITNESS FOR PARTICULAR PURPOSE, OR ANY WARRANTY OTHER WISE ARISING OUT OF THIS SPECIFICATION. GS1 disclaims all liability for any damages arising from use or misuse of this Standard, whether special, indirect, consequential, or compensatory damages, and including liability for infringement of any intellectual property rights, relating to use of information in or reliance upon this document. GS1 retains the right to make changes to this document at any time, without notice. GS1 makes no warranty for the use of this document and assumes no responsibility for any errors which may appear in the document, nor does it make a commitment to update the information contained herein. GS1 and the GS1 logo are registered trademarks of GS1 AISBL. Release 1.0, Draft, 2019 © 2019 GS1 AISBL Page 2 of 16 New EU regulation on the free flow of non-personal data Table of Contents 1. General overview of the EU’s legislative procedure ............................................................................. 4 2. Main changes introduced by the new Regulation ................................................................................. 4 3. Stakeholder reactions to the adoption of the new EU regulation ........................................................... 6 3.1 European Commission – Free flow of data in the EU: a pathway into the cloud .................................. 6 3.1.1 The free flow of non-personal data principle .......................................................................... 7 3.1.2 The data availability principle ............................................................................................... 8 3.1.3 Self-regulation on switching and porting ............................................................................... 8 3.1.4 EU cloud security certification .............................................................................................. 9 3.1.5 A sustainable green cloud ................................................................................................... 10 3.2 EPP Group – Free flow of data: new era for digital economy in Europe ............................................. 11 3.3 S&D Group – Free flow of non-personal data in the EU needs to be transparent and net neutral ......... 11 3.4 BusinessEurope – Making the free flow of data a reality ................................................................. 12 3.5 DIGITALEUROPE – DIGITALEUROPE views on the Regulation on the Framework for the Free Flow of Non-Personal Data .......................................................................................................................... 13 3.6 CISPE – CISPE commits to creating the first ever Cloud Infrastructure Data Portability Code of Conduct after EU Regulation on free flow of data agreed .................................................................................. 14 3.7 AIOTI – EU Free Flow of Non-Personal Data: AIOTI Discussion Paper – March 2018 .......................... 15 3.8 ECIPE (European Centre for International Political Economy) – The Free Flow of Non-Personal Data .... 15 Release 1.0, Draft, 2019 © 2019 GS1 AISBL Page 3 of 16 New EU regulation on the free flow of non-personal data 1 General overview of the EU’s legislative procedure The European Commission presented a framework for the free flow of non-personal data in September 2017 as part of President Jean-Claude Juncker's State of the Union address to unlock the full potential of the European Data Economy. It was announced as one of the key actions in the mid-term review of the Digital Single Market strategy. A provisional political agreement was approved by the European Parliament’s Internal Market and Consumer Protection (IMCO) committee on 12 July 2018. Later on, the plenary endorsed the agreement at first reading and The Council also gave a green light on November 2018. The Regulation was formally signed by the Parliament and the Council on 14 November 2018 and will enter into force in May 2019. It is interesting to highlight that during the EU Council vote on 9 November 2018, the agreement reached with the Parliament was approved by unanimity by all the EU 28 EU Member States. The final text can be accessed here. 2 Main changes introduced by the new Regulation The new free flow of non-personal data rules, as approved, will: • Ensure the free flow of data across borders: the new rules set a framework for data storing and processing across the EU, prohibiting data localisation restrictions. Member States will have to inform the Commission of any remaining or planned data localisation restrictions in limited specific situations of public sector data processing. The Regulation on free flow of non-personal data has no impact on the application of the General Data Protection Regulation (GDPR), as it does not cover personal data. However, the two Regulations will function together to enable the free flow of any data – personal and non- personal – thus creating a single European space for data. In the case of a mixed dataset, the GDPR provision guaranteeing free flow of personal data will apply to the personal data part of the set, and the free flow of non-personal data principle will apply to the non-personal part; • Ensure data availability for regulatory control: public authorities will be able to access data for scrutiny and supervisory control wherever it is stored or processed in the EU. Release 1.0, Draft, 2019 © 2019 GS1 AISBL Page 4 of 16 New EU regulation on the free flow of non-personal data Member States may sanction users that do not provide access to data stored in another Member State; • Encourage creation of codes of conduct for cloud services to facilitate switching between cloud service providers under clear deadlines. This is expected to make the market for cloud services more flexible and the data services in the EU more affordable; • The agreed measures are also in line with existing rules for the free movement and portability of personal data in the EU; • Review: no later than 3 years and 6 months after the date of publication of the Regulation, the Commission shall submit a report evaluating the implementation of the Regulation, in particular as regards: (i) the application of the Regulation to mixed data sets; (ii) the implementation by Member States of the public security exception; (iii) the development and effective implementation of codes of conduct; • Mixed data sets: in the case of a mixed data set, namely a data set composed of both personal and non-personal data, the Regulation shall apply to the non-personal data of the data set. Where non-personal and personal data are inextricably linked, this Regulation should apply without prejudice to Regulation (EU) 2016/679; • Access to data for public authorities: the Commission's proposal provides that where a competent authority has exhausted all possible means of accessing data, it could request the assistance of an authority in another Member State if no specific cooperation mechanism exists. Members believe that such assistance could be requested where a competent authority does not obtain access to the data after contacting the user of the data processing service and where there is no specific cooperation mechanism under EU law or international agreements for the exchange