GDPR 2.0. Upcoming big changes for GDPR enforcement in the E.U.

Brief overview of procedural challenges under GDPR 1.0. 

Although it is undisputed that the EU flagship data protection legal regime has been a major digital policy success, judging only by its global influence, many voices called for its reform in particular with regards to Supervisory Authorities handling of cross-border investigations. This approach is very much consistent with the EU Commission plans that “further progress is required to make the handling of cross-border cases more efficient and harmonised across the EU”.  

At the heart of the reform is the one-stop-shop enforcement mechanism which caused a concentration of investigations in the hands of only few Supervisory Authorities (SA), typically in the member states where the big tech giants established their main European operations such as Ireland or Luxembourg.  

Basically, according to the GDPR, the Lead Supervisory Authority (LSA) in cross-border investigations is the SA of the main establishment of the data controller.  

Nevertheless, despite, the GDPR providing for cooperation and dispute resolution mechanisms between the LSA and other concerned SAs, disagreements on procedural details resulted in important delays with repercussions (i.e., individuals left on the sidelines) on an important number of cross-border investigations. This led to the GDPR success being put into question.  

The European Data Protection Board implication  

In this context, on 28 April 2022, the European Data Protection Board (EDPB) issued a statement on enforcement cooperation also known as the Vienna Statement. In this Statement, the EDPB identified a list of procedural aspects that could be further harmonised in EU law to maximise the positive impact of GDPR cooperation. This list addresses, inter alia, the status and rights of the parties to the administrative procedures, procedural deadlines, requirements for admissibility or dismissal of complaints, investigative powers of Supervisory Authorities and the practical implementation of the cooperation procedure. 

The EU Commission proposal for a GDPR 2.0. 

Following suit, on 4 July 2023, the European Commission issued a Proposal for a Regulation laying down additional procedural rules relating to the enforcement of the GDPR. Practitioners are referring to this Proposal as to GDPR 2.0.  

On 19 September 2023 the European Data Protection Board and the European Data Protection Supervisor releases a Joint Opinion 01/2023 on the latter proposal.  

GDPR 2.0. covers certain procedural aspects aimed at avoiding procedural disagreements between SAs, making the process faster and easier for the complainant, and helping the SAs with more robust decisions.  

Here are some key points in the Commission’s Proposal 

  1. Cross-border complaints. A complaint relating to cross-border data protection or privacy matters will be admissible basis on a unique form completed by the complainant. Within certain procedural terms the receiving SA will send the complaint to the LSA. A complaint may be resolved by amicable settlement between the complainant and the parties under investigation. The translation of the complaint and supporting document will fall under the administration of the supervisory authority with which the complaint was lodged.  
  2. Reaching consensus. The LSA will regularly update and provide relevant information to the concerned SAs. The LSA will additionally submit a draft summary of key issues to the concerned SAs for their comments. Where disagreements arise the LSA will engage with the SA concerned based on their comments on the summary of key issues in an endeavour to reach a consensus at an early stage. Where consensus cannot be reached the European Data Protection Board will be called to adopt an urgent binding decision on the scope of the investigation based on the comments of the supervisory authorities concerned and the position of the lead supervisory authority on those comments. 
  3. Hearing of complainant prior to full or partial rejection of a complaint. The SA with which the complaint was lodged must inform the complainant of the reasons for the intended full or partial rejection of the complaint and set a time-limit within which the complainant may make known her or his views in writing.  
  4. Preliminary findings. LSA will draft and submit preliminary findings before the infringement draft decision. When notifying the preliminary findings to the controller/s and/or processor/s under investigation, the LSA will equally provide them with access to the administrative file while allowing them to write a reply 
  5. Non-confidential version of submissions. An entity submitting information that it considers to be confidential must clearly identify such information giving reasons for the confidentiality claims. The entity must provide a separate non-confidential version of the submission or otherwise, identify the documents or parts of documents which it considers containing business secrets or other confidential information or to identify the parties for which the documents are considered to be confidential.  

Conclusion

GDPR 2.0. is a procedural regulation exclusively, with a limited scope, aiming at setting up enhanced rules to avoid that the SAs would use very lengthy litigation measures before they come to an agreement in cross-border litigation.  

For that reason, GDPR 2.0. is nudging authorities to reach an agreement ahead of litigations by harmonising certain parts of the procedures. At the same time, the proposed rules give EDPB new powers to issue fast decisions ahead of the lengthy formal dispute resolution procedures which have often been pointed at for being the reason for stalling the process of enforcement of the GDPR.  

As regards to timeline for adoption, given the limited scope of this Regulation, the adoption process might be short and might take place under the mandate of the current EU Commission. Else, in case some of the member states impeding that fast adoption, this might be one of those files that is dragged onto the next Commission’s mandate.  

Also, as IAPP is announcing a panel discussion at the upcoming IAPP Europe Data Protection Congress in Brussels, titled “The GDPR Is 5 Years Old: Is It the Age of Maturity?” will explore the topic.  

Wrangu will be present at the IAPP event in Brussels with a team of data protection and privacy professionals on the ground. They will be happy to engage in conversations on the matter and respond to questions.   

At Wrangu, we have a legal team on top of privacy and data protection combined with technical experts to deliver GDPR solutions. Download our brochure or schedule a call to see how we can help solve your GDPR needs.

Author

  • Petruţa Pirvan is a Lawyer and a Data Protection Professional specializing in interpreting data protection international legislation with more than 15 years of practice in her profession. She is a member of the International Association of Privacy Professionals, a Fellow of International Privacy (FIP) and a Certified Data Privacy Manager (CIPM) and Professional for Europe and US (CIPP/E & CIPP/US). She currently acts as a Data Privacy Consultant/Head of Privacy and Compliance at Wrangu.

    View all posts

Author

  • Petruţa Pirvan is a Lawyer and a Data Protection Professional specializing in interpreting data protection international legislation with more than 15 years of practice in her profession. She is a member of the International Association of Privacy Professionals, a Fellow of International Privacy (FIP) and a Certified Data Privacy Manager (CIPM) and Professional for Europe and US (CIPP/E & CIPP/US). She currently acts as a Data Privacy Consultant/Head of Privacy and Compliance at Wrangu.

    View all posts