译者 | 孙书朋 西南政法大学硕士
一审 | 曾梓栩 外交学院本科
二审 | 刘寅 西南政法大学本科
编辑 | 王冰子 烟台大学本科
         于杰 上海对外经贸大学本科
责编|  戚琳颖 大连海事大学本科
EDPB informs stakeholders about the implications of the DPF and adopts a statement on the first review of the Japan adequacy decision
欧盟数据保护委员会向利益相关方通报了《数据隐私框架》可能产生的影响并通过了关于首次审查对日本充分性决定的声明
Brussels, 19 July - During its latest EDPB plenary, the EDPB adopted an information note for individuals and entities transferring data to the U.S.. This note aims to provide concise and objective information regarding the impact of the adequacy decision on transfers to the U.S., the redress mechanisms available under the Data Privacy Framework (DPF), and the new redress mechanism in the area of national security.
7月19日,于布鲁塞尔最近召开的欧盟数据保护委员会全体会议(EDPB)通过了关于个人和实体向美国传输数据的情况说明。该说明旨在就充分性决定对美传输数据产生的影响、《数据隐私框架》(Data Privacy Framework, 简称DPF)下现行的救济机制以及在国家安全领域新的救济机制等方面提供精确、客观的信息。
EDPB Chair, Anu Talus said: “The adoption of the DPF by the European Commission, following the EDPB opinion of February 2023, is an important decision recognising that personal data can now flow from the European Economic Area to the United States, without any further conditions. It is essential that individuals are aware of their rights and that organisations know their obligations, which the EDPB explains in the information note. The EDPB will continue to pay special attention to the correct implementation of this new instrument and we look forward to contributing to the first review of the DPF next year.”
欧盟数据保护委员会主席安努·塔卢斯(Anu Talus)说道:“欧盟数据保护委员会在2023年2月发布意见后,通过了《数据隐私框架》,这是一个重要的决定,该决定承认了个人数据如今无需其他任何条件即可从欧洲经济区流向美国。正如欧盟数据保护委员会在情况说明中所解释的那样,个人意识到自身所享有的权利,组织了解自身所承担的义务,这二者都是非常关键的。欧盟数据保护委员会将会持续特别关注该份新文件是否得到恰当的执行,同时我们也期待为明年《数据隐私框架》的首次审查作出贡献。”
The information note clarifies that transfers based on adequacy decisions do not need to be complemented by supplementary measures. Transfers to the U.S. which are not included in the ‘Data Privacy Framework List’ require appropriate safeguards, such as standard data protection clauses or binding corporate rules. In this respect, the EDPB underlines that all the safeguards that have been put in place by the U.S. Government in the area of national security (including the redress mechanism) apply to all data transferred to the U.S., regardless of the transfer tool used.
(图片来源于网络)
该情况说明阐释了基于充分性决定的数据传输不需要补充附加措施。未被《<数据隐私框架>清单》(Data Privacy Framework List)囊括的对美数据传输行为需要诸如标准数据保护条款或具有约束力的公司规则等适当的保护措施。在这一方面,欧盟数据保护委员会强调无论数据传输使用何种工具,美国政府在国家安全领域(包括救济机制)所实施的保护措施适用于所有传输至美国的数据。
Furthermore, the information note specifies that in the area of national security, EU individuals can submit a complaint to their national data protection authority (DPA) to make use of the new redress mechanism regardless of the transfer tool used to transfer personal data to the U.S.
该情况说明进一步指出,在国家安全领域,无论使用何种工具向美国传输个人数据,欧盟个体均可以利用新的救济机制,向其国家数据保护机构(DPA)申诉。
During the plenary, representatives of the European Commission also gave a presentation on the DPF and the changes following the EDPB Opinion.
全体会议期间,欧盟委员会代表也就《数据隐私框架》以及根据欧盟数据保护委员会的意见所做的修改进行陈述。
Next, the EDPB adopted a Statement on the first review of the Japan Adequacy Decision. The statement focuses mainly on the assessment of the commercial aspects of the Japanese adequacy decision, as the Japanese legal framework has seen some amendments in this area since the issuing of the adequacy decision, which lead to further convergence with the GDPR. These include the extension of the right to object to a processing, the strengthening of the duty to notify data breaches to the Japanese data protection authority and to individuals, and the broadening of the scope of the Japan Act on the Protection of Personal Information (APPI) so that it no longer excludes personal data that are “set to be deleted” within six months.
(图片来源于网络)
随后,欧盟数据保护委员会通过了关于首次审查对日本充分性决定的声明。由于在发布对日本充分性决定后,日本修改了该领域的法律,使其与GDPRz进一步趋同,因此该声明主要从商业层面评估对日本充分性决定。欧盟数据保护委员会的评估包含以下几个方面:
1. 扩大反对数据处理的权利;
2. 加强向日本数据保护机构和个人通报数据泄露的义务;以及
3. 扩展《日本个人信息保护法》(Japan Act on the Protection of Personal Information , 简称APPI)的适用范围,不再排除6个月内“将会被删除”(set to be deleted)的个人数据。
At the same time, the EDPB considers that there are some areas that require closer monitoring by the European Commission, especially concerning the new category of “pseudonymised” personal information in Japanese law and the use of consent in situations of imbalance of power. The EDPB therefore welcomes the European Commission’s commitment to closely monitor these issues.
与此同时,欧盟数据保护委员会认为欧盟委员会需要密切关注一些领域,特别是关于日本法下“匿名化”个人信息这一新的分类,以及在权力失衡情况下同意权的行使。因此,欧盟数据保护委员会欢迎欧盟委员会密切关注上述议题。
Overall, the EDPB agrees with the European Commission’s assessment of the review and welcomes the Commission’s proposal to move to a review cycle of four years.
总之,欧盟数据保护委员会同意欧盟委员会对本次审查所做的评估,并欢迎欧盟委员会就启动每四年一次的审查提出建议。
原文链接:
https://edpb.europa.eu/news/news/2023/edpb-informs-stakeholders-about-implications-dpf-and-adopts-statement-first-review_en
继续阅读
阅读原文