{"id":8218,"date":"2022-04-13T21:20:46","date_gmt":"2022-04-13T19:20:46","guid":{"rendered":"https:\/\/eulawenforcement.com\/?p=8218"},"modified":"2022-07-21T16:13:51","modified_gmt":"2022-07-21T14:13:51","slug":"converting-the-european-data-protection-board-into-a-european-data-protection-agency-red-pill-or-blue-pill","status":"publish","type":"post","link":"https:\/\/eulawenforcement.com\/?p=8218","title":{"rendered":"Converting the European Data Protection Board into a European Data Protection Agency: red pill or blue pill?"},"content":{"rendered":"\n<p>By Giorgia, Lisa-Marie, Shivani, and Emilia<\/p>\n\n\n\n<p><em>You take the blue pill\u2014the story ends, you wake up in your bed and data protection enforcement stays the same. You take the red pill\u2014we make a new agency, and I show you what it could look like.<\/em><\/p>\n\n\n\n<p class=\"has-text-align-center\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"176\" class=\"wp-image-8219\" style=\"width: 400px;\" src=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/morpheus.gif\" alt=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"163\" class=\"wp-image-8220\" style=\"width: 300px;\" src=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/dorpheus.gif\" alt=\"\"><\/p>\n\n\n\n<p class=\"has-text-align-center\">(<a href=\"https:\/\/www.youtube.com\/watch?v=RhlXqYiTz2Q\">Lana Wachowski and Lilly Wachowski, The Matrix, 1999<\/a>)<\/p>\n\n\n\n<p>In \u2018The Matrix\u2019, when the reality of Thomas Anderson begins to fall apart, he is presented with a choice: to take the blue pill which allows him to continue living in contended ignorance, or to take the red pill to learn about reality and express his full potential by becoming his alter ego Neo. It is a risky option which yields challenges, yet ultimately beneficial consequences. Similarly, whilst leaving the status-quo of the enforcement system of the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=NL\">General Data Protection Regulation<\/a> (\u2018GDPR\u2019) provides a comforting yet <a href=\"https:\/\/www.iccl.ie\/wp-content\/uploads\/2021\/09\/Europes-enforcement-paralysis-2021-ICCL-report-on-GDPR-enforcement.pdf\">ineffective<\/a> blue pill, taking the red pill and converting the <a href=\"https:\/\/edpb.europa.eu\/about-edpb\/about-edpb\/who-we-are_en\">European Data Protection Board<\/a> (\u2018EDPB\u2019) into a European Data Protection Agency (\u2018EDPA\u2019) could disrupt yet enhance enforcement of data protection law in the European Union (\u2018EU\u2019).<\/p>\n\n\n\n<p>In today\u2019s digital economy, companies <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-constitutes-data-processing_en\">process<\/a> a significant amount of <a href=\"https:\/\/gdpr-text.com\/read\/article-4\/\">personal data<\/a>. Individuals can benefit from this, for instance by receiving more targeted and relevant information. However, there are also inherent risks to data protection, a <a href=\"https:\/\/ec.europa.eu\/info\/aid-development-cooperation-fundamental-rights\/your-rights-eu\/know-your-rights\/freedoms\/protection-personal-data_en\">fundamental right of every EU citizen<\/a>. For example, in cases of a data breach, individuals can be harmed by identity theft or fraud (<a href=\"https:\/\/www.huntonak.com\/files\/Publication\/cfd01362-a4c2-42b9-a617-c83082a289d7\/Presentation\/PublicationAttachment\/891e6ada-3402-44d1-b1f7-b40c8f3af95a\/Privacy_fallacy.pdf\">Bergkamp, Hunton, and Williams<\/a>, 2002).<strong> <\/strong>The GDPR, therefore, imposes certain <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/rules-business-and-organisations\/principles-gdpr_en\">limitations on personal data processing<\/a>. These are enforced through a hybrid system composed of the EDPB and national <a href=\"https:\/\/edpb.europa.eu\/about-edpb\/about-edpb\/members_en\">supervisory authorities<\/a> (\u2018SAs\u2019). The SAs investigate and enforce companies\u2019 compliance with the GDPR in their respective Member States, while the EDPB functions as a <a href=\"https:\/\/gdpr-text.com\/read\/article-65\/\">dispute resolution body in cases of conflicts between SAs<\/a>, but has no investigative or corrective powers itself. Yet, the EDPB does enjoy corrective powers to a certain extent: It <a href=\"https:\/\/edpb.europa.eu\/system\/files\/2021-06\/edpb_aar_2020_final_27.05.21.pdf\">can impose duties<\/a> on the SAs that require the implementation of EDPB\u2019s decisions, including the adoption of corrective measures. Furthermore, the EDPB can adopt legally <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/consistency-findings\/binding-decisions_en\">binding decisions<\/a>.<\/p>\n\n\n\n<p>Nevertheless, the GDPR\u2019s enforcement, particularly in cross-border cases, has been criticized for being too <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-06-25\/eu-s-broken-gdpr-needs-fixing-departing-privacy-chief-warns?utm_source=piano&amp;utm_medium=email&amp;utm_campaign=10787&amp;pnespid=hfs0radXGAON6TK9B41BRR6lCCcVxFWKhRV9QwLCGw\">complex, slow, and ineffective<\/a>, leading to its underenforcement. For this reason, the Commission Vice President V\u011bra Jourov\u00e1 announced that the <a href=\"https:\/\/techcrunch.com\/2021\/12\/02\/gdpr-centralized-enforcement\/\">GDPR enforcement system might be reformed<\/a>, moving towards a more centralized enforcement. This blog post investigates whether converting the existing EDPB into a EDPA modeled after the <a href=\"https:\/\/www.bankingsupervision.europa.eu\/about\/thessm\/html\/index.en.html\">Single Supervisory Mechanism<\/a> (\u2018SSM\u2019) could solve the current enforcement deficits.<\/p>\n\n\n\n<p><strong>Blue pill: The Gordian knot of the current GDPR cross-border enforcement<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/gordion-1024x549.png\" alt=\"\" class=\"wp-image-8223\" width=\"481\" height=\"257\" srcset=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/gordion-1024x549.png 1024w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/gordion-300x161.png 300w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/gordion-768x412.png 768w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/gordion.png 1068w\" sizes=\"auto, (max-width: 481px) 85vw, 481px\" \/><\/figure>\n\n\n\n<p>In situations where companies control and process personal data across several Member States, the <a href=\"https:\/\/autoriteitpersoonsgegevens.nl\/sites\/default\/files\/atoms\/files\/edpb-one-stop-shop_leaflet.pdf\">one-stop-shop mechanism<\/a> applies: the SA in the Member State of the companies\u2019 main establishment takes the <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/lead-supervisory-authority_en\">lead<\/a> but must cooperate with SAs of other affected Member States through information exchanges, in order to <a href=\"https:\/\/gdpr-text.com\/read\/article-60\/\">reach consensus in the investigation and sanctioning<\/a>. However, this cooperation mechanism exhibits major deficits, in particular in cases where companies, such as <a href=\"https:\/\/www.theguardian.com\/technology\/2022\/jan\/06\/france-fines-google-and-facebook-210m-over-user-tracking-cookies\">Google, Facebook<\/a>, and <a href=\"https:\/\/www.bbc.com\/news\/technology-55317207\">Twitter<\/a>, process data from individuals across the EU.<\/p>\n\n\n\n<p>There are two major drawbacks to the current system:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>The one-stop-shop mechanism places an unproportionate burden on SAs of Member States where many big companies are located (e.g., <a href=\"https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-9-2021-0262_EN.html\">Ireland<\/a>) which, combined with a&nbsp;<a href=\"https:\/\/brave.com\/static-assets\/files\/Brave-2020-DPA-Report.pdf#page=7\" target=\"_blank\" rel=\"noreferrer noopener\">lack of resources<\/a> and possible <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/en\/TXT\/?uri=CELEX:62018CJ0311\" target=\"_blank\" rel=\"noreferrer noopener\">political unwillingness<\/a> to investigate violations sufficiently, leads to <a href=\"https:\/\/www.iccl.ie\/wp-content\/uploads\/2021\/09\/Europes-enforcement-paralysis-2021-ICCL-report-on-GDPR-enforcement.pdf\">enforcement bottlenecks<\/a>;<\/li><li>The EDPB and concerned SAs are highly dependent on the lead SA to investigate sufficiently and share its information. If this is not done in goodwill, then the EDPB does not possess enough evidence to decide disputes between SAs (see <a href=\"https:\/\/edpb.europa.eu\/sites\/default\/files\/files\/file1\/edpb_bindingdecision01_2020_en.pdf\">Decision 01\/2020<\/a>, paras 132-133).<\/li><\/ol>\n\n\n\n<p>Together, these deficits contribute to the underenforcement of the GDPR (<a href=\"https:\/\/eulawenforcement.com\/?p=8038\">Mustert and Bledoeg<\/a>, 2021). Could the transformation of the EDPB, empowered with direct enforcement powers, be the bold step necessary to solve this Gordian knot?<\/p>\n\n\n\n<p class=\"has-text-align-center\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"296\" class=\"wp-image-8224\" style=\"width: 500px;\" src=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/bp.png\" alt=\"\" srcset=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/bp.png 791w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/bp-300x177.png 300w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/bp-768x454.png 768w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n\n\n\n<p><strong>Red pill: Creating an EDPA modeled after the SSM?<\/strong><strong><\/strong><\/p>\n\n\n\n<p>EU agencies play a crucial role in the shared administration of the EU by executing information-gathering, regulatory, and direct enforcement tasks (<a href=\"https:\/\/www.e-elgar.com\/shop\/gbp\/controlling-eu-agencies-9781789905410.html\">Scholten, Strauss, and Brenninkmeijer<\/a>, 2021). There are pros and cons of a centralized agency that enjoys investigative and legally-binding enforcement powers overruling national authorities (<a href=\"https:\/\/www.utrechtlawreview.org\/articles\/abstract\/10.18352\/ulr.302\/\">Scholten and Ottow<\/a>, 2014). Most importantly, a centralized EDPA could increase harmonization and reduce the risks of enforcement bottlenecks, ensuring a cohesive observance of the GDPR throughout the EU. However, optimal results will still only be achieved when national SAs are incentivized to cooperate with a centralized EDPA. This could be achieved if the EDPA is modeled following the role that the European Central Bank (\u2018ECB\u2019) undertakes in the SSM.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/www.bankingsupervision.europa.eu\/legalframework\/ecblegal\/html\/index.en.html\">Regulations<\/a> governing the SSM ensure the soundness of the European banking system. This mechanism confers specific tasks on the ECB regarding policies on the prudential supervision of banks and credit institutions. It functions through a centralized system of enforcement between the ECB and SAs, with the former being ultimately responsible for the <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2013\/1024\/article\/6\">effective functioning of the SSM<\/a>. Although the ECB and SAs enjoy similar powers, the ECB is exclusively competent for supervising and investigating significant banks, whilst SAs are entrusted with the monitoring and investigation of less-significant banks. The <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2013\/1024\/article\/6\">significant status<\/a> is <a href=\"https:\/\/www.bankingsupervision.europa.eu\/organisation\/decision-making\/html\/index.ga.html\">decided by the ECB<\/a> based on banks\u2019 sizes, their economic importance, their cross-border activities, and whether they have requested direct public support. The ECB must cooperate through a system of shared enforcement which permits the ECB to take over institutions overseen by SAs at any time (<a href=\"https:\/\/utrechtjournal.org\/articles\/10.5334\/ujiel.463\/\">Karagianni and Scholten<\/a>, 2018).<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"396\" class=\"wp-image-8225\" style=\"width: 400px;\" src=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp.png\" alt=\"\" srcset=\"https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp.png 950w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp-150x150.png 150w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp-300x297.png 300w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp-768x761.png 768w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp-24x24.png 24w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp-48x48.png 48w, https:\/\/eulawenforcement.com\/wp-content\/uploads\/2022\/04\/rp-96x96.png 96w\" sizes=\"auto, (max-width: 400px) 85vw, 400px\" \/><\/p>\n\n\n\n<p><strong>The solution of an EDPA and SSM model of enforcement<\/strong><\/p>\n\n\n\n<p>In light of the <a href=\"https:\/\/www.politico.eu\/article\/eu-privacy-regulators-clash-gdpr-enforcement\/\">considerations on centralizing the GDPR enforcement<\/a>, the EDPB could be transformed into the EDPA by firstly adopting a regulation on the basis of the <a href=\"https:\/\/ec.europa.eu\/info\/aid-development-cooperation-fundamental-rights\/your-rights-eu\/know-your-rights\/freedoms\/protection-personal-data_en\">fundamental right to data protection<\/a>, and secondly by endowing it with similar <a href=\"https:\/\/lexparency.org\/eu\/32013R1024\/ART_9\/\">supervisory and investigative powers<\/a> as the ECB has within the SSM for <a href=\"https:\/\/lexparency.org\/eu\/32013R1024\/ART_6\/\">\u2018significant\u2019 banks<\/a>. Accordingly, the EDPA will have direct enforcement powers regarding <em>large <\/em>data processing companies. The <a href=\"https:\/\/lexparency.org\/eu\/TFEU\/ART_16\/\">legal basis<\/a> allows for ensuring the GDPR compliance of companies harvesting personal data of EU citizens, while the SSM-like powers allow to share the task of overseeing the personal data processing companies with the supervisory authorities and supervise the overall system. Otherwise, allocating the entire supervision to the EDPA might prove detrimental, especially when comparing the large number of companies controlling and processing personal data in the EU with the <a href=\"https:\/\/www.bankingsupervision.europa.eu\/ecb\/pub\/pdf\/ssm.listofsupervisedentities202202.en.pdf?f313d9dc5f74b24e1baf0210ab25d2de\">few significant banks<\/a> supervised by the ECB. While the criteria of significance in the data-processing field cannot be directly transposed from what is used to determine significant banks, new considerations in terms of the quantity and quality of data a company processes (i.e. <a href=\"https:\/\/edpb.europa.eu\/system\/files\/2022-04\/edpb_statement_20220428_on_enforcement_cooperation_en.pdf\">strategic importance<\/a>) will prove pivotal to determining which entities are supervised by the EDPA.<\/p>\n\n\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>By Giorgia, Lisa-Marie, Shivani, and Emilia You take the blue pill\u2014the story ends, you wake up in your bed and data protection enforcement stays the same. You take the red pill\u2014we make a new agency, and I show you what it could look like. (Lana Wachowski and Lilly Wachowski, The Matrix, 1999) In \u2018The Matrix\u2019, &hellip; <a href=\"https:\/\/eulawenforcement.com\/?p=8218\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Converting the European Data Protection Board into a European Data Protection Agency: red pill or blue pill?&#8221;<\/span><\/a><!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":94,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8218","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts\/8218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/users\/94"}],"replies":[{"embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8218"}],"version-history":[{"count":7,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts\/8218\/revisions"}],"predecessor-version":[{"id":8318,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts\/8218\/revisions\/8318"}],"wp:attachment":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}