The European Commission has proposed a new law to streamline cooperation between data protection authorities when enforcing GDPR in cross-border cases in the EU.
The new regulation will set up concrete procedural rules for the authorities when applying the GDPR in cases which affect individuals located in more than one Member State.
For example, the proposal will introduce an obligation for the lead Data Protection Authority to send a summary of key issues to their counterparts concerned, identifying the main elements of the investigation and its views on the case, and therefore allowing them to provide their views early on.
In 2022, the European Data Protection Board (EDPB) issued the Commission a wish list of suggestions to streamline and improve some procedural aspects of GDPR, such as cross-border investigations.
Currently, the EU has a “one-stop-shop” rule whereby the DPA put in charge of an investigation is based on where the organisation under invesigatin is based.
For many high-profile instances, this falls to the Irish DPA, as many large US tech giants base their European headquarters in Ireland.
This also means that the majority of the fines are paid out into the Irish DPA – their previous rulings have created tension between the Irish DPA and other DPAs, as well as the EDPB itself.
The Irish DPA’s rulings involving these massive tech conglomerates have been routinely challenged by the EDPB, which often decreed harsher judgements and larger fines against tech companies taking residency in Ireland.
The proposal aims to reduce disagreement and facilitate consensus among authorities from the initial stages of the process.
For individuals, the new rules will clarify what they need to submit when making a compliant and ensure that they are appropriately involved in the process.
For businesses, the new rules will clarify their due process rights when a DPA investigates a potential breach of the GDPR.
The EU commission claims that these steps will bring swifter resolution of cases, meaning quicker remedies for individuals and more legal certainty for businesses.
For data protection authorities, the EU Commissions says these new rules will smoothen cooperation and enhance the efficiency of enforcement.
Recommended
- Google Analytics Data Transfer Causes GDPR Fine for Swedish Firms
- UK Data Protection Reform: EU Adequacy May Be at Risk
- CMA Pauses Adobe-Figma Deal as it Could ‘Harm UK Digital Economy’
The new proposal aims to harmonise rules in the arears of complainants rights, the rights of data controllers and processers under investigation, and to streamline cooperation and dispute resolution.
In the first case, the rules brings together the requirements fro a cross-boarder complaint to be admissible, removing the current obstacles brought by DPAs following different rules.
For parties under investigations, the proposal provides them with the right to be heard at key stages in the procedures including during dispute resolution by the overarching European Data Protection Board (EDPB).
Key to the proposal is allowing DPAs to provide their views early on in investigations, and making use of all the tools of cooperation provided by the GDPR, such as joint investigations and mutual assistance. These provisions are set to enhance DPAs’ influence over cross-border cases, facilitate early consensus-building in the investigation, and reduce later disagreements.
The proposal specifies detailed rules to facilitate the swift completion of the GDPR’s dispute resolution mechanism, and provides common deadlines for cross-border cooperation and dispute resolution.





