Ireland faces challenges from privacy ruling
Under a “one-stop-shop” mechanism initially proposed in reforms of EU data protection laws, businesses operating across the EU would only have had to deal with the data protection authority in the country where they are headquartered or have their main European base, even if the alleged mishandling of data affects citizens in another country.
But opposition from some member states that do not want their national regulators to lose policing powers over multinationals such as Google, with an Irish base, led to the proposal being altered so that any “concerned” authority could object to a decision.
That would trigger the intervention of the European Data Protection Board, a still to be created assembly of all 28 EU regulators.
Yesterday, a majority of member states agreed to scrap an option requiring at least a third of concerned authorities to object, diplomats said, potentially giving a single “concerned” authority the right to complain.
Latvia, which holds the rotating European presidency, had suggested rules to ensure a minimum number of regulators object to a decision before it is referred to the European Data Protection Board with the power to overturn the original decision. Diplomats said work on the proposal would continue to make sure that only “relevant and reasoned” objections would trigger the intervention of the board.
One EU diplomat said a quantitative threshold was still possible, highlighting divisions among member states. Currently EU data protection authorities only meet as an advisory group.
Reuters





