Proposed Regulation on the Free Flow of Non-Personal Data in the EU
 
        In short, the proposed regulation concerns data that is not covered in the GDPR. In other words, it is concerned with non-personal data comprising e.g. ordinary business or industrial data, raw machine data, and such information. The proposed regulation will not impose burdens on enterprises as the GDPR does, but will instead seek to facilitate the free movement of non-personal data in the European Union.
Background of the proposal
To understand what the free flow of non-personal data is, one must remember that one of the objectives for the European Union is to remove all obstacles and barriers to trade between Member States, thus creating a single market where goods and services, workers and capital can move freely across borders.
With the digitalisation of the world, this means that also data should flow freely between Member States of the EU. This has been recognised as a key step in enabling the European Digital Single Market.
If disproportionate restrictions to the movement of data across Member States and IT systems are abolished, it has been estimated that an economic growth of 4 % will be stimulated as an effect.
The main obstacles in the way for a free flow of data in the European Union today have been identified as being:
- unjustified data localisation restrictions by Member States' public authorities;
- legal uncertainty about which legislation that is applicable to cross-border data storage and processing;
- a lack of confidence that authorities of a Member State will be able to enforce its powers on data stored in other Member States; and
- difficulties in switching cloud service providers due to vendor lock-in practices.
The proposal and its impact
The proposal mainly imposes obligations for Member States to abolish data localisation rules that restrict the free flow of data and to establish procedures to facilitate requests for official cross-border data access requests made by authorities.
Thus, the proposal is not imposing a regulatory burden on business practitioners in general. However, for enterprises operating in the infrastructure sector of the data ecosystems (such as cloud storage providers), it is worthwhile to know that self-regulatory codes of conduct may be introduced, with the objective of avoiding vendor lock-in and ensuring that users are given clear and transparent information before a contract is entered into. This information would include aspects such as:
- the technical requirements, timeframes and charges that apply if a professional user wants to switch to another service provider, or port data back to its own IT systems;
- information about processes and location of any back-up data;
- the available data formats and supports, required IT configuration, and more.
The European Commission considers that the proposed regulation, complementing the personal data protection rules, is an additional step towards a truly functional common European data space.
Article provided by: Hampus Stålholm (Synch) and Vencel Hodák (Synch)
Discover more about the Cloud Privacy Check(CPC) / Data Privacy Compliance(DPC) project
Director CPC project: Dr. Tobias Höllwarth, tobias.hoellwarth@eurocloud.org
