Take-Aways (AI)
  • EU draft regu­la­ti­on aims to make Euro­pe the lea­ding “data con­ti­nent” and pro­mo­te data exch­an­ge within the Union.
  • Pro­po­sed legis­la­ti­on pro­mo­tes data sha­ring, par­ti­cu­lar­ly in the heal­th­ca­re sec­tor for rese­arch and indi­vi­du­al therapies.
  • The focus is on data secu­ri­ty: data tru­s­tees should act as inter­me­dia­ries and not be allo­wed to use data for their own purposes.
  • Draft remains vague on cri­te­ria for data altru­istic orga­nizati­ons and on pro­tec­tion mea­su­res for per­so­nal data.

The Euro­pean Com­mis­si­on wants to make Euro­pe the “num­ber one” data con­ti­nent. With this goal in mind, Sin­gle Mar­ket Com­mis­sio­ner Thier­ry Bre­ton and Digi­tal Com­mis­sio­ner Mar­gre­the Vesta­ger pre­sen­ted the Draft regu­la­ti­on  on Wed­nes­day, 25.11.2020, in Brussels.

The draft aims to faci­li­ta­te the sha­ring of valuable data­sets within the Euro­pean Uni­on, e.g. through exch­an­ge mecha­nisms and tech­ni­cal stan­dards, in order to crea­te added value for socie­ty. In the Q&A sta­tes that, up to now, it has not been the will that has been lack­ing for such a func­tio­ning exch­an­ge of data, but rather the right tools. Spe­ci­fi­cal­ly, the exch­an­ge of (per­so­nal) data in the area of heal­th­ca­re bet­ween the public sec­tor and com­pa­nies, for exam­p­le, in order to deve­lop indi­vi­du­al therapies.

In the past, many stake­hol­ders would have refrai­ned from exchan­ging data for fear of misu­se. The focus of the draft regu­la­ti­on is the­r­e­fo­re on data secu­ri­ty. Data tru­s­tees, who are not allo­wed to use the (per­so­nal) data for their own pur­po­ses, are to media­te this bet­ween the data source and inte­re­sted third parties.

This is also inten­ded to increa­se the con­fi­dence of data sub­jects in the secu­ri­ty of their data. At the same time, the com­mis­si­on wants to encou­ra­ge citi­zens to “dona­te data” for cha­ri­ta­ble pur­po­ses. In the future, data sub­jects should be able to mana­ge who has access to their data and for what pur­po­se in a per­so­nal area. They should also be able to orga­ni­ze them­sel­ves into data cooperatives.

The draft still reads rather vague­ly, for exam­p­le with regard to the requi­re­ments for orga­nizati­ons that can be reco­gnized as cha­ri­ta­ble (“data altru­istic”). The Com­mis­si­on also sees the focus of the new regu­la­ti­on in the use of non-per­so­nal data. With regard to per­so­nal data, only ter­se refe­rence is made to the pos­si­bi­li­ty of anony­mizati­on and pseud­ony­mizati­on (reci­tal 6). It is the­r­e­fo­re to be expec­ted that the regu­la­ti­on will still under­go signi­fi­cant chan­ges by the Par­lia­ment and the Council.