News
Council on Fundamental Rights Charter
Each year, the European Commission issues a report on the state of affairs of the application of the Fundamental Rights Charter (2014 Report). The Council responded with draft conclusions highlighting, among others, issues related to security and the digital single market. It underlines that security and the respect for fundamental rights “are consistent and complementary policy objectives”. Member States need to “work together to ensure that all security measures comply with the principles of necessity, proportionality and legality, with appropriate safeguards to ensure accountability and judicial redress”. It stresses that the protection of personal data (Art. 8) “should be enhanced with the adoption of the data protection reform package”.
Data protection – Trilogue negotiations can start
EU ministers gave Latvian Presidency a mandate to start trilogue discussions with the European Parliament and Commission this Monday 22 June. A first trilogue could already take place on 24 June before it moves over to the Luxembourgish Presidency. The aim is to wrap up by end of year. Major changes from the current legislation would include that companies processing personal data need to prove that data subjects have given explicit consent; multi-nationals would need to appoint a data protection officer. Non-compliance would lead to fines of up to 2% of annual worldwide turnover. Online service providers need to make it easier for customers to move their data to competitors; serious data breaches would need to be reported. Liability for data breaches and violations under the new scheme would be shared between data controllers (e.g. a bank) and data processors (e.g. a cloud provider). An indicative time table of the EPP Group can be found here.
Data retention – Another one down
After Germany and The Netherlands, the Belgian Constitutional Court has declared the country’s data retention law illegal. The national law had been linked to the EU directive, which was struck down by the European Court of Justice last year. While NGOs, which - together with lawyers - had challenged the law, hail this as a victory of human rights, others consider this a serious step back in terms of legal certainty, law enforcement and efficient cooperation among stakeholders. Their reasoning is that the Belgian law was relatively well-balanced with regards to, for example, safeguards and retention periods, thereby limiting the number of requests for action. Considerable investments into infrastructure and security had already been made. Given current debates on terrorist threats, they argue, it is likely a new law might lose some of these features. Also, at this stage, it is unclear what will happen to the court cases, whose investigations are based on data obtained under the current law.
German parliament approves IT Security Law
Providers of critical infrastructure, such as energy providers, but also providers of telecommunication services, will need to implement minimum security standards and report security incidents to a central authority – otherwise they could face penalties of up to 100,000€. In addition, telecom providers need to warn their customers if they notice an abuse of their systems. According to the text, “critical infrastructure providers” largely correspond to those set out by the Commission’s NIS proposal. However, they will be further defined in a separate law in the coming months. It could therefore be assumed that during the ongoing NIS discussions, Germany will support harmonising requirements for certain providers of critical infrastructure while leaving it up to Member States to flesh out the criteria for additional ones.
IGF workshop proposal approved
“How communities restore trust in the digital environment” – this will be the subject of a debate at the upcoming joint workshop of CENTR, LACTLD, AfTLD and APTLD at the IGF in Brazil in November 2015. Under the leadership of Giovanni Seppia and in cooperation with the ROs, CENTR submitted the proposal earlier this year. The MAG (Multistakeholder Advisory Group) confirmed its approval shortly before the Jamboree. Focusing on cybersecurity, the workshop will provide a forum to showcase examples that illustrate what the ccTLD and wider community has done to increase cybersecurity, expand and deepen the dialogue with local internet stakeholders and support the public good. Several ccTLDs as well as the Council of Europe have already confirmed their participation. Registries are invited to submit showcase examples in a CENTR survey, which will be sent out in the coming weeks.
Net neutrality X 3
Telecoms package: A meeting of EU telecoms ministers on Friday on roaming charges and open internet (sometimes referred to as the “net neutrality debate”) proved disappointing to participants, as deadlock could not be broken. It is now open whether a 4th trilogue will take place under the Latvian Presidency. In the meantime, the European Parliament (EP) has sent its latest compromise proposal to the Council. The EP still insists on abolishing roaming altogether by 2016 while Member States take a more cautious approach fearing that telecoms providers would lose a substantial source of income to ensure innovation. The Council’s latest position still included the idea of a “basic roaming allowance” for customers travelling abroad and a complete ban of roaming only by June 2018. In addition, the EP and Member States are still far away from a common definition of net neutrality with the EP, seemingly internally split.
EuroDIG: A working group proposal on net neutrality failed to reach support among participants of the EuroDIG last week in Sophia. The most contentious issue proved to be “zero rating”, the practice of some mobile carriers to offer customers access to particular content or services at no additional cost. Whereas some saw this as a clear attack on net neutrality, others argued that European ISPs were expected to provide ever higher internet quality, but were not allowed to make money on it. However, the paper was finally rejected due to formalities, as most participants felt that they had learned about it too late.
BEREC report: The Body of European Regulators for Electronic Communications (BEREC) adopted its report on how consumers value net neutrality in Croatia, the Czech Republic, Greece and Sweden.
Priorities of the Luxembourgish Presidency
On 1 July 2015, Luxembourg will take over the Presidency of
the EU from Latvia – the last in row of the Trio Presidency, including Italy,
Latvia and now Luxembourg.
Its priorities focus on growth and jobs, social Europe, migration, energy, the
reform of the Economic and Monetary Union, TTIP and CETA, and climate change.
The adoption of the 2016 EU Budget will be one challenge ahead, boosting
long-term investment into R&D and education another. Tackling problems of
illegal migration, human trafficking and migrants dying in boats will remain a
priority, as well as the fight against terrorism, including the data protection
reform package, the EU-PNR directive, and the European Agenda on Security
(including most likely the NIS directive). Tax policy and transparency will be
a hairy issue for Luxembourg. A number of dossiers that have been kicked off
under the Latvian Presidency will also come on its plate, including the Digital
Single Market Strategy (geo-blocking and copyright), and the regulation on the
European single market for electronic communications (if not concluded by
then).
Update on the NIS directive (June 2015)
Negotiations are ongoing at Council-level with the European Parliament getting more and more frustrated about the “no-progress”, which the Presidency describes as “substantial progress” and the Commission hails as an exercise “breaking new ground”. At this point, it seems very unlikely that negotiations can be concluded under the Latvian Presidency. Current discussions focus on the definition of and jurisdiction applicable to the six categories of internet enablers (including cloud providers, internet payment gates, etc.). Domain name registries, if included, would fall under “critical infrastructure”. The core concerns of the Council are not to harm innovation, growth and security. Flooding governments and CERTS with incident reports could and should not be the goal, as it would “hide the most important incidents”.
Jamboree 2015 – Mixing & mingling, discussing & sharing!
This year’s Jamboree saw an overwhelming number of participants eager to meet and discuss the topics from every possible angle with colleagues from their field of expertise and beyond. More than 200 participants came to Stockholm to attend the Working Group (WG) meetings in the morning and to get involved in the joint and interactive sessions in the afternoon. .SE made them feel at home in Stockholm and experience the dark and cold side of “Nordic Noir”, as well as the bright and convivial side of Swedish culture.
ICANN’s CEO, the “I” farewell tour
By Giovanni Seppia (.eu), Chair of CENTR's Board
Last week at the European Parliament, ICANN’s CEO began what can only be described as his farewell tour. The topic of discussion at the European Internet Forum – formerly known as the European Internet “Foundation” – dinner should have been about the IANA Stewardship Transition. The subject was hardly broached however and failed to engage a broader community in a process that so far has been very limited not in its scope, but in the way actions have been deployed to make it truly “multistakeholder”.