Notes from the IAPP Europe: The EU's plan to safeguard its data sovereignty

The European Commission consultation on safeguarding EU data sovereignty seeks feedback on challenges EU organizations face when accessing, transferring and protecting data across borders.

Contributors:
Laura Pliauškaitė
European Operations Coordinator
IAPP
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
The digital sovereignty discourse is not going anywhere, and the European Commission is looking for input. On 8 July, the Commission opened a targeted consultation on safeguarding the EU's data sovereignty.
The objective is to understand what obstacles entities located in the EU are facing when it comes to data-related dependencies, particularly when accessing or using third-country data and managing risks associated with international transfers of data from the EU. The Commission specifies these may be legal, technical or organizational measures, including localization requirements, authorization, licensing or certification prerequisites, contractual or administrative restrictions, security reviews, lack of transparency, discriminatory treatment, data leakage, forced data access or unauthorized reuse and public authority or judicial access risks.
Many questions prompt for details about the hurdles linked to international data transfers, such as which sectors and value chains are affected, what types of data are impacted, which regions or countries are concerned and what practical issues are created.
The Commission doesn't just want to learn about the obstacles, it is also seeking feedback on the action it can take to tackle these barriers and whether the EU should adopt measures as a response to discriminatory treatment of EU entities when it comes to international data flows.
That consultation is another knot in a string of digital sovereignty flavored initiatives from Brussels recently. But does this specific consultation on safeguarding the EU's data sovereignty tell us more than all the previous discussions? Yes and no.
First, rather than saying something new, it confirms that digital sovereignty remains a top priority in the EU's policy agenda. It has been part of the EU's strategic direction since the beginning of the current Commission's term. With the announcement of the European Data Union Strategy, the Commission put a strong emphasis on acquiring more high-quality data for the EU to be able to compete globally when it comes to technology such as artificial intelligence. Even before this Commission's term, the EU focused on safeguarding its data, launching initiatives such as the European Strategy for Data and Common European Data Spaces.
This consultation also confirms that the digital sovereignty discourse is becoming more targeted. Rather than talking about a broad goal of achieving digital sovereignty, it is time for policymakers to address different specific aspects of it.
Previous discussions on international data transfers were addressed mainly from the data protection angle and in the context of digital trade agreements. This consultation confirms that this scope is being expanded and more attention is given to the flows of nonpersonal data — a fuel of modern economy, determining national competitiveness — building on the framework that laws such as the Data Act started to set out.
While Europe is trying to establish more local solutions, it must ensure this won't separate it from the rest of the world. It will have to find a middle ground between safeguarding its sovereignty and being open enough to benefit from its international partnerships. The consultation states "sovereignty does not preclude openness to trusted partners, including exchange of data across borders, while ensuring a level playing field, security, and consistency with EU values and interests," but it remains to be seen how this balance will be achieved in practice and whether other countries will be on the same page.
Stakeholders can share their experiences until 8 Sept. The intended outcome of this consultation and how it will shape future data-related policies of the EU is not very clear. Although it does not seem to feed into a specific initiative or a defined policy objective, the Commission aims to first focus on understanding the hurdles connected to dependencies in the data ecosystem and only then will it determine the approach to be taken.
This article originally appeared in the Europe Data Protection Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Laura Pliauškaitė
European Operations Coordinator
IAPP



