Desi destinata in principal producatorilor si companiilor care folosesc etichetele RFID pe produse de larg consum, Recomandarea Comisiei priveste si organismele statului. Comisia Europeana prevede, de asemenea, explicit, ca statul trebuie sa se consulte cu cetatenii si societatea civila in vederea elaborarii unui cadru privind protectia vietii private si a datelor personale.
Nu trebuie sa ne amagim: Recomandarea doreste sa stabilieasca metodele de imbunatatire ale folosirii tehnicii RFID asupra populatiei, tinand insa cont de opinia si informarea societatii civile si a opiniei publice privin riscurile existente asupra libertatilor individuale, fapt subliniat in mai multe randuri. Cu toate acestea, conform RFID Journal, producatorii si utilizatorii tehnicii sustin ca aceasta Recomandare le da siguranta ca Uniunea Europeana accepta dezvoltarea pietei RFID. "Recomandarea ne permite sa ne focalizam pe inovatii", a declarat reprezentantul EPCglobal, una dintre companiile "nonprofit" care sustin implementarea rapida a tehnologiei RFID.
De subliniat ca in statele UE Comisia Europeana a declansata o ampla consultare publica inca din 2006.
Ce ne intereseaza pe noi, deci:
Privacy and data protection impact assessments
4. Member States should ensure that industry, in collaboration with relevant civil society
stakeholders, develops a framework for privacy and data protection impact assessments. This
framework should be submitted for endorsement to the Article 29 Data Protection Working
Party within 12 months from the publication of this Recommendation in the Official Journal
of the European Union.
5. Member States should ensure that operators, notwithstanding their other obligations pursuant to Directive 95/46/EC:
(a) conduct an assessment of the implications of the application implementation
for the protection of personal data and privacy, including whether the
application could be used to monitor an individual. The level of detail of the
assessment should be appropriate to the privacy risks possibly associated with
the application;
(b) take appropriate technical and organisational measures to ensure the protection
of personal data and privacy;
(c) designate a person or group of persons responsible for reviewing the
assessments and the continued appropriateness of the technical and
organisational measures to ensure the protection of personal data and privacy;
(d) make available the assessment to the competent authority at least six weeks
before the deployment of the application;
(e) once the framework for privacy and data protection impact assessments as set
out in point 4 is available, implement the above provisions in accordance with
Information security
6. Member States should support the Commission in identifying those applications that might
raise information security threats with implications for the general public. For such
applications, Member States should ensure that operators, together with national competent
authorities and civil society organisations, develop new schemes, or apply existing schemes,
such as certification or operator self-assessment, in order to demonstrate that an appropriate
level of information security and protection of privacy is established in relation to the
assessed risks.
Gasiti aici textul integral al Recomandarii si documentele aditionale: EU recommendation on RFID applications, vezi si the citizen's summary si expected impact assessment (Mai, 2009)
Vezi si EFECTUL SAPTAMANII MARI asupra comisarilor europeni: Comisarul European pentru Societatea Informationala si Media avertizeaza asupra Cipurilor RFID
