News: 1594912343

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Privacy Shield binned after EU court rules transatlantic data protection arrangements 'inadequate'

(2020/07/16)


The EU Court of Justice has struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.

Austrian privacy activist Max Schrems brought the latest edition of the long-running case (informally known as Schrems II) in 2015, complaining that [1]Ireland's data protection agency wasn't preventing Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from beaming his data to the US.

Once his data was in the US, Schrems argued, no EU-style data privacy controls were legally enforceable by him or anyone else in that situation. America's plethora of three-letter spy agencies could then help themselves to it in various legal and not-so-legal ways, at least under EU rules.

Today the EU Court of Justice ruled that the now-dead Privacy Shield arrangement – [2]itself a replacement of Safe Harbor – "does not grant data subjects actionable rights before the courts against the US authorities," meaning EU citizens could not challenge a breach of the arrangement by a company in the US handling EU personal data.

The court said that Section 702 of the US Foreign Intelligence Surveillance Act (explained [3]here by the Electronic Frontier Foundation), when read together with a US presidential order and a policy directive on data collection by spies, failed to meet EU data protection requirements.

And we're back with the third review of Privacy Shield: Meh, sighs the European Commission [4]READ MORE

In doing so, the court ruled against the EU Commission, which [5]only last year said Privacy Shield was working OK .

In effect, the EU court said American spies had too much free rein to harvest EU citizens' data from US companies. Promises to appoint an ombudsman to oversee EU-compliant data protection rules in the States were no good for the EU, ruled its judges, because the ombudsman would have been appointed directly by the US foreign secretary – and had no power to order his country's spies to stop handling EU citizens' data.

The Software Alliance told The Reg it was "pleased that today’s decision by the European Court of Justice (ECJ) upheld Standard Contractual Clauses, consistent with BSA’s amicus brief and arguments submitted to the Court," but "disappointed that the ECJ invalidated the EU-US Privacy Shield."

[6]US Secretary of Commerce Wilbur Ross also said the Department of Commerce was "deeply disappointed that the court appears to have invalidated the European Commission’s adequacy decision underlying the EU-U.S. Privacy Shield."

He added his department hoped to "limit the negative consequences to the $7.1 trillion transatlantic economic relationship that is so vital to our respective citizens, companies, and governments."

Not an immediate screeching halt

The practical effects of the ruling are likely to be limited as data-related "standard contractual clauses" (SCCs, added by firms to contracts governing all EEA-UK data flows), something else Schrems complained about, were not struck down or ruled invalid.

At a press conference late this morning, [7]commission vice-president Vera Jourová, who has responsibility for values and transparency, reassured businesses:

The Court of Justice declared the Privacy Shield decision invalid, but also confirmed that the standard contractual clauses remain a valid tool for the transfer of personal data to processors established in third countries.

This means that the transatlantic data flows can continue, based on the broad toolbox for international transfers provided by the GDPR, for instance binding corporate rules or Standard Contractual Clauses.

"It is clear that the US will have to seriously change their surveillance laws, if US companies want to continue to play a role in the EU market," said Schrems this morning.

GDP-arrrrrrgggghhh! A no-deal Brexit: So what are you going to do with all that lovely data? [8]READ MORE

The US IT and Innovation Foundation (ITIF), meanwhile, complained the ruling was "irresponsible" and would treat the US with a "double standard".

"In the midst of a global pandemic during which global data flows are more vital than ever, [the ruling] puts all global data transfers from the EU at risk and wreaks havoc on the digital economy," said ITIF's Eline Chivot. "It will immediately upend, and in many cases even halt, data transfers between the EU and the United States, leaving many businesses with no suitable alternative."

While it was not immediately clear whether any businesses had stopped moving personal data across the Atlantic after this morning's judgment, Chivot made the point that US laws on government access to personal data were not "unique", seemingly calling on the EU to reject other countries' data access laws in the same way.

Declaring existing mechanisms for holding the US government to account for data abuses not good enough, the EU court ruled that "the very existence of effective judicial review designed to ensure compliance with provisions of EU law is inherent in the existence of the rule of law," adding:

Data subjects may find that the administrative and judicial authorities of the Member States have insufficient powers and means to take effective action in relation to data subjects' complaints based on allegedly unlawful processing, in that third country, of their data thus transferred, which is capable of compelling them to resort to the national authorities and courts of that third country.

The judgment is [9]published (PDF, 63 pages) on the EU Court of Justice website. ®

Get our [10]Tech Resources



[1] https://www.theregister.com/2019/07/10/irish_regulator_feels_heat_over_facebook_schrems_case/

[2] https://www.theregister.com/2016/02/02/safe_harbor_replaced_with_privacy_shield/

[3] https://www.eff.org/702-spying

[4] https://www.theregister.com/2019/10/23/third_review_of_privacy_shield_room_for_improvement/

[5] https://www.theregister.com/2019/10/23/third_review_of_privacy_shield_room_for_improvement/

[6] https://www.commerce.gov/news/press-releases/2020/07/us-secretary-commerce-wilbur-ross-statement-schrems-ii-ruling-and

[7] https://ec.europa.eu/commission/presscorner/detail/en/STATEMENT_20_1366

[8] https://www.theregister.com/2019/09/05/brexit_no_deal/

[9] https://curia.europa.eu/jcms/upload/docs/application/pdf/2020-07/cp200091en.pdf

[10] https://whitepapers.theregister.com/

Standard contractual clauses

Rich 2

I find it strange that the standard contractual clauses were not also struck down. Surely, any data transferred under them is also subject to US government snooping in the same way as under privacy shield. It’s not as if Joe Public has any say in what “standard contractual clauses” their bank/anti-social hangout/on-line supermarket/whatever signs up to

Re: Standard contractual clauses

Woodnag

See https://noyb.eu/en/CJEU-Media-Page

Vera Jourová didn't tell the truth. SCCs are not valid where US gov by US law gets to see the traffic. So not Facebook etc. For bank transactions, fine.

See https://www.twitter.com/maxschrems

"It seems that @VeraJourova is simply ignoring the #CJEU a second time here. The Judgement is clear that you can't just use the SCCs again and there is no "toolbox" to be used when a US company falls under #FISA and alike... "

Re: Standard contractual clauses

Rich 2

So faecesbook and similar pond life really are stuffed then? Their only recourse is to keep their (your) data in the EU?

Re: Standard contractual clauses

Woodnag

Yes. Useful summary here: http://eulawanalysis.blogspot.com/2020/07/you-were-only-supposed-to-blow-bloody.html

"Schrems reformulated his complaint to the Irish Data Protection Commissioner (DPC) about data transfers arguing that the United States does not provide adequate protection as United States law requires Facebook Inc. to make the personal data transferred to it available to certain United States authorities, such as the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) and the data is used in a manner incompatible with the right to private life, and that therefore future transfers by Facebook should be suspended."

Re: Standard contractual clauses

sorry, what?

Those of us in the UK no longer have such protections anyway, what with Brexit and all. When Google shifted all my data to the US back in April I complained to my MP and got a dismissive bunch of drivel back in return saying that my data was just as secure in the US as it would be in the EU.

Re: Standard contractual clauses

Woodnag

Brexit doesn't mean exiting GDPR.

But your MP is right... the 5-eyes share data on each others' citizens to work around "thou shall not spy on thy own" type laws.

Re: Standard contractual clauses

Charlie Clark

Hasn't the matter been handed back to the Irish ICO to establish whether sufficient protection is given? If this isn't the case then the contract is invalid, The contract will be deemed invalid because the US government refuses to declare such data off-limits but will delay things.

Re: Standard contractual clauses

Woodnag

There's a separate case that the Irish DPC is avoiding ruling by being incredibly slow.

https://noyb.eu/en/judicial-review-against-dpc-over-slow-procedure-granted

Re: Standard contractual clauses

spold

Most larger companies will now be completely pissed off after previously having gone through Safe Harbor being struck down. They were reluctant to do Binding Corporate Rules because it was lengthy and expensive This option will now look much more attractive than relying on standard contractual clauses and having those torpedoed in the future, and will decide to suck it up. This may well overload many regulators' work capacity.

BebopWeBop

Schrems has done the world a favour.

Good

Spanners

Was anyone here even a fraction surprised?

Does anyone here believe this will not be part of the thrust of downgrading our data security laws?

Re: Good

Doctor Syntax

Surprised, no.

By "our", who do you mean? The EU's, probably not. UK's maybe. US's - can they get worse?

In other news, birds gotta fly!!

Marketing Hack

I'm not surprised by this at all. Privacy Shield is a fiction invented by the EU and U.S. governments. It's role is to keep trans-Atlantic trade, investment and business partnerships going at the request of the many European companies who want access to the U.S. market, continuing vital U.S. corporate investment in the EU and placating the U.S. government so it continues its security and intelligence cooperation with various EU members. All this while making it look as if the EU is still doing something to protect it's citizens' data.

I'm not at all surprised to see that the European Commission (which is subject to political pressure from the EU Council and nations) gave this their seal of approval, while the courts (which work to a different standard based on law) put Privacy Shield out of it's misery.

More legal misdirection -- good try, but COMPLETELY BESIDE THE POINT!

Anonymous Coward

Quote: "In effect, the EU court said American spies had too much free rein to harvest EU citizens' data from US companies."

*

Pardon my scepticism, but who says the NSA (or their poodle in Cheltenham) isn't hacking European databases EVERY DAY OF THE WEEK?

*

.....never mind data transfers "from US companies"........

*

26 January 1999 -- Scott McNeally -- https://www.wired.com/1999/01/sun-on-privacy-get-over-it/

*

If you want ANY SORT OF PRIVACY...........stay away from the intenet!

"... the standard contractual clauses remain a valid tool ..."

Mike 137

"The Court of Justice declared the Privacy Shield decision invalid, but also confirmed that the standard contractual clauses remain a valid tool for the transfer of personal data to processors established in third countries."

Which is jolly funny as it was pointed out a couple of years back that the standard contractual clauses [1] don't entirely comply with the GDPR . Not really surprising as they were defined in 2001, 2004 and 2010.

The UK ICO wasn't interested when we pointed this out either. Yet another example of "compliance" in quotes?

[1] https://www.jdsupra.com/legalnews/gdpr-the-most-frequently-asked-46813/

It's amazing how much "mature wisdom" resembles being too tired.