An axe age, a sword age, Privacy Shield is riven, but what might that mean for European businesses?
- Reference: 1595251929
- News link: https://www.theregister.co.uk/2020/07/20/privacy_shield_declared_invalid_consequences/
- Source link:
You will no doubt soon be buried under articles taking apart this decision in detail, but allow me summarise most of them for you: US-based facilities handling information of EU citizens will now require their explicit permission, or the EU's rather painful GDPR fines may loom.
There are a number of business communication gotchas to be aware of.
Privacy Shield binned after EU court rules transatlantic data protection arrangements 'inadequate' [2]READ MORE
When an organisation's only customer interface is via Facebook or Twitter (to name the main ones), it forces customers to agree to terms that harm their privacy in order to communicate. Granted, that's not entirely the organisation's problem, until such time as customers are left with no other option because, for instance, it is a utility.
That has not changed from when Privacy Shield was OK for those who preferred not to look too closely, and there is still some margin for using opt-out "standard contractual clauses" (SCCs) that have been not been ruled invalid, for now. Experts say they too will not withstand scrutiny in the longer term, however.
Where it gets interesting is the use of US-based companies for email and messaging. When an EU organisation uses US resources for receiving customer email or messages it is, by default, exporting personal information to a country that is now without adequate privacy protection. The problem: when there has been no prior contact, this happens without the prior permission of said EU customer.
US companies will not want to lose their EU business (and, one could argue, their surveillance ability of their EU customers for whatever monetising activity du jour) so it is likely that they will set up EU-based data centres if they haven't already done so.
This brings us to the newer problematic kid on the block in terms of US law: the "Clarifying Lawful Overseas Use of Data" Act 2018, or CLOUD Act for short, which allows a US court to demand personal data held by a US company, anywhere in the world, sovereignty be damned.
A US provider who has set up EU operations to seek GDPR compliance can therefore still not be considered safe from a privacy perspective (let alone "adequate") as this CLOUD Act considerably exacerbates the conflict between the EU and US federal view of privacy, good state efforts such as the California Consumer Privacy Act (CCPA) notwithstanding.
Smaller organisations without much in the way of IT knowledge and resources are at particularly risk and may be caught out by this. Using services such as Gmail or Microsoft Office 365 now requires a careful re-examination of their Terms & Conditions.
There could be costly consequences. ®
Peter Houppermans is a privacy and IT security expert.
* When it comes to [3]adequacy agreements, for UK businesses, there will be concerns, as [4]some have pointed out, around the fact that the [5]UK_GDPR (which took effect this year but currently mirrors EU law) may quickly begin to diverge from standards established by the GDPR, which would stand in the way of any potential adequacy agreement with the European Commission.
Get our [6]Tech Resources
[1] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[3] https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
[4] https://amberhawk.typepad.com/amberhawk/2020/07/schrems-ii-takeaways-accountability-in-privacy-shield-out-uks-adequacy-determination-at-risk.html
[5] https://www.legislation.gov.uk/uksi/2019/419/made
[6] https://whitepapers.theregister.com/
When an organisation's only customer interface is via Facebook or Twitter I will not deal with them.
No Shit Sherlock
The CLOUD act is exactly why US companies aren't adequate. If they want to do business on the right bank of the pond, they do it within the local laws. If their own stupid laws don't allow that, then what do they spend all that lobbying money for?
Re: No Shit Sherlock
I've suggested previously that the way round this for a US service is to offer a franchise to a an EU business, set up under EU law with EU citizens as owners, officers and staff. The franchise pays for IP - branding and copies of S/W - from the US business. EU data is handled purely within the EU. If data, mail in the example in the article, is to be sent to a non EU, no US destination then it's not routed through the US.
There's another option for EU businesses to use email of course - use an EU owned and based MSP. That's assuming the MSP doesn't simply resell a US-based service (Is BT still reselling Yahoo ! ? Not that that matters now anyway.).
Re: No Shit Sherlock
The problem with that is that for the U.S. company, you are sharing your algorithms, data and many of your deepest secrets with an EU franchisee that is technically free to stop being your franchisee and go do something else, using a lot of the data and secrets you had to share with them. Legally, the arms-length agreement might work, but from a security standpoint it has a number of problems.
Plus I could see issues with general data security (What happens if the franchisee has a huge IT security failure? Does the mothership have any liability?) and will the franchisee's cut of mothership revenues generated be enough to keep the franchisee operating in the marketplace?
Re: No Shit Sherlock
Plus, US companies, including FecesBook and Googs, have no problem complying with requirements from dictatorial countries. They have just never believed that the EU would ever stand up to them.
I say bring it on.
The point of the EU
The fundamental problem is that the EU wants privacy for its citizens, and the USA doesn't.
If the EU doesn't enforce this (or can't or won't), the EU is shown to have no teeth. (as was the case with "safe harbour")
If the EU *can* enforce this, the USA is shown to not be the exceptional little snowflake it thinks it is.
Expect tantrums either way.
Re: The point of the EU
We need Americans to start demanding the same protections.
Won't help with Governmental snooping but we have that issue in the UK too.
Re: The point of the EU
The fundamental problem is that the EU wants privacy for its citizens, but the US does not want privacy for anyone who isnt a US citizen. It doesnt care so much either way about US citizens in this instance.
It is a bit reminiscent of Rome, in terms of standards.
I dont think that the EU CAN do a lot about this, tbh, as so much of the data which lubes up conglomerates and other big businesses transfer all over the place. SCCs might be useful - but they are going to be redrafted too. I dont think that the ECB will have the nutts to really put its foot down. I also doubt the UK would be able to follow suit at this time.
SCCs
The article repeats that SCCs are still legal. But when this story broke the other day, it seemed that that was not actually the case (the judge did not say they were ok and it was a mid-quote / wilful misunderstanding by some bod at the EU).
So what’s the reality?
Reality
Ashley Gorski (ACLU)
@ashgorski
Some reporting is suggesting that the SCCs will remain viable mechanisms for any EU-US transfer. Based on the court's analysis of US law, that's simply not the case. DPCs will be required to halt data flows.
https://twitter.com/ashgorski/status/1283756155152596994
Re: SCCs
An SCC is a civil contract between the EU entity and the foreign entity it wants to shovel data to, that exists outside of (or hand-in-hand with) the inter-governmental Privacy Shield-type agreements. They do not depend on or require such inter-governmental agreements to function - in fact you'd use them in lieu of such inter-governmental agreement. Therefore the concept of SCCs as a civil contract was upheld (or perhaps more accurately, not overturned).
However, the court also recognised that they are civil contracts between the business entities. As such, they are not binding on the governments (of either end), and as civil contracts they must exist within and can be overriden by local laws.
One of the clauses of an SCC requires that the non-EU entity the agreement is with to notify its EU partner if and when the laws of the local country (that is, at time of contract signing or if the local laws later change to make it so) override any SCC contractual provisions that impact privacy of the data. In this way, a, for example, US company if served by an NSL (National Security Letter that usually have criminally enforceable secrecy) doesn't have to tell the EU partner that it has been served with such, but it does have to tell the EU entity that it cannot abide by certain clauses - or the entirety - of the SCC, thus effectively terminating the contract. Although in this example, the fact that an NSL could be served, that the law allows for such, under which a non-US (hell, even effectively US) citizen has no rights, no standing, no recourse to US courts to fight it, is grounds to invoke the clause 5 (from the decision):
141 It follows that Clause 4(a) and Clause 5(a) and (b) in that annex oblige the controller established in the European Union and the recipient of personal data to satisfy themselves that the legislation of the third country of destination enables the recipient to comply with the standard data protection clauses in the annex to the SCC Decision, before transferring personal data to that third country.
There were two prominent US laws (actually a law and a Presidential Executive Order(EO)) that are the prime reasons for overturning Privacy Shield, Section 702 of the FISA, E.O. 12333, and since the mere existence of that law and EO is sufficient to overturn Privacy Shield, they necessarily also nullify SCCs with US entities. This doesn't affect SCCs with non-US entities, which would be taken on a country-by-country basis.
This is why some of the commentary says that SCCs are still valid, because they are. But they overlook the fact that SCCs with US entities are not valid.
Re: SCCs
As I read it SCCs per se are legal but when applied to the US they're worthless because US legislation prevents them being honoured. If you have SCCs with a company in a country that doesn't enable its govt to override them they're OK. I've no idea if such countries exist but I suppose the countries that do override them will have to be excluded one at a time. UK next up?
"When an organisation's only customer interface is via Facebook or Twitter (to name the main ones), it forces customers to agree to terms that harm their privacy in order to communicate."
In that situation no consequences will be undeserved, regardless of how costly they are.