News: 1597411267

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

How do you solve a problem like Privacy Shield? US and EU policymakers kick off discussions

(2020/08/14)


The long-running kerfuffle over the so-called Privacy Shield EU-US data protection agreement took another lurch this week after politicos announced plans to ponder an "enhancement" to the framework.

The [1]joint statement from US Secretary of Commerce Wilbur Ross and European Commissioner for Justice Didier Reynders comes in the wake of a July judgement by the Court of Justice of the European Union in the Schrems II case that effectively [2]took a hatchet to the framework, declaring it invalid.

The Privacy Shield enables the data of EU citizens to be sent to US companies for storage and processing, and has survived [3]repeated reviews by the European Commission. Austrian privacy activist Max Schrems kicked off the long-running case (often referred to as 'Schrems II') complaining that once his data was in the US there were no legally enforceable EU-style protections to prevent US authorities having a nose around in it.

An axe age, a sword age, Privacy Shield is riven, but what might that mean for European businesses? [4]READ MORE

While last month's ruling did not strike down the Standard Contractual Clauses (SCCs) used as opt-outs by many companies, it seems likely that they too will come under the gimlet gaze of the courts before long.

Which brings us back to what can be done to put Humpty back together again and what enhancements could be made to the Privacy Shield to keep the data, and the money, flowing.

Neil Brown, tech lawyer at decoded.legal, told The Register that attempting to patch up the agreement would "end up being a case of 'different wallpaper, same cracks'" and pointed out that while [5]Section 702 of the US Foreign Intelligence Surveillance Act (FISA) and [6]Executive Order 12333 remained in place, "it would be challenging, in my view, to come up with a 'Privacy Shield' arrangement which was not vulnerable to being struck down.

"Again."

Safe Harbour ruled INVALID: Facebook 'n' pals' data slurp at risk [7]READ MORE

What's all this about SCCs – are they good enough or not?

Bill Mew, founder and CEO at Crisis Team, has said SCCs could be on dodgy ground when it comes to FISA 702, since the Act applies to "electronic communication service providers" (ECSPs). "All the US cloud firms fall under FISA 702," he commented, which could have worrying implications for those outsourced to a US outfit, even if the server is located in the EU. Mew described the location of hosting as "irrelevant".

The US's [8]Clarifying Lawful Overseas Use of Data (CLOUD) Act 2018 allows a US court to demand personal data held by a US company, anywhere in the world.

Decoded's Brown told The Register : "The court is clear that, in themselves, the SCCs remain valid."

However, he added: "To achieve a standard of protection which is 'essentially equivalent' to that of the GDPR, companies transferring personal data out of the EU will be expected to do more than simply sign them with the recipient: they need to investigate the laws of each recipient country, and determine that the combination of the SCCs, those laws, and any other measures which they can put in place, give sufficient protection.

"Fine, perhaps, in theory. Until there's a free, consolidated resource of all relevant laws for each country around the world – perhaps a job for the European data protection regulators? — this could be simply out of reach for companies without deep pockets.

"Clearly, each transfer will need its own assessment but, in terms of transfers to the USA, since Privacy Shield has been found to offer insufficient safeguards, one might question if SCCs alone are up to the job. Worse, given the laws which the CJEU felt were particularly problematic, I question what, if any, additional measures a company could use while still getting the benefit of the transfer?

"In practice, since the totality of [9]the ICO's advice is 'take stock of the international transfers you make and react promptly as guidance and advice becomes available', and that it will take a 'risk-based and proportionate approach' to enforcement, one might forgive companies for assuming they need to do very little, if anything, for now."

Julie Brill, corporate vice president for Global Privacy and Regulatory Affairs and Chief Privacy Officer at Microsoft, [10]insisted last month that the SCCs remained valid and that "our customers are already protected under SCCs" – even as Privacy Shield was struck down.

Brill also pointed out that Microsoft had gone as far as the US Supreme Court to challenge orders seeking access to data. Customers, however, would be forgiven for preferring something a little more legislative to depend on rather than the legal largesse of a cloud giant. As Brill observed: "We'll work collaboratively with governments and policymakers as they shape new approaches."

If the Privacy Shield arrangement is to be resurrected in a manner that could resist swatting by the courts, it would need a change in US law. "I suspect that the USA's appetite for doing this is unlikely," said Brown.

Or perhaps those in the EU could be given rights to challenge US surveillance programmes before US courts?

"It's possible, I guess, but seems unlikely."

While politicos ponder what "enhancements" might deal with the blow dealt to the Privacy Shield, companies would do well to take a long, hard look at the T&Cs of their providers or run the risk of being expensively caught out. ®

* Schrems I, for those who recall, was the case that [11]killed off Safe Harbor , the data protection arrangement that Privacy Shield was supposed to replace.

Get our [12]Tech Resources



[1] https://www.commerce.gov/news/press-releases/2020/08/joint-press-statement-us-secretary-commerce-wilbur-ross-and-european

[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[3] https://www.theregister.com/2019/10/23/third_review_of_privacy_shield_room_for_improvement/

[4] https://www.theregister.com/2020/07/20/privacy_shield_declared_invalid_consequences/

[5] https://www.eff.org/702-spying

[6] https://www.archives.gov/federal-register/codification/executive-order/12333.html

[7] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/

[8] https://www.congress.gov/bill/115th-congress/house-bill/4943

[9] https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2020/07/updated-ico-statement-on-the-judgment-of-the-european-court-of-justice-in-the-schrems-ii-case/

[10] https://blogs.microsoft.com/eupolicy/2020/07/16/assuring-customers-about-cross-border-data-flows/

[11] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/

[12] https://whitepapers.theregister.com/

Why has it taken this long?

DavCrav

It's absolutely clear that these two principles are incompatible:

EU: all personal data should be held privately and the US government (for example) cannot look at it whenever it feels like it.

US: all personal data held in the US, or by US companies, can be looked at by the US government whenever it feels like it.

Either one of those two stances has to change, or there will always be an incompatibility.

Re: Why has it taken this long?

Jason Bloomberg

It's absolutely clear that these two principles are incompatible

That's my view as well. It is 'unstoppable force meets immovable object' and it is not resolvable unless one side or both change their position.

My opinion is the EU needs to stand their ground, tell the US to go fuck itself, and deal with the consequences.

Re: Why has it taken this long?

Anonymous Coward

The various US TLA's think (along with the current POTUS) that they rule the world and US Jurisdiction applies everywhere and 'Trumps' (sic) local laws.

It is long past time that the Yanks were told to 'eff off' and then 'Go F**** yourself'.

But other nations won't do that. The current POTUS is so deluded with power that he could very well order 'send in the Marines' and invade a current allie.

Re: Why has it taken this long?

Len

That ally might be Ireland then. Invading a NATO member state (which Ireland is not) would get the US thrown out of NATO, at which point we could just dub it the European Treaty Organisation or something.

This is really testing the EU freedoms of thought and of speech, GDPR etc

Anonymous Coward

http://www.caef.org.uk/d119route3.html

Is a mention of historic accuracy, suggesting that the Winston Churchill (President of honour) , Duncan Sandys (President), {et al} origin of the excellent European Commission project deserves some scrutiny, especially {et al}, in Virginia.

There are other more academic histories, but this page has pictures

Doctor Syntax

"Or perhaps those in the EU could be given rights to challenge US surveillance programmes before US courts?"

Give them rights to challenge them in EU courts would be better. What a pity that for us in the UK it's all academic now.

Doctor Syntax

'different wallpaper, same cracks'

A gem. Give the man a

Neil Brown

Thank you. Beer gratefully accepted :)

Store data in the EU

Len

I haven't had the chance to fully go through all this but at first look it seems that using the exemption to storing data of EU Citizens in the US has now been struck down. I agree with the article that Standard Contractual Clauses (SCCs) are probably next for the chop.

Let's face, even a successor to Privacy Shield would very likely be in breach of the [1]Charter of Fundamental Rights of the European Union that guarantees EU Citizens a whole host of rights. That successor will therefore likely be struck down too.

As a get out clause this means that US firms could still avoid this legal head ache by storing all data of EU Citizens in the EU. That buys quite a bit more time, until a US court order instructs a company to hand this data over and a company needs to decide which law it will break. It's not perfect but it buys more time.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12012P/TXT

Re: Store data in the EU

Tomislav

No, it does not, because CLOUD act (mentioned in the article) gives US TLAs access to all the data held by US companies anywhere in the world, including EU.

Re: Store data in the EU

Len

I know (though technically it doesn't give them access, it gives them power limited to US jurisdiction to instruct someone to provide access), but until the US instructs a company to hand over data the CLOUD act doesn't come into play. And obviously adhering to the CLOUD act is illegal in the EU so a company will then have to decide which law it will break.

There have been anecdotal reports of companies only letting EU Citizens handle data in their Irish data centre to stay out of reach of the CLOUD act. At that point the issue is escalated to head office (look at the Microsoft case) and we get into the territory of how a company can be instructed to tell a subsidiary to hand over data. Microsoft, again, created some legal firewall situation for this scenario with its Office 365 hosting in Germany that is out of reach of the CLOUD act.

This is not fool proof but until the US attempts to use the CLOUD act it is probably the safest bet. Safer than counting on Privacy Shield or SSCs.

Re: Store data in the EU

Yet Another Anonymous coward

Nope, a US company could already have been handed a secret US national security letter telling them to hand over Eu citizens data held in the Eu.

Or they could have just decided to do it anyway in order to be "cooperative" and perhaps be the only approved bidder for a big DoD cloud contract.

Re: Store data in the EU

Len

That is possible, but that US company would be breaking the law with potentially quite severe repercussions. You'd imagine a company would think twice before they take that risk.

Besides, unless you are an American Citizen or live in the US, a National Security Letter carries no weight. You can publish it and decide to ignore its contents. Just don't ever visit the US again. It would be quite a spectacle, by the way, and I'm hoping someone high profile does this some time.

Re: Store data in the EU

alain williams

That is possible, but that US company would be breaking the law with potentially quite severe repercussions. You'd imagine a company would think twice before they take that risk.

Thought 1: Will we get caught ?

Thought 2: Has anyone else been caught ?

Re: Store data in the EU

Len

On point 1, I think the chances of getting caught are pretty high.

Let's say some crook is being prosecuted in the US but their data is stored on Microsoft servers in Ireland (to stay close to an actual event). The incriminating evidence will need to come with context to be admissible. Both the judge and the defense team will want to know how the prosecution got their hands on email XYZ. They might even ask an MS employee to testify where it came from (and a US prosecutor will probably not care about whether MS gets into trouble in some foreign jurisdiction).

If that email was procured by breaking the law, as it will have been if it came from a server in the EU, then the defense team will be very interested in that. As will prosecutors in the EU if they get wind that Microsoft broke the law by providing access to the defendant's emails.

If I were a big tech firm I would definitely worry about being caught. It might take a couple of years but I would put the chances of getting caught a few years after the fact at over 80%.

On point 2, not at this time, no. But do you want to be the first to get caught? The downside of being the first is that you risk being made an example. It would send a powerful message if Microsoft was fined tens of billions of euros or banned from selling their products in the world's biggest developed market for breaking EU law.

Re: Store data in the EU

Yet Another Anonymous coward

Hence parallel discovery

Shady US agency automatically reads all email hosted by a US company from Eu citizens, because what else is their massive new data center for?

They tip-off local law enforcement in the US to stop a certain citizen for a broken brake light and have a look for drugs. When does the NSA involvement come up in court?

Or they pass on a tip to friendly agencies in Europe that somebody a bit brown is emailing somebody in Iran and the friendly country's police respond - by shooting a Brazillian

Re: Store data in the EU

Tomislav

Exactly, we only know what Microsoft (and others) have released publicly. We cannot know what happened behind the scenes and how many requests they decided to silently comply with.

Re: Store data in the EU

Version 1.0

If you are going to store your data in the Cloud anywhere then you are stupid a large corporation if you think that nobody else has access to it secretly, deliberately, or accidentally.

Re: Store data in the Cloud

Steve Davies 3

Whilst you are correct I fear that you are talking to a stable door years after the horse has bolted.

There are hardly any companies or indeed Guberments that are not rushing headlong into the cloud.

I'm sire that it won't be long before a FTSE 500 company goes TITSUP because their Cloud has been hacked and all the data stolen.

Crazy thing

StrangerHereMyself

The crazy thing is, I predicted this would have happen in jest. I said they'll just come up with some other willd-assed scheme and give it some crummy name and alter a few paragraphs in the previous accords. It'll take years before Schremms is able to get it voided again, and in the meantime, the U.S. tech-giants can continue pillaging our data.

They'll continue to do this until Schremms gets the gist and gives up.

Re: Crazy thing

Yet Another Anonymous coward

Or until it starts to affect ordinary people - not just terrorists/drug-smugglers/bogeymen-of-the-day

When Hans Schmidt gets rejected from a job at VW because it may involve travel to the USA and a pre-hire security check says that immigration may reject him because of his twitter following.

Or he can't get travel insurance to holiday in Spain because of the Google searches he did for symptoms - which although illegal in Europe, his insurer is allowed to take advice from it's US parent company

To code the impossible code, This is my quest --
To bring up a virgin machine, To debug that code,
To pop out of endless recursion, No matter how hopeless,
To grok what appears on the screen, No matter the load,
To write those routines
To right the unrightable bug, Without question or pause,
To endlessly twiddle and thrash, To be willing to hack FORTRAN IV
To mount the unmountable magtape, For a heavenly cause.
To stop the unstoppable crash! And I know if I'll only be true
To this glorious quest,
And the queue will be better for this, That my code will run CUSPy and calm,
That one man, scorned and When it's put to the test.
destined to lose,
Still strove with his last allocation
To scrap the unscrappable kludge!
-- To "The Impossible Dream", from Man of La Mancha