News: 1624283530

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Final guidance on Schrems II ruling: Data from EU could be held up if a third country lets authorities access it

(2021/06/21)


The European Data Protection Board (EDPB) has finalised its guidance to businesses in how they should proceed following the Schrems II ruling which struck down the Privacy Shield data-sharing arrangement between the EU and the US.

In its [1]final version of the recommendations [PDF] on supplementary measures to accommodate the ruling, the EDPB said the transfer of data could be impinged on if legislation in a third country allows authorities to access data transferred from the EU, even without the importer's intervention.

In the [2]Schrems II ruling , named after Austrian privacy activist and lawyer Max Schrems, the EU Court of Justice said that Section 702 of the US Foreign Intelligence Surveillance Act together with a US presidential order and a policy directive on data collection by spies failed to meet EU data protection requirements.

[3]

Bringing the case, Schrems argued that once his data was in the US, no EU-style data privacy controls were legally enforceable by him or anyone else in that situation.

[4]

[5]

Other modifications in the guidance include an "emphasis on the importance of examining the practices of third-country public authorities in the exporters' legal assessment to determine whether the legislation and/or practices of the third country impinge – in practice – on the effectiveness of the [6]Art. 46 GDPR transfer tool ," which includes the condition that enforceable data subject rights and effective legal remedies for data subjects are available in the country data is sent to.

Retained in the document is guidance about the use of encryption for protecting data in third countries, as is common with cloud companies moving data between jurisdictions.

[7]European Parliament's data adequacy objection: Doubts cast on UK's commitment to privacy protection

[8]Microsoft bins Azure Blockchain without explanation, gives users four months to move

[9]Privacy activist Max Schrems on Microsoft's EU data move: It won't keep the NSA away

[10]Privacy activist Max Schrems claims Google Advertising ID on Android is unlawful, files complaint in France

As [11]raised by The Register last year , the guidance allows for data sharing with encryption only if the "keys are retained solely under the control of the data exporter, or by an entity trusted by the exporter in the European Economic Area or under a jurisdiction offering an essentially equivalent level of protection to that guaranteed within the EEA."

What is Schrems I? In the first case, arising from a complaint filed with the [12]Irish Data Protection Commissioner in 2011 , privacy activist Max Schrems ultimately toppled the biggest EU-US data sharing deal, Safe Harbor.

The student had alleged that Facebook violated the so-called Safe Harbor agreement which protects EU citizens' privacy, by transferring its users' data to the US National Security Agency (NSA).

In the [13]Schrems I ruling , in 2015, Europe’s highest court ruled that data sharing between the EU and US under the Safe Harbor framework was invalid.

What is Schrems II? The law student brought the latest edition of the long-running case (informally known as Schrems II) in 2015, [14]complaining that Ireland's data protection agency still wasn't preventing Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from beaming his data to the US under Privacy Shield.

In July last year, the [15]EU Court of Justice struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.

The problem arises with bring-your-own-key encryption, as applied by cloud providers, as they could be obliged by the authorities to hand over data. If the exporter uses that cloud service and puts the encryption keys into the cloud, or makes them available to the cloud provider to decrypt and process data inside the cloud, then that data could be intercepted, copied, or manipulated.

The Schrems II ruling already meant international data flows were subject to much closer scrutiny from the supervisory authorities, according to EDPB Chair Andrea Jelinek.

[16]

"The goal of the EDPB Recommendations is to guide exporters in lawfully transferring personal data to third countries while guaranteeing that the data transferred is afforded a level of protection essentially equivalent to that guaranteed within the European Economic Area," she said.

"We want to make it easier for data exporters to know how to assess their transfers to third countries and to identify and implement effective supplementary measures where they are needed. The EDPB will continue considering the effects of the Schrems II ruling and the comments received from stakeholders in its future guidance." ®

Get our [17]Tech Resources



[1] https://edpb.europa.eu/system/files/2021-06/edpb_recommendations_202001vo.2.0_supplementarymeasurestransferstools_en.pdf

[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNC3mypUYOoqo-OQui80XwAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNC3mypUYOoqo-OQui80XwAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNC3mypUYOoqo-OQui80XwAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://gdpr-text.com/read/article-46/

[7] https://www.theregister.com/2021/06/03/uk_data_protection_eu_parl/

[8] https://www.theregister.com/2021/05/13/azure_blockchain_eol/

[9] https://www.theregister.com/2021/05/07/schrems_slams_microsoft_eu_data/

[10] https://www.theregister.com/2021/04/07/max_schrems_google_complaint/

[11] https://www.theregister.com/2020/11/23/european_recommendations_on_schrems_ii/

[12] https://www.theregister.com/2011/10/19/europe_v_facebook_irish_investigation/

[13] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/

[14] https://curia.europa.eu/juris/document/document.jsf?text=&docid=228677&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=12312155

[15] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNC3mypUYOoqo-OQui80XwAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[17] https://whitepapers.theregister.com/

Doctor Syntax

"The goal of the EDPB Recommendations is to guide exporters in lawfully transferring personal data to third countries while guaranteeing that the data transferred is afforded a level of protection essentially equivalent to that guaranteed within the European Economic Area,"

It should also be important guidance for would-be importers - IDS please note.

How long has this been going on?

Rich 2

It never ceases to amaze me how tectonically slow the wheels of the EU move. And all the while, businesses are openly breaking the law on the grounds of “no guidance”.

It’s like all the GDPR complaints being made against the likes of googlies and faecesbook - the EU might get around to addressing the complaints this century. Maybe? Who can tell?

(disclaimer: I’m not in favour of brexit - it’s a shit storm. And the UK gov (of whatever colour) is just as bad as the EU)

The greatest disloyalty one can offer to great pioneers is to refuse to
move an inch from where they stood.