News: 1629207845

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Zoom incompatible with GDPR, claims data protection watchdog for the German city of Hamburg

(2021/08/17)


The acting Hamburg Commissioner for Data Protection and Freedom of Information has officially [1]warned the city's Senate Chancellery not to use the on-demand version of Zoom's videoconferencing software.

Referring to the European Court of Justice [2]Schrems II decision of July 2020, Ulrich Kühn claimed the software violates the EU General Data Protection Directive (GDPR) as "such use is associated with the transmission of personal data to the US."

Kühn stated bluntly:

A data transfer is therefore only possible under very strict conditions, which are not available when the Senate Chancellery is planning to use Zoom.

Dr Gabriela Zanfir-Fortuna, Future of Privacy Forum director, publicly [3]speculated this morning that Zoom had relied "on SCCs, but with insufficient supplemental measures," opining: "A pattern emerges showing public offices, gov agencies & their US-based service providers as the immediate target of Schrems II enforcement... It's going to be a busy fall, folks."

Neil Brown, director at tech-savvy virtual English law firm decoded.legal, told The Register he interpreted the "somewhat oblique" press release to mean the Hamburg DPA considers that Zoom "does not ensure a level of protection for personal data which is 'essentially equivalent' to that afforded by the GDPR."

[4]

Brown added: "Many businesses used to address the international transfers aspect of the GDPR by incorporating the model contract clauses/SCCs into their contracts with organisations in non-adequate jurisdictions.

[5]

[6]

"In Schrems II, the CJEU said that these were not, in themselves, sufficient, and that a transferring controller must do a comprehensive risk assessment, and put appropriate additional measures in place to ensure 'essentially equivalent' protection.

"And that came as a shock to a lot of people, since it rather suggested that the model clauses were not fit for purpose. And, lo and behold, there is a new European set, which is a heck of a lot more complicated."

What is Schrems I? In the first case, arising from a complaint filed with the [7]Irish Data Protection Commissioner in 2011 , privacy activist Max Schrems ultimately toppled the biggest EU-US data sharing deal, Safe Harbor.

The student had alleged that Facebook violated the so-called Safe Harbor agreement which protects EU citizens' privacy, by transferring its users' data to the US National Security Agency (NSA).

In the [8]Schrems I ruling , in 2015, Europe’s highest court ruled that data sharing between the EU and US under the Safe Harbor framework was invalid.

What is Schrems II? The law student brought the latest edition of the long-running case (informally known as Schrems II) in 2015, [9]complaining that Ireland's data protection agency still wasn't preventing Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from beaming his data to the US under Privacy Shield.

In July last year, the [10]EU Court of Justice struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.

Kühn's pronouncement further in the warning (via Google Translate) that the Senate Chancellery had been "unwilling to respond to ... repeated concerns" and had missed deadlines to submit documents and arguments also caught the eye. Brown told The Reg this suggested that the "warning stemmed, at least in part, from a seeming lack of cooperation" by the Senate Chancellery, speculating this might have to do with "political infighting."

[11]Once again, Facebook champions privacy ... of its algorithms: Independent probe into Instagram shut down

[12]Dutch education IT crisis averted as Google agrees to 'major privacy improvements'

[13]UK data watchdog sees its approach to government health tech during COVID-19 outbreak as 'pragmatic'

[14]Euro watchdog will try to extract $900m from Amazon for breaking data privacy laws

[15]Gov.UK vows to chop red tape in the digital sector. What could possibly go wrong?

As for the larger implications of the Schrems II ruling, including the fresh SCCs, Brown commented that it was: "Good news for lawyers, for self-hosted solutions, and for service providers which do not need to transfer personal data to non-adequate jurisdictions. Less good news for anyone facing a pile of new paperwork and lawyers' bills."

Zoom has [16]said its products feature "an explicit consent mechanism for EU users" on its platform and that it has implemented "zero-load" cookies for users whose IP address show they are accessing the site from a EU member state.

[17]

Under the heading "European Data Protection Specific Information," Zoom has said:

Where personal data of users in the EEA, Switzerland, or the UK is being transferred to a recipient located in a country outside the EEA, Switzerland, or the UK which has not been recognized as having an adequate level of data protection, we ensure that the transfer is governed by the European Commission's standard contractual clauses.

We have asked the firm for clarification. The page was last updated on 4 June 2021 – the same day the European Commission published its final Implementing Decision adopting several new standard contractual clauses for the transfer of personal data to third countries. The new SCCs – serving orgs making data transfers to and from the EU and covering both the European processor and the US controller – were responses to deficiencies in previous SCCs brought to light in the Schrems II ruling.

Mind the Brexit gap

The UK's Information Commissioner is [18]currently working on its own draft international data transfer agreement. The regulator also recently moved to draft a UK-specific contractual addendum so that the county will be able bolt on those new EU standard contractual clauses on the international transfer of personal data to allow use of the European Commission's new SCCs in a UK context. Brexit meant Brexit.

In the background is the report from the Taskforce on Innovation, Growth and Regulatory Reform (TIGRR), [19]characterised by a Reg colleague as "a Brexit goon-squad of Tory MPs" which has taken aim at Article 5 of GDPR, which states among other things that data should be "collected for specified, explicit and legitimate purposes" and be "adequate, relevant and limited to what is necessary." The report moaned that this limited "AI organisations from collecting new data before they understand its potential value and they also mean that existing data cannot be reused for novel purposes."

The Commission formally announced its adoption of adequacy decisions for the UK

[20]PDF

on 28 June, which would have been a relief to many businesses in the country relying on EU data flows. However, as critics have pointed out, the adequacy designation may not necessarily stand should a determined effort be made to divert UK legislation too far from the protections afforded to citizens of the EU.

We have asked Zoom for comment. ®

Get our [21]Tech Resources



[1] https://datenschutz-hamburg.de/pressemitteilungen/2021/08/2021-08-16-senatskanzlei-zoom

[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[3] https://twitter.com/gabrielazanfir/status/1427372090001403907

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/saas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRvdOTiGhmPLFCf@37QpBgAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/saas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRvdOTiGhmPLFCf@37QpBgAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/saas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRvdOTiGhmPLFCf@37QpBgAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2011/10/19/europe_v_facebook_irish_investigation/

[8] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/

[9] https://curia.europa.eu/juris/document/document.jsf?text=&docid=228677&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=12312155

[10] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[11] https://www.theregister.com/2021/08/13/algorithmwatch_shut_down/

[12] https://www.theregister.com/2021/08/11/dpa_dutch_google/

[13] https://www.theregister.com/2021/08/04/ico_annual_report/

[14] https://www.theregister.com/2021/07/30/amazon_european_privacy_fine/

[15] https://www.theregister.com/2021/07/07/digital_sector_uk_policy/

[16] https://zoom.us/gdpr

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/saas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRvdOTiGhmPLFCf@37QpBgAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[18] https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/ico-consultation-on-data-transferred-outside-of-the-uk/

[19] https://www.theregister.com/2021/06/22/uk_eu_data_sharing_adequacy/

[20] https://ec.europa.eu/info/files/decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en

[21] https://whitepapers.theregister.com/



Dinanziame

I'm confused; is Zoom supposed to change the way their software works, or change their T&Cs to make them compatible with the GDPR?

GiantKiwi

At this point, pretty much both options.

Joe W

I guess it's more of a note to the Chancellary of the Senate of the Free Hanseatic Town of Hamburg to stop using the on-demand service of Zoom. Pronto.

Should zoom change the way their on-demand service works or how the T&Cs are worded, zoom could again be used. Although I really do wonder why they should use it anyway, as several states are indeed self hosting own platforms (don't know if Zoom is among them, I believe Skype and WebEx are... another good candiate - if there is an on-prem version - would be Microsoft Teams), but I'm really not sure if Hamburg does have its own servers for web conferences / meetings / video calls.

So, yeah, this is how it is supposed to work: a service cannot be offered in the EU (and very definitely should not be used by the government!) if it does not comply with GDPR.

big_D

There are plenty of tools and services that are compliant, like Jitsi, Big Blue Button etc. That are either self-hosted or hosted by EU-only companies, which are compliant.

Joe W

Exactly. Though I am sure that for use by government bodies the rules are quite a bit stricter than just "GDPR-compliant", or at least they should be.

So why they do seem to insist on using Zoom is unclear to me (ok, it's not, it will be "but my son uses it in school, so I am familiar with it" - or something along these lines).

SImon Hobson

So why they do seem to insist on using Zoom is unclear to me

It's there, it's reasonably priced, it's fairly easy to use - and also, I've found that it's fairly easy on system resources on my aging old laptop.

katrinab

No, they are supposed to change the way their software works, and change their T&Cs to make them compatible with the GDPR.

"appropriate additional measures [...] to ensure [...] equivalent protection"

LDS

That's what Zoom has to do - how depends on what and how actually Zoom collects and store user data. It may decide not to move EU data to US, it may keep on moving data to US ensuring the "equivalent protection" and that could be more than a few changes to T&C.

The fundamental problem

Mike 137

The fundamental problem is that US Privacy Shield was struck down by the EU (and indeed Switzerland) in the aftermath of Schrems II, for the simple reason that it offered no real protection in the face of overriding federal law allowing government agencies access to personal data regardless of the terms of contracts between the parties to data transfers.

In practice, under current conditions no agreements between parties, whether based on "standard contractual clauses" or not, can alleviate this problem. The only practical remedy other than a major change to US federal law (which is unlikely to happen) is for the US party to the transfer to limit the data it gathers to a minimum such that it no longer constitiutes "personal data", and even then under a strict interpretation of the EU legislation there are challenges - not least that anonymisation is itself "processing".

Re: The fundamental problem

SImon Hobson

...it offered no real protection in the face of overriding federal law allowing government agencies access to personal data regardless of the terms of contracts between the parties to data transfers

Which is the key point.

We all knew Privacy Figleaf Shield was dead as soon as it was announced. But hey, it bought people another 5 years while Shrems II worked it's way through the system. No doubt TPTB will come up with another grand sounding scheme that everyone can sign up to - and it'll buy another 5 years while Shrems III grinds through the mill and that scheme gets tossed out.

But ultimately, there is a fundamental incompatibility between EU and US law - unless one or both change their law significantly then there will never be a system which withstands scrutiny. I don't believe the EU will change, let's face it, there's enough member countries that understand (thanks to events within living memory) the importance of privacy. And I can't see the US government upsetting the corporate sponsors that bankroll the elected members' ...

So I think we can look forward to "son of Privacy Figleaf" followed by Schrems III; then "son of son of Privacy Figleaf" followed by Schrems IIII; then ...

That's the point!

Joe W

the report from the Taskforce on Innovation, Growth and Regulatory Reform (TIGRR) moaning about GDPR:

GDPR states that data should be "collected for specified, explicit and legitimate purposes" and be "adequate, relevant and limited to what is necessary." The report moaned that this limited "AI organisations from collecting new data before they understand its potential value and they also mean that existing data cannot be reused for novel purposes."

Yes. That is indeed the point. I would use the closing phrase of a certain youtube botany channel, but this would be a bit too blue to leave the comment in place. But I mean it.

Let's just hire every person in Europe to be a bureaucrat

vichardy

The European bureaucracy just seems to know no bounds when it comes to regulations. Maybe this is worthwhile, maybe not but its another reason why the business climate across the pond is subdued compared to the US. Way to many regulations and regulators.

Re: Let's just hire every person in Europe to be a bureaucrat

Irongut

Because we'd all be better off as company slaves working for less than a living wage, with no paid time off, little to no maternity / paternity leave and strapped down by Zuck every night so Palantir can probe us for data. Fuck yeah!

Re: Let's just hire every person in Europe to be a bureaucrat

Anonymous Coward

No, the solution is we all work for Palantir and probe each other

Re: Let's just hire every person in Europe to be a bureaucrat

Filippo

Somehow, I have the feeling that when you write "maybe this is worthwhile", you are not really meaning it.

"why the business climate across the pond is subdued"

LDS

Probably there's more manufacturing in EU that in US where everything was sent abroad because it was cheaper to make. Even handling bank transactions. While many EU products are regarded far higher then their US counterparts.

Sure, looking at the IT sector only the difference is clear. But since the iPhone (built in China..., as well a large part of its inner design, nowadays) that difference has been built mostly on squeezing people to extract as many data as possible to sell ads placements - and little more. Plus all the adverse effects of this "brave new world".

Capitalism without regulations soon becomes a wild west where any rule is broken to advantage the 800 pound gorillas only. Even in US that is being slowly understood.

Well, duh!

big_D

Article 5 of GDPR, which states among other things that data should be "collected for specified, explicit and legitimate purposes" and be "adequate, relevant and limited to what is necessary." The report moaned that this limited "AI organisations from collecting new data before they understand its potential value and they also mean that existing data cannot be reused for novel purposes."

Well, that is basically the point of GDPR, no misuse of the data for things it wasn't originally collected for, and once it has served its purpose, it is to be deleted.

Want to use it for "AI", then spell out exactly what you want and why you want it. And "warehousing the data, because it might become useful someday" is not a valid ground for collecting or storing the data.

b0llchit

That is why I installed [1]Jitsi Meet on a private server when we started to work from home quite some time ago. However, most organizations hopped onto the empty cloud-promise and subsequently have lost all knowledgable personnel for running a private IT infrastructure. Now they are locked into a system that is, one piece by the other, deemed incompatible with the GDPR.

Oh my,... I hear the phrase "I told you so" ringing in so many companies from the techies now... It is embarrassing.

[1] https://jitsi.org/jitsi-meet/

Great Data Purging Revolution

elsergiovolador

Most of these services are non compliant. They harvest data without justification. Running targeted ads on the platform is not a valid reason.

Problem is that nobody dares to prosecute them. Agents prefer to focus on small or medium business, because they have no teeth.

If they were going to pick on a big platform, chances are they would get a job offer or other indecent proposal to drop it.

When billions are at stake, there is nothing these companies cannot do to protect their interests.

Given that GDPR has done nothing for privacy - quite the opposite, I am still of an opinion that this was created to give civil servants an opportunity to get bribes. Corruption is still largely not investigated.

Is a person who blows up banks an econoclast?