EU, US close to replacing defunct Privacy Shield II
- Reference: 1646239209
- News link: https://www.theregister.co.uk/2022/03/02/new_hope_for_privacy_shield/
- Source link:
The earlier legal arrangements to ease the vital sharing data between the two jurisdictions was kiboshed in 2020 when the [1]EU Court of Justice struck down Privacy Shield in what became known as the Schrems II ruling.
What is Schrems I?
In the first case, arising from a complaint filed with the [2]Irish Data Protection Commissioner in 2011 , privacy activist Max Schrems ultimately toppled the biggest EU-US data-sharing deal, Safe Harbor. Schrems had alleged that Facebook violated the so-called Safe Harbor agreement which protects EU citizens' privacy, by transferring its users' data to the US National Security Agency (NSA).
In the [3]Schrems I ruling , in 2015, Europe’s highest court ruled that data sharing between the EU and US under the Safe Harbor framework was invalid.
What is Schrems II?
Schrems, a former law student, brought the latest edition of the long-running case (informally known as Schrems II) in 2015, [4]complaining that Ireland's data protection agency still wasn't preventing Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from beaming his data to the US under Privacy Shield.
In July 2020, the [5]EU Court of Justice struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.
Earlier this week, reports from the State of the Net conference suggested progress is indeed being made on agreeing on a replacement.
"We definitely recognize that there has been a lot of instability in data transfers and that companies are operating in an environment of uncertainty right now," US Department of Commerce Privacy Shield Director Alex Greenstein told the conference.
"We and our partners in Europe are trying to conclude this negotiation as quickly as possible. We recognize this is having an impact on US companies but also EU companies."
[6]
According to legal [7]website Law360 , he said his team and EU officials were tackling ambiguity around international information exchanges as quickly as possible.
[8]
[9]
In the absence of a replacement for Privacy Shield, companies have been forced to fall back on standard contractual clauses, or SCCs, to cover international data sharing between the EU and the US. As well as being time consuming to implement, [10]SCCs may not be watertight .
In January, a ruling by the [11]Austrian data protection authority found that SCCs are not sufficient to comply with EU law and that so-called technical and organisational measures (TOMs), such as data centre security and baseline encryption, are also insufficient.
[12]
The complainant in the case, legal campaign group noyb, had visited the website of a publisher while logged into a Google account, which was linked to the complainant's email address. The site contained embedded HTML code for Google services, including Google Analytics. The website processed personal data such as IP address and cookie data. The data had been transferred to Google, putting it under the purview of the European General Data Protection Regulation (GDPR).
That case was followed by a [13]similar ruling in France .
Accordingb to Sean Heather, senior vice president of regulatory affairs for the US Chamber of Commerce, a data transfer pact will be agreed soon and that tyhe conflict in Ukraine would accelerate it.
[14]
"I do think this has put a renewed emphasis on the importance of transatlantic talks. I'm not in the negotiating room. I'm not at the table, but I feel like we have a chance to see something maybe mid-spring, late spring, early summer. That would be the window that I'm watching right now," Heather commented.
In February, [15]reports suggested officials on both sides of the pond had reached an approach that might involve offering EU citizens the right to submit complaints to an independent judicial body if they believe the US national security agencies have unlawfully handled their personal information. If adopted, it would give EU citizens more privacy rights in the US than Americans currently enjoy.
Reports: ICO says Belgian counterparts ruling on consent preferences means nothing in UK
The UK's Information Commissioner's Office has reportedly said that a decision handed down by the Belgian data protection authority governing the use of preference data in online advertising has no bearing in the UK.
According to a [16]decision handed down by the Belgian data protection authority all data collected "so far" through the Transparency & Consent Framework (TCF) by means of a TC String – part of its consent popup system – must now be deleted by international digital marketing and advertising association IAB Europe.
Over 1,000 firms pay IAB Europe to use TCF. This includes Google's, Amazon's and Microsoft's online advertising businesses.
The decision found the "consent solution" failed to properly request consent, and relies on a lawful basis (legitimate interest) that is not permissible because of the severe risk posed by online advertising tracking under Article 5(1)a, and Article 6 of the GDPR.
The TC String is a coded character string storing information about consent in the context of the realtime bidding (RTB) system OpenRTB.
But [17]a privacy consultancy has said it received a response from the ICO saying that the Belgian decision has no implications on businesses relying on the framework in the UK. The decision only impacted businesses in Belgium, it said.
"As the UK is no longer part of the EU, if the European Data Protection Board and/or other data protection supervisory authority follows the Belgian DPA's decision, this potential development in law at EU level will not have an impact on the UK until appropriate guidance has been issued by the ICO."
The ICO respondent then refused to comment on the lawfulness of mechanisms such as the TCF, simply saying that if it was compliant with UK General Data Protection Regulation (as transposed into UK law before its departure from the EU) and [18]Privacy and Electronic Communications Regulations , then businesses can carry on using it.
The Register has asked the ICO to comment.
[19]EU proposes law forcing manufacturers to share data
[20]EU Data Protection Board probes public sector use of cloud
[21]France says Google Analytics breaches GDPR when it sends data to US
[22]Privacy Shield: EU citizens might get right to challenge US access to their data
The UK currently enjoys an "adequacy" ruling from the EU allowing data sharing between the UK and the trading bloc as long as UK law is in line with relevant EU data law. That ruling can be revisited at any time.
Neil Brown, veteran tech lawyer and boss of decoded.legal, commented: "This will be the third instance of a framework for transfers of personal data from the EU to the USA. Whether it will be as good as the third Back to the Future film, or as bad as the third Matrix film, I've no idea.
"It is hard to see how an agreement alone would survive challenge in the EU, without changes to the USA's laws on surveillance." ®
Get our [23]Tech Resources
[1] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[2] https://www.theregister.com/2011/10/19/europe_v_facebook_irish_investigation/
[3] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/
[4] https://curia.europa.eu/juris/document/document.jsf?text=&docid=228677&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=12312155
[5] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yh@itYNXq9LhBBaBx4w@UQAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://www.law360.com/technology/articles/1468909/us-eu-privacy-shield-talks-inching-closer-to-a-deal
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yh@itYNXq9LhBBaBx4w@UQAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yh@itYNXq9LhBBaBx4w@UQAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2021/11/01/data_transfers_europe/
[11] https://www.theregister.com/2022/01/13/google_analytics_gdpr/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yh@itYNXq9LhBBaBx4w@UQAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2022/02/10/google_analytics_gdpr_breach/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yh@itYNXq9LhBBaBx4w@UQAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://www.theregister.com/2022/02/03/privacy_shield_progress/
[16] https://www.theregister.com/2022/02/02/europe_iab_decision/
[17] https://twitter.com/PrivacyMatters/status/1498642741210882048
[18] https://ico.org.uk/for-organisations/guide-to-pecr/what-are-pecr/
[19] https://www.theregister.com/2022/02/24/eu_proposes_data_law_forcing/
[20] https://www.theregister.com/2022/02/15/edpb_cloud/
[21] https://www.theregister.com/2022/02/10/google_analytics_gdpr_breach/
[22] https://www.theregister.com/2022/02/03/privacy_shield_progress/
[23] https://whitepapers.theregister.com/
"It is hard to see how an agreement alone would survive challenge in the EU, without changes to the USA's laws on surveillance."
And hence we'll be on-track for Schrems III, IV, V etc. because they'll just keep coming up with "new" schemes to kick compliance further down the road.