News: 1653573606

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Campaigners warn of legal challenge against Privacy Shield enhancements

(2022/05/26)


European privacy campaigner Max Schrems is warning that enhancements to the EU-US Privacy Shield data-sharing arrangements might face a legal challenge if negotiators don't take a new approach.

In an [1]open letter , Schrems – the lawyer behind the Schrems II ruling which put an end to the transatlantic data-sharing agreement – said that US assurances of EU citizens' data privacy would be insufficient to avoid another legal challenge.

"We understand that the US has rejected any material protections for non-US persons and is continuing to discriminate against non-US persons by refusing baseline protections, such as judicial approval of individual surveillance measures," the lawyer wrote.

[2]

"We understand that the envisioned deal will largely rely on US executive orders. Having worked on this matter with US surveillance experts and lawyers, such executive orders seem to be structurally insufficient to meet the requirements of the CJEU."

[3]

[4]

In 2020, the European Court of Justice [5]struck down the so-called Privacy Shield after Schrems successfully argued it gave US government agencies access to EU citizens' personal data without commensurate protection.

Since then, companies have been forced to fall back on standard contractual clauses, or SCCs, to cover international data sharing between the EU and US. As well as being time-consuming to implement, [6]SCCs may not be watertight .

[7]

In March, the [8]US and EU announced they had reached an agreement to enhance the Privacy Shield data-sharing arrangement in a way that would "enable predictable and trustworthy data flows between the EU and US, safeguarding privacy and civil liberties," according to European Commission president Ursula von der Leyen.

What is Schrems I?

In the first case, arising from a [9]complaint filed with the Irish Data Protection Commissioner in 2011 , privacy activist Max Schrems ultimately toppled the biggest EU-US data-sharing deal, Safe Harbor. [10]Schrems had alleged that Facebook violated the so-called Safe Harbor agreement which protects EU citizens' privacy, by transferring its users' data to the US National Security Agency (NSA).

In the Schrems I ruling, in 2015, Europe’s highest court ruled that data sharing between the EU and US under the Safe Harbor framework was invalid.

What is Schrems II?

Schrems, a former law student, brought the latest edition of the long-running case (informally known as Schrems II) in 2015, [11]complaining that Ireland's data protection agency still wasn't preventing Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from beaming his data to the US under Privacy Shield.

In July 2020, [12]the EU Court of Justice struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.

However, in the open letter, Schrems said the proposed data sharing policy did not offer sufficient controls over US agencies' access to EU citizen data.

[13]Lawyers say changes to UK data law will make life harder for international businesses

[14]Europe's GDPR coincides with dramatic drop in Android apps

[15]Google chases sovereignty market with EU Workspace Data product

[16]EU, US agree on Privacy Shield enhancements

Schrems said the view was based on "preliminary observations" of the political statements, rather than the final text which is still being negotiated. However, he warned that unless the concerns of his campaign group noyb (none of your business) were addressed, the EU could look forward to another legal challenge.

"We call on the negotiators to continue working for a long-standing, privacy preserving solution for transatlantic flows to avoid a 'Schrems III' decision," he said.

Privacy consultant Bill Mew, founder and owner of Mew Era Consulting, said executive orders had been used by US president Donald Trump to revoke protections in the country's Privacy Act for information held by the state on non-US citizens, part of the basis in law that undermined Privacy Shield. However, a subsequent president could reverse executive orders.

The track record on executive orders had a bearing on the trust between the two parties as they negotiated the final text of an agreement. It would require "a level of commitment and trust on both sides," Mew said.

[17]

He added: "Introducing any judicial process would need to be applied in law – you could not do this with an executive order. Unfortunately there is complete gridlock in Congress and it has proven impossible to introduce any federal privacy law. Adding the need for additional measures to keep the EU happy would make any such legislation even more difficult to pass." ®

Get our [18]Tech Resources



[1] https://noyb.eu/en/open-letter-future-eu-us-data-transfers

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yo@kHS0tJjimOozgq9gVjQAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yo@kHS0tJjimOozgq9gVjQAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yo@kHS0tJjimOozgq9gVjQAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[6] https://www.theregister.com/2021/11/01/data_transfers_europe/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yo@kHS0tJjimOozgq9gVjQAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/03/25/eu_us_privacy_shield_agreement/

[9] https://www.theregister.com/2011/10/19/europe_v_facebook_irish_investigation/

[10] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/

[11] https://curia.europa.eu/juris/document/document.jsf?text=&docid=228677&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=12312155

[12] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[13] https://www.theregister.com/2022/05/16/brexit_data_law/

[14] https://www.theregister.com/2022/05/09/gdpr_europe_apps/

[15] https://www.theregister.com/2022/05/05/google_eu_sovereign/

[16] https://www.theregister.com/2022/03/25/eu_us_privacy_shield_agreement/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yo@kHS0tJjimOozgq9gVjQAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://whitepapers.theregister.com/



Colour me confused

Anonymous Coward

for all this noise, what has *actually* changed for the little man ? Brexit notwithstanding, I can't say I noticed anything apart from news stories about this up till 2020. No one from Google (for example) contacted me to explain what was going on.

It's probably going to take a lot more dynamite to shift my cynicism (especially in the UK) that "Data Protection" laws aren't worth a hill of beans. Or to translate that into realspeak, when was the last time anyone you know received a single penny for their data being illegally used ?

No ?

Point proved.

Re: Colour me confused

Tom Chiverton 1

I'll settle for them stopping selling me behind my back :)

Re: Colour me confused

Anonymous Coward

"It's probably going to take a lot more dynamite to shift my cynicism (especially in the UK) that "Data Protection" laws aren't worth a hill of beans."

Its worse than that in the UK - the ICO this week informed me they will not look into or take any action regarding possible unlawful activity that occurred under the previous Data Protection law (i.e. before 23/05/2018 when GDPR came into force), they say they have no legal means to do so.

Great news for organisations who were breaking the law prior to then - ICO is giving them all a "get out of jail free" card.

However this also has additional implications - in my particular case my personal data stored *currently* by the organisation in question was obtained prior to 23/05/2018 and so ICO are basically saying that they cannot determine the lawfullness of the organisation's storage of my personal data since 23/05/2018 as the ICO cannot/will not look into the lawfullness of the organisation actions when they originally obtaining my personal data in the 1st place many years ago.

'Our' politicians vs Schrems

VoiceOfTruth

They probably regard him as a nuisance. They so badly want to do what Uncle Sam tells them.

Military intelligence is a contradiction in terms.
-- Groucho Marx