EU lawmakers advise against signing US data pact
- Reference: 1676626207
- News link: https://www.theregister.co.uk/2023/02/17/adequacy_decision_us_data_transfer/
- Source link:
It almost goes without saying that the current operation of the technology sector in Europe would not work without US tech companies' services – so data transfers to these American corporations cannot practicably be avoided. However, European rules around privacy, data collection, and data subjects' rights are considerably stronger than those in America, hence the need for rules of engagement that make US companies' treatment of EU data as good as what they'd get at home.
The DPF was announced in March last year and is meant to address concerns raised by the EU's Court of Justice in [1]Schrems II , a 2020 case that struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US.
[2]
EU president Ursula von der Leyen and US president Joe Biden said they'd reached an agreement in principle on the framework for transatlantic data flows at the time, with Biden signing an executive order (EO) on the matter in October last year.
[3]
[4]
But the European Parliament's Committee on Civil Liberties, Justice and Home Affairs (LIBE) is still not happy with what it sees, and has put out a nonbinding [5]draft opinion [PDF] on how adequate it thinks the protection given by the proposed cross-border data rules is. In short: it ain't.
According to the motion filed this week, the latest Data Privacy Framework still falls far short of the General Data Protection Regulation standard EU residents could expect from companies that are regulated within the bloc. The Committee says that "unless meaningful reforms were introduced," the Commish shouldn't proceed. Tech lawyer Neil Brown of decoded.legal told The Register that "In other words... no amount of paperwork will overcome what they perceive to be aspects of US law which they consider to be incompatible with the EU GDPR."
What about standard contractual clauses?
According to the [6]European Commission, model clauses are currently the most used data transfer mechanism, with the Commish adopting modernized standard contractual clauses, or SCCs, to facilitate their use, "in light of the requirements set by the Court of justice in the Schrems II judgment."
Since [7]Privacy Shield was struck down, companies have been forced to fall back on SCCs to cover themselves when sharing data between the EU and US. As well as being time-consuming to implement, [8]SCCs may not be watertight .
Legal eagle Neil Brown said that while businesses can opt to use these, "when one uses the SCCs for transfers to the USA (or elsewhere), one is still required to undertake a transfer risk assessment. Doing them properly is complicated and expensive.
"And some will argue that there is simply nothing which one can do, if personal data need to be accessed from or transferred to the USA, to protect those personal data from the risks identified in Schrems II, such that any transfer risk assessment is either doomed to fail or, if it 'passes', must be incorrect."
He added that conversely, "where a transfer is based on an adequacy decision, there is no need for a transfer risk assessment – the destination is adequate, from an EU data protection perspective – and so the transfer is simpler and cheaper."
LIBE said the rejigged rules did not have the robust government surveillance safeguards and consumer redress mechanisms that it would expect in order "to create actual equivalence in the level of protection" provided to EU residents' transferred data.
Among other issues, it pointed to:
the fact that [US President Biden's] EO does not prohibit the bulk collection of data by signals intelligence, including the content of communications; and
notes that the list of legitimate national security objectives can be expanded by the US President, who can determine not to make the relevant updates public;
The committee also pointed out that "unlike all other third countries that have received an adequacy decision under the GDPR, the US still does not have a federal data protection law." That matters when principles around any "limits" imposed on US SigInt work "will be interpreted solely in the light of US law and legal traditions," it said.
The DPF has provided for a several redress mechanisms. Among other things, Europeans can lodge grievances with the Data Protection Review Court (DPRC) if they believe their personal data was collected in violation of applicable US law.
[9]US executive order a long way from settling EU privacy cases
[10]Open Source Policy Summit: Where FOSS and government meet
[11]Microsoft is changing how it handles device diagnostic data to keep EU sweet
[12]Microsoft is changing how it handles device diagnostic data to keep EU sweet
However, the committee found, the "redress process provided by the EO is based on secrecy and does not set up an obligation to notify the complainant that their personal data has been processed, thereby undermining their right to access or rectify their data."
It also found the DPRC didn't meet the standards of impartiality or independence under the EU's Fundamental Rights charter as the "complainant will be represented by a 'special advocate' designated by the DPRC, for whom there is no requirement of independence" and also that there was route for federal appeal for the data subject.
[13]
If it passes all the European Union hurdles, an adequacy decision for the DPF could be expected around July 2023. Once it is adopted, European businesses will be able to transfer personal data to "participating companies in the United States, without having to put in place additional data protection safeguards."
But is that going to happen? Brown told The Register : "My feeling ... is that there would be scepticism of any US-issued edict, which failed to prohibit bulk collection (and such a prohibition seems highly unlikely), or which permits secret interpretations / expansions of the law." ®
Get our [14]Tech Resources
[1] https://www.theregister.com/Tag/Schrems%20I%20and%20Schrems%20II
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y@9eVHdL8EuGOOy0ytlULAAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@9eVHdL8EuGOOy0ytlULAAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y@9eVHdL8EuGOOy0ytlULAAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.europarl.europa.eu/doceo/document/LIBE-RD-740749_EN.pdf
[6] https://ec.europa.eu/commission/presscorner/detail/en/qanda_22_7632
[7] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[8] https://www.theregister.com/2021/11/01/data_transfers_europe/
[9] https://www.theregister.com/2022/10/10/privacy_shield/
[10] https://www.theregister.com/2023/02/09/open_source_policy_summit/
[11] https://www.theregister.com/2023/02/06/microsoft_eu_data_gdpr/
[12] https://www.theregister.com/2023/02/06/microsoft_eu_data_gdpr/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@9eVHdL8EuGOOy0ytlULAAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
May the EU politicians sign this....
... then expect Schrems III coming soon.
Re: May the EU politicians sign this....
...and the politicians again being told by the EUCJ that they failed the mark.
Thank you.
""My feeling ... is that there would be scepticism of any US-issued edict,"
Yes!
How refreshing, a quote from a British source, given the respect it deserves and spelled correctly.
I know that I keep banging on about this but the change to "International English" aka American English has really put me off the site and judging by other comments it has put off a lot of others as well.
Plus 1, that wasn't so hard, now was it?
Just quit playing games, the U.S isn't going to change it's laws for the GDPR. Just say no data transfers and take the inevitable retaliation.
A harsh reality
Neither standard contractual clauses nor an adequacy decision can actually prevent abuses of personal data by organisations, and adequacy decisions (being a blanket assumptions at national level) exacerbate the problem by completely disregarding the behaviours of individual organisations.
Given the general very low standard of enforcement and the financial clout of many infracting organisations, we have an intractable problem in protecting the rights of data subjects. The only solution is a much more effective approach to enforcement -- one that is proactive rather than solely reactive and that auditably enforces change of behaviour rather than merely imposing financial penalties that, for most organisations, constitute little more than a cost of doing business.
My investigations of non-compliance since the GDPR came into force strongly suggest a very high incidence of intentional non-compliance with the intent of the legislation, partially masked by steering close to the minimal letter of the law and reliant on crafted lack of transparency that prevents data subjects challenging malpractice. This is assisted (at least in the UK) by an obvious unwillingness on the part of the regulator to pursue individual complaints.