EU gives its blessing to reopen data pipelines to the US
- Reference: 1689063611
- News link: https://www.theregister.co.uk/2023/07/11/eu_us_data_pipeline/
- Source link:
The EU-US Data Privacy Framework (DPF) is the third attempt between the trading bloc and the US to iron out privacy kinks in the flow of data about their citizens. This latest agreement marks the EU's determination that "the United States ensures an adequate level of protection – comparable to that of the European Union – for personal data transferred from the EU to US companies under the new framework," the Commission [1]said in a statement.
Key to today's [2]decision [PDF] was an October executive order [3]signed by US President Joe Biden that the Commission said adds new safeguards that address the [4]problems raised with the second attempt at a transatlantic data agreement, Privacy Shield.
[5]
Among the changes singled out by the EC are limits to the [6]access US intelligence agencies have to EU citizen's data "to what is necessary and proportionate," as well as the [7]establishment of a new Data Protection Review Court (DPRC) in the US to which EU citizens would have access.
[8]
[9]
"Today we take an important step to provide trust to citizens that their data is safe, to deepen our economic ties between the EU and the US, and at the same time to reaffirm our shared values," said von der Leyen.
Third time's the charm?
Disagreement with the DPF in the wake of Biden's executive order last year has been nearly constant from EU representatives.
Privacy advocates said the DPF was [10]unlikely to survive a court challenge shortly after the EU released its draft adequacy statement in December. Not long after, the European Parliament's civil liberties commission [11]urged the EC not to sign the adequacy agreement because it didn't properly deal with Privacy Shield concerns.
[12]US vendor accused of violating GDPR by reputation-scoring EU citizens
[13]UK's proposed alt.GDPR will turn Britain into a 'test lab' for data harvesting
[14]First pushback against EU's Digital Services Act and it's not Google
[15]Euro Parliament green lights its AI safety, privacy law
In May, EU parliamentarians passed a resolution urging the EC to delay its adequacy decision because the Framework wasn't "future-proof," a position which was agreed to by a whopping 306 to 27 margin.
"They say the definition of insanity is doing the same thing over and over again and expecting a different result. Just like 'Privacy Shield', the latest agreement is not based on material changes, but on short-term ones political thinking," said Austrian lawyer and privacy activist Max Schrems of EU privacy advocacy group None of Your Business (noyb).
Privacy Shield, and the [16]Safe Harbor rule it replaced, were both struck down due to legal challenges filed by Schrems. According to his group noyb, the long-awaited [17]Schrems III case "will again end up before the European Court of Justice (ECJ) in a few months."
[18]
Schrems and noyb called out several issues in the DPF that they said make it "largely a copy of the failed 'Privacy Shield' agreement."
The data privacy court, it said, will do little to address privacy violations and is given the same latitude to issue [19]non-answers as the Privacy Shield ombudsman, which it replaces. Schrems also has concerns about the use of the word "proportionate" in regard to US intelligence's access to EU citizen data, an [20]issue that was raised as far back as October when Biden and von der Leyen agreed to the DPF's terms.
"The USA will give the word "proportional" a different meaning than the ECJ," noyb asserts, citing the fact that Biden's EO declares mass surveillance under FISA's [21]Section 702 - which permits targeted, warrantless surveillance of non-US citizens - to be proportionate.
[22]
Section 702 of the FISA Amendments Act is also cited as a major reason why the DPF is inadequate, and while its [23]renewal isn't a sure thing, noyb points out it'll remain in effect until at least the end of 2023. With DPF adequacy granted, "the EU has lost all leverage to seek [section 702] reform," Schrems said.
"There is consensus that FISA 702 violates fundamental rights … but the US continues to insist that foreign nationals in the US cannot [invoke] constitutional rights - therefore, from this point of view, violation of their right to privacy is not a problem," the group added.
"Various procedural options" for a new legal challenge have already been planned by noyb, which expects to bring one of its challenges to the ECJ once companies start making use of the DPF in the next few months. Noyb said it's "not unlikely" that a challenge is filed by the end of 2023 or in early 2024, giving the ECJ an opportunity to suspend the DPF until proceedings are closed, likely next year or in 2025.
"Just announcing that something is 'new', 'robust' or 'effective' does not cut it before the Court of Justice. We would need changes in US surveillance law to make this work - and we simply don't have it," Schrems said. ®
Get our [24]Tech Resources
[1] https://ec.europa.eu/commission/presscorner/detail/en/ip_23_3721
[2] https://commission.europa.eu/system/files/2023-07/Adequacy%20decision%20EU-US%20Data%20Privacy%20Framework.pdf
[3] https://www.theregister.com/2022/10/08/in_brief_security/
[4] https://www.theregister.com/2021/06/21/final_guidance_on_schrems_ii/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZK0oQxJCarbLiPg-ukvYwQAAAgw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://www.intel.gov/ic-on-the-record-database/results/oversight/1278-odni-releases-ic-procedures-implementing-new-safeguards-in-executive-order-14086
[7] https://www.justice.gov/opcl/executive-order-14086
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZK0oQxJCarbLiPg-ukvYwQAAAgw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZK0oQxJCarbLiPg-ukvYwQAAAgw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/12/14/eu_us_data_sharing_agreement/
[11] https://www.theregister.com/2023/02/17/adequacy_decision_us_data_transfer/
[12] https://www.theregister.com/2023/06/23/telesign_gdpr_complaint/
[13] https://www.theregister.com/2023/07/06/uk_data_protection_bill/
[14] https://www.theregister.com/2023/06/27/zalando_vlop_lawsuit/
[15] https://www.theregister.com/2023/06/15/european_parliament_ai_act/
[16] https://www.theregister.com/2016/02/02/safe_harbor_replaced_with_privacy_shield/
[17] https://www.theregister.com/Tag/Schrems%20I%20and%20Schrems%20II/
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZK0oQxJCarbLiPg-ukvYwQAAAgw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[19] https://www.federalregister.gov/documents/2022/10/14/2022-22531/enhancing-safeguards-for-united-states-signals-intelligence-activities#p-107
[20] https://www.theregister.com/2022/10/10/privacy_shield/
[21] https://www.theregister.com/2023/06/09/fbi_fisa_section_702_absolutely/
[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZK0oQxJCarbLiPg-ukvYwQAAAgw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[23] https://www.theregister.com/2023/06/14/us_section_702/
[24] https://whitepapers.theregister.com/
Re: As the pot of petunias once said ...
Indeed, just like a whale getting to terms with the situation before dying a splashing death because ground was not inclined to be friends with it.
Be thankful for Max Schrems
But I live in England and so will likely soon lose protection under the GDPR as our government seem set to [1]water down protection .
[1] https://www.openrightsgroup.org/campaign/stop-data-discrimination/
"limits to the access US intelligence agencies have to EU citizen's data"
So, pigs are flying now ?
I have absolutely no confidence that the NSA is not going to get its grubby hands on all that delicious data. The only way to limit the USA's access to EU citizens data is to not send it over in the first place.
But hey, diplomats will be diplomats.
So now, when if ever we find out that the USA has not kept its word, what's Plan B ?
As the pot of petunias once said ...
... "oh no, here we go again"