Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Saturday, 20 August 2016

Which data protection and consumer law applies to Amazon? Comments on the VKI v Amazon judgment



Lorna Woods, Professor of Internet Law, University of Essex

The recent CJEU judgment in VKI v Amazon concerns jurisdiction both in the context of conflict of laws (applicable consumer laws) and the Data Protection Directive.  Essentially, the Court of Justice had to decide which Member State’s data protection law should apply where goods are sold across national borders but within the EU. In this, it forms part of a stream of case law (both decided and pending), dealing with the powers of states (and their institutions) to protect those within their boundaries notwithstanding the digital internal market.

Facts

The case concerned Amazon, a well-known large company engaged in on-line selling. It has a branch established in Luxembourg.  It has a domain name ending ‘.de’ and there is a German language page.  It concludes sales with customers in Austria. The company has no registered address in Austria.  Whenever a customer buys goods via Amazon the transaction is governed by Amazon’s unilaterally imposed standard terms and conditions. One term in the agreement is that the law applicable to the contract is that of Luxembourg. 

A consumer protection body in Austria (VKI) sought to challenge this: Austrian law provides higher protection for the consumer than the equivalent Luxembourgish law and it sought to injunct Amazon on the basis of Directive 2009/22/EC on injunctions for the protection of consumers’ interests through an action brought before the Austrian courts. Amazon countered that it has no legal connection with Austria – it is not established there.  While there were questions regarding the applicable law and the fairness of the jurisdiction clause in the contract in the light of the Unfair Contract Terms Directive, there was another issue concerning data protection. There were clauses in Amazon’s standard terms and conditions which indicated that data might be exchanged with credit-risk assessment and financial services companies in Germany and Switzerland.  Again VKI argued that Austrian data protection rules should apply.

Questions Referred

While on the face of it, the matter might seem to be one of contract law therefore governed by the Rome I Regulation on the law applicable to contractual obligations, the form of relief sought – the injunction – might seem to bring the question within the Rome II Regulation, which regulates the law applicable to non-contractual obligations – a fact which might affect the outcome in the case.  The national court asked whether an action for an injunction fell within Rome II and if so, where the damage might said to have taken place so as determine jurisdiction.  Irrespective of the outcome to that question, the referring court also asked about the impact of the Unfair Contract Terms Directive on the jurisdiction clause. It likewise also wanted to know whether the processing of data should be regulated by Luxembourg alone, or must the processor ‘also comply with the data protection rules of those Member States to which its commercial activities are directed?’

Judgment

The ECJ dealt with the questions on Rome I and II together.  It noted that they should be interpreted consistently with one another, as well as the Brussels I Regulation (which concerns the separate question of which country’s court has jurisdiction in cross-border cases).  The Court referred to its previous case law in relation to the previous Brussels Convention, and the Brussels I Regulation replacing the Convention, to conclude that an action for injunction within the terms of Directive 2009/22/EC (on the protection of consumers’ interests) falls within the meaning of a non-contractual obligation for the purposes of Rome II.  Article 6 of the Rome II Regulation deals with unfair competition.  In that circumstance, the law applicable is that ‘of the country where competitive relations or the collective interests of consumers are, or are likely to be, affected’.  The Court followed the Advocate General (Opinion, para 73) to hold that Article 6(1) covers the use of unfair terms inserted in standard terms and conditions, as ‘this is likely to affect the collective interests of consumers as a group and hence to influence the conditions of competition on the market’ (para 42). Here the relevant country is that where the consumers to whom the undertaking directs its activities reside and who are protected by the relevant consumer protection body (para 43).

Article 4(3) of the Rome II Regulation states that the law of another country applies if it is clear that the tort is manifestly more closely connected with it.  The ECJ approved the approach of the Advocate General (para 77) where he advised that Article 4(3) is not well suited to unfair competition. Article 6 is aimed at protecting collective interests and cannot be displaced by individual agreement (para 45).  Allowing the term of a contract to constitute ‘closer connection’ for the purposes of Article 4(3) would mean that such parties would be able to avoid the conditions for ‘freedom of choice’ set down in Article 14 Rome II.

The question of which law applies to the assessment of the unfairness of the contractual terms, however, falls under Rome I, whether or not it applies to a collective or individual action.

The Court then considered the Unfair Contract Terms Directive (Directive 93/13). That Directive contains the principle that a contractual term which has not been individually negotiated – that is, drafted in advance by the seller/supplier - must be regarded as unfair if it causes a significant imbalance to the detriment of the consumer. The Court agreed with the Advocate General (Opinion para 84) that the terms in issue here fell within that definition (para 63). The question of unfairness is to be determined on the facts by the national court within the scope of criteria determined by the Court of Justice. Since choice of law clauses are in principle permissible, such clauses are only unfair if its wording or context creates an imbalance – so if it is not drafted in intelligible language or if it seeks to deprive consumers of protections from which it would not be possible to derogate.  Here, this means that in relation to an Austrian consumer, the national court will ‘have to apply those Austrian statutory provisions which, under Austrian law, cannot be derogated from by agreement’ (para 70).

The Court then turned to Article 4 of the Data Protection Directive. Under Article 4, each Member State regulates processing carried out in the context of activities of an establishment in that Member State. Essentially the question is whether Amazon was established in Austria. The Court referred to its recent Weltimmo judgment, discussed here, which ruled that an undertaking does not need to have a branch or establishment.  Rather, it is a question of the stability of the arrangement and the effective exercise of activities (para 77) that is important.  Further, Article 4 does not require that the processing is carried out by the undertaking itself; the test is whether processing is carried out in the context of its activities (para 78).  This is a question of fact for the national court.

Comment

In terms of the importance of this judgment, we should note that the facts in issue are not uncommon – many on-line businesses have headquarters in one Member State but conclude contracts across multiple Member States. 

As regards the questions relating to applicable laws generally, we are now in a situation where national courts may have to assess questions pertaining to injunctions according to a different law from that relating to the contract itself.  This is not surprising, given case law in other fields, but it is the first confirmation of this point in the e-commerce context.  As an aside, it is also the first judgment on the Directive on injunctions for the protection of consumers’ interests.  It is worth noting that the Court seemed critical of attempts to bypass the protection in Article of 6 Rome II through the notion of ‘manifestly closer connection’ in Article 4(3).  It also specifically excluded the choice of law clause in the agreement as a determining factor in this regard too.

Perhaps the most interesting aspect is, however, the data protection aspect.  The Court did not go into much detail (perhaps signalling behind the scenes disagreement) and there are some curious silences as to some points touched upon by the Advocate General.  The Advocate General had in fact suggested that Article 4 had a ‘dual role’ (Opinion para 110).  So while Weltimmo might apply to determine applicable law, the broad approach to ‘establishment’ found in GoogleSpain to determine the outer territorial limit of the Data Protection Directive did not apply to the intra-EU setting.  The driver for the decision in GoogleSpain was a desire to ensure that the Data Protection Directive applied at all; it was therefore relevant to external processors (Opinion, para 124).  In this case, if the Austrian laws did not apply then the laws of one of the other Member States would and so the extensive approach would not be necessary.  This distinction was an innovation on the part of the Advocate General; it was certainly not visible in Weltimmo in which the Court relied on its reasoning in GoogleSpain, and nor was it apparent from GoogleSpain.  Further, the Advocate General seemed to be more stringent about finding ‘establishment’ than the Court in Weltimmo.  For example, the fact that Amazon may provide an aftersales service in Austria on its own was insufficient in his view (Opinion, paras 121 and 125); he also discounted the possibility that the accessibility of a website was likewise insufficient for this purpose (Opinion, paras 117 and 120). 

Against this background, the silence of the ECJ on the internal/external point is striking, especially given the repeated references to the Opinion through the rest of its judgment.  So is its silence on the subject of GoogleSpain. The Court’s reasoning is grounded only on Weltimmo.  On the one hand, we could argue that the Court has not agreed with the distinction put forward by the Advocate General, but by not applying GoogleSpain directly here, it has not ruled it out either. Note that the Article 29 Working Party (the advisory body set up by the data protection Directive) had applied the extensive interpretation from GoogleSpain in its updated Opinion 8/2010. The Court here also gave no further guidance on the topic of establishment, taking convenient refuge no doubt in the point that its role is to interpret EU law and not to assess facts.


Photo credit: www.creativeintent.co.uk 

Thursday, 2 April 2015

Vidal-Hall v Google: Strengthening EU law remedies


 

Steve Peers

There are many laws which exist on paper, but cannot easily be enforced practically. One example is data protection law, which relies largely for its enforcement on overworked data protection authorities. Individual ‘data subjects’ whose data protection rights have been infringed can sue the infringing companies directly, but they face a number of barriers in this respect.

In particular, if they have not suffered any direct economic loss, can they sue for non-economic loss? If not, there is probably little point in bringing legal proceedings – and the infringing company faces fewer constraints upon its breach of the law concerned.

Of course, this issue is not unique to data protection law. But this was the subject-matter of the important judgment of the Court of Appeal in Vidal-Hall v Google last week, which relied upon the EU Charter of Rights to strike down UK legislation which limited the ability to sue for non-economic losses as regards EU data protection law. This ruling could have broad implications not only on the enforcement of data protection rights, but also other rights protected by EU law.

Judgment

The case concerned allegations that Google had infringed the data protection rights of users of Apple’s Safari browser, by getting around protections against tracking which were intended to prevent Google from collecting information on those users’ behaviour online. American litigation on the same issue had foundered due to the inability of plaintiffs to obtain damages for non-economic losses under American law, although Google had reached a settlement with federal and state regulators which entailed payment of a large penalty.

As regards UK/EU law, the Court of Appeal had to address four issues: (a) is there a tort of ‘misuse of private information’; (b) whether it was possible to sue for non-economic damage; (c) whether the information involved was ‘personal data’ for the purposes of data protection law; and (d) whether there was an arguable case in tort and data protection law. The Court decided all four issues in favour of the plaintiffs, but that does not mean they have won the case yet: at this stage, the Court of Appeal was only deciding whether documents could be served on Google in the first place.

Remedies for breach of EU law

This judgment raises many important questions of privacy rights and data protection law, and substantially advances the enforcement of those rights and that law in the UK. There are excellent discussions of these finer points already by Jon Baines, Christopher Knight and Alexander Hanff. My focus here is on the broader importance of this judgment for the enforcement of EU law rights.

The starting point in this case is the EU’s data protection Directive, which provides that any person who has suffered damage due to breach of the Directive can receive compensation from the data controller for that breach. The UK Data Protection Act implements that rule by providing (in s. 13) for separate claims for damages and distress, imposing conditions (a link to damages, or data processing for special purposes) upon any claim for distress. UK courts have interpreted s. 13 of the Act to mean that ‘damages’ can only refer to economic loss, with non-economic loss subject to the more restrictive rules relating to ‘distress’.

However, the Court of Appeal ruled that the rule in the EU Directive had a wider meaning, covering both economic and non-economic loss, basing itself on CJEU case law relating to the EU’s package holidays Directive. It based this argument on its interpretation of the aim of the Directive (protecting privacy rights), read alongside the right to privacy in Article 8 ECHR and the data protection rights in Article 7 of the EU Charter of Fundamental Rights.

But what were the consequences of this finding? First of all, the Court of Appeal rejected the possibility of using the CJEU’s principle of indirect effect, set out in case law since Marleasing, to strike down s. 13(2) of the UK Act.  This is undoubtedly correct: CJEU case law makes clear that the principle of indirect effect is a rule of interpretation, requiring national courts to stretch the interpretation of national law on the books as far as possible to ensure that it implements EU law correctly. That principle reaches its limits when national law cannot be interpreted consistently with EU law, as the Court of Appeal determined in this case.

So the Court of Appeal rightly relied instead on Articles 7 and 8 of the Charter (privacy and data protection rights), applying Article 47 of the Charter (the right to a fair trial and effective remedy) to strike down national law, just as it had recently done in Benkharbouche (discussed here). That case involved a claim for employment law rights against foreign embassies, and the Court struck down the relevant provisions of the State Immunity Act to allow the suit to continue (insofar as the claims were based on EU law). The Court of Appeal did limit the impact of Article 47 of the Charter by confirming that it could not be used to strike down legislation where that would involve the courts rewriting a legislative scheme and making complex choices that should be left to the legislature to make. But that was not the case here.

As in Benkharbouche, this judgment offers confirmation of the significant possibilities of using the Charter in human rights litigation. Unlike the prior judgment, it was not necessary in Vidal-Hall to distinguish between claims linked to EU law (where the Charter applies) and claims not connected to EU law (where the Charter does not apply), because all of the claims in this case are linked to EU law. The crucial relevance of that distinction is that the Charter can be used to disapply Acts of Parliament, whereas the Human Rights Act cannot. (Moreover, any UK court can disapply an act of Parliament conflicting with the Charter, whereas only the higher courts can issue declarations of incompatibility with the Human Rights Act).

It is clear from Vidal-Hall that Article 47 can be used not just to strike down Acts of Parliament that confer immunity upon defendants, but also to strike down rules that limit heads of damage that can be recovered. It follows that many other types of restrictions on remedies could be challenged: other forms of standing rules, time limits and restrictions on legal aid, for instance. It is also clear that the ‘complex legislative scheme’ exception should not be interpreted widely: plaintiffs should target their challenges to Acts of Parliament against very precise and specific limitations in order to ensure that the exception does not apply.

The existence of this exception does mean, however, that it might be significantly more difficult to use Article 47 to ask the courts to create an entirely new remedy for breach of EU law, because the counter-argument would be that the creation of new remedies is a complex issue best left to Parliament. On the other hand, plaintiffs in such cases could also argue that the common law should develop to create new forms of remedy to ensure effective protection of Charter rights, just as tort law relating to privacy rights was clarified in Vidal-Hall.  

It should be noted here that the Vidal-Hall litigation concerns the application of a Directive between private parties. The judgment thus clearly demonstrates the importance of the Charter in overcoming the traditional restriction on applying Directives against private parties, where national law is incompatible with the Directives (ie, the lack of ‘horizontal direct effect’ of Directives). The alternative option of bringing a Francovich damages action against the state for its breach of EU law is not even discussed here. Obviously it will always be simpler and cheaper for the plaintiffs to follow the direct route of disapplying the Act of Parliament in the main litigation, as compared to having to bring an action against the State instead – especially in cases like Vidal-Hall, where the merits of the case have not even been tried yet.

Furthermore, it should be emphasised that the court was applying Article 47 of the Charter to disapply UK law, not Articles 7 and 8 of the Charter, which set out the substantive rights to privacy and data protection. That is an important distinction because according to last year’s CJEU ruling in AMS (discussed here), not all Charter rights can be enforced by setting aside national law. The CJEU has yet to rule on whether Articles 7 and 8 can be enforced by this route (it dodged this bullet in Satamedia), but it will be hard to avoid it forever.

Finally, what other areas of EU law could this judgment be relevant to? A lot of EU law concerns economic damages in any event (cf the case law on private damages for breach of EU competition law). Even consumer law is largely about economic loss, too: the package holiday judgment referred to by the Court of Appeal is an exception, because in the case of holidays, consumers’ distress arises from being unable to spend their money on holiday as they had planned.

There is at least one obvious other area of EU law where this judgment may also be relevant: the free movement of EU citizens. It is possible to claim for economic loss in such cases, for instance where a person has lost his job as a result of breach of EU free movement law (see the discussion of a recent Irish judgment here). However, often the loss is purely personal: the inability to spend time with a spouse and children. There may also be some economic costs (due to the need to travel to visit a family member, or a job which is lost or cannot be applied for due to breaches of free movement law), but the inherent loss of family life is surely highly significant too. Moreover, the root human right being protected in such cases is in part the same right as that being protected in Vidal-Hall: the right to private and family life (Article 7 of the Charter, Article 8 ECHR).  The next UK government should ensure full compliance with the law on ‘Surinder Singh’ cases (as discussed here), if it does not wish to expose taxpayers to considerable liability.

Photo credit: milanox.eu 

Barnard & Peers: chapter 6, chapter 9

Tuesday, 23 September 2014

‘The Right to be Forgotten’: The future EU legislation takes shape




Steve Peers

The furore over the ‘right to be forgotten’ in EU data protection law focusses, obviously enough, on the CJEU’s judgment in Google Spain, which obliquely referred to such a right, by means of interpreting the EU’s existing data protection Directive. But in principle the Court’s ruling might have limited impact, since the EU is embarked upon a lengthy process to replace that Directive.

The initial proposal for a new General Data Protection Regulation was tabled by the Commission at the start of 2012, and the European Parliament (EP) voted its opinion on the proposal this spring. For its part, the Council (Member States’ justice ministers) is moving more slowly. So far, it has only agreed its position on the external relations aspects of this proposal. But following the delivery of the Google Spain judgment this spring, it has turned its attention to the right to be forgotten.

The Council had initially discussed this issue in 2012-13 (see a record of those talks here). It then paused to wait for the Court’s judgment. Following that ruling, the incoming Italian Council Presidency then resumed discussions on the issue in July, and tabled a revised version of its proposal a couple of weeks ago. The Council has not yet agreed on this issue (see the Member States’ positions here), and in any event, once the Council has adopted its position on the entire proposal, it would still have to negotiate with the EP.

However, there seems to be an emerging consensus in the Council. Given the importance of the issue, which has attracted more public interest than any EU law issue in the last few months, it’s worth examining where the discussions are going.

First, of all, it should be recalled that the Council has already agreed that search engines like Google, and possibly many other Internet companies not based in the EU, will be subject to the new Regulation, when it agreed on the external relations rules in the proposal.

As for the ‘right to be forgotten’ itself, it’s in Article 17 of the proposed Regulation. The Commission initially proposed that the data subject could exercise the right (which is combined with the current right of erasure) against the original data controller, on one of four grounds: the data are no longer necessary; the data subject withdraws consent or when the storage period has expired; the data subject objects to the processing on specified grounds; or the processing is no longer valid on some other ground. The data controller had to inform third parties of any request to exercise that right.

In this initial proposal, there would be exemptions from the right on grounds of: freedom of expression; public health; historical, scientific or statistical research; compliance with a national or EU legal obligation; or cases where access to the data was merely restricted.  The Commission would have the power to adopt ‘delegated acts’ to spell out the right in more detail.

In the EP’s view, the right could also be exercised directly against third parties, and there would be a further possibility to exercise the right following an order by a court or regulatory authority (presumably including a data protection authority).

In the Council’s latest text, these grounds for exercising the right (as amended by the EP) are retained. The obligation to inform third parties is also retained, but the Italian Presidency’s explanation of its proposal makes clear that this text is taking on board – rather than rejecting – the Court of Justice’s ruling that Google must itself be considered a ‘controller’ of the personal data, and therefore directly subject to data protection rules.

As for the exceptions to the right, the ‘freedom of expression’ exception remains, fleshed out with the wording of Article 10 ECHR, taking ‘due account of the public interest…in relation to the personal quality of the data subject’. The Presidency’s explanations make clear that this awkward wording is meant to encompass the ‘public figure’ exception hinted at (but not elaborated upon) in the Google Spain judgment.  There would also be new exceptions, as regards ‘archiving purposes in the public interest’, social protection, making or defending legal claims, performing a public interest task or exercising official authority. The Commission power to adopt delegated acts has been dropped.

There’s no longer an exception (as regards the right to be forgotten) for the commercial interests of data controllers such as Google. But that won’t really change the status quo, since the CJEU easily found in Google Spain that Google’s economic interests were overruled by the data subject’s right to privacy.

New clauses in the preamble would reflect the CJEU’s ruling on the ‘public figure’ exception, the possibility of complaint either to the controller or to a data protection authority or the courts, and the role of the controller in applying the balancing test. The preamble would also note that the right to be forgotten has to be balanced against other rights; the wording here is taken from Article 52(1) of the Charter, which sets out a general rule on limitations of Charter rights.

What are we to make of these proposals? First of all, it’s clear that the essential features of the Google Spain judgment seem likely to be codified, not overturned, by the new law. This is assumed in the Presidency’s explanatory notes. Indeed, the Google Spain judgment turned on the Court’s reasoning that it was ‘no longer necessary’ to make available (accurate) data on the data subject’s previous financial troubles, via means of Google. And that very ground for exercising the right to be forgotten would be expressly retained in the new legislation.

The other grounds for exercising that right, as set out in the proposal, were not addressed in the judgment, although the Court would likely have ruled that they existed if it had been asked. Here, it’s important to point out the express power to withdraw consent for data processing. This would clearly cover cases of ‘revenge porn’,  where one sexual partner initially agreed to the images being posted on the Internet but withdrew his or her consent when the relationship broke down. (For cases where there was never any consent to posting such images on the Internet, data protection law would have been violated from the outset).

Moving on to the exceptions from the right, the most controversial aspect is the reconciliation of the right to be forgotten with the freedom of expression. As noted above, the proposal codifies but does not clarify the ‘public figure’ exception. There’s a cross-reference to Article 80 as regards the freedom of expression. This Article (in the Commission’s original proposal) reproduces the current ‘journalist exception’ for the ‘processing of personal data carried out solely for journalistic purposes or the purpose of artistic or literary expression’. While some Member States object that this exception does not apply to bloggers (see the footnotes to the latest text), the CJEU took a broad approach to this exception in the case of Satamedia, regarding a company which sends out text messages about people’s tax information as a journalist. On the other hand, the Court did not regard Google itself as a journalist.

The better view is surely that bloggers and anyone otherwise expressing themselves on social media fall within the scope of the ‘freedom of expression’ exception, even if they are not professional journalists. After all, such persons are still exercising their freedom of expression, and it would be deeply unprincipled, in the modern world, to protect that freedom for one group of people but not others. Moreover, such a distinction would clearly violate Article 10 ECHR, in light of the relevant case law of the European Court of Human Rights.

The CJEU did not consider in Google Spain whether freedom of expression could be relied upon to argue that journalists (and others) need unrestricted Internet access to do their jobs properly. So arguably this is still an open issue that could be raised by a journalist in an appropriate case.

More fundamentally, the latest draft entrenches the CJEU’s position that Google is mainly responsible for processing complaints about privacy, without ensuring that it is accountable. In other areas of law, there are reporting requirements imposed upon companies to ensure that they meet their legal, social and ethical obligations. Since Google will in practice usually be in charge of striking the balance between privacy and freedom of expression, the new legislation should require that it report on how it has balanced these rights, so that there can be a public discussion of the appropriateness of its actions.

Finally, how might the new Regulation (in the current draft) apply to Wikipedia and social networks? As discussed in a previous blog post, obviously Wikipedia could try to rely upon the ‘public figure’ exception. It could also try to rely upon the exceptions for archiving or historical interest, although that depends upon the final wording of other provisions of the Regulation.

Equally, the precise application of the new rules to entities like Facebook depends on the final wording of the ‘household exception’ in the new legislation, as well as the open question of how (if at all) the Google Spain judgment applies to user-generated content, as well as user-controlled privacy settings.

Overall, the latest drafts of the new Regulation on the ‘right to be forgotten’ will disappoint not only the fiercest critics of the Google Spain ruling, who regard any limitation of search engine results on privacy grounds as anathema, but also the more moderate critics (like myself) who believe that the ruling failed to strike clearly the right balance between the right to privacy and the right to freedom of expression. It’s not yet too late to urge the Council (and then, the Council and the EP) to address issues such as the unjustified special treatment of journalists, the accountability of search engines and the application of the new rules to other types of Internet use.



Barnard & Peers: chapter 9

Friday, 13 June 2014

Reforming EU data protection law: the Council takes its first baby steps


Steve Peers

The EU’s controversial data protection rules, currently in the form of a Directive dating back to 1995, would be reformed profoundly if a Regulation proposed by the Commission is adopted. Talks on this proposal have been underway since January 2012, with no immediate end in sight. However, in June, for the first time the Council (consisting of Member States’ justice ministers) has agreed its position on part of the proposal. Of course, the Council still has to agree its position on the rest of the text, and then negotiate with the European Parliament, which adopted its position on the entire text this spring. But at least this recent partial Council deal offers the first opportunity to assess the direction of negotiations.

Furthermore, this is a good occasion to assess whether the new legislation might impact upon the application of the controversial Google Spain judgment.

The partial Council deal

The Council deal only concerns the question of how the new EU rules will apply to non-EU countries. However this issue is of great importance in light of the ever-growing use of the Internet and social media, since the EU rules are potentially liable to apply worldwide.

To place the deal in context, it is necessary to look at four different things: (a) the current rules in the 1995 Directive, as interpreted by the CJEU; (b) the 2012 proposal; (c) the Council’s position; and (d) the EP’s position.

In each case, I will look at two different aspects which were addressed by the Council deal. First, when do the standard EU data protection rules apply, even where the company processing data is based outside the EU? Secondly, when do the special rules on external relations apply?

The current rules

Currently Article 4 of the 1995 Directive states firstly that the standard rules apply to a data controller established in a Member State. According to the CJEU in Google Spain, that concept applies at least where a non-EU company has established a subsidiary in a Member State, and that subsidiary carries out activities linked to the business model of the parent company. The current rules go on to say that if the controller is established on the territory of more than one Member State, it must comply with the national law of each of those States.

Furthermore, the standard rules in the 1995 Directive apply where a Member State’s national law applies by virtue of public international law, and where the controller is not established on EU territory, but uses equipment located on a Member State’s territory, unless that equipment is used only for the purposes of transit. This raises the question of whether the use of ‘cookies’,  for instance, amounts to the use of equipment on a national territory, since those cookies are installed on a Member State’s computer.

As for external transfers, the current rules provide (Article 25) that in principle data can only be transferred if there is an ‘adequate level of protection’ in the third country concerned. The Commission can adopt decisions either finding that there is, or is not, an adequate level of protection. By way of derogation (Article 26), Member States must nonetheless allow (unless their national law provides otherwise) external transfers to take place if: the data subject has given unambiguous consent; the transfer is necessary to perform a contract with the data controller or to implement pre-contractual measures which the data subject requested; the transfer is necessary to conclude or perform a contract in the interest of the data subject as a third party; the transfer is ‘necessary or legally required on important public interest grounds’ or related to legal claims; the transfer is in the data subject’s ‘vital interests’; or the transfer is from a register which provides information to the public or to persons with a legitimate interest.

A Member State may authorise an external transfer to a country with an inadequate level of protection if the data controller can offer ‘adequate safeguards’, in particular arising from contractual clauses. The Commission can decide that certain standard contractual clauses offer such protection. 

The 2012 proposal

The 2012 proposal (Article 3) suggests that the new Regulation should apply first of all where a controller or processor is established in the EU. Secondly, it should apply where the data controller is not established in the EU, but the data subjects reside in the Union, and the data controller either offers them goods or services, or monitors their behaviour. Thirdly, as before, it would apply where a Member State’s national law applies by virtue of public international law. The provision concerning the ‘use of equipment’ would be dropped.
As regards external transfers, the 2012 proposal maintains the basic structure of the current rules, but elaborates upon it. So there are more details on what the Commission has to take into account when assessing the adequacy of a third State, including judicial redress and supervisory authorities. Adequacy decisions taken pursuant to the 1995 Directive would remain in force.

External transfers would be permitted on the basis of binding corporate rules, or standard contractual rules adopted by the Commission or a national supervisory authority, or individually negotiated contractual rules authorised by a national supervisory authority. Otherwise transfers would require approval by a supervisory authority. Pre-existing authorisations by a supervisory authority would remain valid.

A new clause would elaborate upon the content of binding corporate rules that would be adopted unilaterally. These would require the approval of a supervisory authority.

Finally, further derogations would be permitted. Compared to the current rules, these would be optional, not mandatory. The new proposal would clarify that consent could only be given after the data subject had been warned of the risks, and that transfers in the data subject’s interest could only be given if the data subject were unable to consent. There would be a new ground of external transfers in the data controller’s or processor’s legitimate interest, subject to safeguards being in place. The concept of the ‘public interest’ justifying such transfers would be further clarified in national or EU law.

The Council position

As regards the standard rules, the Council would amend the Commission proposal to clarify that the rules will apply whether or not the data controller offers goods or services for payment. However, as regards monitoring of behaviour, the rules will only apply if the data controller monitors behaviour within the EU.

For external transfers, the Council would add further detail to the rules regarding the assessment of the adequacy of third states, including a specific reference to participation in regional or multilateral data protection treaties. The Council also wants to give an advisory role to the planned new European Data Protection Board in this process. The Council would require the Commission to monitor the application of its adequacy decisions, and empower it to revoke them. However, the Commission would no longer have the power to adopt a decision specifying that a third State had inadequate protection.

The Council would also permit external transfers to take place on the basis of a code of conduct or a certification mechanism. Transfers in the private interest of the data processor or controller would be subject to a possible override in the data subject’s interests. The Commission would lose powers to define the public interests reasons for transfers, and Member States would gain more powers on this point.  

The EP position

The EP would amend the Commission proposal so that, where the controller or processor is established within the EU, it would not matter where the data was processed. Also, the standard rules would apply to the offering of goods or services or monitoring by data controllers or data processors, and would apply to any sort of monitoring of data subjects, not only the monitoring of behaviour. Unlike the Council, the EP would not limit the monitoring clause to behaviour within the EU. However, like the Council, the EP would apply the rules even if goods or services are not offered for payment.

As for external transfers, the EP agrees with the Council that the Commission should monitor its adequacy decisions, and that there should be a role for the new Board.  However, the EP wants to apply a ‘sunset clause’ to pre-existing adequacy decisions, and retain the power for the Commission to adopt ‘inadequacy’ decisions.

Similarly, pre-existing authorisations of contractual clauses would expire soon after the new rules were adopted, although the EP agrees with the Council that a form of certification process should justify external transfers. For binding corporate rules, the EP wants to ensure consultation of workers where their data is involved, and apply the rules to sub-contractors (the Council approaches the latter issue by referring to groups of companies). As regards the derogations, the EP would reject the idea of transfers in the legitimate interests of controllers.

Finally, the EP has proposed a new ‘Snowden clause’ which would mean that national courts could not recognise the decisions of non-EU courts which ordered the disclosure of personal data. However, this rule would be ‘without prejudice’ to mutual assistance treaties or any other international agreements between a non-EU state and the EU or any Member State.

Comments

One important point should be addressed at the outset: what is the result of the recent EP election on the EP’s position? In the EU system, proposed legislation does not fall simply because there is an election for the EP, or because there will be a new Commission as from November. Rather, the newly elected EP traditionally holds a vote at an early stage to decide whether to reaffirm the positions taken by the previous legislature. Usually it reaffirms almost all of the prior legislature’s positions. It should be recalled that the EP’s position on the data protection Regulation was adopted by a huge majority, and so despite the increase in the number of populist MEPs, a majority in favour of approving the EP’s prior position on this proposal should in principle not be hard to find.

For its part, the incoming Commission will decide whether to withdraw some of its pending proposals, but is very rare for an incoming Commission to withdraw a proposal which is actively under discussion in the Council and EP, such as the data protection proposal.

Moving on to the substance of the issues, as regards the application of the standard rules, all three institutions agree to keep the rule on establishment, extending it to data processors also. The EP’s suggested amendment regarding the location of the data processing is merely a clarification, which is probably not necessary.

The three institutions all agree to drop the ‘use of equipment’ clause, to keep the clause on public international law, and to add a new clause regarding goods and services and monitoring. The EP and the Council also agree that the ‘goods and services’ clause will apply even where there is no payment made. The institutions differ as regards extending the new clause also to data controllers, and differ as regards the exact scope of the monitoring of behaviour.

As for the external transfers rules, all three institutions would keep the current basic structure. They differ as regards: the ‘Snowden clause’ (although this rule is very weak, in light of its exceptions for any international treaties); whether the Commission can adopt an ‘inadequacy decision’ (it has never done so); sunset clauses for prior authorisations; whether private interests can justify external transfers; and the process of determining when the public interest can justify them.

Taken as a whole, the impact of the new rules depends on how the current rules are interpreted. There is no reason to doubt that the ‘establishment’ clause would be interpreted the same way as it was in Google Spain, ie applying at least where a subsidiary’s activity is linked to a non-EU parent company’s business model. But there is no case law clarifying what the ‘use of equipment’ means, and so it is not easy to assess what removal of this clause will mean in practice.

Instead the focus will be on what it means to offer goods or services (whether or not for payment), and what it means to monitor an individual. These concepts are clarified in the preamble, which indicates that the ‘offering goods or services’ rule will apply where there a website seeks to sell its products or services, and its online activity is particularly directed towards EU citizens (in light of the currency or language used). So the intention is apparently not to cover a non-profit body like Wikipedia, or a social network or search engine which does not charge for its services (although some such entities would be covered by the ‘establishment’ rule).

What about ‘monitoring’? Here, the preamble suggests that the new clause applies when an individual’s Internet activities are tracked with a view to profiling him or her. There is no suggestion in the preamble that keeping records of a person’s use of social networks would count as monitoring.  But if that is not the intention, it would be better for the EU legislature to rule it out more expressly. In any event, it is difficult to see how the Council’s limitation regarding the monitoring of behaviour within the EU would work in practice, in light of the nature of the Internet.

As regards the external transfer clauses, their importance depends on whether the standard clauses apply. The greater the number of businesses covered by the standard rules, the less important the external transfer rules are – and vice versa.

It is clear that the external transfer clauses will remain broadly similar to the current rules, so any corporate or NGO strategies regarding these clauses would only need to be amended modestly, rather than be overhauled. The biggest issues may be the EP’s insistence on its ‘Snowden clause’ and its rejection of the idea that external transfers can take place in the data controller’s interest, although the former clause is weak and data controllers can usually pursue their interests by means of obtaining consent or establishing a contractual relationship.

Much of the most difficult work as regards the negotiation of the new rules remains to be done. In fact, it is rather peculiar to negotiate a new law by defining its territorial scope before agreeing on its main substance.

While a vast number of issues will arise in the forthcoming negotiations, the following are particularly relevant to the fallout from the Google Spain decision, in particular as regards its possible impact on social networks and Wikipedia: the interpretation of a ‘data processor’ (which would be particularly significant if the EP gets its way and the entire clause on territorial scope applies to data processors); the possible application of the ‘household exception’ to user-generated content; the exception for journalism; and the definition of the grounds for processing personal data (notably consent and the controller’s legitimate interests).



Barnard & Peers: chapter 9 

Wednesday, 14 May 2014

Towards a Web 3.0? The impact of the Google Spain judgment on social networks and Wikipedia



Steve Peers

If its age could be measured in ‘Internet years’, the EU’s data protection Directive would be prehistoric. This can easily be demonstrated by comparison with the age of Facebook. The Directive was adopted seven years before the virtual panty raid on Harvard students’ privacy that ultimately launched Facebook. Indeed, when the Directive was adopted in 1995, Mark Zuckerberg was eleven years old, and attending primary school. He turns 30 today.

That’s a significant birthday – but is there anything in the Google Spain judgment that would ruin the party? This blog post looks in detail at the possible application of the judgment to two well-known features of the Internet: social networks and Wikipedia.

Long ago (in Internet years), the Internet shifted to a ‘Web 2.0’ model, dominated increasingly by user-generated content such as social networks and Wikipedia (along with blogs and many other forms of such content). The question I want to pose here is whether the Google Spain judgment could launch a ‘Web 3.0’: an Internet dominated by data subjects’ control of their personal data?

Applying the Google Spain judgment to social networks and Wikipedia

Material scope of EU law

First of all, the information placed on social networks and Wikipedia certainly constitutes personal data, at least as far as it concerns living natural persons. It’s an interesting question as to whether the legislation also applies to dead persons: this conjures up the image of the supporters and critics of (say) Ronald Reagan or Margaret Thatcher using data protection law to litigate over the reputation of their heroes (or villains). But the exclusion of legal persons means that data protection law cannot be a vehicle for companies (or other legal persons such as NGOs, political parties, charities or governments) to attempt to remove all traces of criticism of their actions.

As the CJEU has made clear several times, it isn’t relevant that the data was initially (or subsequently) made available elsewhere. This point is relevant to Wikipedia in particular, given the sources it links to for most of its information.  

Placing information on the Internet amounts to ‘data processing’, at least where it is available to the general public. This is particularly relevant to Wikipedia, but it’s also relevant to those social network profiles which are accessible to the outside world. In both cases, the personal data would also be accessible by means of search engines, which means that Google (or other search engines) would be separately liable for securing data protection rights under the conditions set out in the Google Spain judgment.

However, where a social network profile is genuinely closed to the outside world and made accessible only to persons selected by the data subject, the EU’s ‘Article 29’ working party on data protection (a body made up of national data protection supervisors, which gives non-binding advice on the application of EU data protection law) has suggested that the so-called ‘household exception’ in the Directive might apply. This would mean that, since the data could only be seen by a closed circle of (presumably) friends and family, the EU law wouldn’t apply at all. Obviously, though, that exception wouldn’t apply to any processing of the personal data in question by the company which established the social network itself, for direct marketing or other purposes.

Who is the ‘data controller’, ie the person with greater liability for application of EU data protection legislation, as regards social networks and Wikipedia? On this point, there is a clash between the nature of Web 2.0 and the putative Web 3.0, to the extent that the content of the personal data is generated by the users. In principle, each individual chooses how much personal data to place online and who has access to it, and similarly the editors of Wikipedia generate its content. The liability of the social network provider or Wikipedia might arise, however, to the extent that they alter the privacy settings, or could be regarded as controlling (as in Google Spain) the systematic presentation of the data to the outside world.  We can’t forget that in that judgment, the CJEU ruled that there has to be a ‘broad definition of the concept’ of a data controller.

Territorial scope

Back when the Internet was (in Internet years) a teenager, the CJEU ruled in Lindqvist that the special rules on external relations in the data protection Directive should not, by means of the nature of the Internet, become a general regime applicable to the entire world. But in Google Spain, the Court conversely was anxious to ensure that the general rules of the Directive were applicable to companies based outside the EU.

However, this doesn’t mean that all social networks, or Wikipedia, are necessarily subject to the Directive. They are certainly subject to it if they are in the same situation as Google: with a subsidiary in a Member State, which is selling advertising connected to the Internet-related activities of the parent body. But this is surely not the only scenario when the Directive applies to companies based outside the EU. As the CJEU said in Google Spain, the Directive has ‘a particularly broad territorial scope’ and the relevant rules ‘cannot be interpreted restrictively’. So while it is an oversimplification to say that the Directive applies to any entity ‘doing business in the EU’, it probably applies at least where there is a significant local activity (certainly in the form of a branch, possibly in the form of an agent or licensee) by the parent entity, that has some link to its Internet activities.

It is also still open to argue (since the Court did not address the issue) whether a parent company can be regarded as ‘established’ or using equipment on the territory due to its use of domain names, storage of data, and use of crawlers or robots on the territory, or whether the EU Charter of Fundamental Rights imposes broader criteria as regards the territorial scope of the rules.

Of course, there will be practical difficulties enforcing the Directive where a non-EU entity does not have assets in the EU. However, in such cases there might be possibilities to enforce the Directive’s rules by seeking to enforce a court ruling in a non-Member State, or more directly by means of obtaining an injunction to block access to the information which infringes data protection rules. Undoubtedly, such an injunction could be sought against Google, where the data is accessible by means of its search engine, and arguably (by analogy with copyright law) against an Internet service provider.

Personal scope

One interesting question which the Court did not have to deal with in Google Spain was the personal scope of data subjects. For instance, could a celebrity based in America, who finally gets tired of stories about her enormous backside, try to use EU data protection law to prevent access to such stories?

There is no requirement in the Directive that the data subject must be a national of a Member State, and/or domiciled in the EU. Nor do the rules on the territorial scope of the Directive mention this factor. So it must follow that non-EU citizens who are not resident in the EU can rely upon the Directive to assert their data protection rights within Member States. So in principle, at least, the supporters and detractors of Barack Obama or Vladimir Putin could bring their disputes, in the context of editing Wikipedia entries, to the courts and data protection supervisors of EU countries.

While this might sound absurd, in fact there are other reasons which would stand in the way of the application of EU data protection law to such disputes – to which we now turn.

Responsibility of data controllers

Data controllers must ensure that the data quality rules in the Directive are satisfied, and that data was processed in accordance with one of the legal grounds for processing.

On the latter point, one of the crucial factors in the Google Spain case was that Google could only rely (as regards its search engine) on its ‘legitimate [commercial] interest’ in processing personal data, in accordance with Article 7(f) of the Directive. The same provision refers to the interests of third parties, namely freedom of expression. However, the Court held that such interests were overridden by the data subject’s rights in that case, due to the huge invasion of his privacy due to the use of search engines.

Two issues arise here: the balancing test, and the grounds for processing. The first issue is particularly relevant for Wikipedia, since (like Google, as regards its search engine) it must rely on this balancing test in order to justify its processing of personal data, in the absence of other possible grounds to justify it.  
Applying the balancing test, the CJEU ruled on both Google’s interest and the public interest in freedom of expression. As regards Google, the Court stated that its ‘merely economic’ interests were outweighed by the data subject’s. This suggests that a non-profit body like Wikipedia would arguably have a greater claim to assert its interests than a profit-making entity.

As regards the public interest, the Court listed the factors to be considered as ‘the nature of the information’, its ‘sensitivity for the data subject’s private life’, and the public’s interest in the data, which could ‘vary, in particular’, on the data subject’s ‘role…in public life’. It should be recalled that the concept of ‘private life’ usually includes data concerning a person’s activity in public, but here the Court does suggest that there might be a distinction between public and private activities. So the balance tips in favour of freedom of expression the more that the person concerned is a public figure, and the more that the information concerns his or her public activities. So certainly Wikipedia could contain a record of public criticism of a politician; but the sordid details of his intern’s (postponed) dry-cleaning might possibly be another matter.

The crucial question here is whether the test can be regarded as severable: ie can it be argued that even if a person is a public figure, his or her public and private activities can be distinguished? In any event, his or her mistress or children are data subjects in their own right, so would have a data protection right to assert independently of the politician, and are unlikely to be public figures. But of course, some spurned mistresses are very keen indeed to waive their data protection rights.

But who is a public figure in the first place? Presumably the concept has an autonomous meaning in EU law, so it is not up to Wikipedia (or the persons concerned) to determine what it means by themselves. But surely the nature of Wikipedia is a significant factor to take into account when developing and applying such a definition.

As regards the nature of the personal data, what if the information in question reflects very badly upon the person concerned? The CJEU did not address this issue expressly in Google Spain. But it could be argued that it depends on the public interest in receiving that information. So while past financial difficulty does not raise a public interest issue, there is a better case for arguing (say) that a woman who has been groped by a particular car mechanic has every right to warn other women against him via means of social networks.

Another crucial element in the Google Spain judgment was the journalist exception in the Directive. It didn’t apply, because Google itself was not a journalist, and the Court disregarded the use that journalists make of search engines. But where content is user-generated, such as Wikipedia and on blogs, surely the exception must apply, given the Court’s broad approach to it in previous judgments such as Satamedia and Lindqvist. So in that case it could be argued that the exception should be applied in practice by the national courts. Indeed, perhaps the only reason why the CJEU undertook the task of applying the balancing test between privacy and freedom of expression itself in Google Spain was because the journalist exception did not apply.

As for the second issue, social networks will usually be able to point to other grounds justifying the processing of personal data: namely unambiguous consent, and necessity to perform a contract. This raises important questions of how to interpret these grounds for data processing, but these are clearly different issues not addressed at all by the Google Spain judgment.

That judgment would only be relevant as regards the processing of personal data about third parties in social networks, for instance a man ranting about his ex-girlfriend on his Facebook page. The way to resolve situations such as these is for social networks to adopt and apply robust privacy policies, but the Google Spain judgment can only be an indirect source of inspiration for such policies.  

The right to be forgotten

Finally, what of the ‘right to be forgotten’? The Court derived such an implicit right from the rules in the Directive on the relevance of data (one of the data quality principles), given that it might cease to be relevant over a long period of time.  While this can be seen as a positive right for data subjects, conversely it suggests that if information is accurate (and complies with all other rules in the Directive), there is not much of a right for a data subject to object to its dissemination as long as it is relatively fresh.

Conclusion

Is there good reason for Mark Zuckerberg's own knickers to be in a twist, following the Google Spain judgment? The CJEU does suggest that the territorial scope of the Directive is relatively broad, and as such is more likely to apply to social networks and other well-known Internet services than might otherwise have been thought. But it is not yet certain whether and when the Directive does apply to entities whose situation differs from Google’s. Equally the judgment confirms that the material scope of the Directive is broad, and it seems clear enough that its personal scope is broad too.

However, the judgment is unlikely to lead to a ‘Web 3.0’ as regards Internet services besides search engines, because there are basic differences in the substantive data protection law of the EU as it applies to the bodies offering such services. These differences concern in particular: the very nature of user-generated content (arguably changing who is the ‘data controller’); the existence of privacy or editing policies; the public figure exception; the possible application of different, additional grounds for processing personal data; and the Google Spain judgment itself – since it provides for an alternative, more effective means of blocking access to the personal data concerned.


Barnard & Peers: chapter 9



Tuesday, 13 May 2014

The CJEU's Google Spain judgment: failing to balance privacy and freedom of expression



By Steve Peers

The EU’s data protection Directive was adopted in 1995, when the Internet was in its infancy, and most or all Internet household names did not exist. In particular, the first version of the code for Google search engines was first written the following year, and the company was officially founded in September 1998 – shortly before Member States’ deadline to implement the Directive.

Yet, pending the completion of negotiations for a controversial revision of the Directive proposed by the Commission, this legislation remains applicable to the Internet as it has developed since. Many years of controversy as to whether (and if so, how) the Directive applies to key elements of the Web, such as social networks, search engines and cookies have culminated today in the CJEU’s judgment in GoogleSpain, which concerns search engines.

The background to the case, as further explained by Lorna Woods, concerns a Spanish citizen who no longer wanted an old newspaper report on his financial history (concerning social security debts) to be available via Google. Of course, the mere fact that he has brought this legal challenge likely means that that the details of his financial history will become known even more widely – much as many thousands of EU law students have memorised the name of Mr. Stauder, who similarly brought a legal challenge with a view to keeping his financial difficulties private, resulting in the first CJEU judgment on the role of human rights in EU law.

The Court’s judgment

The CJEU addressed four key issues in its judgment: (a) the material scope of the Directive, ie whether it applies to search engines; (b) the territorial scope of the Directive, ie whether it applies to Google Spain, given that the parent company is based in Silicon Valley; (c) the responsibility of search engine operators; and (d) the concept of the ‘right to be forgotten’, ie the right of an individual to insist (in this case) that his or her history be removed from accessibility via a search engine. The details of the Court’s ruling have been summarised by Lorna Woods, but I will repeat some key points here in order to put the following analysis into context.  

Material scope

Does the Directive apply to search engines? The CJEU said yes.  The information at issue was undoubtedly ‘personal data’, and placing it on a website was ‘processing’. A search engine was processing personal data, even though it originated from third parties, because (using the definition in the Directive) it ‘collects’ data from the Internet, then ‘retrieves’, ‘stores’ and ‘discloses’ it. It was irrelevant that the material had been published elsewhere and not altered by Google, as the CJEU had already ruled in the Satamedia case (in the context of tax information published on CD-ROM). Moreover the definition of ‘processing’ does not require that the data be altered.

A second – and perhaps more important point – was whether Google was a ‘controller’ of the data, with the result that it has liability for the data processing.  Again the key issue was Google’s use of data already published elsewhere. The Advocate-General had concluded from this that Google was not a data controller – but the CJEU reached the opposite conclusion. On this point, the Court, ruling that there must be a ‘broad definition of the concept’ of a ‘controller’, distinguished between the original publication of the data and its processing by a search engine: Google undoubtedly controlled the latter activity, by means of its control over the search process. One is unavoidably reminded of the Machiavellian search-engine billionaire who frequently appears on episodes of The Good Wife – although of course he is nothing like the executives of Google.

In particular, the Court ruled that the activities of search engines make information available to people who would not have found it on the original web page, and provides a ‘detailed profile of the data subject’, and so have a much greater impact on the right to privacy than the original website publication.

Territorial scope

Does the Directive apply to search engine companies based in California, with a subsidiary in Spain? The national court suggested three grounds on which this might be the case: the ‘establishment’ in the territory; the ‘use of equipment’ in the territory (as regards crawlers or robots, the possible storage of data and the use of domain names); or the default application of the EU Charter of Fundamental Rights.

The Court found that Google Spain was ‘established’ in the territory, and therefore the data protection Directive, in the form implemented by Spain, applied. It was not necessary to rule on the other possibilities as regards the scope of the Directive, which are very significant in the context of the Internet, so those issues remain open. It should be noted, however, that in light of the objectives of the Directive, the rules on its scope ‘cannot be interpreted restrictively’, and that it had ‘a particularly broad territorial scope’.

Why was Google Spain established there, even though it did not carry out any search engine activities? The CJEU said that it was sufficient that the company carried out advertising activities, these being linked to the well-known business model of Google (selling advertising which was relevant to search engine results).

Responsibility of search engine operators

The CJEU ruled that search engine operators are responsible, distinct from the original web page publishers, for removing information on data subjects from search engine results, even where the publication on the original pages might be lawful. It confirmed that the right to demand rectification, erasure or blocking of data did not apply only where the data was inaccurate or inaccurate, but also where the processing was unlawful for any other reason, including non-compliance with any other ground in the Directive relating to data quality or criteria for data processing, or in the context of the right to object to data processing on ‘compelling legitimate grounds’.

This meant that data subjects could request that search engines delete personal data from their search results, and complain to the courts or data protection supervisory authorities if they refused.  As for Article 7(f) of the Directive, which provides that one ground for processing data (where there was no contract, legal obligation, public interest requirement or consent by the data subject) was the ‘legitimate interests of the controller’, this was a case where (as Article 7(f) provides) those interests were ‘overridden’ by the rights of the data subject.

There has to be a balancing of rights in such cases – including the public right to freedom of expression – but in light of the ease of obtaining information on data subjects, and the ‘ubiquitous’ nature of the ‘detailed profile’ that results from search engine results, the huge impact on the right to privacy ‘cannot be justified by merely the economic interest’ of the search engine operator. The public interest in the information was only relevant where the data subject played a role in public life.

In light of the greater impact of search engine results on the right to privacy, search engines are not only subject to a separate application of the balancing test, but a more stringent application of that test – meaning that the information might remain available on the original website, even if it was blocked from the search engine results. The CJEU states that search engines cannot rely on the ‘journalistic’ exception from the Directive.

The ‘right to be forgotten’

Finally, the CJEU accepts the arguments that the Directive’s requirements that personal data must be retained for limited periods, only for as long as it is relevant, amounts to a form of ‘right to be forgotten’ (although the Court does not say that such a right exists as such). While it leaves it to the national court to apply such a right to the facts of this case, the Court clearly guides the national court to the conclusion that the data subject’s rights have been violated.

Comments

The essential problem with this judgment is that the CJEU concerns itself so much with enforcing the right to privacy, that it forgot that other rights are also applicable.

As regards the right to privacy, the Court’s analysis is convincing. Of course, information on a named person’s financial affairs is ‘personal data’, and it has long been established that prior publication is irrelevant in this regard – a particularly important point for search engines. Equally, the Court had previously ruled (convincingly) in the Lindqvist judgment that placing data online is a form of ‘data processing’. 

While it is less obvious that Google is a ‘data controller’, given that it does not control the original publication of the data, the Court’s conclusion that search engines are data controllers is ultimately convincing, given the additional processing that results from the use of a search engine, along with the enormous added value that a search engine brings for anyone who seeks to find that data. In this sense, Google is a victim of its own success.

Similarly, as regards the territorial scope of the Directive, it would be remarkable if Google, having established a subsidiary and domain name in Spain and sought to sell advertising there, would not be regarded as being ‘established’ in that country. The sale of advertising in connection with free searches is, of course, the key element of Google’s business model (leaving aside the many other companies, such as YouTube and Blogger, that Google has acquired over the years), and making money is surely one of the ‘activities’ of any business that aims to make profits.

The separate liability of Google as a ‘data controller’ obviously justifies the Court’s conclusion that it might, in appropriate cases, be required to take down material from its search engine results that infringes the data protection directive. This is most obviously relevant where that data is inaccurate or libellous, but that is not the case here, where the personal data is simply embarrassing.

So, in the absence of another legitimate ground for processing (which will normally be the case as regards search engines), the case ultimately turns on the balancing of interests between the data subject, the search engine and other Internet users. And here is where the Court’s reasoning goes awry.

In its previous judgment in ASNEF, the Court ruled that Spanish law failed to apply the correct balance between data subjects and direct marketing companies, because by banning any use of personal data which was not already public, it implicitly did not give enough weight to the company’s right to carry on a business. But here the Court makes no reference to that right, even though Google’s methods are as central to its business model as the use of private personal data is for direct marketers. Indeed, Google’s highly targeted advertising (not as such an issue in this case) is itself obviously a form of direct marketing.

Also in ASNEF, the Court criticised the Spanish law for its automaticity, because it failed to weigh up the interests of companies and data subjects in individual cases. But in Google Spain, it is the Court which sets out an automatic test: the economic interest of the search engine is overridden if the individual is not a public figure.

The interests of other Internet users are only briefly mentioned, even though Article 7(f) requires only a balancing of interests between not only as between the data controller (ie, the search engine in this case) and the data subject, but also as regards third parties to whom the data are disclosed, ie the general public. Oddly, the Court does not expressly refer to the Charter right to freedom of expression (it’s in Article 11 of the Charter), and does not expressly link its statements about the balancing test to the case law of the European Court of Human Rights on the best way to balance privacy and freedom of expression.

Furthermore, unlike in ASNEF, the Court makes no mention of Article 52 of the Charter (the provision dealing with limitation of Charter rights, including in the interest of protecting other rights, which also requires consistent interpretation with the ECHR). It should also be noted that, in deciding the key freedom of expression issue itself, the Court has departed from its prior approach (in Satamedia and Lindqvist, for instance) of leaving it to the national courts to decide on this issue.

The Court’s dismissal of the journalistic exception also contradicts its willingness to agree, in Satamedia, that merely sending personal tax data by text message to nosy neighbours could constitute ‘journalism’. Here, of course, it is not Google which is the journalist; but Google is a crucial intermediary for journalists. If journalism can consist of sending out tax information by text message, it could also equally consist of commenting (for whatever reason, and in whatever forum) on an individual’s past financial problems. And there is no reason why the passage of time should count against the exercise of the right of freedom of expression – although that factor should be relevant, as the Court says, as regards the right to privacy.

Consequences of the judgment

Obviously, today’s judgment only concerns search engines, but it may have broader relevance than that.  Its relevance to social networks will soon be considered in another post on this blog. For search engines, those which are less successful than Google might not have an ‘establishment’ within the meaning of this judgment, which raises the question of whether they would otherwise have an establishment, use equipment on the territory, or can be covered due to the Charter.

More broadly, any non-EU company with a subsidiary selling advertising in an EU Member State in connection with its Internet services must obviously be regarded as covered by the data protection Directive by analogy with this judgment, without prejudice to those broader possibilities.

As for those search engines which do fall within the scope of the judgment, most obviously Google, it seems that their legal obligations are considerably greater than what they had thought them to be. They must respond to individual complaints that the personal data which can be found about that individual is simply too old to be relevant any more, whether it is accurate or not, and they can be challenged before the courts or a supervisory authority if they do not comply.  In fact, an individual could also take action to this end before a supervisory authority.

Could a supervisory authority act of its own motion to enforce this judgment? Probably not, because the rights at issue in this case are triggered by individual complaints. Some people assiduously search Google to see what results they can find on themselves; in this context, I should point out that I am not the same ‘Steve Peers’ from Essex who has been convicted for non-payment of council tax. But others are unaware of, or don’t care about, or couldn’t be bothered to challenge, or are positively thrilled about, the existence of old information about them which can be found by means of using Google.

So not everyone who might conceivably be embarrassed by such old information will complain to Google, but a considerable number are likely to do so. Google’s liability extends to responding to such individuals, but not to completely changing the way it processes personal data in the absence of such complaints. 

Interesting questions may arise, however, as regards the interpretation of the rules set out in the judgment: what exactly is a public figure, and how long has to pass before personal data is no longer relevant? For instance, a job applicant can certainly object to Google if its search results include pictures of her dancing drunkenly on a table in 1998. But she could hardly argue that a record of last night’s debauchery must be 'forgotten'  already - even if she cannot remember it herself. 

Such disputes may well prove an opportunity to argue that the remit of this judgment is narrower than it first appears, or even to request (which any national court can do) that the Court reverse at least some aspects of its judgment. For now, however, the CJEU has established a potentially far-reaching right to be forgotten, with possible significant impacts at least on the activity of search engines. While in the Lindqvist judgment, the Court was keen to ensure that the data protection Directive was adapted to the reality of the Internet, in Google Spain it seems to demand that the Internet should rather be adapted to the Directive. 

As for the initiative to amend the Directive (to be replaced by a general data protection Regulation), this judgment might speed that process up, since Internet companies now have an incentive to use the process as an opportunity to limit their liability compared to what it would otherwise be - rather than (before the judgment) an interest in slowing the process down, in order to avoid an increase in that liability. Time will tell what the result of that negotiation will be.


Barnard & Peers: chapter 9