Showing posts with label USA. Show all posts
Showing posts with label USA. Show all posts

Tuesday, 7 October 2025

The General Court of the European Union upholds the Data Privacy Framework

 


 

Dr Samira Allioui, Research fellow, Centre d'études internationales et européennes, Université de Strasbourg

Photo credit: Ibrahim Rustanov, via Wikimedia Commons

French Member of Parliament Philippe Latombe, who also sits on the board of the French data protection authority, the Commission Nationale de l’Informatique et des Libertés, brought an action, in his personal capacity, in the General Court of the European Union calling for the annulment of the Data Privacy Framework. On Wednesday, September 3, the General Court of the European Union dismissed MP Philippe Latombe's appeal against the Data Privacy Framework adequacy decision, the agreement governing data transfers between the EU and the United States, at the heart of a long legal saga. Since Latombe's case was brought as an action for annulment and not as a preliminary question by a national court, he not only had to prove that the deal was substantively wrong, but also that he was directly affected in order to be entitled to bring an action at all.

The DPF is the successor to the EU-U.S. Privacy Shield (the Privacy Shield), after the adequacy decision on the EU side adopted in light of the Privacy Shield was declared invalid in 2020 by the CJEU following litigation by privacy advocate Maximilian Schrems, acting through not-for-profit NOYB (none of your business), in the landmark case of Schrems II. The Privacy Shield was the successor to the EU-U.S. Safe Harbor Framework, which was declared invalid in 2015 in Schrems I. In response, the United States established the Data Protection Review Court (DPRC). The European Commission approved the DPF in July 2023.

Personal data transferred from the European Union to third countries is no longer subject to the GDPR in those countries. This requires compliance with certain safeguards prior to transfer, with the aim of ensuring adequate data protection in the destination country. An adequacy decision is one of the mechanisms for ensuring this protection, and the GDPR provides for a Commission decision recognizing, after a thorough examination, that the law of a third country offers guarantees deemed adequate.

It is clear that even though American law has since evolved towards greater oversight of intelligence services, one particular issue has long been a problem in US-EU relations: access to effective remedies in the United States, allowing Europeans affected by transatlantic transfers to challenge the processing of their data. This issue was already the subject of progress in 2022 with Executive Order 14086, which paved the way for a challenge mechanism. This allowed the European Commission to adopt a new adequacy decision in 2023, the very one that is being challenged in the Latombe case.

The new ruling

This new ruling is therefore part of a series of developments relating to transatlantic transfers. The fundamental issue is the adequacy of the safeguards provided abroad, and therefore the degree of requirement that the European Union must have vis-à-vis the states to which data are transferred. However, on this point, the reasoning followed by the General Court of the European Union contrasts sharply with the rulings handed down by the Court of Justice of the European Union in the Schrems I and II cases. In the Schrems II ruling, the Court insisted that "the third country must offer guarantees to ensure an adequate level of protection essentially equivalent to that guaranteed in the European Union," while also using the terms "essential equivalence" and "substantial equivalence" interchangeably. Only the latter expression—"substantial equivalent"—is adopted by the General Court, although it gives it a scope that appears to be weakened.

In its assessment of the adequacy of American law, the Court appears to be less demanding than the Court of Justice. In recent years, the latter has initiated a particularly demanding jurisprudential movement in matters of personal data protection, giving rise to numerous tensions with Member States, which themselves struggle to comply with the requirements of the Court of Justice. While the Schrems I and II judgments were perfectly in line with this trend, the Court's judgment seems to propose another direction, perhaps more favorable to national security issues.

In any case, in its analysis of the conditions to be met to conclude that foreign law is adequate, the Court draws its inspiration primarily from the ECtHR case of Big Brother Watch v. United Kingdom. On the contrary, the major decisions of the CJEU – we are thinking in particular of the La Quadrature du Net I case – dealing with the activities of intelligence services are not considered relevant by the Court. The latter were particularly demanding, where the ECtHR recognizes certain margins of appreciation for States, in particular due to the very sensitive nature of intelligence and national security issues.

The next developments?

Since this is a General Court ruling, it is likely that there will be an appeal to the CJEU. Let us assume, however, that the Court upholds the existing adequacy decision. Another fundamental question would inevitably arise. The General Court is not taking into account recent developments in US law, particularly since the return of President Donald Trump. However, some of the guarantees applicable in US law, highlighted by the General Court, already appear to be weakened. Let us give an example: the Privacy and Civil Liberties Oversight Board (PCLOB) which role is fundamental, particularly because it is involved in the appointment of members of the Data Protection Review Court, whose independence and impartiality are discussed at length in the General Court's ruling. However, President Donald Trump has terminated the terms of several PCLOB members, preventing it from functioning. The impact this could have on transatlantic data transfers has already been the subject of debate in the European Parliament and the United States. The saga surrounding transatlantic data transfers could thus, despite the Court's ruling, be the subject of new twists and turns.

Today, more than 2,800 US companies are DPF-certified, allowing them to continue relying on the adequacy decision (Article 45 of the GDPR) as the legal basis for their transatlantic transfers Data Privacy Framework. However, while this prevents massive disruptions to data flows, the stability of the framework is not guaranteed. It must be actively monitored, given regulatory or judicial events that may disrupt it.

Plus, if Mr. Latombe can still appeal the General Court's decision to the CJEU, it is uncertain whether the CJEU would follow the General Court's reasoning. It should be recalled here that the CJEU has in the past held that adequacy decisions must be assessed on the basis of the legal and factual situation at the time of the appeal, while in Latombe, the General Court departed from this standard and stated that decisions must be assessed on the basis of the situation at the time of their adoption (i.e., under the previous administration). Finally, the European Commission could, in theory, decide to suspend or repeal the DPF if it considers in the future that US law no longer provides sufficient protection for European Economic Area personal data.

Tuesday, 25 April 2023

The ‘sidelining’ of the European Parliament from the EU-US Trade and Technology Council (TTC): TTC(s) as post-Democracy Divas or Disasters?

 


 



Professor Elaine Fahey, Institute for the Study of European Law, City Law School, City, University of London*

Elaine.fahey.1@city.ac.uk

 

* Professor of Law at the City Law School, City, University of London; Jean Monnet Chair in Law and Transatlantic Relations 2019-2022; co-director of the Institute for the Study of European Law (ISEL), City Law School since 2016; in 2023, Visiting Professor at the American University, Washington College of Law (WCL) and Senior Land Steiermark fellow at the University of Graz; Research interests: EU law, global governance, EU external relations and the EU as a global digital actor.

 

 

The EU-US Trade and Technology Council (TTC)

 

A Transatlantic Trade and Technology Council (TTC) has been set up quickly by the European Union (EU) with the US at the outset of the US Biden administration. It is not a trade negotiation and does not adhere to any specific Article 218 TFEU procedure, although it has many signature ‘EU’ characteristics. The TTC has high-minded goals to ‘solve’ global challenges on trade and technology with its most significant third country cooperating partner.  Yet it is notably not the only recent Council proposed by the EU- there is also a new EU-India Trade and Technology Council. These new Councils represent a new modus operandi for the EU to engage with ‘complex’ partners, comprising executive to executive engagement, meeting agency counterparts regularly in close groups in an era of EU trade policy deepening its stakeholder and civil society ambit overall. The TTC has a vast range of policy-making activities, traversing many areas of EU law.  Their precise selection and future is difficult to understand in EU regional trade and data policy, seemingly pivoting, like US trade law, to executive-led soft law.

 

One entity not officially to be found within the TTC is the European Parliament (EP).  The EP is formally not part in any way of the EU-US Trade and Technology Council (EU-US TTC).  The TTC has held three ‘high-level’ political meetings so far escribed as executive to executive ‘ministerial’ meetings steer cooperation within the TTC and guide its 10 working groups on technology standards, secure supply chains, tech regulation, global trade challenges, climate and green technologies, investment screening and export controls. The first two meetings focused on launching the TTC and setting its agenda, while the third – in December 2022 – was described as a ‘shift to deliverables’. The TTC strikingly has a vast range of global law-making goals and has received public critique for either ‘under-performing’ or for its overbroad focus. It comes at the back of significant EU-US collaboration in data privacy.

 

This short blog considers the merits of the placement of the EP. It considers its de facto and de jure ‘sidelining’ from this era of EU-US relations, in an ostensible age of parliamentarisation and widening participation.  

 

EP powers in external relations: increasingly empowered at all stages … to a point

 

The EP is increasingly empowered politically and legally in international relations including important powers of consent to approve international agreements in a wide variety of circumstances, pursuant to the EU treaties in Article 218(6)(a) TFEU, with information and veto rights. The EP is excluded from the critical stage of the opening of negotiations on external relations agreements.  Many of its powers represent a very end-point of diplomacy, politics and technical issues, in reality, temporally earlier issues are increasingly important in a world where soft international economic law prevails and trade agreements are viewed as old-fashioned. As a result, the EP uses many soft law resolutions to advocate legal positions in the shadow of its veto. The EP has, however, also been granted important information rights in Article 218(10) TFEU, which have been given constitutional significance by the CJEU in key caselaw initiated by the EP.

 

However, similar to or mimicking the US the EU increasingly uses ‘soft’ international arrangements rather than formal international agreements in establishing relations with non-EU states.  Yet the use of the many forms of soft law in EU external relations runs the risk that parliamentary influence is by-passed.  

 

 

The EP in EU-US relations: a striking history of litigation and evolving legal powers

 

The EP record on EU-US relations is quite striking, from civil liberties to trade, using its many and evolving legal powers. The EP litigated notoriously the EU-U.S. Passenger Name Records Agreement (PNR) and swiftly rejected the EU-US Transatlantic Terror and Financing Programme (TFTP) (Swift) giving it ever more legal prominence in EU-US relations. The EP did not issue recommendations on the opening of EU-US trade negotiations in 2019 and the EP notably even rejected a draft resolution recommend the opening of Trump-era EU-US trade talks relating to concerns as to the Trump administration, Eastern European country visas for the US, accepting the so-called mini-Lobster trade agreement with difficulty. The EP had a highly prominent role in compelling more transparency to the EU-US Transatlantic Trade and Investment Partnership (TTIP), through illegal leaking negotiation texts in the public interest.

 

The EP in TTC: self-sidelining?

 

However, it can now be said that the EP is not per se helping itself as to TTC. The EP has once received a briefing from the Commission through its INTA Trade committee on the TTC. The EP thus appears to be ‘monitoring’ the TTC through INTA- although this seems very odd as to why EP technology and industry committees might be any less involved than trade in a ‘trade and technology’ venture. One meeting of the INTA committee with two Commissioners held in December 2022 few tech committees MEPs were invited – and appeared to have few critical questions of the TTC. The EP has issued one critical press release via its trade committee publicly, in late 2022 but little else, critical of its lack of trade results. However, democratic scrutiny has been repeatedly mentioned by the EP as to the TTC-  via the European Parliamentary research service ‘EPRS’ briefings - rather than via an EP resolution- arguably downgrading its importance and EP engagement with it.

 

 

Stakeholders and the TTC - civil society, industry and the EP all lumped in together?

 

It is important to say that the TTC has a range of engagement strategies for stakeholders. A TTC Stakeholder Assembly was organised by the Trade and Technology Dialogue (TTD) which adopts the EU international relations lexicon of dialogues with stakeholders, increasingly found in EU trade negotiations and resulting agreements. One may say that it is confusing series of alphabetised meetings called the TTD, meant to support the TTC. The sheer range of issues and topics considered by the TTD by zoom- using breakout rooms- is particularly remarkable and easily accused of being ill-focused. The lack of formal accountability here appears striking also with stakeholder sessions run by thinktanks for the EU. High level US administration, professional lobbyists and/ or thinktanks and EU institutions all appear here to have privileged input and capacity to influence and scrutinise- but less so the EP.

 

 EU in the US:-  increasing EP and EEAS physical site offices

 

The sidelining of the EP in the TTC is notable given the EU’s ratcheting up of institutions and diplomacy in the US recently. In 2010, the EU established a dedicated structure with the explicit task of channelling and deepening ties between the EU and US legislatures - a European Parliament Liaison Office (EPLO) – notably with no US equivalent. The EPLO sits alongside physically the European External Action Service (EEAS) in Washington DC in the same building entitled the ‘The EU and US,’ but notably on the floor below it (metaphorically?). EPLO Washington DC has added a ‘hard’ dimension to institutionalising the EU-US inter-parliamentary relationship. Aside from the EEAS office in Washington DC and the EPLO in Washington DC alongside it, the EU recently opened its new EEAS office in San Francisco, California, as a self-professed global centre for digital technology and innovation. Its mission was said to be to promote EU standards and technologies, digital policies and regulations and governance models, and to strengthen cooperation with US stakeholders, including by advancing the work of the EU-US TTC. The office was said to work under the authority of the EU Delegation in Washington, DC, in close coordination with Headquarters in Brussels and in partnership with EU Member States consulates in the San Francisco Bay Area- but again without any mention of or reference to the EP or EPLO in the US.

 

 

Conclusions: the real harm of soft law councils?

 

The EP is arguably legally excluded from the new era of soft international economic law that the EU is readily subscribing to, to a high degree. The rights of the EP have evolved significantly - even in an age of soft law in international relations.  The TTC is following an EU law blueprint in effect legitimising its executive-led action but it is also acting contrary to the thrust of much EU international relations practice which is about widening and deepening participation.

 

The harm of ‘soft law’ councils remains very real if it becomes mainly executive to executive sidelining of parliaments.

 

Where entities such as the US have declared trade agreements to be old fashioned in favour of soft law framework agreements, the EU had always appeared less so inclined as a rules-based multilateralist.

 

The EP in transatlantic relations has been highly effective, engaged and participating and should not necessarily be formally excluded from this new era of EU-US relations, privileging TTC contacts.

 

 

Thursday, 16 July 2020

“You Were Only Supposed to Blow the Bloody Doors Off!”: Schrems II and external transfers of personal data





Lorna Woods, Professor of Internet Law, University of Essex

The Court of Justice today handed down the much anticipated ruling on the legality of standard contractual clauses (SCCs) as a mechanism to transfer personal data outside the European Union.  It forms part of Schrems’ campaign to challenge the ‘surveillance capitalism’ model on which many online businesses operate: there are other challenges to the behavioural advertising model ongoing.  While this case is clearly significant for SCCs and Facebook’s operations, there is a larger picture that involves the Court’s stance against mass (or undifferentiated) surveillance. This formed part of the background to Schrems I (Case C-362/14, discussed here), but has also been relevant in European jurisprudence on the retention of communications data. This then brings us to a third reason why this judgment may be significant. The UK, like the US, has a system for mass surveillance and once we come to the end of the year data controllers in the EU will need to think of the mechanisms to allow personal data to flow to the UK. The approach of the Court to mass surveillance in Schrems II is therefore an indicator of the approach to a similar question in relation to the UK in 2021.

Background

The General Data Protection Regulation provides that transfer of personal data may only take place on one of the bases set out in the GDPR. The destination state may, for example, have an ‘adequacy decision’ that means that the state in question ensures an adequate (roughly equivalent) level of protection to the ensured by the GDPR (Article 45 GDPR).  The original adequacy agreement in relation to the United States (safe harbour) was struck down in Schrems I because it failed to ensure that there was adequate protection on a number of grounds, some of which related to the safe harbour system itself, but some of which related to the law in the US, specifically that which allowed mass surveillance.  While the safe harbour was replaced by the Privacy Shield under Decision 2016/1250 on the Privacy Shield (Privacy Shield Decision) which improved some of the weaknesses as regards the operation of the mechanism itself, including the introduction of an ombusdman system, little if anything has changed in relation to surveillance.

Another mechanism for transfer of personal data outside the EU is that of SCCs, which are private agreements between the transferor (data controller) and transferee. Article 46(1) GDPR states that where there is no adequacy decision “a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available”. Article 46(2) GDPR lists possible mechanisms including standard data protection clauses. The Commission has produced a model form of these agreements in Commission Decision 2010/87 (SCC Decision). 

Following the outcome of Schrems I, Schrems reformulated his complaint to the Irish Data Protection Commissioner (DPC) about data transfers arguing that the United States does not provide adequate protection as United States law requires Facebook Inc. to make the personal data transferred to it available to certain United States authorities, such as the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) and the data is used in a manner incompatible with the right to private life, and that therefore future transfers by Facebook should be suspended.  These transfers are currently carried out on the basis of SCCs as approved by the SCC Decision.  The DPC took the view that this complaint called into question the validity of that decision as well as the Privacy Shield Decision, which moved the issue back into the courts. The Irish High Court referred the question to the Court of Justice and it is the outcome in this ruling that we see today.

The Judgment

The Advocate General in his Opinion (discussed here) suggested to the Court that the SCC Decision was valid; the problem was the context in which it operated. He took the view that the Privacy Shield’s validity should be considered separately. Crucially, he held that data controllers need to determine the adequacy of protection in the destination state. This in practice is difficult; while a data controller might have some control over what the recipient does with the data (how processed, data security etc), it would have little control over the general legal environment. In any event, data controllers would be required to make specific country assessments on this, which could be challenged by dissatisfied data subjects.  The Court took a slightly different approach. It agreed with its Advocate General that the SCC Decision was valid, but it struck down the Privacy Shield.

The Court made a number of findings. The first relates to the scope of inquiry and to competence. Given that national security lies outside the GDPR (and outside EU competence), should questions about the processing of data for purposes of public security, defence and State security be outside the scope of the GDPR rules. Following its position in Schrems I, the Court (like its Advocate General) rejected this argument [para 83, 86, 88]: the transfers of personal data by an economic operators for commercial purposes, even if that personal data is then processed by the authorities of the destination state for national security reasons, remains within the GDPR framework. Exclusions from the regime should be interpreted narrowly (citing Jehovan todistajat (Case C-25/17), discussed here).

In determining the level of protection the GDPR requires, the Court re-iterated its stance from Schrems I and following the reasoning of its Advocate General in this case held that we are looking for a level of protection “essentially equivalent” to that in the EU- and bearing in mind that the GDPR is understood in the light of the EU Charter.  So not only must the terms of the SCCs themselves be taken into account but also the general legal environment in the destination State.  The Court summarised:

…..the assessment of the level of protection afforded in the context of such a transfer must, in particular, take into consideration both the contractual clauses agreed between the controller or processor established in the European Union and the recipient of the transfer established in the third country concerned and, as regards any access by the public authorities of that third country to the personal data transferred, the relevant aspects of the legal system of that third country, in particular those set out, in a non-exhaustive manner, in Article 45(2) of [the GDPR]. [para 105]

The Court noted that the national supervisory authorities are responsible for monitoring compliance with EU rules, and may check compliance with the requirements of the GDPR (following on from the position under the DPD established in Schrems I), and the national regulatory authorities have significant investigative powers. Where the SCCs are not complied with – or cannot be complied with – the national regulatory authorities must suspend or prohibit transfers and the Commission’s competence to draft SCCs does not restrict the powers of national authorities to review compliance in any way.  In this the Court’s approach is broadly similar to that of the Advocate General.  As regards an adequacy decision, a valid adequacy decision is binding, until such time as it may be declared invalid; this does not stop individuals from being able to complain.

Applying the principles to the SCC Decision, the Court noted that the standards bind only the parties to the agreement. Consequently, although there are situations in which, depending on the law and practices in force in the third country concerned, the recipient of such a transfer is in a position to guarantee the necessary protection of the data solely on the basis of standard data protection clauses, there are others in which the content of those standard clauses might not constitute a sufficient means of ensuring, in practice, the effective protection of personal data transferred to the third country concerned. [para 126]

Does this possibility mean that the SCC Decision is necessarily invalid? The Court held not. Unlike an adequacy agreement which necessarily relates to a particular place, the SCC decision does not. The SCCs therefore may require supplementing to deal with issues in individual cases.  Moreover, the SCC Decision includes effective mechanisms that make it possible to ensure compliance with EU standards [para 137].  Specifically, the SCC Decision imposes an obligation on a data exporter and the recipient of the data to verify, prior to any transfer, whether that level of protection is respected  in the third  country  concerned. The recipient of the data must inform the data controller of any inability to comply with the SCCs, at which point the data controller is obliged to suspend transfers and/or terminate the contract. The SCC Decision is therefore valid; the implications of this in practice for this case were not drawn out. The Court in the end held that

…. unless there is a valid European Commission adequacy decision, the competent supervisory authority is required to suspend or prohibit a transfer of data to a third country pursuant to standard data protection clauses adopted by the Commission, if, in the view of that supervisory authority and in the light of all the circumstances of that transfer, those clauses are not or cannot be complied with in that third country and the protection of the data transferred that is required by EU law, in particular by Articles 45 and 46 of that regulation and by the Charter of Fundamental Rights, cannot be ensured by other means, where the controller or a processor has not itself suspended or put an end to the transfer [operative ground 3].

The existence of an adequacy decision is then key. Turning to the Privacy Shield Decision, the Court set the same analytical framework, emphasising the GDPR is understood in the light of the Charter and the rights to private life, to data protection and to an effective remedy. In assessing the decision, the Court noted that it awards primacy to the requirements of US national security, public interest and law enforcement, which the Court interpreted as condoning interference with the fundamental rights of persons whose data are transferred.  In the view of the Court, access and use of personal data by US authorities are not limited in a way that is essentially equivalent to EU law – the surveillance programmes are not limited to what is strictly necessary and are disproportionate. Further, data subjects are not granted rights to take action before the courts against US authorities. The Ombudsperson mechanism, introduced by the Privacy Shield Decision as an improvement on the position under safe harbour, is insufficient.  The Court therefore declared the Privacy Shield invalid.

Comment

The most obvious consequence of this ruling is that of how data transfers to the US can continue? The Privacy Shield is no more, and its demise has consequences for the operations of SCCs in practice. Given the weaknesses in the general legal system from the perspective of the Court of Justice, weaknesses over which the data controller/exporter can have little control, how can the requirements to individually assess adequacy be satisfied?  Are there, however, any other mechanism on which data transfers could be carried out?

In this context, we should note how the Court has interpreted the provisions of Chapter V to create a common baseline for standards, despite differences in wording between Arts 45 and 46 GDPR.  Article 45 deals with adequacy decisions and it requires that there is “an adequate level of protection”; Article 45(2) then lists elements to be taken into account – notably respect for the rule of law and human rights and “relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data”. It was this provision that was interpreted in Schrems I to require a level of protection that is ‘essentially equivalent’. Article 46(1) – which is relevant to the other mechanisms by which transfers may take place, including agreements between public authorities and binding corporate rules as well as SCCs – says something different. Article 46(1) requires “appropriate safeguards” and “enforceable data subject rights and effective legal remedies for data subject”. This is then not necessarily the same – at least in terms of simple wording – as Article 45(1). The Court however has read Articles 46 and 45 together so as to ensure that, as required by Article 44, data subjects’ rights are not undermined. This brings the essential equivalence test across to Article 46 [see para 96] and not just SCCs, but all the other mechanisms for data transfer listed in Art 46(2).  More specifically the factors to be taken into account when considering whether there are appropriate safeguards match the list set out in Article 45(2). 

The Court also emphasised that the requirements of the GDPR must be understood in the light of the EU Charter as interpreted by the Court itself [para 100].  In this context, the backdrop of the Court’s approach to fundamental rights – specifically the right to private life in Art 7 EU Charter – is significant.  The Court in a number of cases involving the bulk retention of communications and location data by telecommunications operators so that those data could be accessed by law enforcement and intelligence agencies found those requirements – because they applied in an undifferentiated manner irrespective of suspicion across the population – to be disproportionate (Digital Rights Ireland and Others, Cases C-293/12 and C-594/12; Tele2/Watson (Cases C-203/15 and C-698/15), discussed here and here). The Court has also criticised the use of passenger name records (PNR) data (Opinion 1/15 (EU-Canada PNR Agreement, discussed here)) and particular the use of automated processing.  The Court in its review of the facts referred to a number of surveillance programmes and that the referring court had found that these were not ‘essentially equivalent’ to the standards guaranteed by Article 7 and 8 EU Charter.  This would seemingly cause a problem not just for the adequacy agreement, but for an operator seeking to rely on SCCs – or on any other mechanism listed in Art 46(2).

This brings to the forefront Article 49 GDPR, referred to by the Court as filling any ‘vacuum’ that results from its judgment, which allows derogations for external transfers in specific situations, notably that the data subject has consented or that the transfer is necessary for the performance of a contract. While these might at first glance give some comfort to data controllers a couple of words of caution should be noted. First, these reflect the grounds for lawful processing and should be interpreted accordingly. Notably ‘explicit consent’ is a high bar – and all consent must be freely given, specific informed and unambiguous – and it should be linked to a specific processing purpose (on consent generally, see EDPB Guidelines).  The ground that something is necessary for a contract does not cover all actions related to that contract – in general a rather narrow approach might be anticipated (see EDPB Guidance). 

The final point relates to the UK. The UK perhaps infamously – also has an extensive surveillance regime which has been the subject of references to the Court of Justice (as well as a number of cases before the European Court of Human Rights). Crucially, the regime does have some oversight and there is an independent tribunal which has a relaxed approach to standing. Nonetheless, bulk collection of data is permissible under the Investigatory Powers Act, and it is an open question whether the Court of Justice would accept that this is necessary or proportionate, despite the changes brought in since the Tele2/Watson ruling on the communications data rules. Further, the UK has entered into some data sharing agreements with the US which have given rise to disquiet in some parts of the EU institutions. Whilst a member of the EU it benefitted in terms of data flows from not having to prove the adequacy of its safeguards. From 2021 that will change.  In the light of the approach of the Court of Justice, which can be seen as reemphasising and embedding its stance on surveillance, obtaining an adequacy agreement may not be so easy for the UK and given the similarity in approach underpinning Articles 45 and 46 GDPR, other mechanisms for data flow may also run into problems if this is the case. For now, the jury is out.

Photo credit: Security Dive

Saturday, 21 December 2019

The AG Opinion in Schrems II: Facebook, national security and data protection law





Lorna Woods, Professor of Internet Law, University of Essex


Last week a CJEU Advocate-General gave an opinion in the case of Schrems II, the latest challenge to US national security rules as they apply to transfers of personal data from the EU (via Facebook). The original Schrems case (discussed here) shocked the data protection world when the Court of Justice of the EU (ECJ) ruled that the adequacy decision with regards to the United States (which simplified personal data transfers between the EU and the US) was invalid and – effectively - that US practices were incompatible with the EU Charter. Companies transferring data to the US turned to other legal mechanisms to legitimise the transfer of data and Schrems II (Data Protection Commissioner v. Facebook Ireland Limited, Maximillian Schrems (Case C-311/18)) concerns one of these mechanisms: standard contractual clauses (SCCs). Surely, given the similar context and the fact that those under US jurisdiction must comply with US law, the outcome must be the same?

The Facts

Max Schrems aimed to stop the transfer of his personal data from the EU to the US under SCCs, following on from the finding in Schrems I that US law did not provide sufficient safeguards for individuals’ privacy rights in the context of bulk surveillance. This resulted in an action being brought by the Irish Data Protection Commissioner (DPC). The DPC took the view that her assessment of whether the transfers were valid depended on whether the model SCCs (established by the European Commission by Decision 2010/87/EU) were valid and she brought an action before the Irish courts, which resulted in an 152 page judgment and a reference to the ECJ, to determine this.

The reference comprised 11 questions, which the Advocate General bundled into a number of topics:

-          the applicability of EU law when data transferred is processed for national security purposes in third countries;
-          the level of protection required;
-          the impact of the non-binding nature of an SCC on the authorities of a third country on the validity of Decision 2010/87;
-          the validity of Decision 2010/87 in the light of the EU Charter; and
-          an assessment of the Privacy Shield decision (the replacement adequacy decision for transfers to the US, following the finding in Schrems I that the previous decision, known as ‘Safe Harbour’, was invalid).

The Opinion

The first issue was whether the fact that the concerns regarding privacy occur in the policy space of national security (an area outwith EU competence) affects the applicability of the data protection directive (DPD) or the replacement law, the GDPR. Those rules are designed for the commercial sphere. As the Advocate General noted,

The significance of that question … lies in the fact that, if such a transfer fell out side the scope of EU law, all the objections raised ...would be rendered baseless [101].

Given the Court’s approach in Schrems I, it is unsurprising that the answer here was that the locus of regulation was the commercial activity that was being undertaken. The purpose of the transfer was not that of allowing the data to be processed for national security [106]. So, ‘the possibility that the data will undergo processing by the authorities of the third country of destination for the purposes of the protection of national security does not render EU law inapplicable...’ [108].

The second issue at which the Advocate General looked was that of the level of protection. He accepted that the approach of the Court in Schrems I to adequacy decisions (under Article 25(6) DPD, and now Article 45(3) GDPR) is also relevant to SCCs so that the ‘appropriate safeguards’ envisaged by Article 46 GDPR should ensure data subjects benefit from a level of protection ‘essentially equivalent’ to that which follows from the GDPR [115]. While the adequacy decision mechanism and the SCC mechanism both aim towards the same objective, the way they each achieve it may be different: the underlying difference between the mechanisms is that the adequacy decision considers whether the protections provided by law in the destination country are adequate; the SCCs accept that they are not and provide other safeguards [120, see also 123-4].

Validity of Decision 2010/87

Moving on to the question of validity of Decision 2010/87 in the light of the EU Charter, the fact that SCCs are not binding on the third country undermines the ability of the recipient of the data always to respect the data protection safeguards contained in the SCC. The Advocate General considered this in the context of the question the Irish Court raised regarding the obligations on the national supervisory authority to suspend transfer [122]. The Advocate General proposed that:

-          SCCs may be assessed only on the ‘soundness of the safeguards’ they each provide;
-          safeguards may be reduced/eliminated as a result of the law of the third country;
-          the mechanism imposes on the exporter/controller or the national supervisory authorities, on a case-by-case basis, to prohibit or suspend transfers.

The Advocate General concluded that this did not invalidate the Decision but rather raised the question of ‘whether there are sufficiently sound mechanisms to ensure that transfers based on the standard contractual clauses are suspended or prohibited where those clauses are breached or impossible to honour’ [127]. He also highlighted the requirement in Article 46(1) GDPR that data subjects’ rights must be enforceable and remedies available.

Obligations on data controllers

The SCC imposes obligations on exporter and importer to comply with the terms of the contract. Given the obligations on the data controller (the person in control of the uses to which the data is put) imposed by the GDPR, where the exporter is aware that the importer cannot honour the terms of the SCC, the controller does not have a choice to suspend transfer but is required to do so [132]. The Advocate General also suggested that the parties should carry out an examination into whether the law of the third country would entail such a breach [135]. The rights of the data subject are ensured as against the exporter/controller under the SCC in Decision 2010/87 and the data subject may also apply to the national supervisory authorities.

Obligations on the supervisory authorities

The Advocate General proposed that national supervisory authorities are required to order the suspension of the transfer. Specifically, the right to suspend is not only to be used in exceptional cases (this follows amendment of the SCC terms in the light of Schrems I) and recital 11 of Decision 2010/87 is ‘obsolete’ [143].  The Advocate General emphasised that

‘the exercise of the powers to suspend and prohibit transfers …. is no longer merely an option left to the supervisory authorities’ discretion’ [144].

Article 58(2) GDPR, which sets out the powers of supervisory authorities, should be understood in the light of Article 8(3) EUCFR and Article 16(2) TFEU (both of which provide that compliance with data protection law should be overseen by an independent authority) – the Advocate General inferred that this meant the authorities have to act in such a way as to ensure the proper application of the GDPR. This imposes a due diligence requirement on the authorities, as well as an obligation to react appropriately to infringements. Failure to do so can lead to judicial action, and this re-emphasises that the obligation on the national supervisory authorities is ‘strict’, not discretionary [150].

The DPC had contended that this obligation is insufficient: it fails to address the systemic problems of inadequate safeguards; and that the approach leaves unprotected those whose data have already been transferred. The Advocate General disagreed; while problems existed they were not sufficient to invalidate the decision. He stated that:

EU law does not require that a general and preventive solution be applied for all transfers to a given third country that might entail the same risks of violation of fundamental rights [154].

As regards, effective redress for those already affected, the Advocate General emphasised the roles of the supervisory authorities to take corrective measures and the rights under Article 82 GDPR.

Privacy Shield

The Advocate General than took the view that it was unnecessary to consider the ‘Privacy Shield’ decision, in part because it assumes that the general level of law and protection in the recipient state need to afford adequate protection for SCCs to be available – a point which the Advocate General had already rejected.  Nonetheless the Advocate General did produce some guidance for the Court were it to consider the issue.

The finding of adequacy under the Privacy Shield does not preclude a national supervisory authority from exercising its powers. A number of parties challenged (directly or indirectly) the finding of adequacy in relation to the Privacy Shield. He suggested that when considering the comparison between the law and safeguards of the third country the appropriate comparison would be with the approach of the Member States to their own national security within the framework of the European Convention on Human Rights (ECHR) [207] and that those standards must be known in advance. The Advocate General discussed the scope of the national security exception, defined as:

activities connected with the protection of national security in so far as they constitute activities of the State or of States authorities that are unrelated to fields in which individuals are active [para 210, citing inter alia Tele2 Sverige and Watson (Cases C-203/15 and C-698/15, discussed here)].

The Advocate General suggests that the exclusion covers measures ‘that are directly implemented by the State for the purposes of national security, without imposing specific obligations on private operators’ [211]. He notes that where private operators are involved the law is less clear with the earlier PNR judgment (Parliament v Council and Commission (Cases C-317/04 and C-318/04)) seemingly pointing in a different direction from more recent jurisprudence including Tele2/Watson.  He proposed a number of ways to reconcile the two lines of cases:

-          Tele2/Watson arose where operators were required to keep data; the airlines kept the data for their own commercial purposes [218];
-          Tele2/Watson arises where operators are required to cooperate as regards the access to the data, irrespective of whether there is a prior obligation to retain data - because the provision required the operators to engage in data processing [219-220].

The Advocate General favoured the second approach, suggesting it was also in line with Schrems I and that, once national authorities have the data and engage in further processing of them, such processing is not caught by the scope of the GDPR. In this view of the Advocate General, this means verification must take place by reference first to the GDPR and Charter and secondly by reference to the ECHR.

A further issue was whether continuity of protection means that measures must be in place during transit (e.g. through submarine cables). Article 44 GDPR refers to ‘after transfer’ which could mean after arrival or once transfer has been initiated. Relying on a teleological interpretation, the Advocate-General adopted the second interpretation.

Moving on to the validity of the Commission’s assessment of adequacy, the Advocate General assessed whether the Commission’s findings warranted the adoption of an adequacy decision, recalling the principles set down in Schrems I allowing for ‘a certain flexibility in order to take the various legal and cultural traditions into account’ but ‘that certain minimum safeguards and general requirements for the protection of fundamental rights that follow from the Charter and the ECHR have an equivalent ...’ [249].  It was this essential equivalence that the referring court challenged. The Advocate General re-stated case law from both Courts that recognised the existence of an interference, and as far as the ECJ is concerned it does not matter whether the data are sensitive. Further:

the obligation to make the data available to the NSA, in so far as it derogates from the principle of confidentiality of communications, entails in itself an interference even if those data are not subsequently consulted and used by the intelligence authorities [259].

As regards the requirement that interferences must be provided for by law, the Advocate General – treating the approach of the ECJ and ECtHR together states that this test means that:

regulations which entail an interference … lay down clear and precise rules governing the scope and application of the measure at issue and imposing a minimum of requirements, in such a way as provide the persons concerned with sufficient guarantees to protect their data against the risks of abuse and also against any unlawful access to or use of data [para 265, citing Digital Rights Ireland (discussed here), Tele 2 Sverige, Opinion 1/15 (discussed here), Weber and Saravia, Zakharov (discussed here) and Szabo and Vissy].

The Advocate General doubted whether the US framework met this threshold [266].  Following existing jurisprudence, however, the Advocate General accepted that the very essence of Article 7 or 8 was not compromised.  In this, the Advocate General noted that the position of the ECtHR was that such surveillance could, in principle, be capable of justification [282].

National security has long been accepted as a legitimate public interest ground justifying interferences with rights. The scope of ‘national security’ was challenged. The Advocate General accepted that some aspect of foreign affairs might fall within ‘national security’; further objectives dealt with under ‘foreign intelligence information’ could constitute other public interest objectives but that these would have a lesser weighting in a proportionality analysis. However, ‘it may be asked whether those measures are defined sufficiently clearly and precisely to prevent the risk of abuse and to permit a review of the proportionality.’ [289].

The Advocate General nonetheless considered the necessity and proportionality aspects, within the framing set down by Schrems I in particular. The Advocate General also noted the safeguards required by Article 23(2) GDPR. He doubted whether the selection criteria were sufficiently clear and precise and whether there were sufficient guarantees to prevent the risk of abuse noting in particular the difference between the requirement that an activity be ‘as tailored as feasible’ is not the same as an activity which is strictly necessary [300], nor does it necessarily forewarn data subjects [307]. There is no prior review. He therefore concluded that he had doubts about the adequacy of protection provided.

The next issue was the right to an effective remedy and the impact of the introduction of the Ombudsperson Mechanism which is intended to compensate for some of the deficiencies in the US system.  The Advocate General noted that the Article 47 right is in addition to the requirement that there be independent oversight/authorisation of surveillance activities. Re-iterating Schrems I, where there is no possibility to pursue legal remedies, the national rules do not respect the essence of the right. The right include that of receiving confirmation from national authorities whether or not they are processing data as well as being notified about an investigation once it would no longer jeopardise that investigation (though the ECtHR has not made this aspect a requirement). The US system is deficient in these aspects. The Advocate General considered whether the Ombudsperson Mechanism compensates but was not convinced. Such a body to be effective must be established by law and be independent. The Advocate General noted that the mechanism satisfied neither requirement and is not subject to judicial control.

Comment

A cursory look at the conclusion to the Opinion might suggest that there will be no change in the approach to data transfers and that in general this was a bit of a defeat for Schrems. This would mis-characterise the position (and also overlook the fact that it was the DPC that was arguing for invalidity of the SCC decision, not Schrems).  The Opinion is divided broadly into two topics: the first which deals the legality of the SCC decision and the second which deals with the Privacy Shield adequacy decision. 

The Advocate General may have suggested that the Decision underlying the SCCs should not be considered invalid but this does not mean that those transferring data to the US can ignore the privacy concerns. The response of the Advocate General - in avoiding challenging the underlying system itself - is to rely on decentralised, and ultimately private, enforcement by the exporter/data controllers, but also by the national supervisory authority.  This obligation is described in rather strong terms; certainly a data exporter cannot be passive but must investigate conditions and if it finds problems it must act to suspend transfers. A head in the sand approach – if the Court follows the reasoning of the Advocate General – is unlikely to be successful. For national supervisory authorities the obligation seems still stronger and the obligation to assess on a case by case basis potentially increases their workload. Underpinning this again is the threat of legal action by data subjects. While empowering data subjects is probably to be regarded as positive, viewing private enforcement of regulation as an essential element of that scheme is problematic.  It assumes data subjects have the energy and the resources to take action – a real weakness in this approach, despite the possibility for class actions.

It is noteworthy that while the Advocate General heads the section on the acceptability of the Decision as its acceptability under the Charter, in practice his analysis focuses on the right to a remedy. This leaves the impact of the transfers on privacy and data protection (especially against a backdrop of bulk surveillance) under-considered.  Further, the Advocate-General seems to assume that the ability to sue in the EU (under Article 80 causes of action) compensates for the difficulties in standing and lack of remedies in the relevant third country, and assumes that compensation is adequate (as opposed to more behavioural remedies such as ceasing processing).  This aspect of the analysis is in marked contrast to the considerations discussed under the Privacy Shield section.

While the ruling on the impact of national security in the early part of the Opinion may not come of much surprise, it is potentially significant for the UK. At the moment, as a member of the EU, the activities of its security and intelligence services mainly lie outside the ECJ’s purview (though note pending reference on scope of this: Privacy International v Secretary of State for Foreign and Commonwealth Affairs (Case C-623/17)); once it becomes a third country (and subject to any negotiated agreement) national security becomes a relevant consideration.  This difference between EU States and third countries did not escape the attention of those making representations before the court. On this difference, the Advocate General when discussing the comparison that must take place to come to any decision on whether a third State’s data privacy protections are essentially equivalent argues that, in regards to interferences arising in the context of national security (which falls outside EU law and therefore the scope of the Charter), the relevant standards are to be found in the ECHR. 

As noted, however, that boundary is somewhat uncertain and consequently the extent to which it is consistent with earlier jurisprudence, including Schrems I, open to question. The approach of the Advocate General does seem to move away from the approach in the PNR judgment, which was based on looking at the provision’s purpose to determine whether it fell within the national security exception. Perhaps the forthcoming cases will develop a clear and consistent line on this point going forward. The significance of drawing a boundary between the EU Charter and the ECHR lies in the extent of difference in approach of the Strasbourg and Luxembourg courts to bulk surveillance, especially that in relation to communications data. On this, the Big Brother Watch case (discussed here and here) is heading to the ECtHR Grand Chamber.

As regards the second aspect, having noted that the Advocate General seeks to avoid commenting on the Privacy Shield, some of his comments in this regard (made ‘in the alternative’) highlight some real problems for that system. In his discussion he beds his reasoning both in the ECJ’s jurisprudence but also that of the ECtHR.  The Opinion constitutes a clear statement as to the applicability of the law to ‘automated’ surveillance and also as to the requirement of legality (which is not particularly clear as regards the Strasbourg jurisprudence).  In this, as well as in the context of necessity and proportionality of the measures the Advocate General was not convinced the US framework passed the tests. This is not just one problem to fix, but many.  While the Advocate General did not the difference in the jurisprudence between the two courts, this difference did not seem to lead to a different outcome in terms of his assessment of the acceptability of the US regime.

If the Court chooses to consider this question, there will be some serious difficulties going forward for data flows.  Whether the approach will stick is a question; the ECJ has been under pressure to step back from its stance on bulk collection and automated assessment of data in particular. Some of the surveillance issues will be returning to the Court in a bevy of cases: in addition to Privacy International see La Quadrature du Net & Ors v Commission (Case T-738/16); La Quadrature du Net & Ors and French Data Network & Ors (Cases C-511-12/18); and Ordre des barreaux francophones et germanophone, Académie Fiscale ASBL, UA,  Liga voor Mensenrechten ASBL, Ligue des Droits de l’Homme ASBL, VZ, WY,  XX v Conseil des ministres (Case C-520/18). Further Advocates-General opinions in several of these cases are set for January.

Barnard & Peers: chapter 9
Photo credit: Forbes

Tuesday, 10 April 2018

Extradition to non-EU countries – further developments in EU case law



Professor Steve Peers, University of Essex*

Today's ECJ judgment in Pisciotti on the extradition of citizens of a different Member State to a non-EU country (in this case, the USA) adds to its case law in this area – and has some interesting implications for Brexit. The new ruling builds on the September 2016 Petruhhin judgment on extradition of the citizens of another Member State to Russia, which I discussed in detail here.

The case concerns an Italian citizen extradited to the USA after being arrested while in transit in Germany. Having pled guilty and served his sentence in the USA, he returned and sued for damages, arguing that Germany should have treated him the same as German citizens, who cannot be extradited outside of the EU.

As in its previous judgment, the ECJ ruled that extradition of the citizen of a different Member State to a non-EU country in principle falls within the scope of EU law, since it interferes with free movement rights. In this case, the existence of an EU/US extradition treaty also brought the case within the scope of EU law, but the free movement point is more significant, since it brings non-EU extradition cases within the scope of free movement law whether the EU has an extradition treaty with the relevant non-EU country or not.

Moreover, the Court adopted a broad interpretation of free movement for this purpose, confirming that Mr Pisciotti could rely on his free movement rights even where he was only briefly in transit through another Member State. In fact, in its intervening 2017 ruling in Schotthöfer, it had accepted that even cancelling a presentation in another Member State due to fear of facing extradition from that State to a non-EU country was sufficient to trigger the application of free movement law.  On that basis, any EU citizen who wants to challenge an extradition request from a non-EU country by relying on EU free movement law in principle could arguably bring the issue within the scope of free movement law by buying a ticket for a cheap flight (or other transport) to another Member State and then cancelling it, claiming fear of extradition.

Of course, it does not follow that such a challenge will succeed on the merits. After noting that the EU/US extradition treaty left it open to Member States to refuse to extradite their own citizens, the Court pointed out that extradition of citizens of other Member States has to comply with EU law, whether issues arose under an extradition treaty with the EU, with the Member State concerned, or pursuant to national constitutions. Next, the Court confirmed its prior ruling that while in principle citizens of another Member State must be treated the same as nationals of the State they are in, this does not extend to absolute equal treatment as regards refusal to extradite that State’s own citizens (a rule which many States apply to their own citizens, except within the European Union). That’s because it’s justified to derogate from the equality rule on the grounds of avoiding impunity for prosecution for criminal offences. (Note that while the latest case, and the first case, decided by the ECJ concern pending prosecutions, the intervening Schotthöfer case concerned a sentence for a criminal offence. The Court did not discuss the possibility of transferring that sentence).

This derogation is subject to the principle of proportionality. Again applying that rule, the Court ruled that this means that the Member State which the fugitive is a citizen of must also be contacted and be given the option to prosecute. The Court rejected objections of Member States to the Petruhhin ruling on this front, restating the priority given to prosecution by the EU citizen’s Member State of nationality – if that State has jurisdiction to prosecute. (The position of dual citizens of two Member States – or of a Member State and a non-EU country – hasn’t been addressed yet). Presumably where a sentence has already been handed down, the Member State of nationality should be given, by analogy, the opportunity to transfer the sentence under the relevant international treaty (assuming that the Court did not intend Schotthöfer to rule out sentence transfers entirely).

Impact on Brexit

After Brexit day, there are two periods to consider as regards extradition between the UK and the EU. First of all, the European Arrest Warrant law will apply during the transition period, but the EU27 position is that some Member States want to refuse extradition of their own citizens for constitutional reasons (see Article 168 of the latest draft of the withdrawal agreement, which is not yet fully agreed). It might be arguable whether this line of case law on extradition to non-EU countries also applies; perhaps the withdrawal agreement (or at least a declaration to it) should address this. At the end of the transition period, the validity of outstanding European Arrest Warrants issued before that date is governed by Article 58 of the draft agreement, although that text has not been agreed yet either.

After the transition period ends – unless it is somehow extended – then either the UK and EU will fall back on general extradition law, or conclude a new treaty dealing with these issues. The UK government prefers the latter option, and I have discussed this idea here. Again the question will arise whether this case law on non-EU countries will apply, and that question will arise under either scenario. In today’s judgment, the Court of Justice analysed the text of the EU/US extradition treaty, and it would equally have jurisdiction to rule (for the EU side) on how to interpret any EU/UK treaty; but note that it said such treaties have to give way to the application of primary EU law (the Treaties) in any event. So the Court’s approach – give a Member State the possibility of prosecuting its own nationals first, where it has jurisdiction – will necessarily limit extradition to the UK after the end of the transition period.  

Human rights

Although today's ruling did not mention human rights, presumably because Mr Pisciotti had already served his sentence in the USA without any reported allegation of human rights concerns, the ECJ's earlier ruling in Petruhhin said the risks of torture or other inhuman or degrading treatment in Russia had to be considered pursuant to the EU Charter of Fundamental Rights, taking account of the relevant ECJ and ECHR case law. Subsequently, the ECJ ruling in Schotthöfer said extradition to face the death penalty in a non-EU country is ruled out. These limitations to extradition on human rights grounds will be relevant to any non-EU country; let us hope that there is never any reason for a genuine concern as regards the UK on these grounds after Brexit.

*Disclosure: I am a special adviser to the House of Lords EU Committee on an inquiry into a future EU/UK security treaty. The comments in this blog post are purely personal.

Barnard & Peers: chapter 25, chapter 27

Photo credit: capitalfm.co.ke