Showing posts with label data protection Regulation. Show all posts
Showing posts with label data protection Regulation. Show all posts

Wednesday, 16 June 2021

Who has jurisdiction over Facebook Ireland? The CJEU rules on the GDPR 'one stop shop'

 



 

Lorna Woods, Professor of Internet Law, University of Essex

 

Introduction

 

This recent CJEU judgment concerns the one stop shop in the GDPR and the way that very large corporations that have operations in most if not all Member States are regulated.  Facebook has its European headquarters in Ireland so that the Irish Data Protection Commissioner (DPC) is ‘lead authority’ – that is, the DPC has primary responsibility for regulating Facebook under the GDPR.  There have been some concerns about how this one stop shop has been working, especially since some of the larger companies have tended to establish themselves in the same, small Member State. The one stop shop mechanism relies on trust between the Member States, but different Member States have varying degrees of enthusiasm for the enforcement of data protection and also have different levels of money to throw at the issue. As is the case with other one-stop shop mechanisms in other legislation, there are exceptions or ways for other affected regulators to be involved. This case is about the space left to those other regulators.

 

Facts

 

In 2015 the Belgian Privacy Commissioner (subsequently the Data Protection Authority) sought an injunction in the Belgian courts against Facebook Belgium with the objective of ending alleged infringements of data protection laws by Facebook through the collection and use of information on the browsing behaviour of Belgian internet users, whether or not  they  were  Facebook  account  holders,  by  means  of  various  technologies,  such  as  cookies, plug-ins (like or share buttons) or pixels. The matter ended up in the Hof van beroep te Brussel (an appeal court) which was uncertain as to the effect of the one stop shop in the GDPR on the competence to the Belgian Data Protection Authority to bring action against Facebook Belgium. So while Article 55(1) GDPR establishes the principle that each national regulatory authority is competent to carry out its role as regards its own national territory, Article 56(1) states:

 

the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor.

 

Judgment

 

The central question concerned the circumstances in which, given the one stop shop established by Article 56(1) GDPR, a supervisory authority could take action in relation to specific instances of processing. In this, the Court emphasised two underpinning considerations: that the high level of data protection applied across the EU; and that the one stop shop depended on the process for cooperation laid down in Article 60.

 

While Article 60 envisages that it is the responsibility of the lead authority to adopt decisions in relation to cross-border processing, and that position is the general rule, there are exceptions found in Articles 56(2) (matter only affecting its own territory) and Article 66 (urgency procedure). The Court noted, however, that the exercise of these provisions “must be compatible with the need for sincere and effective cooperation with the lead supervisory authority” as set [para 60] – but this obligation applies also to the lead authority - so that it cannot eschew dialogue with those other authorities [para 63]. Specifically, any  relevant  and  reasoned  objection  made  by  one  of  the  other  supervisory  authorities has the effect of blocking, at least temporarily, the adoption of the draft decision of the lead supervisory authority.

 

In terms of the protection of fundamental rights, the Court noted this allocation of responsibilities is compatible with the Charter. It noted that:

 

the use of the ‘one-stop shop’ mechanism cannot under any circumstances have the consequence that a national supervisory authority, in particular the lead supervisory authority, does not assume the responsibility incumbent on it under Regulation 2016/679 to contribute to providing effective protection of natural persons from infringements of their fundamental rights as recalled in the preceding paragraph of the present judgment, as otherwise that consequence might encourage the practice of forum shopping, particularly by data controllers, designed to circumvent those fundamental rights and the practical application of the provisions of that regulation that give effect to those rights [para 68].

 

The Court noted that legal action by a regulatory authority could not be completely excluded- for example when the lead supervisory authority has not responded to a request for information (see Article 61(8) GDPR), where there is an urgent need for the adoption of final measures (Article 66(2) GDPR), or where the matter is referred for consideration by the European Data Protection Board (EDPB) (Article 64(2) GDPR). In this instance, the Belgian DPA asked the DPC to respond to its request for mutual assistance as expeditiously as possible, but no response was given.

 

The Court also addressed the question of whether the data controller must have a ‘main establishment’ in the territory of that other regulator, concluding that there was no such prerequisite [para 84]. A third question asked whether the non-lead supervisory would be limited as to which body to sue – that is, whether it can take action against the main establishment of the controller or against the establishment that is located in its own Member State. In the national proceedings in this case, the litigation was brought against Facebook Belgium although the headquarters of the Facebook group is situated in Ireland and Facebook Ireland is the sole controller with respect to the collection and processing of personal data throughout the European Union. Facebook Belgium was set up to sell advertising in Belgium but also to lobby the EU institutions. The Court determined that the non-lead regulatory authority may take action with respect to the main establishment of the controller located in that authority’s own Member State but also with respect to another establishment of that controller, provided that the object of the legal proceedings is data processing  carried out in the context of the activities of that establishment and that that authority is competent to exercise that power [para 96].

 

A fourth question addressed the impact of the change in regime from the Data Protection Directive (which did not have a one stop shop) and the GDPR. The Court distinguished between actions brought before the date the GDPR became applicable and actions after that date. As regards the first situation, such legal action may be continued (on the basis of the Directive); for other actions the GDPR rules apply – and this allows such a regulatory authority to take action where one of the exceptions applies.

 

The Court held that Article 58(5) GDPR (on the power of data protection authorities to bring legal proceedings) has direct effect, so that the relevant authorities may rely on the provision even when it has not been specifically implemented in the national legal system.

 

Comment

 

This seems to be a balanced judgment in which the Court aims to reconcile competing pressures.  It has re-emphasised the one stop shop, but is aware of the unevenness of resources and alive to the risk of forum shopping against that background.  One of the key elements of this judgment is the Court’s emphasis on the obligation to cooperate, which applies to lead authority and other authorities alike. Nonetheless, while the lead regulator must be given the chance to act, lead regulators cannot choose to ignore the importunate demands of other national regulators – whether for lack of resources, or other reasons (eg a different assessment as to what’s important).  The significance of this comes down to the concerns about the effectiveness of the DPC (especially bearing in mind the size of the companies under the DPC’s jurisdiction).  Against this background, the judgment will probably be welcomed by privacy advocates. Whether it is equally good from the perspective of data controllers, at least those based in Ireland, seems far less likely. What is potentially problematic from the perspective of the data controller is the greater unpredictability of the data protection regime. This may be less about fragmenting standards (especially if the decision is referred to the EDPB) but about where enforcement actions may start; this agenda may not rest entirely in the hands of the lead authority.

 

Photo credit: Niamfrifruli, via Wikimedia Commons

Wednesday, 20 January 2021

When data protection authorities dispute jurisdiction under the GDPR ‘one-stop-shop’: the AG opinion in Facebook Belgium

 



Lorna Woods, Professor of Law, University of Essex

 

Introduction

 

Like their comic-book counterparts, the national data protection authorities in EU Member States, given their super regulatory powers by EU legislation, sometimes pause in battling high-tech villains – to fight with each other instead. To resolve such conflicts of jurisdiction, the GDPR created a one-stop-shop system to determine which authority could bring proceedings in principle.

 

This case is the first judicial test of the one-stop-shop in the GDPR and its lead supervisory authority (LSA) mechanism, according to which the main responsibility with the EU for regulating a data controller under the GDPR falls to the regulator of the jurisdiction in which the controller has its main establishment (Article 56 GDPR).  While Article 56 establishes the idea of the lead supervisory authority based on the location of the controller’s main establishment, it operates without prejudice to Article 55 GDPR, which gives each national supervisory authority competence to regulate, and other provisions envisage that, even when not a lead supervisory authority, national supervisory authorities retain some interests in regulation.  Further, the GDPR envisages cooperation between the national supervisory authorities.  The question here is about the circumstances in which this residual competence may be exercised.  The question arises against a backdrop in which some differences in approach to regulation can be detected and perhaps some distrust between the different national supervisory authorities (as also illustrated with the difficulties in agreeing the fine for Twitter in relation to a data breach that lead to the first decision of the European Data Protection Board (EDPB) under Article 65 GDPR).

 

Facts

 

The Belgian data protection authority commenced proceedings against Facebook in its local courts, alleging that Facebook had unlawfully collected and used personal data relating to the private browsing information of Internet users in Belgium, through the use of cookies and the like (and there was some discussion as to whether the technologies in issue actually fell ratione materiae within the GDPR as opposed to the e-Privacy Directive).  Although initiated under the Data Protection Directive, given the length of time the matter is now concerned with the GDPR and on that basis Facebook argued that the Belgian data protection authority was no longer competent because Facebook fell within the jurisdiction of the Irish Data Protection Commission (DPC).  The matter was referred to the Court of Justice, specifically referring to legal proceedings against Facebook Belgium in respect of the cross-border processing of personal data that took place after the GDPR has become applicable, given that the data-processing entity was Facebook Ireland Ltd.

 

Opinion

 

The Advocate General’s opinion in this case (Case C-645/19 Facebook Belgium v Gegevensbeschermingsautoriteit, Opinion 13 January 2021) sought to chart a middle ground between the two positions argued before the court as to whether only the LSA may take action. While he agreed that the primary responsibility lay with the LSA, in his view the consequences of that position were not as extreme as Facebook sought to claim. 

 

The Advocate General took a literal and systemic approach to the interpretation of Article 56 (referring also to Recital 124 in the GDPR preamble) to find that the LSA has general competence over cross-border data processing.  Any role for other national supervisory authorities is exceptional [45]-[46].  The fact that Article 56, which sets up the LSA mechanism, is said to operate without prejudice to Article 55, attributing competence to the various national supervisory authorities, does not change this position. Such an interpretation would deprive Article 56 of any meaning [52].  This is incompatible with the importance ascribed to the LSA mechanism by where it is placed: the second provision in the relevant section of the regulation, before all the other general provisions on ‘tasks’ and ‘powers’ in that section. Significantly, Chapter VII (cooperation) refers back to Article 56.

 

In the view of the Advocate General, the GDPR makes it ‘clear that that is meant to be the procedure to be followed when enforcement action against cross-border processing is necessary’ (emphasis in original) [56]. Consequently, the term ‘without prejudice’ does not refer to competence but refers to the fact that ‘all supervisory authorities naturally retain the general powers assigned to them by virtue of Article 55 (and Article 58) of the GDPR’ [57].  The Advocate General therefore confirmed the approach of the EDPB in Opinion 8/2019 which views Article 56(1) as an ‘overriding rule’ and as ‘lex specialis’ taking priority over the general rules of competence in Article 55 in the circumstances specified in Article 56. To take the approach put forward by the Belgian data protection authority would frustrate the purpose of the GDPR as found in recital 10, and return the position to that under the Data Protection Directive.

 

It was also argued that Article 58(5) means that all supervisory authorities must be able to start judicial proceedings against any potential infringement of the data protection rules affecting their territory, irrespective of the (local or cross-border) nature of the processing; the one-stop shop mechanism applies only to administrative action.  The Advocate General criticised this interpretation for, again, taking one provision in isolation and out of context.  Article 58(5) of the GDPR sets out ‘powers that are to be given to all supervisory authorities without exception’ but ‘does not regulate the situations and manner in which that power to bring proceedings is to be exercised’ [65].  The distinction between judicial and administrative proceedings was unjustified in the light of the text and structure of Article 58 as a whole. The interpretation proposed by the Belgian data protection authority ‘would not allow a supervisory authority to (administratively) investigate, prepare, process, and decide, but would allow it instead immediately to bring judicial proceedings before a court’ [71], which is netiher reasonable nor appropriate.

 

The Advocate General then supported his arguments through a teleological and historical interpretation of the GDPR and its emphasis to avoid fragmentation (Recital 9), incoherence and double regulation.  The one stop shop mechanism was the means introduced to achieve this goal.  However, the Advocate General noted that the Commission’s original proposal for a very strict idea of the one stop shop gave rise to discussions with the Council and the Parliament, leading to the introduction of a number of exceptions, including a concern to emphasis the proximity between data subjects and the relevant supervisory authorities. [85] The Advocate General described this process as turning the one stop shop mechanism ‘into a more balanced two-pillar mechanism’  with an enhanced role for the other supervisory authorities [87].

 

The third approach to interpreting the GDPR adopted by the Advocate General is that of a Charter -oriented approach, to ensure maximum protection of Articles 7, 8 and 47 of the EU Charter of Fundamental Rights. The Advocate General criticised what in his view was an assumption that a high level of protection requires a multiplicity of authorities that may enforce compliance with the GDPR.  Rather, a high level of protection requires a coherent framework, as seen in recitals 7, 9 and 10 GDPR, for coherent application of the rules.  In the view of the Advocate General

 

a coherent and uniform level of protection certainly does not preclude that protection from being placed at a high level. It is simply a question of where that uniform yardstick should be set [97].

 

A second issue relating to rights concerns the proximity of the complainant and the relevant national supervisory authority and its impact of the right of that individual to complaint (as in Article 78 GDPR). This is specifically so given that the data subject has the right to choose where to launch legal action under Article 79 between the courts of the Member States where the controller or processor has an establishment or where the data subjects reside.  The position would be slightly more difficult as regards the right to challenge the action (or inaction) of a national supervisory authority: such actions should be brought before the courts of the Member State where the supervisory authority is established. (Article 78 and Recital 143). The Advocate General however envisaged that a complaint could be lodged with the complainant’s home supervisory authority, whether or not that authority is the LSA so safeguarding the right to the data subject to take action in his or her home jurisdiction [104].  The Advocate General accepted that this structure may lead to practical problems though these at the moment lie in the realm of conjecture.

 

The Advocate General finally considered concerns about a risk of under-enforcement.  First and specifically as regards criminal enforcement, the Advocate General commented that while the cooperation and consistency mechanisms

 

are obligatory for the supervisory authorities, they do not apply to other Member States’ authorities, in particular those charged with the task of prosecuting criminal offences (emphasis in original) [110].

 

More generally, and in the view of the Advocate General, more importantly the GDPR does not operate so as to make the LSA the sole enforcer in cross border situations. The system is built on cooperation and consensus (Article 60(1)) and persistent disputes are referred to the EDPB to the extent that ‘the LSA’s position in that regard is no stronger than that of any other authority’ [111]. The GDPR also contains provisions to deal with regulatory inertia. The Advocate General suggests two enforcement routes, though he accepts that both are cumbersome and potentially paper tigers:

 

-          a supervisory authority may request another supervisory authority to provide ‘information and mutual assistance in order to implement and apply the GDPR as provided in Article 60 and a failure of the LSA to respond would give rise  by virtue of Article 61 to a right on the part of the requesting authority to ‘adopt a provisional measure on the territory of its Member State in accordance with Article 55(1)’, triggering the urgent processes under Article 66.

-          Article 64 provides a mechanism whereby matters producing effects in more than one Member State  are brought to the EDPB, though it is not clear what the legal effect of such a decision would be.

 

If under-enforcement turns out to be a real problem, for example where the one stop shop mechanism ‘were to lead to regulatory ‘nests’ for certain operators who, after having effectively chosen their national regulator themselves by accordingly placing their main establishment within the Union, rather than being monitored, they would in fact be shielded from other regulators by a specific LSA’ [124], then the entire system would be ripe for major revision. The GDPR is still in its infancy, however, and it would be a bad idea for the Court to fundamentally alter the GDPR structures without evidence.

 

Thus, the GDPR permits the supervisory authority of a Member State to bring proceedings before a court of that State for an alleged infringement of the GDPR with respect to cross-border data processing, despite not being the LSA, provided that it does so in the situations and according to the procedures set out in the GDPR [140]. The position does not change depending on whether the controller has a secondary establishment in another Member State [143]. Nor does it matter whether the national supervisory authority commences legal proceedings against the controller’s main establishment or against the establishment situated in its own Member State [147]. In this, the Advocate General dismissed an argument based on Article 55(1) that a national supervisory authority can only act within its own state, and therefore only against local establishments; the territorial element relates to the effects of the data processing [152].  By creating a central point for enforcement the LSA mechanism implies that the LSA must be able to take action against actors established other than in its territory [155].  Finally, the Advocate General confirmed that Article 58(5) has direct effect as well as direct applicability.

 

Comment

 

Both sides had claimed victory in this opinion. Facebook emphasises the re-iteration of the LSA mechanism and the Belgian authorities point to the fact that the Advocate General made clear that the LSA is not the sole enforcer in such cases.   If the Court follows its Advocate General, this should give some comfort to those operating in multiple jurisdictions that they will not continue to face the difficulties of multiple and potentially incoherent enforcement found under the Data Protection Directive.  Nonetheless, the result of the GDPR is not a simple, bright-line allocation of jurisdiction to one national supervisory authority.

 

Firstly, there are moreover a number of exceptions to the LSA mechanism, which also reflect the ‘two-pillared’ nature of the enforcement system.  These arise when:

 

-          supervisory authorities act outside the material scope of the GDPR;

-          the processing is necessary for compliance with a legal obligation, in the public interest or in the exercise of official authority;

-          processing is carried out by controllers that have no establishment in the European Union;

-          a national supervisory authority other than the LSA considers that there is an urgent need to act in order to protect the rights and freedoms of data subjects (Art. 66 GDPR); or

-          the LSA decides not to handle the case.

 

Beyond this, however, the Advocate General emphasised the importance of cooperation within the system, implicitly pointing towards the need towards an EU settlement on the question of standards that lies in the shadows of this case (see eg. para 97). An LSA cannot ride roughshod over the views of other relevant national supervisory authorities; this is potentially a prophylactic against the creation of ‘nests’ for privacy averse data controllers. The approach to interpretation, while it allowed the Advocate General to bring through the delicate balance between potentially conflicting concerns, reflects approaches typically adopted in the interpretation of EU law, emphasising the purposive approach.  In any event, the Opinion drew out the existence of possible mechanisms by which the failure of an LSA to act – whether through choice or because of resourcing – could be challenged and decisions of the other national regulatory authorities/EDPB put in place.  In this, the Opinion is a welcome review of the mechanisms in the GDPR, a set of systems which are complex and not necessarily easily understood.

 

In terms of enforcement of the GDPR, it is important to remember that enforcement does not lie in the hands of the national regulatory authorities alone; and the Opinion reminds us of this in terms both of direct enforcement of data subjects’ rights but also in terms of challenging the inaction of a national supervisory authority. Here the choice of jurisdiction is not determined by the LSA mechanism.  Strategic litigation, including some forum shopping, may still be possible.

 

Given the starting point for this case was the use of cookies the question of the relationship between the e-Privacy rules and the GDPR arises.  The Advocate General confirmed that more than one legislative instrument could apply. This then raises the question of jurisdiction and whether such overlap might undermine the one stop shop – though this difference might be addressed through the revision of the e-Privacy regime (a process which has been fraught with delay).  A similar question might arise in relation to criminal law enforcement.

 

Where this leaves Facebook and the Belgian authorities is not yet clear. This is of course an opinion, not the judgment of the Court.  While the Court usually follows the opinion of its Advocate General it is not obliged so to do.  Moreover, action against the Irish DPC, the LSA as regards Facebook, has settled a judicial review action brought by Max Schrems in respect of the DPC’s failure to stop data transfers to the US. While this is action, it does not cover exactly the same issues brought by the Belgian authorities.

 

 

Friday, 25 May 2018

Right to erasure (right to be forgotten) under the GDPR – the danger of “rewriting history” or the individual’s chance to leave the past behind




Ketevan Kukava, PhD Student in Law, Tbilisi State University

In the internet age, when vast amount of information can be stored indefinitely and can be easily retrieved by means of a mouse click, controlling one’s personal data seems a particularly difficult task to do. Complete erasure of data from digital memory once it becomes publicly available is questionable from technological and practical point of view. As a result, the burden of remembering past events and behavior after they have lost their relevance and permanent digital accessibility of information can have significant implications for individuals at the present time.

While the internet and digitization has brought about huge benefits in terms of access to wide range of information, content-creation and public dissemination, its major downside is losing control on one’s personal data and the difficulties related to forgetting.  In his book “Delete: The Virtue of Forgetting in the Digital Age” Viktor Mayer-Schoenberger points out:

“Since the beginning of time, for us humans, forgetting has been the norm and remembering the exception. Because of digital technology and global networks, however, this balance has shifted. Today, with the help of widespread technology, forgetting has become the exception, and remembering the default“.

The debate over achieving a balance between privacy and freedom of expression has reached its highest level in the internet age. Some argue that removing lawfully published information from search results might pose the risk of Orwell’s dystopian history-rewriting. However, on the other hand, individual’s interest in controlling their personal data, leaving the past behind, and removing the past burden should not be underestimated.  

The General Data Protection Regulation (GDPR), which will become applicable on 25 May 2018, tries to answer the challenges emerged as a result of technological advancements in the digital age. Apart from ensuring uniform rules regarding personal data protection throughout the European Union (as the directive 95/46/EC by its nature left certain leeway to the states in terms of its implementation), the GDPR provides some additional guarantees, such as a clearer formulation of the right to erasure (right to be forgotten) which is probably one of the most controversial and hotly debated issues within the scope of the GDPR. Right to erasure (right to be forgotten) guarantees deletion of data when an individual no longer wants their data processed and there is no legitimate reason to keep it.

Although Directive 95/46/EC does not explicitly guarantee “the right to be forgotten”, in the widely known Google Spain judgment the Court interpreted legal provisions of the Directive in such way which made it possible to satisfy the data subject’s complaint. In particular, the Court relied on data subject’s right of access to data (the rectification, erasure or blocking of data the processing of which does not comply with the provisions of this Directive) as well as data subject’s right to object, which obliged the operator of a search engine to remove from the list of results displayed following a search made on the basis of a person’s name links to web pages, published by third parties and containing information relating to that person.

Right to erasure (“right to be forgotten”) guaranteed by Article 17 of the GDPR empowers the data subject “to obtain from the controller the erasure of personal data concerning him or her without undue delay”, and obliges the controller “to erase personal data without undue delay”. This provision is applicable when certain grounds determined by the Regulation exist, including when the data subject withdraws consent on which the processing is based, and where there is no other legal ground for the processing.

One of the basis for erasing personal data is the data subject’s objection to the processing when there are no overriding legitimate grounds for the processing (Article 17(1)(c)). Notably, in such case the obligation of demonstrating compelling legitimate grounds is imposed upon the controller. While according to the Data Protection Directive, the data subject had to demonstrate “compelling legitimate grounds relating to his particular situation” and processing should no longer involve those data in case of a justified objection (Article 14(a)), according to the GDPR, “the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims” (Article 21(1)).

Article 17 of the GDPR imposes obligations upon the controller which according to the definition provided in Article 4 “alone or jointly with others, determines the purposes and means of the processing of personal data.” Further, apart from erasing personal data, additional duties are foreseen by the Regulation when the controller has made the personal data public: “The controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data” (Article 17(2)). Notably, the GDPR foresees certain exceptions from the above mentioned provisions, including when processing is necessary for exercising the freedom of expression and information, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, etc. (Article 17(3)).

Despite the significance of the efforts aimed at ensuring the data subject’s control over their own personal data, the very nature of the internet and constantly developing technologies might still pose certain legal and practical challenges in achieving the aims of being forgotten. In Google Spain the Court itself stressed “the ease with which information published on a website can be replicated on other sites and the fact that the persons responsible for its publication are not always subject to European Union legislation” (paragraph 84). Indeed, once information is made publicly available, tracking personal data, controlling their further replication and their subsequent total erasure might seem practically impossible. Moreover, Google Spain is also a good illustration of the so-called “Streisand effect”, as the Spanish citizen who wanted to be forgotten ended up in publicizing his personal information more widely.

Probably, the practical difficulty of total erasure is the major rationale behind the focus of the GDPR on taking reasonable steps and obliging the controller to communicate erasure of personal data “to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort” (Article 19).

One of the important issues related to the enforcement of the right to be forgotten is the territorial scope of the Regulation and its applicability to companies incorporated outside the EU. Similar to the Data Protection Directive, the GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller in the Union. Furthermore, the Regulation explicitly stresses that this rule is applicable “regardless of whether the processing takes place in the Union or not” (Article 3(1)).  According to Recital 22, establishment implies the effective and real exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect.

Additionally, the GDPR determines that the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union are subject to the GDPR where the processing activities are related to:

(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b) the monitoring of their behaviour as far as their behaviour takes place within the Union (Article 3(2)).

Therefore, companies based outside the EU are not released from data protection obligations imposed by the GDPR when offering goods or services, or monitoring behavior of data subjects within the EU, which ensures significant extraterritorial reach of the GDPR.

Broad territorial scope of the GDPR together with high administrative fines in case of infringements of the Regulation (Article 83) is viewed as a strict regime by privacy sceptics and has given rise to a debate. However, on the other hand, there is no doubt that the legal framework should be adjusted in order to answer modern-day privacy challenges. In parallel with technological developments, privacy concerns increase which necessitates the emergence of appropriate safeguards and legal regulation.

Proportionality remains the significant principle which is explicitly guaranteed by the GDPR. In particular, Recital 4 declares that “the right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality.” Furthermore, Article 85 of the GDPR refers to exemptions and derogations for processing carried out “for journalistic purposes and the purposes of academic, artistic or literary expression” if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.

When enforcing the right to be forgotten in the online world, important questions arise whether the information should be removed globally. Google Spain judgment and its legal implications are of particular significance in this regard. In response to the requests submitted regarding removing certain URLs, Google started to delist links from all European versions of Google Search (like google.de, google.fr, google.co.uk, etc) simultaneously. Moreover, Google also started to use geolocation signals (like IP addresses) to restrict access to the delisted URL on all Google Search domains, including google.com, when accessed from the country of the person requesting the removal. However, the French data protection authority required Google to apply the right to be forgotten to all searches on all Google domains. Following the reference by French court, the Court of Justice has to decide on the question whether the ‘right to de-referencing’ be “interpreted as meaning that a search engine operator is required, when granting a request for de-referencing, to deploy the de-referencing to all of the domain names used by its search engine so that the links at issue no longer appear, irrespective of the place from where the search initiated on the basis of the requester’s name is conducted”. It should be noted that the global removal of information might produce negative consequences worldwide. As stressed by Google, “how long will it be until other countries - perhaps less open and democratic - start demanding that their laws regulating information likewise have global reach?”

Guaranteeing the right to erasure under the GDPR cannot be considered as a silver bullet answer to the risks and challenges of the internet age, however, the value of the overall aim of the regulation – increased control of individuals of their personal data - should not be underestimated. Can we have a realistic expectation of privacy online and how much valuable information might be lost in translating legal requirements into practice? – Probably these questions gain more and more relevance, and necessitate taking due account of the very nature and the challenges of the internet age.

Photo credit: PR Week

Wednesday, 20 December 2017

Privacy and data protection in universities: recent ECJ and ECtHR rulings




Professor Steve Peers, University of Essex

Privacy and data protection are different legal concepts, derived from different legal instruments, applied by different courts at European level. But the two concepts often overlap, and the relevant courts (the ECJ, interpreting the EU data protection Directive and other relevant EU laws, and the European Court of Human Rights, interpreting the right to privacy in the ECHR) sometimes make reference to the other’s case law and legal texts.

In the last month, each court has given a ruling on the respective rights in the context of universities or other academic institutions. This is a good opportunity to contrast the two courts’ different approaches in comparable cases, and to draw broader conclusions about the importance of these rights in the context of education.

Students and exam scripts: the Nowak case

In today’s judgment in Nowak, the ECJ ruled on the application of the EU’s current data protection Directive to exam scripts. The Directive will be replaced by the General Data Protection Regulation – the ‘GDPR’ – from next May, but the outcome of this judgment would likely be the same under the Regulation, especially since (as noted below) the Court makes some mention of the GDPR already in this judgment. 

Mr Nowak is a trainee accountant in Ireland who failed a crucial exam four times. He applied for all personal data held on him by the Institute of Chartered Accountants of Ireland, but it refused to send him a copy of the exam script. He complained to the Irish data protection supervisory authority, but it ruled that exam scripts were not personal data; moreover his complaint was vexatious. He challenged the authority through four levels of Irish courts, losing at every stage until the Supreme Court ruled that his complaint was inadmissible. But since that Court was uncertain as to whether exam scripts were personal data, it decided to ask the Court of Justice to interpret the relevant EU law.

The ECJ began its ruling by applying the Directive’s definition that ‘personal data’ is ‘any information’ relating to an identified or identifiable person. A student is either identified by name or necessarily identifiable via an examination number. (It’s fortunate that the Court confirmed the latter point, since I’ve used it in classes for years as an example of when an individual is ‘identifiable’).

According to the Court, it’s not relevant whether the examiner can identify the person at the time of marking, and it’s possible for the means of identification to be split up between different people, because the administrative staff will match the exam marks to each student later. This confirms the practice of anonymous marking – as well as many other aspects of life where registration numbers are used when processing data to preserve confidentiality.

But is the exam script (and the examiner’s comments on it) information relating to such a person? The Court reiterates that the Directive has a wide scope in general, and then confirms that the notion of ‘any information’ has a wide scope in particular: ‘not restricted to information that is sensitive or private, but potentially encompasses all kinds of information, not only objective but also subjective, in the form of opinions or assessments, providing that it ‘relates’ to the data subject’.

Applying that definition, exam candidates’ answers are linked to them personally, since they show (among other things) each candidate’s intellect, knowledge and judgment. The purpose of collecting the answers is to assess the candidate’s abilities and suitability, and the use of the answers can affect the candidate’s rights or interests, for instance to access a profession. All this is equally true if (as in this case) the exam is open book.

More significantly for academics, comments on the exam are also personal data. They constitute an opinion relating to the candidate, in particular an evaluation of the candidate’s abilities, and have an effect upon that candidate. It doesn’t matter that these comments are also personal data relating to the examiner, since information can constitute personal data relating to more than one person.

Nor does it matter that the rules on access and rectification of the data apply, once information is defined as ‘personal data’. The Court anxiously points out that rectification can’t mean that an exam candidate can alter incorrect exam answers, since the right to rectify is linked to the purpose why the data was collected – in this case, to assess the candidate’s abilities. What could be rectified is errors like a missing cover sheet, or one candidate’s exam script being confused with another candidate’s script. Moreover, exam sheets might have to be destroyed once they are no longer relevant, as a consequence of data protection law.

Furthermore the Court usefully points out that the candidate does not have a right to the exam questions (!) – presumably meaning access in advance of the exam – since those questions as such are not personal data in respect of the candidate.

The Court’s final – and very vague – point is that restrictions can be placed upon access to data, both under the Directive and (under more circumstances) the GDPR. Frankly, it’s not clear what point the judges are trying to make here, since this observation is not then applied to the facts of the case.

Comments

The practical outcome of the judgment is that markers of scripts will have to be careful what they write on them. Peevishly sniping “I’m sick of this student already” would be a bad idea; so would angrily scribbling “f*@! the Vice Chancellor!”. Rather the comments should relate to a fair assessment of the content of the script.

While some academics will be understandably concerned about their workload, there’s no reason why data protection law should impact on how detailed such comments should be – or indeed if there are any comments at all. That’s an issue for universities and other educational institutions to determine.  Having worked in a legal environment where exam scripts and comments are available to students for many years, in my experience at least there are no particular problems.

Data protection law judgments are often criticised for a lack of common sense, but there’s some sign of that uncommon commodity here: the Court rules out the obvious absurdities of students correcting an exam paper after it has been handed back, or having a right to advance knowledge of the exam questions. It does not mention some of the broader educational policy arguments for its judgment though: the accountability of markers to students, and the potential usefulness of comments on exam scripts as feedback for students, which is perhaps what the frustrated Mr Nowak was seeking here. Of course, the latter point is dependent on how detailed the comments are: the judgment does not rule out markers simply writing the infamous phrase "Good as far as it goes".

Privacy in lecture theatres: the Antovic and Mirkovic v Montenegro case

So professors must be accountable to students in the context of exam marking; but to what extent can their privacy be affected by attempts to make them accountable to university management? In this case, the Dean of the mathematics school in a university decided to start taping university lectures, for the twin reasons of protecting university property and ‘surveillance of teaching’.

It’s not known if professors responded by writing “f*@! the Dean!” on exam scripts. Rather more pragmatically, some of them complained to the data protection supervisory authority, which ruled, after initial hesitation, that the university had breached data protection law. (Comparing this to the Nowak case, it’s striking that the watchdog based outside the EU barked louder than the watchdog based inside it).

The professors then challenged the university in court for breaching their right to privacy as regards the period when the video surveillance was applied. They lost in the national court, so challenged the state before the European Court of Human Rights (ECtHR) instead.

The ECtHR ruled in the professors’ favour by a 4-3 margin, although on the crucial issue – whether a right to privacy even existed, and if so, why – they split three ways, with no one view commanding a majority. In light of this close result, it remains to be seen whether Montenegro might ask the ECtHR Grand Chamber to review this ruling.

All judges agreed that the key question was whether there was a ‘reasonable expectation of privacy’. In this case, the majority ruled that in light of previous ECtHR judgments (most notably the recent Barbulescu ruling on employer monitoring of employee Internet use, discussed here), such an expectation usually applied to workplace spaces.

That meant there was an interference with privacy rights, which could be justified under Article 8(2) ECHR if the interference was in accordance with the law and had a specified legitimate aim. Here the interference was not in accordance with the law, since the law did not lay down the possibility for surveillance of teaching and set a condition (which was not met here) that surveillance could be used for surveillance of property only if no other means was possible. So there was no need to assess whether a legitimate aim existed.

For two concurring judges, the conclusion that there was an interference with the right to privacy was correct, but should have been reached on other grounds. Rather than focus on the surveillance taking place in the workplace, the key issue should have been the activities being carried out. Lectures are an occasion to discuss ideas and interact with students, and formed part of the expression of academic freedom. (Note that the applicants did not argue a breach of Article 10 ECHR, setting out the freedom of expression).

For the dissenting judges, there was no interference with the right to privacy at all. The case law, in their view, only protected a reasonable expectation of privacy in some circumstances, which did not apply here in light of certain safeguards: there was no audiotape; the professors were not identifiable due to blurring of faces; and there was limited further use of the tapes.

Comments

The ECtHR did not discuss EU data protection law, but EU rules would likely have led to a comparable result (adapted to dats protection law), for yet another different set of reasons. In its judgment in Rynes (discussed here), the ECJ ruled that the data protection Directive applies to CCTV recordings unless they only record activities inside a home (the ‘household exception’ in the Directive). That would suggest that recordings of lecture theatres are covered by the Directive. The dissenting judges’ analysis of whether the professors were ‘identifiable’ seems, with respect, superficial in light of the Nowak judgment: was there really no way to deduce, in light of time stamps for instance, who would have been lecturing at that time?

Of the two lines of reasoning in the judgment supporting the application of the right to privacy, the concurring judges’ analysis is more convincing. ‘Surveillance of teaching’ is a notion that excites authoritarians in general, and hard Brexiteers in particular. Given that the exceptions to Article 8 ECHR can apply only if necessary in a ‘democratic society’, it makes sense to take account specifically of the importance of academic freedom when assessing whether the right to privacy has been interfered with – and more broadly of a worrying shift toward illiberal democracy in too many countries across Europe. It would also have been useful to state that ‘surveillance of teaching’ is not a legitimate ground for interference with the right to privacy.

Regardless of the safeguards in place, the announcement of an intention to place teaching under surveillance has a chilling effect on professors and students alike. While university management has a legitimate interest in ensuring that professors turn up to teach, and do so competently, there are many other routes to this end – student complaint or feedback procedures, for instance. Indeed, judgments like Nowak, as I noted already, help to ensure academics’ accountability to students. It’s unfortunate that this judgment missed the opportunity to directly confirm the importance of academic freedom as one of the pillars of democracy – rejecting the ever-louder screeching of those denouncing those with different opinions as ‘enemies of the people’.

Barnard & Peers: chapter 9
JHA4: chapter II:7

Photo credit: ZDnet

Friday, 3 November 2017

Who’s responsible for what happens on Facebook? Analysis of a new ECJ opinion



Lorna Woods, Professor of Internet Law, University of Essex

Who is responsible for data protection law compliance on Facebook fan sites? That issue is analysed in a recent opinion of an ECJ Advocate-General, in the case of Wirtschaftsakademie (full title: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein v Wirtschaftsakademie Schleswig-Holstein GmbH, in the presence of Facebook Ireland Ltd, Vertreter des Bundesinteresses beim Bundesverwaltungsgericht).

This case is one more in a line of cases dealing specifically with the jurisdiction of national data protection supervisory authorities, a line of reasoning which seems to operate separately from the Brussels I Recast Regulation, which concerns jurisdiction of courts over civil and commercial disputes.  While this is an Advocate-General’s opinion, and therefore not binding on the Court, if followed by the Court it would consolidates the Court’s prior broad interpretation of the Data Protection Directive.  While this might be the headline, it is worth considering a perhaps overlooked element of the data-economy: the role of the content provider in providing individuals whose data is harvested.

Facts

Wirtschaftsakademie set up a ‘fan page’ on Facebook.  The data protection authority in Schleswig-Holstein sought the deactivation of the fan page on the basis that visitors to the fan page were not warned that their personal data would be collected by the by means of cookies placed on the visitor’s hard disk. The purpose of that data collection was twofold: to compile viewing statistics for the administrator of the fan page; and to enable Facebook to target advertisements at each visitor by tracking the visitors’ web browsing habits, otherwise known as behavioural advertising.  Such activity must comply with the Data Protection Directive (DPD) (as implemented in the various Member States).  While the content attracting visitors was that of Wirtshaftsakademie, it relied on Facebook for data collection and analysis. It is here that a number of preliminary questions arise:

-          Who is the controller for the purposes of the data protection regime;
-          Which is the applicable national law; and
-          The scope of the national supervisory authority’s regulatory competence?

Opinion

Controller

The referring court had assumed that Wirtschaftsakademie was not a controller as it had no influence, in law or in fact, over the manner in which the personal data was processed by Facebook, and the fact that Wirtschaftsakademie had recourse to analytical tools for its own purposes does not change this [para 28]. Advocate General Bot, however, disagreed with this assessment, arguing that Wirtschaftsakademie was a joint controller for the purposes of the DPD – a possibility for which Article 2(d) DPD makes explicit provision (paras 42, 51, 52].  The Advocate General accepted that while the system was designed by Facebook so as to facilitate a data-driven business model and Wirtschaftsakademie was principally a user of the social network [para 53]. The Advocate General highlighted that without the participation of Wirtschaftsakademie the data processing in respect of the visitors to Wirtschaftsakademie could not occur; and he could end that processing by closing the relevant fan page down. In sum:

Inasmuch as he agrees to the means and purposes of the processing of personal data, as predefined by Facebook, a fan page administrator must be regarded as having participated in the determination of those means and purposes. [para 56]

Advocate General Bot further suggested that the use of the various filters included in the analytical tools provided meant that the user had a direct impact on how data was processed by Facebook. To similar effect, a user can also seek to reach specific audiences, as defined by the user.  As a result, the user has a controlling role in the acquisition phase of data processing by Facebook. The Advocate General rejected an formal analysis based on the terms of the contract concluded by the User and Facebook [para 60] and the fact that the user may be presented with ‘take it or leave it’ terms, does not affect the fact that the user may be a controller.

As a final point, the Advocate General referred to the risk of data protection rules being circumvented, arguing that:

had the Wirtschaftsakademie created a website elsewhere than on Facebook and implemented a tool similar to ‘Facebook Insights’ in order to compile viewing statistics, it would be regarded as the controller of the processing needed to compile those statistics [para 65].

A similar approach should be taken in relation to social media plug ins (such as Facebook’s like button), which allow Facebook to gather data on third party websites without the end-user’s consent (see Case C-40/17 Fashion ID, pending).

Having recognised that joint responsibility was an important factor in ensuring the protection of rights, the Advocate General – referring to the approach of the Article 29 Working Party on data protection – clarified that this did not mean that both parties would have equal responsibility, but rather their respective responsibility would vary depending on their involvement at the various stages of processing activities.

Applicable Law

Facebook is established outside the EU, but it has a number of EU established subsidiaries: the subsidiary which has responsibility for data protection is established in Ireland, while the other subsidiaries have responsibility for the sale of advertising.  This raises a number of questions: can the German supervisory authority exercise its powers and if so, against which subsidiary?

Applicable law is dealt with in Article 4 DPD, which refers to the competence of the Member State where the controller is established but which also envisages the possibility, in the case of a non-EU parent company, of multiple establishments.  The issue comes down to the interpretation of the phrase from Art. 4(1)(a), ‘in the context of the activities of an establishment’, which according to Weltimmo cannot be interpreted restrictively [para 87].  The Advocate General determined that there were two criteria [para 88]:

-          An establishment within the relevant Member State; and
-          Processing in connection with that establishment.

Relying on Weltimmo and Verein für Konsumenteninformation the Advocate General identified factors – which are based on the general freedom of establishment approach to the question of establishment looking for real activity through stable arrangements – the approach is not formalistic. Facebook Germany clearly satisfies these tests.

Referring to Article 29 Working Party Opinion 8/2010, the Advocate General re-iterated that in relation to the second criterion, it is context not location that is important. In Google Spain, the Court of Justice linked the selling of advertising (in Spain) to the processing of data (in the US) to hold that the processing was carried out in the context of the Spanish subsidiary given the economic nexus between the processing and the advertising revenue.  The business set up for Facebook here is the same, and the fact that there is an Irish office does not change the fact that the data processing takes place in the context of the German subsidiary.  The DPD does not introduce a one-stop shop; to the contrary, a deliberate choice was made to allow the application of multiple national legal systems (see Rec 19 DPD), and this approach is supported by the judgment in Verein für Konsumenteninformation in relation to Amazon.  The system will change with the entry into force of the General Data Protection Regulation (GDPR), but the Advocate General proposed that the Court should not pre-empt the entry into force of that legislation (due May 2018) in its interpretation, as the cooperation mechanism on which it depends is not yet in place [para 103].

Regulatory Competence

By contrast to Weltimmo, where the supervisory authority was seeking to impose a fine on a company established in another Member State, here the supervisory authority would be imposing German law on a German company.  There is a question, however, as to the addressee of any enforcement measure. On one interpretation, the German regulator should have the power only to direct compliance on the company established on its territory, even though that might not be effective. Alternatively, the DPD could be interpreted so as to allow the German regulator to direct compliance from Facebook Ireland. Looking at the fundamental role of controllers, Advocate General Bot suggested that this was the preferred solution. Article 28(1), (3) and (6) DPD entitle the supervisory authority of the Member State in which the establishment of the controller is located, by contrast to the position in Weltimmo, to exercise its powers of intervention without being required first to call on the supervisory authority of the Member State in which the controller is located to exercise its powers.

Comment

The novelty in this Opinion relates to the first question is significant because the business model espoused by social media companies depends on the participation of those providing content, who seem at the moment to take little responsibility for their actions.  The price paid by third parties (in terms of data) is facilitated by them, allowing them to avoid or minimise their business costs.  Should there be a consistency of enforcement applications against such users, this may gradually have an effect on the underlying platform’s business model.  While it is harder to regulate mice than elephants, at least these mice appear to be clearly within the geographic jurisdiction of the German regulator – and will remain so even when the GDPR is in force.

The Advocate General went out of his way to explain that there was no difference between the situation in issue here and that in the other relevant pending case, Case C-40/17 Fashion ID.  This case concerns the choice by a website provider to embed third party code allowing the collection of data in respect of visitors in the programming for the website for its own ends (increased visibility of and thus traffic to the website): the code in question is that underpinning the Facebook ‘like’ button, but would also presumably include similar codes from Twitter or Instagram.

If there was any doubt from cases – for example Weltimmo – about whether there is a one-stop shop (ie only one possible supervisory authority with jurisdiction across the EU) in the Data Protection Directive, the Advocate General expressly refutes this point.  In this context, it seems that this case adds little new, rather elaborating points of detail based on the precise factual set-up of Facebook operations in the EU. It seems well-established now that – at least under the DPD - clever multinational corporate structures cannot funnel data protection compliance through a chosen national regime.

It may be worth noting also the broad approach of the Advocate General to Google Spain when determining whether processing is in the context of activities. There the Court observed that:

‘in such circumstances, the activities of the operator of the search engine and those of its establishment situated in the Member State concerned are inextricably linked since the activities relating to the advertising space constitute the means of rendering the search engine at issue economically profitable and that engine is, at the same time, the means enabling those activities to be performed [Google Spain, para 56]

Here, the Advocate General focussed on the fact that social networks such as Facebook generate much of their revenue from advertisements posted on the web pages set up and accessed by users and that there is therefore an indissoluble link between the two activities.  Thus it seems that the Google Spain reasoning applies broadly to many free services paid for by user data, even if third parties – for example those providing the content on the page visited – are involved too. 

Of course, the GDPR does introduce a one-stop shop. Arguably therefore these cases are of soon to be historic interest only.  The GDPR proposes that the regulator in respect of the controller’s main EU establishment should have lead responsibility for regulation, with regulators in respect of other Member States being ‘concerned authorities’.  There are two points to note: first, there is a system in place to facilitate the cooperation of the relevant supervisory authorities Art 60), including possible recourse to a ‘consistency mechanism’ (Art 63 et seq); secondly, the competence of the lead authority to act in relation to cross-border processing in Article 66 operates without prejudice to the competence of each national supervisory authority in its own territory set out in Article 55.  The first of these two points concerns the attempt to limit regulatory arbitrage and a downward spiral of standards in the GDPR as applied and the broad approach to establishment. The interest of the recipient state in regulating means that there may be many cases involving ‘concerned authorities’.  The precise implications of the second point are not clear; note however that it seems that the one-stop shop as regards Facebook would not stop data protection authorities taking enforcement action against users such as Wirtschaftsakademie.


Photo credit: Deccan Chronicle