Showing posts with label personal data. Show all posts
Showing posts with label personal data. Show all posts

Wednesday, 10 December 2025

Image Rights and False Claims, Data Protection and Intermediary Immunity: the case of Russmedia

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Image credit: US Department of Defense

 

This Grand Chamber judgment of the Court of Justice in X v Russmedia Digital and Inform Media Press (Case C-492/23) handed down on 2 December 2025 concerns the scope of data protection rights and intermediary immunity in the context of the non-consensual use of someone’s image.  The judgment identifies:

- when someone has responsibilities under the GDPR,

- the relationship between those regulatory obligations and intermediary immunity, and

- the steps an data controller could take to satisfy those GDPR obligations.

 

It has been described as reshaping the obligations of online operators in the EU, while others have questioned how far the points in the judgments may be generalised to other situations.

 

Judgment

 

The Facts

 

Russmedia owns an online marketplace on which advertisements may be published. An unidentified user posted an advertisement falsely representing X as offering sexual services. The advert included X’s photographs (though there is no suggestion that these were intimate images) and phone number, all without her consent. Once notified, Russmedia removed the advert within an hour but the advertisement had been shared across several third party websites and remained accessible. X sued in the national courts in respect of her image rights, rights to reputation and data protection rights. The Romanian courts struggled with the question of whether Russmedia could claim the benefit of intermediary immunity (under the e-Commerce Directive (Directive 2000/31), provisions now replaced by the Digital Services Act (DSA)) and the extent of the obligations under the GDPR.

 

Is Russmedia subject to Obligations under the GDPR?

 

Obligations under GDPR arise when (1) personal data are (2) processed by (3) a data controller.

 

The CJEU commenced its analysis by noting the the information contained in the advert about X was personal data for the purposes of the GDPR and moreover that claims about a person’s sex life (implied in the advert) constituted “sensitive” personal data as protected by Article 9 GDPR, and that remained the case whether or not the claim was true.  Classification of the data as special category data means that there is a higher threshold to show lawful processing of those data. 

 

The Court further noted that “the operation of loading personal data on a webpage constitutes processing” for the purposes of the GDPR (para 54) and therefore covered the publication of the advert.

 

While this puts the advert within the scope of the GDPR, its obligations apply to data controllers and processors, so the question was whether, given Russmedia had no control over the content of the advert, was it a controller or joint controller? The Court reiterated previous jurisprudence to say (para 58) that:

 

any natural or legal person who exerts influence over the processing of such data, for his or her own purposes, and who participates, as a result, in the determination of the purposes and means of that processing, may be regarded as a controller in respect of such processing.

 

It noted also that there may be more than one entity which is a controller in respect of processing – this is the idea of joint controllers, although they may not have equal responsibility depending on the facts (para 63).  Joint decision making is not necessary for there to be joint controllers.

 

While the test for “controller” requires that the person processing the data does so for their own purposes, the Court added that this could include the situation “where the operator of an online marketplace publishes the personal data concerned for commercial or advertising purposes which go beyond the mere provision of a service which he or she provides to the user advertiser”  (para 66).  The Court in this case pointed to the fact that the terms of use give Russmedia “considerable freedom to exploit the information  published on that marketplace” including “the right to use published content, distribute it, transmit it, reproduce it, modify it, translate it, transfer it to partners and remove it at any time” (para 67). Russmedia is therefore not publishing solely on behalf of the user placing the advert. The Court also noted that Russmedia make the data in the advert accessible, allows the placing of anonymous adverts and sets the parameters for the dissemination of adverts (likely to contain personal data).

 

As a result of finding that the advert publishing platform was a joint controller the GDPR obligations bite in relation to the advert and must be able to demonstrate that the advert is published lawfully, which includes the requirement for consent for sensitive data (para 84 and 93) and the requirement for accuracy.  The CJEU notes that once published online and accessible to any Internet user, such data may be copied and reproduced on other websites, so that it may be difficult, if not impossible, for the data subject to obtain their effective deletion from the Internet.  The adds to the seriousness of the risks facing the data subject.

 

The GDPR also requires the implementation of technical and organisational measures – and this should be considered in the design of the service so that such data controllers can identify adverts containing sensitive data before they are published and to verify that such sensitive data is published in compliance with the principles of the GDPR (para 106).  Further, the controller must ensure that there are safety measures in place so that adverts containing sensitive data and not copied and unlawfully published elsewhere (para 122).

 

Are the GDPR Obligations Affected by Intermediary Immunity?

 

While the immunity provisions in the e-Commerce Directive are far-reaching, the e-Commerce Directive specified that it was not to apply to the Data Protection Directive (the legislation in  force at the time the e-Commerce Directive was drafted) and that included the immunities; the Court concluded that this meant the e-Commerce Directive could not interfere with the GDPR. It also specified that GDPR requirements here cannot be classified as general monitoring (which is prohibited by the e-Commerce Directive (and now the DSA)).

 

 

Conclusions, Implications and Questions

 

The ruling in this case does not match existing industry practice. It is not a bolt out of the blue, however, but builds on existing jurisprudence (eg Fashion ID (Case C-40/17)).  While the obligations required of Russmedia in this case may indicate, to some, a landmark shift in the Court’s approach, the judgment does rely on the specific facts in the case and, specifically, the point that “sensitive” data, which effectively requires explicit consent, is in issue. In principle, this could be relevant to other forms of sensitive content, notably non-consensual intimate images (NCII). Certainly, it re-emphasises data protection as a route for victims’ redress, if not preventing harm in the first place.

 

The ruling clarifies that a range of activities typically carried out by platforms - structuring, categorizing, and monetizing user content, can amount to determining “the purposes and means of processing personal data”, the test for responsibility as a controller under the GDPR (article 4 GDPR). In taking this approach, it differed from the Opinion of its Advocate-General (AG’s Opinion, para 120).  The Court noted that the definition of controller in the GDPR is broad – and this is to support the protection of individuals’ fundamental rights to privacy and data protection. Once a body is a controller, that body must be able to demonstrate compliance with the data protection principles, and take appropriate technical and organisational measures to ensure data processing is carried out in accordance with the GDPR. 

 

Here, some of the points that the Court relied on to determine that Russmedia was a joint controller could well be relevant to other services and not just online marketplaces. For example, many sites have broad terms of service similar to those the Court highlighted here; other services also allow anonymous posting and a key feature of many services is the making available of that content for advertising revenue purposes, as well as controlling how content is promoted. (Note the decision of the court in YouTube and Cyanado (Joined Cases C-682/18 and C-683/18), which suggested that automated content curation did not mean that a service is not neutral, is not directly relevant here as it relates to the conditions for maintaining intermediary immunity – and see Russmedia, AG’s Opinion, para 155)  It is unclear how many of these criteria need to be present for a service to constitute a controller in relation to the personal data in third party content it publishes (though the Court seems to list them as alternatives, suggesting any of them would suffice), or whether less far-reaching terms of service may be sufficient to stop a platform being a joint controller.  Where these conditions are satisfied, its impact need not be limited to advertising but to organic content containing third party personal data too.

 

The Court’s confirmation that the clear wording of the e-Commerce Directive, excluding the Data Protection Directive (the predecessor legislation to the GDPR) from its scope, meant that an intermediary cannot escape its own data protection responsibilities does not affect immunity from liability in respect of unlawful content.  Note that this decision was based on the wording of the e-Commerce Directive. This language has not been carried over to the DSA, which is expressed to operate without prejudice to, inter alia, the GDPR. It is not clear if or how this would change the Court’s interpretation. Immunity provisions from the e-Commerce Directive have been carried across to the DSA (albeit with a “carve out” in respect of consumer law in Article 6(3) DSA). While the EDPB has published guidance on the interplay of the GDPR and the DSA, it has looked at the question of the impact of the DSA requirements on data protection rather than the impact of data protection on the DSA.

 

The judgment suggests that services should design checks into their services to ensure compliance with the data protection obligations including pre-publication checks as to whether sensitive data is included and to check the identity of the person posting the material. Of course, while some sorts of posts (eg NCII) clearly constitute sensitive personal data, the outer edges of this category might not be clear cut. The Court here noted that the category should be interpreted broadly (para 52). It could be that some of the obligations could be passed on to the user uploading the advert through terms of service, though this might be capable of being abused by some users.  Further, the CJEU expects the site to prevent third party scraping so far as is possible – the judgment does not introduce strict liability in this regard.  What technical measures would be sufficient in practice remains uncertain.   This is very different from the reactive response required to maintain immunity under the e-Commerce Directive – and which has been the dominant framing until now. Assuming the position on immunity does not change, services may have to implement new systems, probably including automated tools and may ultimately affect choice of business model for some services.

 

There are questions about how this ruling impacts the DSA. How does a pre-check system differ from general monitoring. General monitoring is prohibited under Article 8 DSA (though specific monitoring is not)? The CJEU stated that systems to ensure GDPR compliance could not be classified as “general monitoring” (para 132) – but did not explain this statement any further. There is an argument to say that all content will need to be scanned to identify that which contains sensitive personal data – and by contrast to checking against a database of known CSAM images, for example, which might be considered specific monitoring, this is a more open ended obligation. It is unclear whether there are other routes to pre-check which do not involve content scanning.  The requirements to check whether the person posting the personal data is the person to which the data relates (or is otherwise lawfully processing) may make, for example, anonymity difficult to maintain and it is unclear what level of identity verification would be acceptable.  There are also questions about how this system of pre-checks affects the neutrality of the platform and consequently the possibility for the platform to claim immunity (in respect of other claims relating to the content) under Article 6 DSA.

 

The position in the UK may be slightly different, however. Section 6(1) European Union (Withdrawal) Act provides that decisions of the CJEU post-dating 31 December 2020 do not bind UK courts although they may have regard to such judgments. The provisions which would have had the effect of removing the status of binding precedent from decisions of the CJEU made on or before that date have now not been brought into force (but they remain on the statute book), as the Labour Government revoked the relevant commencement regulations.  Furthermore, old case law from the Northern Irish courts (pre-dating Brexit), CG v. Facebook, suggested the the e-Commerce Directive (the relevant law at the time) could apply to data protection claims.

Sunday, 13 October 2024

Latest Updates on The Legitimate Interest Ground for Processing Personal Data (Article 6(1)(f) of GDPR): the latest CJEU Case and EDPB New Guidelines

 

 




 

Aolan Li*

*The author is a third-year PhD candidate in Law at Queen Mary University of London. Her ongoing doctoral thesis research delves into the application of Article 6(1)(f) of GDPR from a comparative perspective. Email: aolan.li@qmul.ac.uk

Photo credit: TheDigitalArtist, via Wikipedia Commons

 

A positive spirit has spread among business-side stakeholders across the EU since the Court of Justice of the European Union (CJEU) published its preliminary ruling in the Koninklijke Nederlandse Lawn Tennisbond case (C-621/22) on 4 October 2024, where the court confirms a purely commercial interest could constitute a legitimate interest for processing personal data under Article 6(1)(f) of GDPR. Commentators go as far as to say - “what this means is that under the GDPR, your data can be used without your consent solely for a company’s commercial interests.”

The preceding saying is a total misunderstanding. The positive spirit should have been dampened as, on 9 October 2024, the European Data Protection Board (EDPB) published its new guidelines on Article 6(1)(f) for public consultation (hereafter as the new EDPB guidelines).

Bearing in mind the optimistic bubbles in the market, this writing articulates the EDPB’s stringent stance on the application of Article 6(1)(f) of GDPR, focusing on what has changed compared to the Article 29 Data Protection Working Party’s opinion on the legitimate interest ground under Directive 95/46/EC (hereafter as the WP29 Opinion).

General remark

The newly published EDPB guidelines align with the WP29 Opinion in some basic stances. First and foremost, the recognition of a legitimate interest is not itself sufficient to rely on Article 6(1)(f) of GDPR as a legal basis (this is why the saying is misleading) as there are three cumulative conditions for its application. Secondly, Article 6(1)(f) of GDPR should not be used “by default” nor as a “last resort”. The open-ended nature of Article 6(1)(f) has a unique role in the EU data protection law.

Not surprisingly, the new EDPB guidelines also substantially update the WP29 Opinion.

The update is partially attributed to judgments of CJEU issued after the adoption of the WP29 Opinion, including Rīgas (Case C-13/16), Fashion ID (C-40/17), TK (C-708/18), MICM (C-597/19), Meta v Bundeskartellamt (C-252/21), SCHUFA Holding (Joined Cases C-26/22 and C-64/22), and the latest Koninklijke Nederlandse Lawn Tennisbond (C-621/22). Many practical examples in the new guidelines mirror scenarios disputed in the abovementioned cases. For example, example 4 is analogous to Rīgas.

Building upon more detailed case law, the new EDPB guidelines are more logical and clearly articulated. Unlike the WP29 Opinion, the new guidelines make effects to draw a clearer line between the six grounds for legitimising data processing under Article 6(1) of GDPR. Also, the new guidelines follow the now well-accepted three-step approach to applying Article 6(1)(f), which was established by the CJEU in its judgment in Rīgas.

The update also corresponds to the evolvement of the law itself (GDPR vs Data Protection Directive). GDPR has strengthened data subject rights. It is worth noting the improvement of the right to object - a specific right for the processing based on Article 6(1)(e) and (f) of GDPR - as the burden of proof has been reversed on the controller. Also, GDPR and CJEU case law have escalated the reasonable expectation of data subjects to a more significant position in determining the application of Article 6(1)(f) of GDPR. Therefore, the new guidelines are observed to enhance the position of data subjects accordingly.

Besides being consistent with legislative developments and the CJEU’s case law, the EDPB is observed to add its unique understanding to narrow down the scope of Article 6(1)(f) of GDPR; here’s why I said the EDPB takes a stringent stance. The next part provides more discussions.

Overall, the new guidelines have been compiled from rich and up-to-date sources and provide much more nuanced interpretations of Article 6(1)(f) of GDPR. However, one might lament that Part IV of the new guidelines hesitates to touch on the application of Article 6(1)(f) of GDPR in more complicated and controversial contexts. For example, its application in the credit scoring industry seems like a real-world need, as demonstrated in SCHUFA Holding. Let alone its silence on applying Article 6(1)(f) of GDPR in AI-related scenarios.

The writing below touches on the substantial content of Article 6(1)(f) of GDPR. However, it does not intend to sketch the 37-page guidelines reductively. Instead, it aims to highlight the stringent stance of the new guidelines, read together with the Koninklijke Nederlandse Lawn Tennisbond case.

The Three Steps Approach

As mentioned above, three cumulative conditions must be fulfilled to rely on Article 6(1)(f) of GDPR as a legal basis, called the three steps approach, which are 1) the pursuit of a legitimate interest by the controller or by a third party; 2) the need to process personal data for the purposes of the legitimate interest(s) pursued; 3) the interests or fundamental freedoms and rights of the concerned data subjects do not take precedence over the legitimate interest(s) of the controller or of a third party (the new EDPB guidelines, p 2).

For the first step, the new guidelines narrow down the scope of interests with respect to the controller’s own interests and disentangle the third party’s interests from wider public interests.

As the information circulated, the qualifier “legitimate” is interpreted broadly, covering any interests that are not contrary to the law (Koninklijke Nederlandse Lawn Tennisbond, para 49).

However, sourced to the CJEU judgment in Meta v. Bundeskartellamt, the new guidelines confine that “as a general rule, the interest pursued by the controller should be related to the actual activities of the controller.” (the new EDPB guidelines, para 19) It means that, within the meaning of Article 6(1)(f) of GDPR, a controller whose activity is economic and commercial in nature is only allowed to pursue economic and commercial-related interests.

Other legitimate but non-economic/commercial interests might fall within the scope of interest(s) pursued by a third party. The new guidelines clarify that the controller needs to demonstrate the legitimate interest(s) are pursued by one or more specific third parties (para 20-25) and should not be confused with broader public interests despite the fact they can overlap, as seen in SCHUFA Holding.

Remarkably, the new EDPB guidelines indicate that relying on the interest(s) pursued by a third party in the first step is generally more challenging to pass the latter two steps (the necessity and balance test) than relying on the controller's own interests. (para 30)

For the second step, the processing involved should be necessary for the purposes of that interest identified in the first step, called the necessity test. The concept of necessity has its own free-standing meaning in EU law. The controller must demonstrate that there are no other reasonable, just as effective, but less intrusive alternatives to achieve the pursued legitimate interests.

Despite no given example in the new EDPB guidelines, the CJEU judgment in Koninklijke Nederlandse Lawn Tennisbond provides a least intrusive scenario in the direct marketing context. To be brief, without asking for consent, a Netherlands sports federation (KNLTB) sold its members’ personal data to its sponsors for the latter’s marketing purposes. The court considers it possible for KNLTB “to inform its members beforehand and to ask them whether they want their data to transmitted to those third parties for advertising or marketing purposes.” (para 51) The court deems a procedure as such may involve the least intrusion of data subjects’ rights and compliance with data minimisation principles. As will be explained below, the proposed approach resonates with the right to object and controllers’ notification obligations.

For the third step, the balance test entails a balancing of the controller side's rights and interests against those of the data subject side. The controller needs to ascertain, on a case-by-case basis, that the processing at issue would not disproportionately impact the data subject’s rights and interests.

One can observe the improved position of data subjects directly from the structures of exercising the balance test in the new EDPB guidelines and the WP29 Opinion. (See table below)

Methodology for the balancing test under new EDPB guidelines

Methodology for the balancing test under the WP29 opinion

 

The data subjects’ interests, fundamental rights and freedoms.

 

 

Assessing the controller’s legitimate interest. -      Exercise of a fundamental right;

-          Public interests/the interests of the wider community;

-          Other legitimate interests;

-          Legal and cultural/societal recognition of the legitimacy of the interests.

 

 

 

The impact of the processing on data subjects, including

-          The nature of the data to be processed;

-          The context of the processing;

-          Any further consequences of the processing.

 

 

 

Impact on the data subjects

-          Assessment of impact;

-          Nature of the data;

-          The way data are being processed;

-          Reasonable expectations of the data subject;

-          Status of the data controller and data subject.

 

 

 

The reasonable expectations of the data subject.

 

 

Provisional balance.

 

 

The final balancing of opposing rights and interests, including the possibility of further mitigating measures.

 

 

Additional safeguards applied by the controller to prevent any undue impact on the data subjects.

 

Despite most of the content continuing to work, some remarkable points exist.

Firstly, the reasonable expectation of the data subject has been escalated to an independent element. It goes beyond the controller’s notification obligation and highlights the data subject’s genuine understanding; as the new EDPB guidelines put it, more than the mere fulfilment of Articles 12, 13, and 14 is needed to consider that the data subject can reasonably expect the said processing. (para 53)

Secondly, the mitigating measures, be it technical and organisational, within the meaning of Article 6(1)(f) of GDPR must go beyond existing principles and obligations set out in the GDPR. In this sense, the new EDPB guidelines encourage controllers who intend to rely on Article 6(1)(f) of GDPR to pursue a higher level of personal data protection than legal obligations.

Data subject rights

A comprehensive review of the enhanced data subject rights under the GDPR goes beyond the subject matter of this writing. Calling back to the least intrusive approach proposed in Koninklijke Nederlandse Lawn Tennisbond, this part of the writing articulates the significance of controllers’ notification obligations and data subjects’ right to object in the context of Article 6(1)(f) of GDPR.

The court considers that KNLTB can inform its members beforehand. KNLTB’s notification obligations are set out in Articles 13 and 14 of GDPR. Its members (data subjects) should be informed about, among other things, the legal basis of processing, the specific legitimate interests pursued by KNLTB or its sponsors, and data subject rights. According to Article 13(3), KNLTB should inform its member concerned prior to further processing.

The court also considers it good practice for KNLTB to ask members concerned whether they want their data transmitted to third parties for advertising or marketing purposes. One might feel at odds with the reintroduction of “consent” in assessing Article 6(1)(f) of GDPR. Actually, it is better to understand the “ask” as informing its members concerned about their right to object under Article 21 of GDPR.

The objection to direct marketing based on Article 6(1)(f) of GDPR is absolute. In other cases, however, the controller might have compelling legitimate grounds to disapprove the right. Here, it involves another balancing test to determine whether the controller has a compelling legitimate ground. Unlike Directive 95/46, the burden of proof is on the controller.

The new EDPB guidelines promote the idea that the controller’s compelling legitimate grounds can only be recognised in exceptional cases. The controller cannot circumvent the right to object by merely showing that the processing would be beneficial to the controller. Rather, the concept of compelling is understood as essential to the controller.

From the preceding standpoint, the right to object has been improved in favour of the data subject, and it is not much inferior to the right to withdraw consent.

Concluding remarks

In conclusion, while the CJEU’s preliminary ruling in the Koninklijke Nederlandse Lawn Tennisbond case initially sparked optimism among business stakeholders by holding that purely commercial interests could qualify as legitimate under Article 6(1)(f) of the GDPR, this enthusiasm is misplaced. The ongoing EDPB’s new guidelines underscore a more restrictive interpretation of the legitimate interest ground than the earlier WP29 Opinion, reinforcing the need for careful application and a balanced approach to personal data protection. This writing calls for a self-reassessment of GDPR compliance, in particular for controllers relying on legitimate interest as a main legal basis.

Friday, 4 August 2017

Transferring personal data outside the EU: Clarification from the ECJ?



Lorna Woods, Professor of Internet Law, University of Essex

Opinion 1/15 EU/Canada PNR Agreement, 26th July 2017

Facts

Canadian law required airlines, in the interests of the fight against serious crime and terrorism, to provide certain information about passengers (API/PNR data), which obligation required airlines under EU data protection regulations to transfer data to outside the EU.  The PNR data includes the names of air passengers, the dates of intended travel, the travel itinerary, and information relating to payment and baggage. The PNR data may reveal travel habits, relationships between two individuals, information on the financial situation or the dietary habits of individuals. To regularise the transfer of data, and to support police cooperation, the EU negotiated an agreement with Canada specifying the data to be transferred, the purposes for which the data could be used, as well as some processing safeguard provisions (e.g. use of sensitive data, security obligations, oversight requirements, access by passengers).  The data was permitted to be retained for five years, albeit in a depersonalised form.  Further disclosure of the data beyond Canada and the Member States was permitted in limited circumstances.  The European Parliament requested an opinion from the Court of Justice under Article 218(11) TFEU as to whether the agreement satisfied fundamental human rights standards and whether the appropriate Treaty base had been used for the agreement.

Opinion

The Court noted that the agreement fell within the EU’s constitutional framework, and must therefore comply with its constitutional principles, including (though this point was not made express), respect for fundamental human rights (whether as a general principle or by virtue of the EU Charter – the EUCFR).

After dealing with questions of admissibility, the Court addressed the question of appropriate Treaty base. It re-stated existing principles (elaborated, for example, in Case C263/14 Parliament v Council, judgment 14 June 2016, EU:C:2016:435) with regard to choice of Treaty base generally: the choice must rest on objective factors (including the aim and the content of that measure) which are amenable to judicial review.  In this context the Court found that the proposed agreement has two objectives: safeguarding public security; and safeguarding personal data [opinion, para 90].  The Court concluded that the two objectives were inextricably linked: while the driver for the need to PNR data was protection of public security, the transfer of data would be lawful only if data protection rules were respected [para 94].  Therefore, the agreement should be based on both Article 16(2) (data protection) and Article 87(2)(a) TFEU (police cooperation).  It held, however, that Article 82(1)(d) TFEU (judicial cooperation) could not be used, partly because judicial authorities were not included in the agreement.

Looking at the issue of data protection, the Court re-stated the question as being ‘on the compatibility of the envisaged agreement with, in particular, the right to respect for private life and the right to the protection of personal data’ [para 119].  It then commented that although both Article 16 TFEU and Article 8 EUCFR enshrine the right to data protection, in its analysis it would refer to Article 8 only, because that provision lays down in a more specific manner the conditions for data processing.  The agreement refers to the processing of data concerning identified individuals, and therefore may affect the fundamental right to respect for private life guaranteed in Article 7 EUCFR as well as the right to protection to personal data in Article 8 EUCFR. The Court re-iterated a number of principles regarding the scope of the right to private life:

‘the communication of personal data to a third party, such as a public authority, constitutes an interference with the fundamental right enshrined in Article 7 of the Charter, whatever the subsequent use of the information communicated. The same is true of the retention of personal data and access to that data with a view to its use by public authorities. In this connection, it does not matter whether the information in question relating to private life is sensitive or whether the persons concerned have been inconvenienced in any way on account of that interference’ [para 124].

The transfer of PNR data and its retention and any use constituted an interference with both Article 7 [para 125] and Article 8 EUCFR [para 126]. In assessing the seriousness of the interference, the Court flagged ‘the systematic and continuous’ nature of the PNR system, the insight into private life of individuals, the fact that the system is used as an intelligence tool and the length of time for which the data is available.

Interferences with these rights may be justified.  Nonetheless, there are constraints on any justification: Article 8(2)  of the EU Charter specifies that processing must be ‘for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law’; and, according to Article 52(1) of the EU Charter, any limitation must be provided for by law and respect the essence of those rights and freedoms. Further, limitations must be necessary and genuinely meet objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others. 

Following WebMindLicenses (Case C‑419/14, judgment of 17 December 2015, EU:C:2015:832, para 81), the law that permits the interference should also set down the extent of that interference. Proportionality requires that any derogation from and limitation on the protection of personal data should apply only insofar as is strictly necessary. To this end and to prevent the risk of abuse, the legislation must set down ‘clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards’, specifically ‘indicat[ing] in what circumstances and under which conditions a measure providing for the processing of such data may be adopted’ [para 141], especially when automated processing is involved.

The Court considered whether there was a legitimate basis for the processing, noting that although passengers may be said to consent to the processing of PNR data, this consent related to a different purpose. The transfer of the PNR data is not conditional on the specific consent of the passengers and must therefore be grounded on some other basis, within the terms of Article 8(2) EUCFR. The Court rejected the Parliament’s submission that the meaning of ‘law’ be restricted to ‘legislative act’ internally. The Court, following the reasoning of the Advocate General, found that in this regard the international agreement was the external equivalent of the legislative act.

In line with its previous jurisprudence, the Court accepted that public security is an objective of public interest capable of justifying even serious interferences with Articles 7 and 8 EUCFR. It also noted that everybody has the right to security of the person (Art. 6 EUCFR), though this point was taken no further. The Court considered that PNR data revealed only limited aspects of a person’s private life, so that the essence of the right was not adversely affected [para 151]. In principle, limitation may then be possible. The Court accepted that PNR data transfer was appropriate, but not that the test of necessity was satisfied. It agreed with the Advocate General that the categories of data to be transferred were not sufficiently precise, specifically ‘available frequent flyer and benefit information (free tickets, upgrades, etc.)’, ‘all available contact information (including originator information)’ and ‘general remarks including Other Supplementary Information (OSI), Special Service Information (SSI) and Special Service Request (SSR) information’. Although the agreement required the Canadian authorities to delete any data transferred to them which fell outside these categories, this obligation did not compensate for the lack of precision regarding the scope of these categories.

The Court noted that the agreement identified a category of ‘sensitive data’; it was therefore to be presumed that sensitive data would be transferred under the agreement. The Court then reasoned:

any measure based on the premiss that one or more of the characteristics set out in Article 2(e) of the envisaged agreement may be relevant, in itself or in themselves and regardless of the individual conduct of the traveller concerned, having regard to the purpose for which PNR data is to be processed, namely combating terrorism and serious transnational crime, would infringe the rights guaranteed in Articles 7 and 8 of the Charter, read in conjunction with Article 21 thereof [para 165]

Additionally, any transfer of sensitive data would require a ‘precise and particularly solid’ reason beyond that of public security and prevention of terrorism. This justification was lacking. The transfer of sensitive data and the framework for the use of those data would be incompatible with the EU Charter [para 167].

While the agreement tried to limit the impact of automated decision-making, the Court found it problematic because of the need to have reliable models on which the automated decisions were made. These models, in the view of the Court, must produce results that identify persons under a ‘reasonable suspicion’ of participation in terrorist offences or serious transnational crime and should be non-discriminatory. Models/databases should also be kept up-to-date and accurate and subject to review for bias. Because of the error risk, all positive automated decisions should be individually checked.

In terms of the purposes for processing the data, the definition of terrorist offences and serious transnational crime were sufficiently clear. There were however other provisions, allowing case-by-case assessment.  These provisions (Article 3(5)(a) and (b) of the treaty) were found to be too vague.  By contrast, the Court determined that the authorities who would receive the data were sufficiently identified. Further, it accepted that the transfer of data of all passengers, whether or not they were identified as posing a risk or not, does not exceed what is necessary as passengers must comply with Canadian law and ‘the identification, by means of PNR data, of passengers liable to present a risk to public security forms part of border control’ [para 188].

Relying on its recent judgment in Tele2/Watson (Joined Cases C‑203/15 and C‑698/15, EU:C:2016:970), which I discussed here, the Court reiterated that there must be a connection between the data retained and the objective pursued for the duration of the time the data are held, which brought into question the use of the PNR data after passengers had disembarked in Canada.  Further, the use of the data must be restricted in accordance with those purposes. However,

where there is objective evidence from which it may be inferred that the PNR data of one or more air passengers might make an effective contribution to combating terrorist offences and serious transnational crime, the use of that data does not exceed the limits of what is strictly necessary [para 201].

Following verification of passenger data and permission to enter Canadian territory, the use of PNR data during passengers’ stay must be based on new justifying circumstances. The Court expected that this should be subject to prior review by an independent body. The Court held that the agreement did not meet the required standards.  Similar points were made, even more strongly, in relation to the use of PNR data after the passengers had left Canada. In general, this was not strictly necessary, as there would no longer be a connection between the data and the objective pursued by the PNR Agreement such as to justify the retention of their data. PNR data may be stored in Canada, however, when particular passengers present a risk of terrorism of serious transnational crime. Moreover, given the average lifespan of international serious crime networks and the duration and complexity of investigations relating to them, the Court did not hold that the retention of data for five years went beyond the limits of necessity [para 209].

The agreement allows PNR data to be disclosed by the Canadian authority to other Canadian government authorities and to government authorities of third countries. The recipient country must satisfy EU data protection standards; an international agreement between the third country and the EU or an adequacy decision would be required. There is a further, unlimited and ill-defined possibility of disclosure to individuals ‘subject to reasonable legal requirements and limitations ... with due regard for the legitimate interests of the individual concerned’. This provision did not satisfy the necessity test.

To ensure that the individuals’ rights to access their data and to have data rectified is protected, in line with Tele2/Watson, passengers must be notified of the transfer of their PNR data to Canada and of its use as soon as that information is no longer liable to jeopardise the investigations being carried out by the government authorities referred to in the envisaged agreement. In this respect, the agreement is deficient. While passengers are told that the data will be used for security checks/border control, they are not told whether their data has been used by the Canadian Competent Authority beyond use for those checks.  While the Court accepted that the agreement provided passengers with a possible remedy, the agreement was deficient in that it did not guarantee in a sufficiently clear and precise manner that the oversight of compliance would be carried out by an independent authority, as required by Article 8(3) EUCFR.

Comment

There are lots of issues in this judgment, of interest from a range of perspectives, but its length and complexity means it is not an easy read. Because of these characteristics, a blog – even a lengthy blog – could hardly do justice to all issues, especially as in some instances, it is hardly clear what the Court’s position is.

On the whole the Court follows the approach of its Advocate General, Mengozzi, on a number of points specifically referring back to his Opinion. There is, as seems increasingly to be the trend, heavy reliance on existing case law and it is notable that the Court refers repeatedly to its ruling in Tele2/Watson.  This may be a judicial attempt to suggest that Tele2/Watson was not an aberration and to reinforce its status as good law, if that were in any doubt. It also operates to create a body of surveillance law rulings that are hopefully consistent in underpinning principles and approach, and certainly some of the points in earlier case law are reiterated with regards to the importance of ex ante review by independent bodies, rights of redress and the right of individuals to know that they have been subject to surveillance.

The case is of interest not only in regards mass surveillance but more generally in relation to Article 16(2) TFEU. It is also the first time an opinion has been given on a draft agreement considering its compatibility with human rights standards as well as the appropriate Treaty base. In this respect the judgment may be a little disappointing; certainly on Article 16, the Court did not go into the same level of detail as in the AG’s opinion [AG114-AG120]. Instead it equated Article 16 TFEU to Article 8 EUCFR, and based its analysis on the latter provision.

As a general point, it is evident that the Court has adopted a detailed level of review of the PNR agreement.  The outcome of the case has widely been recognised as having implications, as –for example – discussed earlier on this blog.  Certainly, as the Advocate General noted, possible impact on other PNR agreements [AG para 4] which relate to the same sorts of data shared for the same objectives.  The EDPS made this point too, in the context of the EU PNR Directive:

Since the functioning of the EU PNR and the EU-Canada schemes are similar, the answer ofthe Court mayhave a significant impact on the validity of all other PNR instruments …. [Opinion 2/15, para 18]

There are other forms of data sharing agreement, for example, SWIFT, the Umbrella Agreement,  the Privacy Shield (and other adequacy decisions) the last of which is coming under pressure in any event (DRI v Commission (T-670/16) and La Quadrature du Net and Others v Commission (T-738/16)).  Note that in this context, there is not just a question of considering the safeguards for protection of rights but also relates to Treaty base.  The Court found that Article 16 must be used and that – because there was no role for judicial authorities, still less their cooperation – the use of Article 82(1)(d) is wrong.  It has, however, been used for example in regards to other PNR agreements.  This means that that the basis for those agreements is thrown into doubt.

While the Court agreed with its Advocate General to suggest that a double Treaty base was necessary given the inextricable linkage, there is some room to question this assumption.  It could also be argued that there is a dominant purpose, as the primary purpose of the PNR agreement is to protect personal data, albeit with a different objective in view, that of public security. In the background, however, is the position of the UK, Ireland and Denmark and their respective ‘opt-outs’ in the field. While a finding of a joint Treaty base made possible the argument of the Court that:

since the decision on the conclusion of the envisaged agreement must be based on both Article 16 and Article 87 TFEU and falls, therefore, within the scope of Chapter 5 of Title V of Part Three of the FEU Treaty in so far as it must be founded on Article 87 TFEU, the Kingdom of Denmark will not be bound, in accordance with Articles 2 and 2a of Protocol No 22, by the provisions of that decision, nor, consequently, by the envisaged agreement. Furthermore, the Kingdom of Denmark will not take part in the adoption of that decision, in accordance with Article 1 of that protocol. [para 113, see also para 115]

The position would, however, have been different had the agreement be found to have been predominantly about data protection and therefore based on Article 16 TFEU alone.

Looking at the substantive issues, the Court clearly accepted the need for PNR to challenge the threat from terrorism, noting in particular that Article 6 of the Charter (the “right to liberty and security of person”) can justify the processing of personal data. While it accepted that this resulted in systemic transfer of large quantities of people, we see no comments about mass surveillance. Yet, is this not similar to the ‘general and indiscriminate’ collection and analysis rejected by the Court in Tele2/Watson [para 97], and which cannot be seen as automatically justified even in the context of the fight against terrorism [para 103 and 119]? Certainly, the EDPS took the view in its opinion on the EU PNR Directive that “the non-targeted and bulk collection and processing of data of the PNR scheme amount to a measure of general surveillance” [Opinion 1/15, para 63]. It may be that the difference is in the nature of the data; even if this is so, the Court does not make this argument. Indeed, it makes no argument but rather weakly accepts the need for the data.  On this point, it should be noted that “the usefulness of large-scale profiling on the basis of passenger data must be questioned thoroughly, based on both scientific elements and recent studies” [Art. 29 WP Opinion 7/2010, p. 4]. In this aspect, Opinion 1/15 is not as strong a stand as Tele2/Watson [c.f para 105-106]; it seems that the Court was less emphatic about significance of surveillance even than the Advocate General [AG 176].

In terms of justification, while the Court accepts that the transfer of data and its analysis may give rise to intrusion, it suggests that the essence of the right has not been affected. In this it follows the approach in the communications data cases.  It is unclear, however, what the essence of the right is; it seems that no matter how detailed a picture of an individual can be drawn from the analysis of data, the essence of the right remains intact.  If the implication is that where the essence of the right is affected then no justification for the intrusion could be made, a narrow view of essence is understandable.  This does not, however, answer the question of what the essence is and, indeed, whether the essence of the right is the same for Article 7 as for Article 8.  In this case, the Court has once again referred to both articles, without delineating the boundaries between them, but then proceeded to base its analysis mainly on Article 8.

In terms of relationship between provisions, it is also unclear what the relationship is between Art 8(2) and Art 52.  The Court bundles the requirements for these two provisions together but they serve different purposes. Article 8(2) further elaborates the scope of the right; Article 52 deals with the limitations of Charter rights.  Despite this, it seems that some of the findings will apply Article 52 in the context of other rights. For example, in considering that an international agreement constitutes law for the purposes of the EUCFR, the Court took a broader approach to meaning of ‘law’ than the Parliament had argued for.  This however seems a sensible approach, avoiding undue formality. 

One further point about the approach to interpreting exceptions to the rights and Article 52 can be made. It seems that the Court has not followed the Advocate General who had suggested that strict necessity should be understood in the light of achieving a fair balance [AG207].
 
Some specific points are worth highlighting. The Court held that sensitive data (information that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, information about a person’s health or sex life) should not be transferred. It is not clear what interpretation should be given to these data, especially as regards proxies for sensitive data (e.g. food preferences may give rise to inferences about a person’s religious beliefs).

One innovation in the PNR context is the distinction the Court introduced between use of PNR data on entry, use while the traveller is in Canada, and use after the person has left, which perhaps mitigates the Court’s acceptance of undifferentiated surveillance of travellers.  The Court’s view of the acceptability of use in relation to this last category is the most stringent.  While the Court accepts the link between the processing of PNR data on arrival, after departure the Court expects that link to be proven, and absent such proof, there is no justification for the retention of data. Does this mean that on departure PNR data of persons who are not suspected of terrorism or transnational crime should be deleted at the point of their departure? Such a requirement surely gives rise to practical problems and would seem to limit the Court’s earlier acceptance of the use of general PNR data to verify/update computer models [para 198].

One of the weaknesses of the Court’s caselaw so far has been a failure to consider investigatory techniques, and whether all are equally acceptable.  Here we see the Court beginning to consider the use of automated intelligence techniques.  While the Court does not go into detail on all the issues to which predictive policing and big data might give rise, it does note that models must be accurate.  It also refers to Article 21 EUCFR (discrimination).  In that this section is phrased in general terms, it has potentially wide-reaching application, potentially even beyond the public sector.

The Court’s judgment has further implications as regards the sharing of PNR and other security data with other countries besides Canada, most notably in the context of EU/UK relations after Brexit. Negotiators now have a clearer indication of what it will take for an agreement between the EU and a non-EU state to satisfy the requirements of the Charter, in the ECJ’s view. Time will tell what impact this ruling will have on the progress of those talks.

Barnard & Peers: chapter 25
JHA4: chapter II:9

Photo credit: ctvnews.ca

Wednesday, 4 January 2017

IP addresses as personal data - the CJEU's judgment in C-582/14 Breyer



Marcin Kotula, Legal Officer at the European Commission

The views expressed are purely those of the author and may not in any circumstances be regarded as stating an official position of the European Commission

Background

In the Breyer case the CJEU was asked by the German Supreme Court (Bundesgerichtshof) if dynamic IP addresses are personal data within the meaning of the EU Data Protection Directive and to what extent they can be stored and processed to ensure the general operability of websites. Mr Breyer, the applicant in this case, is a German politician and privacy activist. He visited various websites of the German federal institutions. The information about the IP addresses of the visitors (or more precisely of the owners of the devices from which the websites were visited) as well as the information about the name of the accessed web page or file, the terms entered in the search fields, the time of access and the quantity of data transferred is stored in the log files after the visit.

One of the aims of the storage of those data is to prevent cyberattacks and enable prosecution of those who committed them. Mr Breyer did not agree with the storage of his IP address after the consultation of the websites and in the proceedings before the German court he requested the German government to cease this practice. The case eventually went up to the German Supreme Court which decided to seek interpretative guidance from the CJEU.

The questions of the German Supreme Court were specifically focussed on dynamic IP addresses. These are less privacy-invasive than static IP addresses. The difference between them is that the dynamic ones change with every new connection to the internet and the static ones do not. IP addresses are assigned by Internet Service Providers (ISPs) and take the form of a series of digits. In principle, in itself they do not reveal the identity of a specific natural person but can be combined with other information to identify the owner of a device that connects to the internet. Typically such other information is at the disposal of the ISP. In its Scarlet Extended judgment of 2011 the CJEU clarified that, from the perspective of the ISP, IP addresses are personal data. However, in the Breyer case the scenario was different. The German federal institutions which run the websites only had the IP addresses and the additional information that is needed to identify the visitors of those websites was held by the ISPs. The CJEU was asked to clarify if the German federal institutions (the data controllers) should treat the IP addresses as personal data even if they are not in possession of this additional information.

The CJEU's analysis

In its judgment of 19 October 2016 the CJEU referred to the definition of personal data in Article 2(a) of the Data Protection Directive 95/46/EC. This definition covers any information that relates to an individual who is identifiable, either directly or indirectly. In consequence, information can be regarded as personal data even if it does not itself identify a specific person.

Further indications on how to assess identifiability are given in Recital 26 of the Directive. This Recital clarifies that when determining if a given person is identifiable one should look at all the means that the data controller or any other person are likely to reasonably use to identify the person. On the basis of those indications the CJEU went on to examine if it is reasonably likely that the IP addresses held by the German federal institutions will be combined with the additional information held by the ISPs. The CJEU followed the line taken on this point in the Opinion of the Advocate General  (AG) and stated that the combination would not be reasonably likely if it was prohibited by law or disproportionately difficult in terms of time, cost and man-power. In the German scenario, the ISPs are not allowed to directly transmit such information to website providers. On the other hand, in the event of cyber-attacks the website providers can contact the competent authorities which then can obtain the additional information from the ISPs. The availability of this legal channel led the CJEU to conclude that, for the German federal institutions, the IP addresses of the visitors of their websites are personal data because these visitors can be identified with the help of the competent authorities and of the ISPs.

The CJEU then examined if the German federal institutions can store and process the IP addresses after the end of the visit of their website to ensure the general operability of the websites. Under the relevant provisions of the German Law on telemedia (Telemediengesetz - TMG) the collection and processing of users' data is allowed only in so far as this is necessary to facilitate and charge for the specific use of the online service. This does not seem to include the purpose of ensuring the general operability of the websites. The CJEU was therefore asked to clarify if the German provisions are compatible with Article 7(f) of the Data Protection Directive. The latter Article authorises the processing of personal data when it is necessary for the legitimate interests of the data controller or of third parties to whom the data are disclosed. This authorisation does not apply if the legitimate interests are overridden by the fundamental rights and freedoms of the person whose data is at stake (the data subject).

Since the maintenance of the operability of the websites and the prevention of cyberattacks might ultimately lead to criminal proceedings against the perpetrators the CJEU contemplated if the processing of IP addresses in such circumstances is not excluded from the Directive altogether. It looked into Article 3(2) first indent of the Directive which excludes the processing of personal data carried out in the context of criminal law activities of the State. It concluded that in the scenario at hand the German federal institutions are not acting as State authorities but rather as individuals.

As far as Article 7(f) is concerned the CJEU referred to its case-law (the ASNEF judgment of 2011). This judgment acknowledges that the legal bases for the processing of personal data that are set out in Article 7 of the Directive are exhaustive and that the Member States cannot add any new principles or impose additional requirements in that regard. Under Article 5 of the Directive the Member States can merely specify the conditions under which the processing is lawful but this needs to remain within the limits of Article 7 and of the objective of the Directive which seeks to strike a balance between the free movement of personal data and the protection of private life.

Against this background, the CJEU found that by excluding the possibility of processing to ensure the general operability of the websites the German provisions go further than just specifying the conditions of lawfulness. For the CJEU, these provisions should enable the balancing of the objective of ensuring the operability of the websites with the fundamental rights and freedoms of the users. Normally this balancing is to be carried out on a case-by-case basis. The German provisions exclude this possibility by categorically prescribing the result of this balancing from the outset. 

Comments

The judgment of the CJEU is generally in line with the previous case-law on the Data Protection Directive which tends to favour a wide interpretation of the main concepts of the Directive, such as the definitions of personal data and of processing. This interpretation is also compatible with the view of the Article 29 Data Protection Working Party which (in its Opinion of 2007) considers IP addresses as personal data with only one exception, i.e. of addresses allocated in cyber cafes or similar places where the users of computers are normally anonymous.

The reply of the CJEU to the second question, i.e. if the IP addresses can be processed to ensure the general operability of the websites might, to a certain extent, be open to interpretation. On the one hand, the CJEU acknowledges that the purpose of ensuring the operability of the website is a legitimate aim of the German federal institutions under Article 7(f) of the Data Protection Directive. On the other hand, it reminds that such legitimate aims must be weighed against the fundamental rights and freedoms of the data subjects. Thus, it would seem that the provider of the website might not always be allowed to retain IP addresses without any further considerations. Instead, he might need to weigh the opposing interests when assessing individual situations. The CJEU itself does not spell out the criteria which should be taken into account when carrying out this kind of assessment.

An interesting suggestion was made in the Opinion of the AG. When analysing the wording of Recital 26 which reads that the assessment of the identifiability of a person must look at all the means that might be used not only by the data controller but also by any other person he comes to the conclusion that the formulation "any other person" should rather be understood as meaning only certain third parties which are accessible to the data controller and which the latter might reasonably approach to obtain the additional information. The CJEU did not address this issue in its judgment but by analysing only the option where the German federal institutions turn to the authorities that are competent to prosecute cyberattacks which then approach the ISPs to obtain the additional information the Court stayed within the limits of the suggestion put forward by the AG because these two third parties were either directly or indirectly accessible to the federal institutions. On the other hand, the question of the German court specifically mentioned the ISPs as the source of the additional information and did not ask about other possible scenarios.

Another interesting point was made in the course of the CJEU's analysis of whether the processing of IP addresses can be excluded from the Data Protection Directive as an activity of the State in the area of criminal law. Both the Court and the AG did not see any room for this exclusion to apply in the case at hand because the German Federal institutions were not acting in their capacity of public authorities when they processed the IP addresses. For the CJEU and the AG they acted as individuals. However, the term "individual" is normally used as a synonym for "natural person". For example the full titles of EU and international data protection instruments refer to the "protection of individuals with regard to the processing of personal data" (Data Protection Directive 95/46, Regulation 45/2001, Convention No. 108 of the Council of Europe).

This might be important in the context of another exclusion under the Data Protection Directive, namely the exclusion of the processing of personal data by natural persons in the course of a purely personal or household activity. Although it seems counterintuitive for a public authority to invoke an exception that is intended for natural persons it does not seem to be impossible when looking at the case-law of the CJEU on the exclusions. Out of the three CJEU cases which dealt with the latter exclusion, two of them (Rynes, Lindqvist) related to situations where personal data was indeed processed by a natural person, but the Satamedia case involved the processing by a private  company.
 
In Satamedia, the CJEU on the one hand concluded that Satamedia and Markkinapörssi were private companies and therefore could not rely on the exception for the State activities in criminal law. On the other hand, it then analysed if their processing could not be excluded as a purely personal or household activity and rejected this option because the companies in question were making the collected data accessible to an unrestricted number of people. Given the CJEU's and the AG's firm assertion in the Breyer case that the German federal institutions were processing IP addresses as individuals and the fact that the CJEU did not rule out this option in the case of private companies it seems possible to envisage a public authority invoking the private and household exclusion. In any event, the substantive conditions attached to the personal and household exception are rather strict. In all of the three previous CJEU cases mentioned above this exclusion was rejected because the data in question was published on the internet, made accessible to an unrestricted number of people or was outside the private setting of the person who collected it (videosurveillance of public spaces).

Finally, the scenario in the Breyer case seems to be very similar to pseudonymisation of personal data, i.e. a concept introduced in the new General Data Protection Regulation (GDPR, which will apply from 25 May 2018) and defined therein as  "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person". Under the GDPR pseudonymous data are nevertheless treated as data relating to an identifiable person and hence personal data but pseudonymisation is taken into account in the application of some of its provisions.


Photo credit: Digiquip group