Showing posts with label social networks. Show all posts
Showing posts with label social networks. Show all posts

Wednesday, 5 November 2025

From COVID-19 to digital well-being: Precaution in the internal market




Daan Bodson, LL.M in European Union Law, Université Panthéon-Assas (Paris 2)

Photo credit: US Dept of Defense, via Wikimedia Commons

 

Introduction

More than two years after the WHO declared COVID-19 no longer a global emergency, its impact is still felt. Remote work has become routine in many sectors, younger generations speak more openly about mental health, and the pandemic has left its mark on EU law. Faced with extraordinary circumstances, Member States adopted extraordinary restrictions, which in turn prompted courts to revisit how fundamental freedoms like free movement are balanced against public health.

Many of the measures aimed at restricting the spread of the virus involved limiting the free movement of individuals, one of the fundamental rules of the EU legal order. When these restrictions were challenged before the EU courts, both the ECJ and the EFTA Court delivered landmark rulings. For the first time, they brought the precautionary principle squarely into free movement case law.

This contribution revisits that jurisprudence and asks what it means beyond the pandemic. Since neither court confined its reasoning to COVID-19, the question arises: can precaution also justify restrictions in other policy fields marked by scientific uncertainty? I argue that Nordic Info (C-128/22, 5 Dec 2023) and LDL (E-5/23, 21 Mar 2024) lowered the threshold for Member States to justify restrictions under the precautionary principle, and that this reasoning can also support measures against mental health risks from social media usage.

 

The case law: Nordic Info and LDL

Setting the stage: National measures aimed at limiting the spread of COVID-19

On December 5th of 2023, the ECJ rendered its Nordic Info judgement, in which it ruled on the legality of a Belgian measure banning all non-essential travel to “red-listed countries”. These red-listed countries were designated based on epidemiological data available at the time. The national measure was challenged by a travel agency specializing in trips to Scandinavia. In the LDL judgement, rendered by the EFTA Court a few months after Nordic Info, the Court ruled on the legality of a Norwegian law requiring individuals travelling from abroad into Norway to subject themselves to a quarantine period spent in a specific “quarantine hotel”.

Both courts readily classified these measures as restrictions on the free movement of persons under the EU Citizens’ Directive (and its extension to the EEA). This legislation, however, allows for restrictions on grounds of public health (Art. 27 & 29), yet sets some safeguards to these limitations, such as a right to an effective remedy, and a proportionality check (Art. 31).

In both cases, the main legal question thus was whether or not the restrictions were considered proportionate. Remarkably, and for the first time in free movement case law, both courts expressly included the precautionary principle into this proportionality test. This novel introduction could significantly reshape the proportionality assessment in situations where the precautionary principle applies.

Understanding the precautionary principle

The precautionary principle is well-established in EU law. It regularly appears in judgments of both the ECJ and the EFTA Court and informs many policy fields. At its core, the principle provides a legal and policy tool for decision-makers faced with scientific uncertainty combined with potential risks. Where evidence of harm is insufficient, inconclusive, or uncertain, but the stakes are significant, legislators may intervene proactively without waiting for full scientific proof. As the ECJ stated in Nordic Info: “if there is uncertainty as to the existence or extent of risks to human health, a Member State must be able, under the precautionary principle, to take protective measures without having to wait until the reality of those risks becomes fully apparent” (para. 79).

In practice, the principle applies when there are indications of risk but no certainty about its precise magnitude, its long-term effects, or the most effective mitigating measures. In such cases, national or EU legislators retain discretion to determine the level of protection they wish to guarantee. The degree of scientific uncertainty will, however, shape the extent of that discretion: the greater the uncertainty, the broader the space for precautionary action.

This principle features in many fields of EU policy. The TFEU explicitly prescribes that the principle shall guide the EU’s environmental policy. ECJ case law (e.g., C-157/96) and legislation (e.g., regulation 178/2002) has further broadened the scope of application of the principle to all types of risks to environmental, human, animal, or plant health.

The European Commission’s 2000 Communication on the precautionary principle further clarified its scope and criteria. The Communication underlined that the precautionary principle doesn’t allow for arbitrary restrictions. Measures must still comply with broader EU law requirements, such as proportionality, non-discrimination, consistency, examination of costs and benefits and dynamic review. These principles ensure that precaution remains balanced and doesn’t overly interfere with the internal market.

The novelty: introduction of the precautionary principle in free movement case law

Whilst the precautionary principle itself is far from new in the EU legal order, its application in free movement case law in the Nordic Info and LDL cases is new. In both cases, the courts were confronted with a situation of scientific uncertainty: at the time, there was no conclusive knowledge about how COVID-19 spread, how lethal it was, or which measures were most effective. Yet Member States had to act to protect public health. Against this background, the courts held that the precautionary principle applied, granting national authorities wider discretion to define their own level of health protection and to adopt restrictive measures to limit contagion.

Ordinarily, the proportionality test for restrictions on free movement follows three steps:

-          Suitability: the measure must be capable of achieving its stated aim.

-          Necessity: there must be no less restrictive measure that is equally effective.

-          Proportionality stricto sensu: the benefits of the measure must outweigh the rights it restricts.

What changed in these cases is that the precautionary principle softened the evidentiary demands at each stage:

-          Suitability: Instead of requiring proof that the measure was demonstrably effective, it was sufficient that, in light of limited scientific knowledge, the measure appeared reasonably capable of achieving its aim.

-          Necessity: Courts did not demand a fully substantiated comparison of alternatives. A measure passed this step unless it was evident that another, less restrictive option would be equally effective (Nordic Info, para. 90).

-          Proportionality stricto sensu: In the balancing of interests, scientific uncertainty itself tipped the scales in favor of public health. Far-reaching restrictions were upheld even without full certainty as to their effectiveness.

In short, the precautionary principle did not replace the proportionality test but recalibrated it: lowering the threshold of proof and granting Member States greater leeway when acting under conditions of scientific uncertainty.

 

Beyond COVID-19: precautionary principle and digital well-being

The case law on COVID-19 restrictions carries implications well beyond the pandemic itself. Crucially, neither the ECJ nor the EFTA Court confined their reasoning to emergency circumstances, and Advocate General Emiliou even stressed in his Opinion in Nordic Info that the case had to be assessed under the “ordinary” rules of EU law. This suggests that the interpretive shift brought by the precautionary principle is not an exceptional tool for crisis management, but part of the general framework for justifying restrictions on free movement.

This raises a broader question: if precaution can justify far-reaching measures in times of scientific uncertainty about public health, could it also apply in other fields where risks are emerging but not yet conclusively proven? One particularly pressing area is digital well-being. With growing evidence of the mental health risks linked to social media and addictive algorithms, especially for young people, the same legal reasoning could potentially empower Member States to adopt preventive measures.

Social media, addictive algorithms and associated mental health risks

Social media platforms rely on algorithms that continuously predict and adapt to user preferences. By generating personalized feeds designed to maximize engagement, these systems keep users online longer and, in turn, increase advertising revenues.

Growing evidence links such addictive algorithms and the use of social media generally to negative mental health outcomes, particularly among children and adolescents. Users are frequently exposed to harmful content, such as unrealistic body images, and research increasingly associates prolonged social media use with depression, anxiety, body dysmorphia, and even suicidal thoughts.

Because social media is a relatively recent phenomenon, the long-term effects are not yet fully known. Scientific studies are emerging, but uncertainty remains inherent: it is difficult, perhaps impossible, to precisely measure the long-term mental health consequences of algorithm-driven platforms, especially for young people.

The EU has begun to acknowledge these risks. The Digital Services Act (“DSA”) of October 2022 introduces obligations for “very large online platforms and search engines,” requiring them to conduct risk assessments, explicitly covering algorithmic systems, and to implement reasonable mitigation measures. This reflects a policy shift toward more stringent obligations for these large platforms, aimed at enhancing, among other things, user well-being.

The precautionary principle: more space for Member States to act?

Despite the DSA, Member States may wish to go further in protecting citizens’ mental health. Insofar as measures do not interfere with harmonized EU law, Member States can determine their desired level of protection and take adequate measures. In practice, this could mean considering specific obligations on tech manufacturers (e.g., better parental control tools) or even on the accessibility of devices to minors.

National measures in this area are likely to restrict the free movement of services, and possibly freedom of establishment or free movement of goods. Ordinarily, such measures would face steep hurdles, since they would need to be justified and proportionate, which typically was a high bar. However, under the Nordic Info and LDL rulings, Member States now enjoy wider leeway to justify such restrictions. The introduction of the precautionary principle into free movement law means that scientific uncertainty no longer necessarily blocks preventive regulation.

For precaution to apply, three conditions must be present:

-          a potential risk, including mental health risks for humans;

-          scientific uncertainty about its scope or effects, and

-          the absence of full proof or consensus related to the extent of the risk and / or the most suitable mitigating measures.

In the case of digital well-being, these conditions seem to be met. Academic research points to a range of mental health risks from social media use, but the extent of the danger and the precise causal links remain unsure. Member States could take precautionary measures in multiple forms. Even though harmonized EU legislation, such as the DSA, bars Member States from introducing measures within this field, some measures are still imaginable. For example, States could require phone manufacturers to include robust parental control tools by default. Alternatively, Member States could consider a ban on design features such as auto-play or endless scroll for under-16s, or even impose an age limit for the sale of smartphones (as considered by the UK government).

The significance of Nordic Info and LDL is that these measures no longer need conclusive scientific proof to survive judicial scrutiny. It is enough that they seem reasonably appropriate, and that no evident less restrictive alternative exists. In balancing fundamental rights, the courts signaled that precaution may tilt the scales in favor of public health, even when other freedoms, such as free movement of services or freedom to conduct business, are affected.

 

Conclusion

The COVID-19 pandemic was not only an unprecedented test for Europe’s health systems, but it also challenged the boundaries of EU law. In Nordic Info and LDL, the courts expanded the role of the precautionary principle in free movement, potentially lowering the evidentiary threshold for Member States to justify restrictive measures. Importantly, this reasoning was not tied to emergency conditions, which opened the door for its application in other contexts.

The growing, though inconclusive, evidence linking social media usage and addictive algorithms to mental health issues raises the question of whether the evolving case law could justify regulatory measures to protect mental health in the digital space. By extending the application of the precautionary principle, the legal precedents set in these cases could pave the way for stronger regulations aimed at safeguarding online well-being, particularly regarding social media platforms and their addictive features.

Thursday, 14 January 2021

The proposed Digital Markets Act: overview and analysis


 


 

Professor Lorna Woods, University of Essex

 

Background

 

The Digital Markets Act (DMA) proposal is stable-mate to the Digital Services Act (DSA) proposal (discussed here) developed as part of a suite of actions to tackle concerns about the operation of the digital environment.  If enacted, it will form part of a complex tapestry of measures dealing with information society and electronic communications services of one form or another – found in to name but a few - the European Electronic Communications Code (which covers OTT voice services); the Audiovisual Media Services Directive (which covers video on demand potentially including some YouTube channels for example, as well as video sharing platforms); the P2B Regulation; and, of course, the e-Commerce Directive (which the DSA develops).  It will also be developed against a backdrop of increasing competition law enforcement actions against a number of large players in the market.  The EU is not the only actor taking steps and one important question will be how compatible these various initiatives are, as well as how effective.

 

Overview of the Proposal

 

Based on the recognition that platforms are a key structuring element of the current digital economy, the proposal provides for ex ante restrictions on an identified list of services, but only when those services are provided by operators which meet certain thresholds.  The Commission has enforcement responsibilities and powers, with similarities to those found in the competition field.

 

The relevant services are those which the Commission has identified as “core platform services” (CPS) (defined Art. 2(2)):

 

a)      online intermediation services;

b)      online search engines;

c)      online social networking services;

d)     videosharing platform services;

e)      number-independent interpersonal communication services;

f)       operating systems;

g)      cloud computing services; and

h)      advertising services provided by an operator which provides any of the services in (a)-(g).

 

While some of these terms are defined in other instruments (eg ‘information society service’, ‘online search engine’ and ‘video sharing platform service’, included no doubt to try to ensure coherence across the digital regulatory space, some are novel (eg ‘online social networking service’ and ‘software application stores’).  It remains to be seen how clear these definitions are.

 

The service operators who will be caught by the rules in this regulation are those designated as a “gatekeeper” according to Article 3. Article 3(1) contains a three stage test:

 

-          the existence of a significant impact on the internal market;

-          the operation of a CPS “which serves as an important gateway for business users to reach end users”; and

-          an entrenched and durable position in its operations.

 

These are assessed by quantitative criteria (based on turnover or market value, and user reach), producing a rebuttable presumption about the status of the operator, and refined by reference to qualitative criteria.  It is initially for the company itself to make this assessment and to notify the Commission.

 

Article 5 lists the obligations for gatekeepers and Article 6 contains a list of further actions that may be specified in respect of a gatekeeper. The obligations include positive obligations and prohibitions, essentially behaviours identified from previous competition investigations and against which competition rules seem insufficiently effective. These rules have been set down in some detail though the proposal envisages that the Commission may update the list of prohibited practices in the light of enforcement experience. This is important as otherwise closely specified rules could be overly rigid and not deal with developments in the market or practice. This, then, could introduce some element of future proofing.  The Regulation also provides for the possibility of exceptions, including exemption for overriding reasons of public interest (public morality, public health and public security).

 

            Prohibited Practices

 

-          refrain from combining personal data sourced from these core platform services with personal data from any other services offered by the gatekeeper or with personal data from third-party  services, and  from signing  in  end  users  to  other  services  of  the gatekeeper in order to combine personal data (this would catch, for example, the situation where logging into Gmail leads to you being logged into YouTube – this has come up in investigations into Facebook also) (Art5(a));

-          refrain from preventing or restricting business users from raising issues with any relevant public authority relating to any practice of gatekeepers (Art 5d);

-          refrain from requiring business users to use, offer or interoperate with an identification service of the gatekeeper (Art 5e);

-          refrain from requiring business users or end users to subscribe to or register with any other core platform services – this is a ban on tying (Art 5f);

-          refrain from using any not publicly available data about the activities of business users or their end users to compete with those business users, an issue that arose in the Amazon investigation (Art 6(1)(a));

-          Prevent end users from un-installing any pre-installed software applications (Art 6(1)(b));

-          Rank the own products of the gatekeeper more favourably than similar third-party products – this came up in the Google Shopping decision (Art 6(1)(d));

-          Technically restrict the ability of end users to switch between and subscribe to different software applications and services to be accessed using the gatekeeper’s operating system – ie, lock ins are not permitted (Art 6(1)(e)).

 

            Positive Obligations

 

-          allow business users to offer the same products or services to end users through third party online  intermediation  services  at  prices or  conditions  that  are  different  from those offered through the online intermediation services of the gatekeeper (MFN clauses) – currently platforms impose significant restraints on their business users in this regard as can be seen for example in the eBooks settlement (Art 5b));

-          allow  business  users  to  promote  offers  to  end  users  acquired  via  the  core  platform service, and to conclude contracts with these end users regardless of whether for that purpose they  use  the  core  platform  services  of  the  gatekeeper  or  not (so for example Apple’s requirement to use its in-app purchase system or even its app store) (Art 5c));

-          allow end users to access and use software application of a business user where software was  acquired  without using the core platform services of the gatekeeper (Art 5c));

-          provide  advertisers  and  publishers  to  which  it  supplies  advertising  services price information in relation to advertising services (Art 5g);

-          allow  the  installation  and  effective  use  of  third  party  software  applications  or software  application  stores  using,  or  interoperating  with,  operating  systems  of that gatekeeper  and  allow  these  software  applications  or  software  application stores  to  be accessed  by  means  other  than  the  core  platform  services  of  that gatekeeper (Art 6(1)(c));

-          apply FRAND conditions to rankings (Article 6(1)(d)), which might also reflect concerns in the P2B Regulation;

-          give business users and providers of ancillary services (eg payment processors, cloud hosts, digital identity providers, and ad-tech sellers) access to and interoperability with the same operating system, hardware or software features that are available or used by the gatekeeper itself (Art 6(1)(f));

-          provide data to allow independent verification of ad inventory (Art 6(1)(g));

-          ensure effective data portability – and real-time access (art 6(1)(h));

-          provide business users free of charge with effective, high-quality, continuous and real-time access to and use of aggregated and non-aggregated data (subject to GDPR) – this essentially ensures businesses can have access to their own business data (Art 6(1)(i));

-          provide third-party providers of search engines with access on fair, reasonable and non-discriminatory (FRAND) terms to ranking, query, click and view data generated by end users (Art 6(1)(j));

-          FRAND conditions for access for business users to the gatekeeper’s app store (Art 6(1)(k)).

 

By contrast to the position under competition law, in acting against these behaviours the Commission would not have to prove their impact on competition on the market, though the Commission’s ability to intervene under its competition powers remain unaffected.  The Commission seems therefore to have decided that concerns about pro-competitive effects of some behaviours (including self-preferencing) do not outweigh gains from clear rules for efficient enforcement. There have been some concerns that these closely defined prohibitions may not be appropriate for all gatekeepers, and it remains to be seen how the refinement levers of qualitative factors (as regards the designation as gatekeeper in the first place) and the obligations that are susceptible to specification (in Article 6) operate.

 

Note that these provisions apply to services that are offered across the gatekeeper’s core services; they do not require the interoperability of core services necessarily, nor benefit third party service providers who do not operate on the core services. 

 

The regulation also introduces provisions empowering the Commission to carry out market investigations for any of three purposes: identifying gatekeepers that are not captured by the quantitative thresholds of the DMA; identifying other services that should be added to the list of core platform services or new practices that may be unfair; identifying proportionate behavioural or structural remedies in the case of systematic infringement of the rules by a gatekeeper. Article 10 gives the Commission the power to adopt delegated acts to update the lists in Articles 5 and 6 when it discovers unfair practices in a market investigation.  This new tool is arguably less far reaching than the new competition tool originally envisaged because of competence issues and the limits of Article 114 TFEU.

 

The DMA obliges gatekeepers to inform the Commission of any proposed merger or acquisition involving another provider of core platform services or of any other services provided in the digital sector. For these purposes, it is irrelevant whether such an acquisition triggers a notification requirement under the EU (or national) merger control rules. This is not a specialist merger regime, but is to allow the Commission to review gatekeeper designations and obligations.

 

The DMA provides for up to 10 percent of a gatekeeper’s global annual revenue in fines for violating its rules, similar to those penalties available in competition cases.   Structural remedies remain a possibility in the case of ongoing problems or recalitrant actors (Article 16) but only where there are no equally effective behavioural remedies.

 

Comment

 

The Commission’s proposal is based on the assumption that there are problems and that reliance on competition tools is insufficient to deal with the problems, partly because of the length of time an investigation may take – for example, the Google Search case took in excess of 6 years.  The European Court of Auditors has recently published a report to similar effect.  Specifically as regards the DMA, the Regulation flags at Recital 10 the need to ensure contestability of markets – and in this it seems to reflect ordoliberal concerns found in many decisions where it has sought to protect the market, with knock on benefits perhaps to small and medium sized enterprises.  The proposal therefore adds additional measures as a complement to competition rules.  It seeks to introduce ex ante regulation to the generally ex post competition provisions and so avoid questions about the definition of markets, assessment of dominance and identification of the theory of harm (for example impact on nascent competition or on innovation).  Instead the key question is whether an operator is a “gatekeeper”.

 

Admittedly the cases that have come up under the competition rules in relation to the digital environment have been based on complex facts and raised difficult questions about application of the usual principles, but the resort to ex ante additional regulation is not new. This double pronged approach has been used before, notably in the not-so-very-distant field of telecommunications – though it should be noted that this approach is not unique to electronic communications sectors.  The EU approach to telecommunications can be seen as a model for the DMA as regards another aspect too: the decision not to embark on structural separation of big players, or at least not as a first port of call, but instead to rely on requiring them to open their platforms to providers of other services, whether direct substitutes or related services.  This approach can be seen in the liberalisation of the telecommunications sector from the late 80’s on, for example in the Access Directive.  As in the debate for data protection, there is the question as to whether financial penalties will ever be enough for companies as rich as the big tech companies.  Some (probably American commentators) see the unwillingness to break companies up as a significant weakness.

 

Another notable point is the role of the Commission.  By contrast to the telecommunications regime, where the national regulatory authorities have had a distinct and important role, enforcement powers lie with the Commission exclusively – perhaps reflecting the early position with regard to competition enforcement, where implementation of EU competition law was consolidated at EU level.  National authorities will however participate in a Digital Markets Advisory Committee that will assist the Commission.  This location of power at the EU level can be seen in other aspects of the proposal. The form of instrument proposed is a regulation, meaning it would be directly applicable in Member States’ legal systems without implementation. Moreover, the regulation seems to be envisaged as total harmonisation in this field.  Article 1(5) specifies that:

 

 “Member States shall not impose on gatekeepers further obligations by way of laws, regulations or administrative action for the purpose of ensuring contestable and fair markets”,

 

though the field to which this prohibition applies is restricted.  Nonetheless, this point is likely to be contentious.

 

As noted, a central question is the identification of gatekeepers and there are likely to be questions about the operators to which the DMA applies (and no specific platform has been named).Arguably, there will be difficulties in identifying criteria that work across the range of activities that platforms provide.  The assessment (which falls on the companies themselves) is a mix of assessing whether CPS are in issue and then looking at the Gatekeeper criteria.  Two points should be noted; the existing definitions are themselves complex and the developing market challenges them; secondly, it is unclear how the qualitative criteria will operate to rebut the presumptions based on the numbers.  There have been some comments that this definition will need to be improved as the proposal makes it way through the legislative process.

 

One final question relates to the relationship between this instrument (and its motivations) and that of the GDPR (and possibly the ePrivacy Directive) with their emphasis on the user and the user’s privacy.  While some of the ex ante prohibitions seem to flow in the same direction as data protection rules (notably the obligation to refrain from combining personal data as well as the tying of identity services), there might be some tension with data portability by businesses and access to user data, which will likely be – at least to some extent – subject to GDPR controls.  It remains to be seen how the two will operate together, and whether competition concerns operate to undercut data protection.

 

Photo credit: via Wikimedia commons

 



Friday, 13 June 2014

Reforming EU data protection law: the Council takes its first baby steps


Steve Peers

The EU’s controversial data protection rules, currently in the form of a Directive dating back to 1995, would be reformed profoundly if a Regulation proposed by the Commission is adopted. Talks on this proposal have been underway since January 2012, with no immediate end in sight. However, in June, for the first time the Council (consisting of Member States’ justice ministers) has agreed its position on part of the proposal. Of course, the Council still has to agree its position on the rest of the text, and then negotiate with the European Parliament, which adopted its position on the entire text this spring. But at least this recent partial Council deal offers the first opportunity to assess the direction of negotiations.

Furthermore, this is a good occasion to assess whether the new legislation might impact upon the application of the controversial Google Spain judgment.

The partial Council deal

The Council deal only concerns the question of how the new EU rules will apply to non-EU countries. However this issue is of great importance in light of the ever-growing use of the Internet and social media, since the EU rules are potentially liable to apply worldwide.

To place the deal in context, it is necessary to look at four different things: (a) the current rules in the 1995 Directive, as interpreted by the CJEU; (b) the 2012 proposal; (c) the Council’s position; and (d) the EP’s position.

In each case, I will look at two different aspects which were addressed by the Council deal. First, when do the standard EU data protection rules apply, even where the company processing data is based outside the EU? Secondly, when do the special rules on external relations apply?

The current rules

Currently Article 4 of the 1995 Directive states firstly that the standard rules apply to a data controller established in a Member State. According to the CJEU in Google Spain, that concept applies at least where a non-EU company has established a subsidiary in a Member State, and that subsidiary carries out activities linked to the business model of the parent company. The current rules go on to say that if the controller is established on the territory of more than one Member State, it must comply with the national law of each of those States.

Furthermore, the standard rules in the 1995 Directive apply where a Member State’s national law applies by virtue of public international law, and where the controller is not established on EU territory, but uses equipment located on a Member State’s territory, unless that equipment is used only for the purposes of transit. This raises the question of whether the use of ‘cookies’,  for instance, amounts to the use of equipment on a national territory, since those cookies are installed on a Member State’s computer.

As for external transfers, the current rules provide (Article 25) that in principle data can only be transferred if there is an ‘adequate level of protection’ in the third country concerned. The Commission can adopt decisions either finding that there is, or is not, an adequate level of protection. By way of derogation (Article 26), Member States must nonetheless allow (unless their national law provides otherwise) external transfers to take place if: the data subject has given unambiguous consent; the transfer is necessary to perform a contract with the data controller or to implement pre-contractual measures which the data subject requested; the transfer is necessary to conclude or perform a contract in the interest of the data subject as a third party; the transfer is ‘necessary or legally required on important public interest grounds’ or related to legal claims; the transfer is in the data subject’s ‘vital interests’; or the transfer is from a register which provides information to the public or to persons with a legitimate interest.

A Member State may authorise an external transfer to a country with an inadequate level of protection if the data controller can offer ‘adequate safeguards’, in particular arising from contractual clauses. The Commission can decide that certain standard contractual clauses offer such protection. 

The 2012 proposal

The 2012 proposal (Article 3) suggests that the new Regulation should apply first of all where a controller or processor is established in the EU. Secondly, it should apply where the data controller is not established in the EU, but the data subjects reside in the Union, and the data controller either offers them goods or services, or monitors their behaviour. Thirdly, as before, it would apply where a Member State’s national law applies by virtue of public international law. The provision concerning the ‘use of equipment’ would be dropped.
As regards external transfers, the 2012 proposal maintains the basic structure of the current rules, but elaborates upon it. So there are more details on what the Commission has to take into account when assessing the adequacy of a third State, including judicial redress and supervisory authorities. Adequacy decisions taken pursuant to the 1995 Directive would remain in force.

External transfers would be permitted on the basis of binding corporate rules, or standard contractual rules adopted by the Commission or a national supervisory authority, or individually negotiated contractual rules authorised by a national supervisory authority. Otherwise transfers would require approval by a supervisory authority. Pre-existing authorisations by a supervisory authority would remain valid.

A new clause would elaborate upon the content of binding corporate rules that would be adopted unilaterally. These would require the approval of a supervisory authority.

Finally, further derogations would be permitted. Compared to the current rules, these would be optional, not mandatory. The new proposal would clarify that consent could only be given after the data subject had been warned of the risks, and that transfers in the data subject’s interest could only be given if the data subject were unable to consent. There would be a new ground of external transfers in the data controller’s or processor’s legitimate interest, subject to safeguards being in place. The concept of the ‘public interest’ justifying such transfers would be further clarified in national or EU law.

The Council position

As regards the standard rules, the Council would amend the Commission proposal to clarify that the rules will apply whether or not the data controller offers goods or services for payment. However, as regards monitoring of behaviour, the rules will only apply if the data controller monitors behaviour within the EU.

For external transfers, the Council would add further detail to the rules regarding the assessment of the adequacy of third states, including a specific reference to participation in regional or multilateral data protection treaties. The Council also wants to give an advisory role to the planned new European Data Protection Board in this process. The Council would require the Commission to monitor the application of its adequacy decisions, and empower it to revoke them. However, the Commission would no longer have the power to adopt a decision specifying that a third State had inadequate protection.

The Council would also permit external transfers to take place on the basis of a code of conduct or a certification mechanism. Transfers in the private interest of the data processor or controller would be subject to a possible override in the data subject’s interests. The Commission would lose powers to define the public interests reasons for transfers, and Member States would gain more powers on this point.  

The EP position

The EP would amend the Commission proposal so that, where the controller or processor is established within the EU, it would not matter where the data was processed. Also, the standard rules would apply to the offering of goods or services or monitoring by data controllers or data processors, and would apply to any sort of monitoring of data subjects, not only the monitoring of behaviour. Unlike the Council, the EP would not limit the monitoring clause to behaviour within the EU. However, like the Council, the EP would apply the rules even if goods or services are not offered for payment.

As for external transfers, the EP agrees with the Council that the Commission should monitor its adequacy decisions, and that there should be a role for the new Board.  However, the EP wants to apply a ‘sunset clause’ to pre-existing adequacy decisions, and retain the power for the Commission to adopt ‘inadequacy’ decisions.

Similarly, pre-existing authorisations of contractual clauses would expire soon after the new rules were adopted, although the EP agrees with the Council that a form of certification process should justify external transfers. For binding corporate rules, the EP wants to ensure consultation of workers where their data is involved, and apply the rules to sub-contractors (the Council approaches the latter issue by referring to groups of companies). As regards the derogations, the EP would reject the idea of transfers in the legitimate interests of controllers.

Finally, the EP has proposed a new ‘Snowden clause’ which would mean that national courts could not recognise the decisions of non-EU courts which ordered the disclosure of personal data. However, this rule would be ‘without prejudice’ to mutual assistance treaties or any other international agreements between a non-EU state and the EU or any Member State.

Comments

One important point should be addressed at the outset: what is the result of the recent EP election on the EP’s position? In the EU system, proposed legislation does not fall simply because there is an election for the EP, or because there will be a new Commission as from November. Rather, the newly elected EP traditionally holds a vote at an early stage to decide whether to reaffirm the positions taken by the previous legislature. Usually it reaffirms almost all of the prior legislature’s positions. It should be recalled that the EP’s position on the data protection Regulation was adopted by a huge majority, and so despite the increase in the number of populist MEPs, a majority in favour of approving the EP’s prior position on this proposal should in principle not be hard to find.

For its part, the incoming Commission will decide whether to withdraw some of its pending proposals, but is very rare for an incoming Commission to withdraw a proposal which is actively under discussion in the Council and EP, such as the data protection proposal.

Moving on to the substance of the issues, as regards the application of the standard rules, all three institutions agree to keep the rule on establishment, extending it to data processors also. The EP’s suggested amendment regarding the location of the data processing is merely a clarification, which is probably not necessary.

The three institutions all agree to drop the ‘use of equipment’ clause, to keep the clause on public international law, and to add a new clause regarding goods and services and monitoring. The EP and the Council also agree that the ‘goods and services’ clause will apply even where there is no payment made. The institutions differ as regards extending the new clause also to data controllers, and differ as regards the exact scope of the monitoring of behaviour.

As for the external transfers rules, all three institutions would keep the current basic structure. They differ as regards: the ‘Snowden clause’ (although this rule is very weak, in light of its exceptions for any international treaties); whether the Commission can adopt an ‘inadequacy decision’ (it has never done so); sunset clauses for prior authorisations; whether private interests can justify external transfers; and the process of determining when the public interest can justify them.

Taken as a whole, the impact of the new rules depends on how the current rules are interpreted. There is no reason to doubt that the ‘establishment’ clause would be interpreted the same way as it was in Google Spain, ie applying at least where a subsidiary’s activity is linked to a non-EU parent company’s business model. But there is no case law clarifying what the ‘use of equipment’ means, and so it is not easy to assess what removal of this clause will mean in practice.

Instead the focus will be on what it means to offer goods or services (whether or not for payment), and what it means to monitor an individual. These concepts are clarified in the preamble, which indicates that the ‘offering goods or services’ rule will apply where there a website seeks to sell its products or services, and its online activity is particularly directed towards EU citizens (in light of the currency or language used). So the intention is apparently not to cover a non-profit body like Wikipedia, or a social network or search engine which does not charge for its services (although some such entities would be covered by the ‘establishment’ rule).

What about ‘monitoring’? Here, the preamble suggests that the new clause applies when an individual’s Internet activities are tracked with a view to profiling him or her. There is no suggestion in the preamble that keeping records of a person’s use of social networks would count as monitoring.  But if that is not the intention, it would be better for the EU legislature to rule it out more expressly. In any event, it is difficult to see how the Council’s limitation regarding the monitoring of behaviour within the EU would work in practice, in light of the nature of the Internet.

As regards the external transfer clauses, their importance depends on whether the standard clauses apply. The greater the number of businesses covered by the standard rules, the less important the external transfer rules are – and vice versa.

It is clear that the external transfer clauses will remain broadly similar to the current rules, so any corporate or NGO strategies regarding these clauses would only need to be amended modestly, rather than be overhauled. The biggest issues may be the EP’s insistence on its ‘Snowden clause’ and its rejection of the idea that external transfers can take place in the data controller’s interest, although the former clause is weak and data controllers can usually pursue their interests by means of obtaining consent or establishing a contractual relationship.

Much of the most difficult work as regards the negotiation of the new rules remains to be done. In fact, it is rather peculiar to negotiate a new law by defining its territorial scope before agreeing on its main substance.

While a vast number of issues will arise in the forthcoming negotiations, the following are particularly relevant to the fallout from the Google Spain decision, in particular as regards its possible impact on social networks and Wikipedia: the interpretation of a ‘data processor’ (which would be particularly significant if the EP gets its way and the entire clause on territorial scope applies to data processors); the possible application of the ‘household exception’ to user-generated content; the exception for journalism; and the definition of the grounds for processing personal data (notably consent and the controller’s legitimate interests).



Barnard & Peers: chapter 9 

Wednesday, 14 May 2014

Towards a Web 3.0? The impact of the Google Spain judgment on social networks and Wikipedia



Steve Peers

If its age could be measured in ‘Internet years’, the EU’s data protection Directive would be prehistoric. This can easily be demonstrated by comparison with the age of Facebook. The Directive was adopted seven years before the virtual panty raid on Harvard students’ privacy that ultimately launched Facebook. Indeed, when the Directive was adopted in 1995, Mark Zuckerberg was eleven years old, and attending primary school. He turns 30 today.

That’s a significant birthday – but is there anything in the Google Spain judgment that would ruin the party? This blog post looks in detail at the possible application of the judgment to two well-known features of the Internet: social networks and Wikipedia.

Long ago (in Internet years), the Internet shifted to a ‘Web 2.0’ model, dominated increasingly by user-generated content such as social networks and Wikipedia (along with blogs and many other forms of such content). The question I want to pose here is whether the Google Spain judgment could launch a ‘Web 3.0’: an Internet dominated by data subjects’ control of their personal data?

Applying the Google Spain judgment to social networks and Wikipedia

Material scope of EU law

First of all, the information placed on social networks and Wikipedia certainly constitutes personal data, at least as far as it concerns living natural persons. It’s an interesting question as to whether the legislation also applies to dead persons: this conjures up the image of the supporters and critics of (say) Ronald Reagan or Margaret Thatcher using data protection law to litigate over the reputation of their heroes (or villains). But the exclusion of legal persons means that data protection law cannot be a vehicle for companies (or other legal persons such as NGOs, political parties, charities or governments) to attempt to remove all traces of criticism of their actions.

As the CJEU has made clear several times, it isn’t relevant that the data was initially (or subsequently) made available elsewhere. This point is relevant to Wikipedia in particular, given the sources it links to for most of its information.  

Placing information on the Internet amounts to ‘data processing’, at least where it is available to the general public. This is particularly relevant to Wikipedia, but it’s also relevant to those social network profiles which are accessible to the outside world. In both cases, the personal data would also be accessible by means of search engines, which means that Google (or other search engines) would be separately liable for securing data protection rights under the conditions set out in the Google Spain judgment.

However, where a social network profile is genuinely closed to the outside world and made accessible only to persons selected by the data subject, the EU’s ‘Article 29’ working party on data protection (a body made up of national data protection supervisors, which gives non-binding advice on the application of EU data protection law) has suggested that the so-called ‘household exception’ in the Directive might apply. This would mean that, since the data could only be seen by a closed circle of (presumably) friends and family, the EU law wouldn’t apply at all. Obviously, though, that exception wouldn’t apply to any processing of the personal data in question by the company which established the social network itself, for direct marketing or other purposes.

Who is the ‘data controller’, ie the person with greater liability for application of EU data protection legislation, as regards social networks and Wikipedia? On this point, there is a clash between the nature of Web 2.0 and the putative Web 3.0, to the extent that the content of the personal data is generated by the users. In principle, each individual chooses how much personal data to place online and who has access to it, and similarly the editors of Wikipedia generate its content. The liability of the social network provider or Wikipedia might arise, however, to the extent that they alter the privacy settings, or could be regarded as controlling (as in Google Spain) the systematic presentation of the data to the outside world.  We can’t forget that in that judgment, the CJEU ruled that there has to be a ‘broad definition of the concept’ of a data controller.

Territorial scope

Back when the Internet was (in Internet years) a teenager, the CJEU ruled in Lindqvist that the special rules on external relations in the data protection Directive should not, by means of the nature of the Internet, become a general regime applicable to the entire world. But in Google Spain, the Court conversely was anxious to ensure that the general rules of the Directive were applicable to companies based outside the EU.

However, this doesn’t mean that all social networks, or Wikipedia, are necessarily subject to the Directive. They are certainly subject to it if they are in the same situation as Google: with a subsidiary in a Member State, which is selling advertising connected to the Internet-related activities of the parent body. But this is surely not the only scenario when the Directive applies to companies based outside the EU. As the CJEU said in Google Spain, the Directive has ‘a particularly broad territorial scope’ and the relevant rules ‘cannot be interpreted restrictively’. So while it is an oversimplification to say that the Directive applies to any entity ‘doing business in the EU’, it probably applies at least where there is a significant local activity (certainly in the form of a branch, possibly in the form of an agent or licensee) by the parent entity, that has some link to its Internet activities.

It is also still open to argue (since the Court did not address the issue) whether a parent company can be regarded as ‘established’ or using equipment on the territory due to its use of domain names, storage of data, and use of crawlers or robots on the territory, or whether the EU Charter of Fundamental Rights imposes broader criteria as regards the territorial scope of the rules.

Of course, there will be practical difficulties enforcing the Directive where a non-EU entity does not have assets in the EU. However, in such cases there might be possibilities to enforce the Directive’s rules by seeking to enforce a court ruling in a non-Member State, or more directly by means of obtaining an injunction to block access to the information which infringes data protection rules. Undoubtedly, such an injunction could be sought against Google, where the data is accessible by means of its search engine, and arguably (by analogy with copyright law) against an Internet service provider.

Personal scope

One interesting question which the Court did not have to deal with in Google Spain was the personal scope of data subjects. For instance, could a celebrity based in America, who finally gets tired of stories about her enormous backside, try to use EU data protection law to prevent access to such stories?

There is no requirement in the Directive that the data subject must be a national of a Member State, and/or domiciled in the EU. Nor do the rules on the territorial scope of the Directive mention this factor. So it must follow that non-EU citizens who are not resident in the EU can rely upon the Directive to assert their data protection rights within Member States. So in principle, at least, the supporters and detractors of Barack Obama or Vladimir Putin could bring their disputes, in the context of editing Wikipedia entries, to the courts and data protection supervisors of EU countries.

While this might sound absurd, in fact there are other reasons which would stand in the way of the application of EU data protection law to such disputes – to which we now turn.

Responsibility of data controllers

Data controllers must ensure that the data quality rules in the Directive are satisfied, and that data was processed in accordance with one of the legal grounds for processing.

On the latter point, one of the crucial factors in the Google Spain case was that Google could only rely (as regards its search engine) on its ‘legitimate [commercial] interest’ in processing personal data, in accordance with Article 7(f) of the Directive. The same provision refers to the interests of third parties, namely freedom of expression. However, the Court held that such interests were overridden by the data subject’s rights in that case, due to the huge invasion of his privacy due to the use of search engines.

Two issues arise here: the balancing test, and the grounds for processing. The first issue is particularly relevant for Wikipedia, since (like Google, as regards its search engine) it must rely on this balancing test in order to justify its processing of personal data, in the absence of other possible grounds to justify it.  
Applying the balancing test, the CJEU ruled on both Google’s interest and the public interest in freedom of expression. As regards Google, the Court stated that its ‘merely economic’ interests were outweighed by the data subject’s. This suggests that a non-profit body like Wikipedia would arguably have a greater claim to assert its interests than a profit-making entity.

As regards the public interest, the Court listed the factors to be considered as ‘the nature of the information’, its ‘sensitivity for the data subject’s private life’, and the public’s interest in the data, which could ‘vary, in particular’, on the data subject’s ‘role…in public life’. It should be recalled that the concept of ‘private life’ usually includes data concerning a person’s activity in public, but here the Court does suggest that there might be a distinction between public and private activities. So the balance tips in favour of freedom of expression the more that the person concerned is a public figure, and the more that the information concerns his or her public activities. So certainly Wikipedia could contain a record of public criticism of a politician; but the sordid details of his intern’s (postponed) dry-cleaning might possibly be another matter.

The crucial question here is whether the test can be regarded as severable: ie can it be argued that even if a person is a public figure, his or her public and private activities can be distinguished? In any event, his or her mistress or children are data subjects in their own right, so would have a data protection right to assert independently of the politician, and are unlikely to be public figures. But of course, some spurned mistresses are very keen indeed to waive their data protection rights.

But who is a public figure in the first place? Presumably the concept has an autonomous meaning in EU law, so it is not up to Wikipedia (or the persons concerned) to determine what it means by themselves. But surely the nature of Wikipedia is a significant factor to take into account when developing and applying such a definition.

As regards the nature of the personal data, what if the information in question reflects very badly upon the person concerned? The CJEU did not address this issue expressly in Google Spain. But it could be argued that it depends on the public interest in receiving that information. So while past financial difficulty does not raise a public interest issue, there is a better case for arguing (say) that a woman who has been groped by a particular car mechanic has every right to warn other women against him via means of social networks.

Another crucial element in the Google Spain judgment was the journalist exception in the Directive. It didn’t apply, because Google itself was not a journalist, and the Court disregarded the use that journalists make of search engines. But where content is user-generated, such as Wikipedia and on blogs, surely the exception must apply, given the Court’s broad approach to it in previous judgments such as Satamedia and Lindqvist. So in that case it could be argued that the exception should be applied in practice by the national courts. Indeed, perhaps the only reason why the CJEU undertook the task of applying the balancing test between privacy and freedom of expression itself in Google Spain was because the journalist exception did not apply.

As for the second issue, social networks will usually be able to point to other grounds justifying the processing of personal data: namely unambiguous consent, and necessity to perform a contract. This raises important questions of how to interpret these grounds for data processing, but these are clearly different issues not addressed at all by the Google Spain judgment.

That judgment would only be relevant as regards the processing of personal data about third parties in social networks, for instance a man ranting about his ex-girlfriend on his Facebook page. The way to resolve situations such as these is for social networks to adopt and apply robust privacy policies, but the Google Spain judgment can only be an indirect source of inspiration for such policies.  

The right to be forgotten

Finally, what of the ‘right to be forgotten’? The Court derived such an implicit right from the rules in the Directive on the relevance of data (one of the data quality principles), given that it might cease to be relevant over a long period of time.  While this can be seen as a positive right for data subjects, conversely it suggests that if information is accurate (and complies with all other rules in the Directive), there is not much of a right for a data subject to object to its dissemination as long as it is relatively fresh.

Conclusion

Is there good reason for Mark Zuckerberg's own knickers to be in a twist, following the Google Spain judgment? The CJEU does suggest that the territorial scope of the Directive is relatively broad, and as such is more likely to apply to social networks and other well-known Internet services than might otherwise have been thought. But it is not yet certain whether and when the Directive does apply to entities whose situation differs from Google’s. Equally the judgment confirms that the material scope of the Directive is broad, and it seems clear enough that its personal scope is broad too.

However, the judgment is unlikely to lead to a ‘Web 3.0’ as regards Internet services besides search engines, because there are basic differences in the substantive data protection law of the EU as it applies to the bodies offering such services. These differences concern in particular: the very nature of user-generated content (arguably changing who is the ‘data controller’); the existence of privacy or editing policies; the public figure exception; the possible application of different, additional grounds for processing personal data; and the Google Spain judgment itself – since it provides for an alternative, more effective means of blocking access to the personal data concerned.


Barnard & Peers: chapter 9