Jose Felgueroso
Abogado | Attorney

  • Home
  • Blog


The End of the Privacy Shield Agreement between the European Union and the United States

info@josefelgueroso.com

Versión en español

2020-11-09

Last July, the Court of Justice of the European Union (CJEU) invalidated a decision of the European Commission implementing the Privacy Shield Agreement, thus eliminating one mechanism to transfer personal data from the European Union to the United States.

Summary of the Judgment

The High Court of Ireland referred several questions to the CJEU related to the adequate level of protection provided for personal data transferred from the European Union to the United States under the Privacy Shield and the standard contractual clauses approved by the European Commission. The CJEU ruled the following:

  • The General Data Protection Regulation (GDPR) applies to the commercial transfer of personal data from an economic operator established in the European Union to an economic operator established in a third country, regardless of whether that data is used by the authorities of the third country to protect national security;
  • The European Commission's decision implementing the Privacy Shield Agreement between the European Union and the United States is invalid;
  • the European Commission's decision on standard contractual clauses for the transfer of personal data to processors established in third countries is valid.
Source: Pixabay.

Background and Procedural History

Maximilian Schrems is an Austrian national, a resident of that country, and a Facebook user. All Facebook users in the European Union enter into a contract with Facebook Ireland, which then transfers the personal data of European users to Facebook Inc. ("Facebook USA"), a company based in the United States.

In a previous case (Schrems I), Schrems complained to the Irish Data Protection Commissioner about Facebook Ireland's personal data transfers to Facebook USA, challenging the validity of Decision 2000/520 of the European Commission (the "Safe Harbor Decision"), which had found that the safe harbor principles issued by the US Department of Commerce provided adequate protection to personal data transferred from the European Union to the United States. The Irish Data Protection Commissioner rejected Schrems's complaint, and Schrems appealed to the Irish High Court, which referred several questions to the CJEU. As a result, the CJEU invalidated the Safe Harbor Decision.

The Irish High Court then referred the case to the Irish Data Protection Commissioner, which asked Schrems to reformulate his complaint in view of Decision 2010/87/EU of the European Commission on standard contractual clauses for the transfer of personal data to third countries (the "Standard Contractual Clauses Decision"). Facebook Ireland transferred much personal data to Facebook USA based on the Standard Contractual Clauses Decision.

Schrems claimed that United States law requires Facebook USA to provide personal data to United States authorities, and that the Standard Contractual Clauses Decision did not justify the transfer of personal data to the United States. Schrems asked the Irish Data Protection Commissioner to prohibit the transfer of personal data to Facebook USA.

The Irish Data Protection Commissioner then issued a draft decision indicating that United States law did not provide remedies compatible with the Charter of Fundamental Rights of the European Union (the "EU Charter"), and that the standard contractual clauses did not remedy the legal defects.

For its part, the European Commission, following the invalidation of the Safe Harbor Decision, adopted the Privacy Shield Decision, which found that the EU-US Privacy Shield provided an adequate level of protection for personal data transferred from the European Union to self-certified organizations in the United States. The EU-US Privacy Shield created the Privacy Shield Ombudsperson and included certain limitations and safeguards applicable to the access and use of personal data by United States authorities for law enforcement and other public interest purposes.

The Irish Data Protection Commissioner brought an action before the Irish High Court, which in turn referred the following questions, among others, to the CJEU:

  • Does the GDPR apply to commercial transfers of personal data from the European Union to the United States, when the personal data would be provided to United States authorities for purposes of national security?
  • How does one determine the adequate level of protection for personal data in the context of the transfer of personal data to a third country?
  • Does the Standard Contractual Clauses Decision violate the EU Charter?
  • Does the figure of the ombudsperson in the US State Department remedy the limited judicial remedies under United States law?
  • If the standard contractual clauses are inconsistent with a third country's surveillance laws, are the data protection agencies of EU member states required to suspend data flows to the third country?
  • Does the Privacy Shield Decision bind the data protection agencies of EU member states?

This article will focus on the validity of the Standard Contractual Clauses Decision and the Privacy Shield Decision.

The Standard Contractual Clauses Decision

The CJEU ruled that the Standard Contractual Clauses Decision is valid, as it found that it provides adequate safeguards for the transfer of personal data to third countries.

The transfer of personal data from the European Union to a third country must not violate rights recognized in the GDPR. If the European Commission has not issued an adequacy decision about the level of data protection of a third country, the data controller or processor must take adequate safeguards to protect the personal data transferred to the third country. In particular, the safeguards must provide enforceable data subject rights and effective legal remedies, including compensation and judicial and administrative redress for violations of rights.

In 2010, the European Commission determined that the standard contractual clauses provide adequate safeguards for the transfer of personal data to third countries.

Although the standard contractual clauses do not bind the authorities of third countries, the CJEU found that they contain safeguards. A recipient of personal data in the third country who cannot comply with the standard contractual clauses must inform the data controller about its inability to comply. In addition, if the data controller or the processor breaches the standard contractual clauses, the data subject is entitled to compensation. Finally, if the third-country recipient complies with an obligation in the third country that goes beyond what is necessary in a democratic society, the recipient breaches the standard contractual clauses.

Moreover, under the GDPR, the European Commission has no authority to restrict the powers of national data protection agencies, which can suspend the transfer of personal data, if necessary. If the third-country recipient notifies the data controller of a legislative change that has a negative impact on the standard contractual clauses and the controller continues to transfer personal data to the third country, the controller must forward the notification to the national data protection agency, which can suspend the transfer of personal data to the third country; if the European Commission has issued an adequacy decision for that third country, the national data protection agency can refer the matter to the European Data Protection Board. In addition, the data controller may include additional safeguards in the standard contractual clauses; if the controller or processor cannot take the required additional measures, the controller, the processor, or the national data protection agency must suspend the transfer of personal data to the third country.

The Privacy Shield Decision

The CJEU invalidated the Privacy Shield Decision, as it concluded that it failed to provide adequate protection to the personal data transferred from the European Union to the United States.

A transfer of personal data from the European Union to the United States must provide protection that is equivalent to the one provided by EU law, and in particular it must not undermine the rights recognized in the GDPR.

National data protection agencies have a key role in supervising the transfer of personal data outside the European Union. If a national data protection agency determines that a third country offers an inadequate level of data protection, it must take action, such as prohibiting the transfer of personal data to that country. If the European Commission, however, finds that a third country offers an adequate level of protection, the data protection agencies of member states are bound by that finding, but can still initiate court proceedings that may eventually lead to a reference for a preliminary ruling from the CJEU.

The adequacy of the level of protection of a third country is determined by the contractual clauses between the data controller or processor and the recipient, and the legal system of the third country read in light of the EU Charter. Any limitations on rights and freedoms must be clearly and precisely provided by law, must respect the essence of those rights, and be necessary taking into account the general interest and the rights of others. In addition, data subjects must have access to effective judicial or administrative redress.

The United States has a number of surveillance programs related to national security.

Section 702 of the Foreign Intelligence Surveillance Act (FISA) is one of them: if the Foreign Intelligence Surveillance Court (FISC) approves it, the attorney general or the director of national intelligence can authorize the surveillance of non-US citizens outside the United States. This is the basis for the programs PRISM (under which communications service providers must provide to the National Security Agency (NSA) communications based on certain attributes) and UPSTREAM (under which telecommunications companies must allow the NSA to copy and filter communications based on certain attributes). The FISC authorizes surveillance programs, not the surveillance of individuals, and section 702 does not provide limitations on surveillance or guarantees for non-US persons.

Presidential Policy Directive 28 (PPD28) provides procedures for the safeguarding of personal information collected from signals intelligence activities, but it does not grant to data subjects rights actionable in court.

Executive Order 12333 provides surveillance authority for intelligence agencies. Under this executive order, the NSA can access data in transit from abroad to the United States. Like PPD28, this executive order fails to grant rights actionable in court.

The Privacy Shield Decision provides certain principles for the transfer of data to the United States, but it states that national security and law enforcement have primacy over those principles. Thus, the CJEU found that the Privacy Shield Decision enables interference with fundamental rights.

Regarding the redress available to data subjects, the CJEU found that judicial redress was limited, and the existence of a Privacy Shield Ombudsperson failed to compensate for those limitations. In particular, the Ombudsperson reports to the United States secretary of state, there are no guarantees that the executive will not dismiss the Ombudsperson, and the decisions of the Ombudsperson do not bind the intelligence services. In sum, the existence of the Ombudsperson fails to provide a level of protection equivalent to the right to an effective remedy and a fair trial under the EU Charter.

In sum, the CJEU found that section 702, Executive Order 12333, and PPD28 fail to provide minimum safeguards for the rights of data subjects based in the European Union whose data is transferred to the United States. Accordingly, the CJEU concluded that the Privacy Shield Decision is invalid, because the transfer of personal data from the European Union to the United States under it fails to provide a level of protection equivalent to the level provided under EU law.

Significance of the Judgment

Privacy Shield was one mechanism for the transfer of personal data from the European Union to the United States. After the CJEU decision summarized above, other mechanisms remain, such as binding corporate rules, standard contractual clauses, and exemptions for specific situations.

Standard contractual clauses are likely to become the most common basis for regular transfers of personal data to the United States between different companies. The standard contractual clauses will not provide adequate protection in all cases, and sometimes the parties will have to include additional provisions to achieve that protection. Although standard contractual clauses do not bind the authorities of third countries, the parties to the contract must ensure that personal data is processed with an adequate level of protection; in some cases, the data protection agencies of EU member states may take their own measures, including the suspension of transfers of personal data.