The General Data Protection Regulation (GDPR) provides that ‘European’ personal data may not simply be provided to persons and organisations outside the European Economic Area. This is only permitted if the level of protection in the third country broadly corresponds to the level of protection within the EU. Between the EU and the US, this was intended to be achieved through the Privacy Shield arrangement concluded between companies and a private organisation. It is therefore not government legislation. This made it possible under the GDPR to share personal data from the EU to the US (a third country), because it was supposed to provide adequate protection. The recent Schrems II ruling of the Court of Justice of the European Union (CJEU) puts an end to this practice as of 16 July 2020.
Why does Privacy Shield offer insufficient protection by European standards?
The GDPR sets out a number of routes by which personal data can, under certain circumstances, be transferred to parties in third countries. One of these is transfer on the basis of adequacy decisions, whereby it is decided that a particular country offers adequate protection to individuals against the infringement of their privacy. The Privacy Shield arrangement fell under this route. However, the Court decided that the EU-US Privacy Shield did not, after all, sufficiently protect personal data.
Firstly, because it could not be guaranteed that the personal data would not be used for purposes other than those for which it was provided. The main reason for this is US legislation. US intelligence and security services, in certain circumstances, have the right under the Cloud Act to access and use the data of EU citizens, for example in combating terrorism. According to the Court, this interference is not limited to what is strictly necessary, and as a result there is too great a risk of arbitrariness and improper use. Moreover, according to the Court, there are insufficient legal avenues available to the data provider and the data subject to oppose this interference. All in all, the Privacy Shield arrangement is an infringement of the European and universal (human) right to data protection. The Court therefore declares the adequacy decision concerning the Privacy Shield invalid.
What consequences does this have for everyday practice?
There are quite a number of companies and organisations that transfer personal data, on the basis of the EU-US Privacy Shield arrangement, to parties that store this data on US territory. Think, for example, of Microsoft and all the personal data that is processed and stored daily via US servers using Microsoft Office365. Microsoft was the first American company to join the Privacy Shield. From 16 July 2020, all companies that do business with Microsoft and have not made a conscious choice for European servers are therefore acting in breach of the GDPR. This is probably the majority of Dutch business.
What is the solution to this problem?
Fortunately, the GDPR does mention other ways of transferring personal data to parties in third countries. Examples of these are ‘transfers based on appropriate safeguards’ and transfers via ‘Binding Corporate Rules’. In the same ruling, the CJEU decided that transfer of personal data to third countries is still possible via model contracts (Standard Contractual Clauses (“SCCs”)). But this too is only permitted if the level of protection in the third country broadly corresponds to the level of protection within the European Union. The Court states that, when assessing this level of protection, account must be taken of the contractual provisions themselves (i.e. the content of the SCCs), and the relevant aspects of the legal system of the third country to which the data is being sent (such as any access by government authorities). The controller, i.e. the companies choosing their email applications and hosting providers, will have to assess for themselves whether the personal data is well protected in the specific circumstances of the case when transferred to a party in a third country. Moreover, the controller will have to document this assessment carefully, because of the accountability obligation under the GDPR. That will not be an easy task.
A more concrete European guidance document is on the way.
The European Data Protection Board (EDPB) is currently investigating, incidentally, what the concrete consequences of the Schrems II ruling are with regard to the Privacy Shield. In the near term, the EDPB will provide more explanation about additional measures that organisations can include in model contracts.
Do you need advice on this topic? Then fill in our contact form, call us on 020-3450152 or email us at info@thelegalprivacycompany.com.
Would you like to be directly informed of relevant legal developments for SMEs from now on? Then sign up for our monthly Legal Alert newsletter and follow our company page on LinkedIn.
Nothing changes as often as laws and regulations. We would like to point out that our blogs may no longer be in line with current laws and regulations and may therefore be outdated. If you have questions or a problem relating to this blog, or if you require legal assistance, please contact us.