logo text

Showing posts with label Binding Corporate Rules. Show all posts
Showing posts with label Binding Corporate Rules. Show all posts

Tuesday, 3 May 2016

You can't rely on the US Privacy Shield yet - EU report says 'must do better'


You’ll recall that on February 29th 2016, following months of intense negotiations, the European Commission unveiled the current proposals for the proposed new EU-U.S. Privacy Shield to enable compliant transfer of personal data from the EU to the US following the dismantling of the US Safe Harbor Scheme.  You’ll see our original blog article about it here.  As discussed in our original Blog, this proposed new compliance mechanism seemed fraught with political wrangling from the beginning.

It is disappointing, if not unsurprising perhaps, that the EU Article 29 Working Party (made up of data protection regulators from 28 Member States) (“Art29 WP”) recently declared that in their view the proposed self-certification US Privacy Shield is insufficient to protect the privacy of EU citizens and fails to meet EU adequacy standards. This means that anyone ‘holding out’ for the Privacy Shield to be finalised and turning a blind eye to compliance involving transfers of personal data to the US must certainly no longer continue to do so. It doesn’t look like there will be a definite solution in relation to the Privacy Shield anytime soon.

Although it was noted by the Art 29 WP that the Privacy Shield had made some improvements to the old US Safe Harbor Scheme, there were still a number of great concerns raised.  For example, the lack of clear rules surrounding data retention, over-collection and sharing of information for national security purposes and insufficient legal remedies for EU citizens. 

While the Art29 WP also raised some concerns about the adequacy of Binding Corporate Rules and the EU Standard Contractual Clauses, it has made clear that organisations can, for now, continue to use these mechanisms to enable compliance when transferring personal data outside the EEA. The Art29 WP will look into this issue again when the European Commission has made its decision on the adequacy of the Privacy Shield regime. Although this is expected to happen by June 2016, recent reports have made this deadline look rather shaky. 

At the end of April 2016, the U.S. Undersecretary of Commerce for International Trade made it clear that the U.S is not keen renegotiate the Privacy Shield and that believed that although the Art29 WP’s report was important, the U.S was not inclined to upset the “delicate balance that was achieved” through the Privacy Shield negotiations.

The continued debate means that organisations that already transfer personal data across the water to the U.S face sustained uncertainty. 

Don't get caught out without a compliant US transfer solution in the meantime. If you need our advice on how to transfer personal data legally to the U.S, please contact us.

Thursday, 4 February 2016

Ding Dong Safe Harbor is dead: Long Live the EU-US Privacy Shield???

Announcement of the new ‘EU-US Privacy Shield’


We have previously reported the demise of the US Safe Harbor scheme in our October 2015 and January 2016 Pritchetts Blog reports.


Just after the end of 3 month so called grace period that was introduced to try and find a new compliance mechanism to permit transfer of personal information from the EEA to the USA, the European Commission announced that a new agreement had been reached on 2nd February 2016.


Key Facts about the new US international personal data transfer compliance mechanism:

  • The new scheme will replace the previous US Safe Harbor Scheme and is to be called the ‘EU-US Privacy Shield’; It is due to come into force within 3 months - if agreed (see below);
  • According to Andrus Ansip, the Vice-President of the European Commission, and VÄ›ra Jourová, Commissioner for Justice, Consumers and Gender Equality, who made the announcement, the new arrangement reflects the requirements set out by the European Court of Justice in the case of Maximilian Schrems v. Data Protection Commissioner (C-362-14) (which we have reported on previously here); On announcing the new scheme VÄ›ra Jourová said: “The new EU-US Privacy Shield will protect the fundamental rights of Europeans when their personal data is transferred to US companies. For the first time ever, the US has given the EU binding assurances that the access of public authorities for national security purposes will be subject to clear limitations, safeguards and oversight mechanisms. Also for the first time, EU citizens will benefit from redress mechanisms in this area. In the context of the negotiations for this agreement, the US has assured that it does not conduct mass or indiscriminate surveillance of Europeans. We have established an annual joint review in order to closely monitor the implementation of these commitments.”
 
EU negotiators suggested that the new scheme will:
  • Create tougher obligations on US companies storing personal data relating to EEA citizens;
  • Enhanced enforcement by the US Department of Commerce and Federal Trade Commission; 
  • More co-operation between the US and EEA data protection regulators; 
  • Limit access to EEA personal data by US public authorities; 
  • Create rights for EEA citizens to raise any concerns about the scheme with a new Ombudsman.

The European Commission are to prepare a draft adequacy decision, which is then to be discussed with the EU Article 29 Working Party.

 

 

So is that it? Are we all set to use the new ‘EU-US Privacy Shield’ in 3 months’ time?


We have reported previously on the views of the EU Article 29 Working Party (“Art29 WP”) on this issue. That group have continued meeting over the last few months to consider alternative options to the US Safe Harbor Scheme, primarily the use of the approved EC Standard Contractual Clauses and Binding Corporate Rules.


Now, following announcement of the proposed new EU-US Privacy Shield, the Art29 WP has released a statement setting out their current view that although the European Commission have agreed to go ahead with the new EU-US Privacy Shield, the Art29 WP were not involved in negotiations over the new scheme and as a result only have verbal commitments from the European Commission that the issues previously raised by the Art29 WP have been adequately dealt with.

The Art29 WP have set out four key protections that must be put in place, following EEA case law, before any US international personal data transfer takes place: 

  • Personal data should be processed based on clear, precise and accessible rules, including those allowing individuals to properly understand the various locations where their data are transferred; 
  • The principles of necessity and proportionality must be exercised in relation to the transfer of personal data. A balancing exercise should be carried out to consider the rights of individuals as well as the purposes for which data are collected and accessed for national security reasons; 
  • An effective, impartial and independent oversight mechanism should exist to monitor the collection of and access to personal data; 
  • Effective remedies must be made available to individuals to defend their rights.


The Art29 WP have also:
  • Expressed reservations about whether the new scheme will ensure these protections are in place and have made it clear that they would like to see full documentation relating to the proposed new scheme by the end of February 2016 in order to consider these issues further. Only then will it be able to issue a detailed statement on its views;
  • Indicated that it has similar concerns about the other compliance mechanisms currently permitting EU-US transfer ( for example, binding corporate rules and the use of the EC model contractual clauses). The group plan to carry out an analysis of these other options also;
  • Arranged to hold an extraordinary plenary meeting in late March 2016. Following that group will consider what personal data transfer mechanisms remain valid for US personal data transfers. The Chairperson of the Art29 WP, Isabelle Falque-Pierrotin, hopes that a final decision could be made by the end of April 2016;
  • Made it clear that in the meantime personal data transfer to the US cannot carry on relying on the previous Safe Harbor scheme. It encourages organisations to consider putting the other EEA international data transfer compliance mechanisms in place.


The European Parliament have also issued some concerns about the proposed new scheme in its press release stating amongst other concerns that “MEPs also voiced strong concerns over the envisaged safeguards to limit data collection, underlined the need to ensure an independent and individual complaints mechanism as well as access to judicial redress for EU citizens”.



The reaction to this new scheme has been mixed across Europe. One commentator from the Group of the Alliance of Liberals and Democrats for Europe stated: "We urgently need a thorough legal appraisal of the safeguards offered by the US. The legal status of these safeguards is very unclear. It is highly doubtful that they offer meaningful protection to European citizens, or if they meet the standards set by the ECJ."



So what do we do now, especially if we are not even sure that the Privacy Shield will go ahead?



Given the apparent reluctance to commit to the Privacy Shield from many of the European Authorities, it seems that the Privacy Shield is far from a done deal.


No doubt some national data protection authorities will take a more hard line approach to enforcement in this area over the coming months. Although we believe the ICO are likely to take a light touch approach to enforcement action in the short term, ultimately, doing nothing and waiting for a political solution is not really an option for organisations.


As above, it has been made absolutely clear that reliance on the old Safe Harbor scheme is no longer legal. Any organisations who have been taking a ‘wait and see’ approach have therefore a lot to do and fast.


For now, the Art29 WP has confirmed its position that the model clauses and binding corporate rules remain valid transfer mechanisms, pending deeper analysis.


Any organisations that have been relying on these compliance mechanisms to transfer data to the US may therefore decide to continue taking a ‘wait and see approach’ in relation to these approaches. Although, those in jurisdictions with tougher regulatory regimes may find that their regulators begin to take more stringent action, so watch this space.



We set out our thoughts on what compliance action you should consider taking at this stage under the heading ‘How have businesses reacted to the development?’ in our January Blog article. That Blog also sets out the likely changes under the proposed new European General Data Protection Regulation. Our opinion set out in that Blog remains the same after recent announcements.


Please do consider contacting Pritchetts if we can be of any assistance to you in carrying out analysis of your compliance options or indeed helping you put alternative compliance mechanisms in place.

Thursday, 22 October 2015

3 months grace period to put US data transfer compliance measures in place post Schrems



How are the Article 29 Working Party and the EU member states reacting to the recent ECJ ruling on Safe Harbor?


Initial Comment and Guidance

Following the ECJ judgment on Schrems on 6th October 2015, various regulators issued statements and guidance within a short space of time. For example: the EU Article 29 Working Party, the UK Information Commissioner’s Office and the Spanish DPA published statements (see links provided) on the judgment.  In basic terms each of those statements said they would consult with other EU data protection authorities to issue more detailed guidance for organisations on what to do next.  The European Commission also said that it will issue "clear guidance" in the coming weeks to prevent member states' data authorities issuing conflicting rulings.

German Schleswig-Holstein Guidance

On 14th October 2015, Germany’s northern Schleswig-Holstein state issued its own guidance following the ECJ decision.  There are 16 federal states in Germany and each one directly oversees data protection matters.  Their approach can differ and Schleswig-Holstein is known to take a very conservative and stringent approach.  Perhaps unsurprisingly then, they produced a very strict paper, in which they questioned whether compliant data export to the USA could even be based on EU Model Clauses and further queried whether consent would be valid.

The Schleswig-Holstein authority draws on Article 5 (b) which outlines that an importer has to warrant “that it has no reason to believe that the legislation applicable to it prevents it from fulfilling the instructions received from the data exporter and its obligations under the contract.” The authority believes an importer in the US is no longer in the position to give such a warranty.

Also, the controllers transferring data to a US processor should “take into consideration terminating the data transfer agreement or suspending the data transfers.” Schleswig-Holstein states: “In consequential application of ECJ’s decision a data transfer based on model clauses is no longer admissible”.

This strict interpretation of the recent ruling – if adopted – would certainly call into question the operations of many multi-national companies where transferring data to the US.  Internal compliance management and monitoring within companies of all sizes, but most especially within the big multi-nationals, is set to become a hot topic. 

Ultimately though, as this particular German authority is the only one likely to publish such a formal response, all eyes are turning to the response and guidance from the Article 29 Working Party group.

So what is the WP29 view?

The European Article 29 Working Party group met on 16th October 2015 to discuss the consequences of the ECJ’s ruling.  

Their subsequent statement has urged EU Member States and institutions to come together with the US authorities to work on appropriate political, legal and technical solutions to enable legally compliant data transfers to the US that also protect the fundamental rights of EU citizens.

It has also indicated that further analysis of the ECJ decision will be undertaken to look at its impact on other means of transferring data used by some companies - such as the European Standard Contractual Clauses and the Binding Corporate Rules. 

The WP29 group has indicated that, for now, other alternative EU approved compliance transfer mechanisms can continue to be put in place to ensure compliance, but it has warned that:  

  • National data protection authorities can use their relevant powers to investigate and take punitive steps to protect individuals in the event of a complaint; 
  • These national DPA’s could even come together the co-ordinate enforcement action if compliance solutions are not agreed with the US authorities by the end of January 2016.

So given that the EU-US Safe Harbor Scheme has been invalidated as a compliant transfer mechanism thanks to the Shrems case, organisations have effectively been given 3 months grace to consider their business processes and to adopt relevant legal and technical solutions when transferring personal data to the US in order to remain compliant.  

If you require any further information or advice on how to stay compliant when transferring data to the US, on implementing the European standard contractual clauses to ensure compliance, or indeed with any other data protection or privacy matter then please do not hesitate to contact Pritchetts.