Showing posts with label Europe. Show all posts
Showing posts with label Europe. Show all posts

Monday, December 30, 2019

European Privacy: Complexity and High Stakes

European Union FlagEurope has the world's strongest data protection laws, and highest potential sanctions for non-compliance (€20MM or 4% of global revenue, not to mention criminal penalties!), so it makes sense for privacy professionals with global responsibility to become well-versed in European data protection law.  After working intensely in 2017 and 2018 to help my colleagues in Europe establish a GDPR program for one of the world's largest consumer-facing companies, and having remained actively involved in European data protection matters since, I finally felt I had the knowledge and experience to pursue certification in European data protection from the International Association of Privacy Professionals.  Today, I received that certification. 

According to the IAPP, which is the world's premier (and largest) data protection certification organization, a CIPP/E designation means one has "the comprehensive...knowledge, perspective and understanding to ensure compliance and data protection success in Europe." To demonstrate mastery of the field, all applicants must pass a rigorous exam which covers all of the topics listed here, including European legal frameworks, institutions, history, treaties, private sector laws, public sector laws, national laws, norms and standards, and best practices.

If you have an interest in obtaining the CIPP/E designation, I'd be happy to talk with you about it, and specifically how I studied for the examination.

Going forward, I might be posting more content to this blog relating to European data protection (I've been writing and speaking about it since 2015), if the posts receive enough traffic to indicate interest.

(P.S.- Special thanks to my friend and brilliant Italian lawyer Fabio Svizzero for the many hours spent explaining the nuances of EU data protection law and customs!)

Tuesday, June 28, 2016

BREXIT: Unchartered Territory for EU and UK Data Protection Standards

My law partner, Deana Labriola, has written a piece about the Brexit and its impact on the GDPR. 


BREXIT: Unchartered Territory for EU and UK Data Protection Standards

| Deana A. Labriola
So what changed on June 23, 2016? Maybe everything, and then again, maybe nothing at all.  The UK is leaving the EU.  While this decision will have far reaching implications for years to follow, it may be far less impactful for data protection laws, at least in the short term.


You can read the rest here:   http://www.wardandsmith.com/articles/brexit-unchartered-territory-for-eu-and-uk-data-protection-standards

Monday, May 30, 2016

European Data Protection Supervisor Rejects Proposed U.S. Privacy Shield

Today, the European Data Protection Supervisor (EDPS) delivered a crushing blow to the proposed Privacy Shield, sending U.S. and European negotiators back to the drawing board.


Readers of this blog know about the collapse of the EU/US data privacy Safe Harbor framework (which had been in place since 2000) and the efforts to negotiate a trans-Atlantic resolution (see my prior posts here, here and here).  The EU/US Safe Harbor was struck down by the EU Court of Justice last year, and officials have been scrambling to replace it.  This spring, the U.S. Department of Commerce released a proposal (the "Privacy Shield") designed to satisfy European officials that U.S. organizations could be trusted with information about Europeans.  I have already described that proposal in relative detail, here.

The European Data Protection Supervisor (EDPS), appointed in 2014, is an independent institution of the EU, responsible European law "for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to privacy, are respected." Under Article 28(2) of Regulation 45/2001, the European Commission is required, "when adopting a legislative Proposal relating to the protection of individuals' rights and freedoms with regard to the processing of personal data", to consult the EDPS. Since the submission of the proposed Privacy Shield to the EDPS, officials on both sides of the Atlantic have been holding their respective breaths in anticipation of this Opinion.

Earlier today, EDPS Giovanni Buttarelli declared that the Privacy Shield was "not robust enough." Although "a step in the right direction" it was deemed inadequate. Specific criticisms involve safeguards, judicial redress, and routine access by U.S. governments.  In Opinion 4/2016, titled "Opinion on the EU-U.S. Privacy Shield draft adequacy decision", the EDPS outlined three main recommendations (integrating data protection principles, limiting exceptions, which are referred to in EU law as "derogations", and improving redress and oversight mechanisms) as well as five secondary recommendations. You can read the full text of the EDPS Opinion for yourself here

The sense of urgency is real. The General Data Protection Regulation (technically regulation EU 2016/679, but known simply as the "GDPR") becomes effective in May 2018, and the Privacy Shield was intended to take effect before the GDPR in order to satisfy its requirements in addition to the existing EU legal framework.

Stay tuned, as there is certainly much more to come.



Sunday, March 6, 2016

Has The U.S. Found A "Privacy Shield" That The E.U. Can Live With?

Regular readers know I've been writing recently (here and here) about the collapse of the EU/US data privacy Safe Harbor framework and the efforts to negotiate a trans-Atlantic resolution. This is a major issue for U.S. organizations that do business in Europe or with Europeans. 

On Monday (February 29), the U.S. Department of Commerce released a proposal (the "Privacy Shield") designed to "provide[] a set of robust and enforceable protections for the personal data of EU individuals." The Privacy Shield release is *just* 132 pages, which you can read here

To rely upon the Privacy Shield framework, a U.S. based organization would be required to self-certify to the Department of Commerce and publicly commit to comply with the Privacy Shield's requirements. While joining the Privacy Shield framework will be voluntary, once an organization undertakes to comply with the Framework’s requirements, the commitment will become enforceable under U.S. law. Key elements are outlined in a "fact sheet" here, including the following:
  • The Privacy Shield contains seven distinct categories of "principles" including notice, choice, accountability for onward transfer, purpose limitation, recourse, enforcement and liability among others. (These should sound familiar to those who previously complied with the Data Protection Directive.)
  • U.S. entities will continue to self-certify.
  • U.S. entities will adopt a privacy policy statement which will become legally enforceable.
  • When a U.S. entity's privacy policy is available online, it must include a link to the Department of Commerce’s Privacy Shield website and a link to the website or complaint submission form to investigate individual complaints.
  • A U.S. entity must inform individuals of their rights to access their personal data, the requirement to disclose personal information in response to lawful request by public authorities, which enforcement authority has jurisdiction over the organization’s compliance , and the organization’s liability in cases of onward transfer of data to third parties.
  • Privacy Shield participants must limit personal information to the information relevant for the purposes of processing. Additional personal information may not be collected and retained.
  • To transfer personal information to a third party acting as a data controller, a Privacy Shield participant must:
    • Comply with the Notice and Choice Principles.
    • Enter into a contract with the third-party controller that provides that such data may only be processed for limited and specified purposes consistent with the consent provided by the individual and that the recipient will provide the same level of protection as the Principles.
  • To transfer personal data to a third party acting as an agent, a Privacy Shield participant must:
    • Transfer such data only for limited and specified purposes;
    • Ascertain that the agent is obligated to provide at least the same level of privacy protection as is required by the Principles;
    • Take reasonable and appropriate steps to ensure that the agent effectively processes the personal information transferred in a manner consistent with the organization’s obligations under the Principles;
    • Upon notice, take reasonable and appropriate steps to stop and remediate unauthorized processing; and
    • Provide a summary or a representative copy of the relevant privacy provisions of its contract with that agent to the Department upon request.
  • Privacy Shield participants must respond promptly to inquiries and requests by the Department of Commerce for information relating to the Privacy Shield Framework.
  • Privacy Shield participants must make public any relevant Privacy Shield-related sections of any compliance or assessment report submitted to the FTC if the organization becomes subject to an FTC or court order based on non-compliance.
  • If an organization leaves the Privacy Shield Framework, it must annually certify its commitment to apply the Principles to information received under the Privacy Shield Framework if it chooses to keep such data or provide “adequate” protection for the information by another authorized means.
There's still a big question mark: A genuine uncertainty exists as to whether the proposal will be approved (i.e., deemed "adequate") in Brussels.  If the EU determines that the Privacy Shield framework is adequate, the U.S. Department of Commerce will begin accepting certifications from U.S. organizations promptly.



Wednesday, December 16, 2015

New European Privacy Plan Released!

Yesterday the European Parliament and Council announced they have (finally) agreed upon a new General Data Protection Regulation (the GDPR).  This is really big news for all U.S. companies that do business in Europe or with Europeans!


The GDPR has not yet been voted into law, but the agreed-upon language is probably quite close to the final law.  The International Association of Privacy Professionals (of which I'm a certified member) has published a great, concise list of the key provisions, which I commend to you:


• The law applies to any controller or processor of EU citizen data, regardless of where the controller or processer is headquartered.


• Notification of a data breach that creates significant risk for the data subjects involved must be made within 72 hours of the discovery of the breach.


• New powers are provided to data protection authorities, including the ability to fine organizations up to four percent of their annual revenue.


• Many organizations will now be required to appoint a data protection officer.


• Personal data may only be collected for “specified, explicit and legitimate purposes."  The text also introduces principles of “data minimization,” “accuracy,” “storage limitation” and “integrity and confidentiality.”


• The GDPR requires “accountability,” which means the “controller shall be responsible for and be able to demonstrate compliance” with the law.


• Processing of data will only be allowed with explicit consent, to perform a contract, to comply with a legal obligation, to protect the vital interests of the data subject, or to perform a task in the public interest.


• That consent has to be demonstrable upon demand, can be retracted by the data subject at any time.


• There will still be variation from member state to member state.


• Children under the age of 16 will need to get parental approval to give consent unless the member nation passes a law to lower the age no lower than 13.


• Special categories of personal data are established that include genetic, biometric, health, racial and political data, among others.


• Data controllers have to provide any information they hold about a data subject free of charge and within one month of request.


• A “right to erasure” is established, where controllers are required to delete personal data...even if the data has been made public already.

The next legislative step is for the EU Parliament’s Committee on Civil Liberties, Justice and Home Affairs ("LIBE Committee") to vote on the text tomorrow  (December 17) and if it passes, the full Parliament is expected to vote in January.

There is much more to come on this very significant development.  I will be sharing commentary on Twitter (@MattCordell and @PrivacyLawNC) and on LinkedIn as I come across it.

Source: https://iapp.org/news/a/gdpr-we-have-agreement/



Tuesday, October 6, 2015

The EU/US Safe Harbor Is No Longer Safe, Says The EU's Highest Court. Is Your Data A Liability?

freefoto.com
Today, Europe's top court, the European Court of Justice, ruled that a 15-year-old pact between the United States and the European Union which allowed American organizations to handle the personal data of Europeans (the EU/US Safe Harbor) was invalid. The decision will have massive, far-reaching implications for American businesses and other organizations that are active in Europe.



The Backdrop



Trans-Atlantic data transfers involving the personal information of Europeans must comply with the Data Protection Directive, which is a European pact that has been adopted by each member state (i.e., most of Europe, but not Switzerland). The Directive requires that a transfer of personal data to a non-EU country may take place only if that country ensures an adequate level of data protection and privacy. The Directive also provides that the EU Data Protection Commission may determine that a non-EU country ensures an adequate level of protection as a result of that country's own domestic privacy laws or an international treaty.



The Facts



The challenge to the Safe Harbor arose in legal proceedings between an Austrian citizen, Mr. Maximilian Schrems, and the Irish Data Protection Commissioner concerning the Commissioner's refusal to investigate a complaint made by Schrems. Schrems has been a Facebook user since 2008, and some or all of the data provided by Schrems to Facebook was transferred from Facebook’s Irish subsidiary to servers located in the United States. Schrems lodged a complaint with the Irish Commissioner, alleging that, in the light of the revelations made in 2013 by Edward Snowden concerning the activities of the US intelligence services (specifically the NSA), the law and practice of the United States do not offer sufficient protection against surveillance.



The Issues



In response to Schrems' allegations, Facebook pointed out that it was fully compliant with the EU/US Safe Harbor and the US Department of Commerce's requirements for participation in the Safe Harbor. The Irish Commissioner refused to consider the complaint because the EU Data Protection Commission had long ago ruled (in 2000) that the EU/US Safe Harbor was a valid basis for the trans-Atlantic transfer of personal data of European citizens. (As a technical legal matter, the case was a challenge of the validity of Commission Decision 2000/520/EC (26 July 2000) pursuant to Directive 95/46 on the adequacy of the protection provided by the safe harbor privacy principles and related FAQ issued by the US Department of Commerce.)



The Court's Conclusions



The Court concluded that the decision by the EU Data Protection Commission that the EU/US Safe Harbor is valid did not preclude a member nation's Data Protection Commissioner (in this case Ireland) from reaching the opposite conclusion. The Court ruled that the Irish Commissioner should have heard the complaint and made an independent determination whether the EU/US Safe Harbor provides adequate protection of the personal information of EU citizens in light of the fact that the US government's surveillance programs might not respect the privacy of EU citizens as interpreted under EU law.


The Court went further to evaluate the 2000 decision of the EU Data Protection Commission. It determined that in the US, national security, public interest, orlaw enforcement interests prevail over the Safe Harbor scheme, so that US organizations are required by US law to disregard the protective rules laid down by the Safe Harbor when they conflict with US policy interests. The Court then concluded that US law, and the Safe Harbor, enable interference by United States national security and law enforcement authorities with the fundamental rights of Europeans. This interference is incompatible with the Directive, said the Court.



Having reached these conclusions, the Court held that the Irish Commissioner was required to evaluate Schrems’ complaint "with all due diligence" and following its "investigation," was obligated to "decide whether, pursuant to the Directive, transfer of the data of Facebook’s European subscribers to the United States should be suspended on the ground that that country does not afford an adequate level of protection of personal data." The Court essentially remanded the case to the Irish Commissioner with instructions to evaluate the issues, and with the subtext that the EU/US Safe Harbor is inadequate.



You can read the Court's decision here, and the Court's press release here.



No appeal is possible, because the European Court of Justice is the equivalent of the U.S. Supreme Court--the court of last resort. Simultaneously, European leaders and US officials are negotiating a new agreement on trans-Atlantic data transfers. Today's decision will no doubt create a new degree of urgency in those talks.



What Does It Mean to Your Organization?



In other words, the Safe Harbor is no longer SAFE at all!The likely outcome of this decision is that transfers of personal data made under the auspices of the Safe Harbor may violate European data protection laws. In other words the Safe Harbor is not really "safe" after all. Without the Safe Harbor, each country in the EU could reach different conclusions as to whether US privacy laws and practices satisfy the EU's Directive, which would require US companies to address each member nation's laws individually rather than satisfying a single set of EU requirements. This could create enormous obstacles to US organizations doing business in Europe.



As a result, organizations are well-advised to take a belt-and-suspenders approach (or "belt-and-braces" as they say across the Atlantic) by ensuring that data transfers are justified on another basis (in addition to compliance with the Safe Harbor). Those other bases include "binding corporate resolutions" (in which the organization essentially passes a binding corporate resolution and to comply with EU law with respect to EU personal data) and "model clauses" (which are contractual obligations to comply with EU privacy requirements). The binding corporate resolutions and model clauses have frequently been deemed more onerous for US organizations than the Safe Harbor's requirements, and have historically been less popular among US organizations.



- Matt Cordell