Posted in

Privacy Shield – Houston, We Still Have a Problem!

Imagine posting a picture on Facebook of yourself and your mates clubbing and the next thing you know you are getting a phone call from a United States (U.S.) government representative asking you about your night out.

Scary, isnt it? This way George Orwells quote Big Brother is Watching You in his book 1984, is becoming fact rather than being fiction.[1] In order to prevent this from happening the European Commission (EC) has been working on an agreement with the U.S., called the Privacy Shield, to impose obligations on U.S. companies to protect personal data of EU citizens when transferring data between the EU and the U.S.

This agreement was formed following the destruction of the previous agreement, Safe Harbour, which was in place between the two continents. The previous agreement was ruled invalid by the European Court of Justice in the Schrems case.

By discussing the difference between both agreements in this article, it will become clear that the EC needs to have a closer look at the Privacy Shield agreement they are about to sign with the U.S. in order to protect its citizens from any 1984-scenario to become reality.

Why did the Safe Harbour agreement get destroyed by Schrems?

As a matter of background information, Max Schrems lodged a complaint with the Irish Data Protection Authority (DPA). He took the view that, in the light of Snowdens revelations concerning the activities of the U.S. intelligence services, the law and practices of the U.S. offer no real protection against surveillance of the data transferred to that country.

Before Schrems ruling, the U.S. and the European Union (EU) transferred data on the basis of Safe Harbour. This was an agreement between the two continents that gave U.S. companies the opportunity to self-certify in order to comply with privacy laws protecting the EU citizens. The agreement consisted of seven principles. If a company did not comply, it could be penalised by the FTC.

The European Court of Justice (Court) ruled the Safe Harbour agreement invalid in favor of Schrems. The Court stated that permitting the public authorities to have access to data on a generalised basis must be regarded as compromising the right to the respect for private life.[2] Generalised access can only be applied if strictly necessary.[3] Furthermore, the Court made the observation that the possibility to pursue legal remedies for individuals was not provided for in the agreement. Lastly, the Court found that the agreement denied national supervisory authorities their powers.

So, what is the Privacy Shield about?

On the back of the complaint by privacy activist Max Schrems on October 6<sup>th</sup> of last year, the Court ruled the Safe Harbour agreement invalid. Since, the EC and the U.S. Department of Commerce (DoC) have put together a new agreement regarding data protection standards for data transfers across the Atlantic, referred to by the E.U.-U.S. Privacy Shield.

In a nutshell this new agreement imposes stronger obligations on U.S. companies to protect EU citizens personal data. Similar to Safe Harbour, companies have to self-certify annually to ensure they meet the requirements of the new agreement in order to protect the personal data of Europeans. The DoC and the Federal Trade Commission (FTC) in the U.S. will monitor and enforce the implementation. In case of repeated violation of compliance, companies will be sanctioned or excluded from the agreement. As a consequence, transferring data across the two continents would become an illegal activity for these companies.

For the first time ever the U.S. has assured that any access of public authorities to personal data will be subject to clear limitations. However, the Privacy Shield agreement describes six exceptions under which bulk collection of data would still be possible.[4]

Mass data gathering is still possible under Privacy Shield

The EC claims the new Privacy Shield agreement reflects the requirements set by the Court in the Schrems ruling. However, the definition of the six exceptions is quite broad. Mass and undefined data gathering, on the basis of these exceptions, is therefore not necessarily proportionate.

Going back to you. Youre clinging your sweaty hand around your phone whilst trying to understand why the U.S. government is calling you. The exceptions under which the U.S. is able to require access to data are quite ambiguously formulated. So lets say one of your mates brought a friend to the club, who you had never met before. Apparently that friend has close connections to someone who is accused of being a member of a terrorist organisation. Does this give the U.S. the right to access your data and follow up on it?

The first question to answer is, can the U.S. classify your evening out as a risk of terrorism and use that as an exception to access your data? One could argue either way, but what becomes obvious in your case is that the criteria are defined in such broad fashion that it is difficult for any individual to gain protection from them. As such, the new agreement still does not safeguard respect for private life nor does it provide sufficient protection of it. Therefore, it might not provide the adequate level of protection, since transfer may only take place if the third country in question ensures an adequate level of protection, barring the permitted derogations.[5] When a third country does not ensure an adequate level of protection the EU Member State shall take the measures necessary to prevent any transfer of data.

Enforcement of the Privacy Shield

So, youve hung up the phone, trembling and still figuring out what just happened. Some of the questions circling through your mind, trying to recall your answers and whether youve said the right thing: what were you doing in the club, how long did you stay for, who were you with, did you know everyone, how did you know them.?

After a while everything is starting to sink in and the anger is creeping up. What gave the U.S. the right to call you? You were just having fun with some friends. Why should that be any of their business? You would like to raise a complaint under the new EU-U.S. Privacy Shield conditions. How do you go about that?

Lets assume you find a way of arguing that this particular case cannot be classified under the exception of counter-terrorism. Under the new agreement you are able to redress directly with Facebook, who is obliged to respond to you within 45 days. You can also go directly to the DPA in your country, which will work with the U.S. DoS and FTC to investigate and resolve the situation. Lastly, you can redress through the ombudsperson in the U.S who reports to the U.S. authorities, under the Secretary of State. And if all of that does not get you anywhere, you can pursue prosecution under U.S. law.

Redressing with the company who passed on your personal data was already a possibility in the Safe Harbour agreement. The Privacy Shield agreement differentiates itself from the previous agreement by empowering the national supervisory authorities to solve the issue straight with the DoS and the FTC in the U.S. This remedy is put in place as a direct response to the Schrems ruling. However, it does not provide any guarantees to the person who raises the complaint.

The Court in the Schrems ruling also explicitly made a point of stressing the need of independence when it comes down to examining national authorities.[6] One could claim that since the ombudsperson reports into U.S. authorities under the Secretary of State, this solution could hardly be seen as independent. Furthermore, the ombudsperson is not obliged to provide any motivation when judging a transfer to be compliant or not. On top of that the FTC and DoC do not have any obligation to take a complaint on.

Lastly, one could question whether the possibility for EU citizens to object in the U.S. court is one they would be able to pursue. First of all, the EU citizen needs to be able to proof his loss. If he can, the objection will be handled under U.S. law, to be specific under the U.S. Privacy Act of 1974. This regulation does not offer the same level of protection as the European data protection legislation does. Therefore: is the Courts issue, expressed in the Schrems ruling, regarding the lack of possibilities to pursue legal remedies, really resolved with this new agreement?

All in all, the Privacy Shield does pay attention to means of enforcement. It is questionable how effective these are though, since all of them are means on U.S. grounds. Hence, there is a language barrier and insufficient knowledge of the U.S. legal system for EU citizens to act effectively.

The different privacy views of the U.S. and the EU

EU citizens have the right to respect for their private and family life, including protection of their privacy.[7] Privacy is a continuously changing concept and the interpretation of it depends on socio-cultural factors and varies by context.[8] There is a clear difference between the European culture emphasizing the protection of the right of respect and personal dignity, versus the U.S. tradition, which is oriented towards the values of freedom.[9] Since societies have become more international over the last decades, the difference in point of view between the EU and the U.S. has become more prevalent when it comes to privacy.[10].This is an important notion, as the enforcement of the rights for EU citizens provided by the Privacy Shield can solely be claimed on U.S. grounds.

How the Privacy Shield and Safe Harbour differ

In short, it has to be said that the Privacy Shield agreement gives you certainly more possibilities to appeal than the previous Safe Harbour agreement did. Both agreements let companies, with oversea data capturing activities, self-certify. In your case, you could contact Facebook and tell them to withhold from sending your party picture to a third party, including the U.S. government.

On top of that, the new agreement now gives you the opportunity to raise your complaint with your DPA who will connect with the U.S. DoS and FTC, or express your dissatisfaction with an ombudsperson in the U.S. If all these routes fail, you can prosecute under U.S. law. These were all measures that were not provided for under Safe Harbour. Having said that though, the effectiveness of these could be questioned.

Lastly, the new agreement prevents the possibility of mass and undefined data gathering by default. The default now is that this is not allowed, unless there is reason for exception. However, the issue with these exceptions is that they have been formulated in broad terms and therefore mass and undefined data gathering can fail to be proportionate.

Houston, we still have a problem!

The new Privacy Shield agreement makes one wonder whether this is solely legislation for show or whether we are actually trying to accomplish something essential to protect our privacy values in Europe? Or in Schrems words: They tried to put ten layers of lipstick on a pig, but I doubt the Court and the DPAs now suddenly want to cuddle with it.

The chances are that this new agreement will not pass the Court. If this is meant to be a real attempt to protect art. 8 ECHR, the EC should reconsider the safeguard they are providing EU citizens, by having a closer look at the exceptions. With more narrowly defined exceptions you would not have to doubt whether your party evening could be classified as being linked to terrorism. Nor would Facebook when its asked to pass on the data.

The EC should also rethink the enforcement measures. Providing you with an independent and effective body to raise your complaints to, should you not agree with the exception rule that was followed to pass on your party picture. A step in the right direction could perhaps be to have the ombudsperson report to a European body or maybe the United Nations.

This article was co-authored by Menno Weij. Menno Weij specializes in ICT law, outsourcing, eCommerce, privacy as well as copyright and trademark law. In terms of copyright and trademark law, Mennos practice focuses mainly on software and Internet related aspects. He provides legal advice, assists in drafting, reviewing and negotiating complex ICT contracts and litigates regularly. Follow Menno on Twitter: @MennoWeij

  1. Orwell, 1949

  2. art. 8 of the European Convention on Human Rights. Paragraph 92-94 Schrems, https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62014CJ0362&from=NL

  3. paragraph 127 Digital Rights Ireland and Others https://curia.europa.eu/juris/document/document.jsf?text=&docid=145562&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=1051936

  4. Detecting and countering certain activities of foreign powers, counter-terrorism, counter-profileration, cybersecurity, detecting and countering threats to US or allied armed forces, combating transnational criminal threats, including sanctions evasion https://www.fbi.gov/about-us/nsb/fbis-policies-and-procedures-presidential-policy-directive-28-1

  5. The adequate level of protection is defined in art. 25 paragraph 2 EU Directive 95/26. The derogations in art. 26 EU Directive 95/26.

  6. Paragraph 36.1, 40, 57, 62, 99 Schrems. Art. 47 EU Charter of Fundamental Rights.

  7. Art. 8 ECHR.

  8. Habermas 1996, pp. 366, 368.

  9. Whitman 2004, pp. 1160-1164

  10. Dommering & Asscher 2006, pp. 146-147, 154-155.

Image: actonline.org

Vinne Schifferstein is a digital business professional with global experience in both B2C and B2B across the industries of Publishing, Education, Healthcare and Online marketing. Over the years she has led many digital media projects, ranging from digital product management, digital marketing, E-commerce, CRM, market research and user experience. She has a special interest in the cross over between business and the legal implications of data and copyright protection. 

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.