Showing posts with label Personal data. Show all posts
Showing posts with label Personal data. Show all posts

Monday, 27 March 2017

Lawyers from 28 countries analyse the legal challenges faced by start-ups

The 3rd IBA Silicon Beach Conference - All Along the Spectrum – From Start-Up to IPO/Exit and Beyond was held in Santa Monica, California from 1 to 3 February 2017. We at ELZABURU’s entrepreneurship and start-ups area (Legal & Business Department) had the chance to attend this international gathering as the only representatives from Spain.   

IBA (International Bar Association) is the largest lawyer network in the world. The conference brought together internationally renowned lawyers and expert academics, public institution representatives, entrepreneurs and venture capitalists to analyse the legal challenges faced by start-ups(1).

The conference offered interesting panel sessions and dynamic roundtable discussions on current issues, latest trends and strategies for developing, expanding, funding and exiting from a start-up company.

Of particular interest as far as IP is concerned were the sessions on the legal implications of the development of mobile applications, as well as those in which participants shared experiences in the development of a start-up company’s effective IP protection strategy. Without going into a full summary of the sessions, we would like to highlight the following debates and ideas:

1. Apps of Things (AoT)

The development and use of digital tools and services is growing at lightning speed.

Some time ago, we attended a vehement legal debate on this subject, which constitutes a global strategic priority and an area of intense legislative development.

Nevertheless, the sector referring to Apps of Things (AoT) - apps which turn our day-to-day objects into connected, intelligent devices capable of catering for a wide range of user needs, deriving from, and made possible by, the concept of the Internet of Things (IoT) – continues to be a trend, generating fresh challenges for lawyers and developers alike, and in this market start-ups play a particularly important role.   

The extent of personal data collection and exchange is continuing to grow significantly. People are disseminating an ever-increasing volume of personal data on a global scale. In fact, we have recently been coming across unprecedented cases concerning the implications of the collection of data and personal information by new technological devices that are, by default, “permanently active” and continuously recording, for instance, the voices of users within the private setting of their homes. We refer here to the recent privacy cases involving the intelligent device “Amazon Echo”, which includes the new voice control system (“Alexa”), one of the most promising recent technological advances(2).

These incidents ensure that the debate on the meaning and scope of the right to personal data protection, the new privacy model and user security is kept alive.

Friday, 21 October 2016

Brexit: Prospects for data protection

The decision made by the British people in the 23 June 2016 referendum has multiple consequences, many of them legal. Some have already been addressed, but the issue of what Brexit could mean for European citizens’ privacy and data protection rights has been pushed to the background.

The regulatory framework for data protection in the European Union conferred total freedom of circulation on data within the 28 Member States.  The United Kingdom’s exit from the EU, and consequently from that legislative environment, will therefore mean that its citizens will be considered as established in a third country, and issues such as those currently existing with the United States will have to be contended with.  Basically, sending data from any EU country to the UK will constitute an international data transfer, with the legal effects that this entails.
    
Obviously, given the importance of massive data processing for a company from any sector, the UK is not going to remain aloof from its former fellow Member States, since not interacting with the EU in this field would leave it out of the game in a sphere that is vitally important for the economy.   

This situation obviously gives rise to uncertainty -which will have to be cleared up by the British government in the coming months- concerning the decision to be made on the subject of data protection in the island State.

Friday, 15 July 2016

The European Commission launches the EU-U.S. Privacy Shield

On 12 July 2016, the European Commission adopted a new arrangement for international exchanges of data between the United States and the European Union, namely, the “Privacy Shield”.

The need for this new framework arose from the judgment rendered by the CJEU last October in the Schrems case. In its decision, the European Court pointed out the serious deficiencies in the previous “Safe Harbor” arrangement, to the extent that it was ruled invalid. [see our article on Safe Harbor]

In that regard, in February 2016 it was announced that there would be a new framework that would provide the necessary guarantees for the transatlantic flow of EU citizens’ personal data.  Just this month, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés –CNIL-) asked Facebook to stop compiling the data of users who did not have an account with the social media site and to stop transferring that data to the U.S., thus creating a growing awareness of transatlantic data transfers throughout the whole of Europe.   

For this reason, this new arrangement has been in the spotlight in a number of sectors ever since it was conceived.

The final wording of the arrangement seeks to reflect the following principles: 
  • Robust obligations on companies that handle data
  • Transparency and clear safeguards on U.S. government access                
  • Effective protection of individual rights
  • Annual joint review mechanism              

Those principles will be implemented by the following means: U.S. companies handling European citizens’ data will have to register to be on the “Privacy Shield” list and self-certify that they meet the standards set out by the arrangement; there will also be dispute resolution mechanisms that may be accessed by citizens who consider their rights to have been violated within the context of this system; and there will be cooperation between the European Commission and the U.S. Department of Commerce.                                        

The above measures merely seek to ensure an adequate level of protection of the personal data of EU citizens, as well as assurances for U.S. companies which, as market operators, handle that data. 

The adequacy decision is now in force, though U.S. companies will not be able to register to be on the aforementioned list until 1 August 2016. As regards EU citizens, the European Commission has announced that it will be publishing a guide to help get complaints procedures against companies underway.  For the time being, information has been provided in FAQ format along with the press release.

As is typically the case where such momentous issues are concerned, the terms of this new arrangement have been subject to heavy debate.

Figures such as the Euro MP Jan–Philipp Albrecht consider that although the arrangement might, at first glance, appear to provide guarantees, the practical application of its mechanisms could render it meaningless.  He highlights the intricate and complex nature of the rules for legal redress for unauthorised use of citizens’ personal data due to the large number of intermediaries involved, such as arbitration bodies and national authorities.  Also, a number of sectors have pointed out that the wording concerning mass surveillance echoes the “Safe Harbor” framework almost word for word.

It should nevertheless be noted that the “Privacy Shield” has been tweaked throughout the drafting process to accommodate the suggestions and opinions of the many authorities on the subject, such as the Article 29 Working Party, the European Parliament and the European Data Protection Supervisor.  

This provides another tool to promote trade between the European Union and the United States, one that is based on a vision that offers more guarantees as far as citizens’ rights are concerned.




Visit our website: http://www.elzaburu.es/en  

Wednesday, 7 October 2015

No Safe Harbour: Sailing in the tempest (Case Maximillian Schrems v Data Protection Commissioner)

The long-awaited decision in Case C-362/14 Maximillian Schrems v Data Protection Commissioner was finally issued on 6 October 2015. Controversial in its findings, this preliminary ruling sheds new light on the ongoing debate regarding the collection, transfer and processing of EU citizens’ data by US companies, and the processing of that data by US intelligence agencies within the framework of the PRISM program.


Background information

Mr. Schrems, an Austrian citizen, has been a Facebook user since 2008. In the case of all users residing in the EU, some or all of the data with which they provide Facebook is transferred from Facebook’s Irish subsidiary to servers located in the United States, where it is processed.

Mr. Schrems lodged a complaint with the Irish supervisory authority (the Data Protection Commissioner) on the grounds that, in light of the revelations made by Edward Snowden in 2013 concerning the activities of the United States intelligence services (in particular, the NSA), the law and practice in force in the United States did not offer sufficient protection against surveillance by the public authorities of data transferred to that country. The Irish supervisory authority rejected the complaint on the basis of the decision of 26 July 2000, which considered that under the “safe harbour scheme” the United States ensured an adequate level of protection of the personal data transferred (known as the Safe Harbour Decision).

Mr. Schrems then filed an appeal with the High Court of Ireland, which considered that the issue prompting his action was closely related to EU law since, according to that High Court, the Safe Harbour Decision did not comply with the principles set forth in the judgments in C-293/12 and C-594/12, EU:C:2014:238.


Preliminary questions submitted to the CJEU

On 17 July 2014, the High Court of Ireland, before which the case had been brought, submitted the following questions to the Court of Justice for a preliminary ruling:

(1)  Whether in the course of determining a complaint which has been made to an independent office holder who has been vested by statute with the functions of administering and enforcing data protection legislation that personal data is being transferred to another third country (in this case, the United States of America) the laws and practices of which, it is claimed, do not contain adequate protections for the data subject, that office holder is absolutely bound by the Community finding to the contrary contained in [Decision 2000/520] having regard to Article 7, Article 8 and Article 47 of [the Charter], the provisions of Article 25(6) of Directive [95/46] notwithstanding?

(2)  Or, alternatively, may and/or must the office holder conduct his or her own investigation of the matter in the light of factual developments in the meantime since that Commission decision was first published?

The Advocate General’s Opinion of 23 September 2015

According to the Opinion of the Advocate General (Yves Bot), a company, by merely having a Safe Harbour certification, would not automatically comply with the European data directive on export requirements.

This argument had already been made in Communication COM(2013) 846 and Communication COM(2013) 847.

As was to be expected, the CJEU followed the arguments put forward by the Advocate General.


Wednesday, 14 May 2014

The CJEU endorses the "right to be forgotten" in the EU

Paul David
(via Flickr)

On 13 May 2014, the Court of Justice of the European Union (CJEU) handed down its judgment in case no. C-131/12 between Google and the Spanish Data Protection Agency (AEPD).

On 5 March 2010, Mr. Costeja González filed a complaint with the AEPD against the publisher Vanguardia Ediciones S.L., Google Spain, S.L. and Google Inc. In the complaint he requested that La Vanguardia be required to remove or alter pages so that his personal data no longer appeared, or to use certain tools made available by search engines in order to protect the data. Mr. Costeja González also requested that Google Spain or Google Inc. be required to remove or conceal the personal data relating to him so that they ceased to be included in the search results and no longer appeared in the links to La Vanguardia. All these requests were based on the fact that the embargo proceedings to which Mr. Costeja González had been subjected at the time had been fully resolved for a number of years and were now entirely irrelevant.

On 30 July 2010 the AEPD dismissed the complaint against the publisher and upheld the complaint against Google Spain, S.L. and Google Inc., requiring them to withdraw the data from their index and prevent future access thereto. Google Spain, S.L. and Google Inc. proceeded to lodge appeals against the Audiencia Nacional (Spain’s High Court) requesting that the AEPD’s judgment be vacated.

Under these circumstances, the Audiencia Nacional suspended the proceedings and referred a series of preliminary questions to the CJEU:


  • The territorial application of EC Directive 95/46;
  • The definition of the scope of responsibility of search engines as providers of content in relation to EC Directive 95/46;
  • And the scope of the right of erasure and the right to object in relation to the right to be forgotten.

First of all, the CJEU classified the activity of a search engine which consists of “finding information published or placed on the internet by third parties, indexing it automatically, storing it temporarily and, finally, making it available to internet users according to a particular order of preference” as “processing of personal data”, thus converting the operator of the search engine into the controller of that processing of personal data, and the guarantor that the requirements of EC Directive 95/46, as well as the full and effective protection of the rights of the individuals in question, be fulfilled.

Turning to the territorial application, the CJEU rejected Google’s argument that Google Search did not carry out the processing of personal data as part of its activities in Spain. The CJEU ruled that Google Spain, S.L. must be regarded as an establishment within the meaning of Directive, since it is the subsidiary of Google Inc. in Spain. When a company with a seat in a third state has an establishment in a Member State and carries out the processing of personal data for the purposes of the service of a search engine in the Member State establishment, the Directive considers that this processing is carried out ‘in the context of the activities’ of the establishment if the intention is to promote and sell its goods and services in that Member State.

With regard to the extent of the responsibility of search engines as content providers in relation to the Directive, the CJEU stated that the controller of a search engine is obliged to remove from the list of results displayed following a search made on the basis of a person’s name links to web pages published by third parties and containing information relating to that person.  The CJEU added that this obligation also exists in a case where that name or information is not erased beforehand or simultaneously from those web pages, and even when the publication is lawful. According to the CJEU, a structured overview of the information relating to the individual in question may potentially affect his private life.

The CJEU in turn identified the need to consider the user’s right to access information on the one hand, and the affected individual’s right to protect his personal data on the other. This balance depends on the nature of the information in question and the role played by the affected individual in public life.

Finally, the CJEU introduced the possibility that after a certain time the affected individual may exercise his right to be forgotten and request that the list of results obtained be removed. If it is found that the list of results is at this point in time incompatible with the Directive, the information and the links displayed therein must be removed. These results are to be deemed incompatible when they appear to be inadequate, irrelevant or no longer relevant, or excessive in relation to the purposes for which they were processed and in the light of the time that has elapsed.

This judgment affects more than 220 appeals lodged by Google against decisions issued by the AEPD that are currently pending before the Spanish Audiencia Nacional.



Visit our website: http://www.elzaburu.es/

Thursday, 24 April 2014

Directive on the retention of data declared invalid by the Court of Justice

Via Wikimedia

On 8 April 2014 the Court of Justice handed down its judgment in the cases of Digital Rights Ireland against the Irish authorities and of the Austrian Constitutional Court against the Government of Carinthia and Mr Seitling, Mr Tschohl and other complainants, Cases C-293/12 and C-594/12, declaring the invalidity of the Directive on the retention of telecommunications and electronic communications data of 2006, hereinafter the “Directive”, with effect from the date on which the Directive entered into force.

What were the requirements of the Directive? What type of data was retained?

With the goal of combating terrorism and other serious offences, the Directive required telecommunications companies and internet operators to register and retain the following data from all types of telephone calls (fixed and mobile as well as unanswered calls) and e-mails during a period of between 6 and 24 months, depending on the applicable legislation in each state:

  • In the case of fixed telephones, the data of the calling telephone number and destination number, the names and addresses of the persons calling and those to which the telephone numbers were registered at the time of connection, as well as the telephone service used and from where they were calling, but not the content of the conversation, which required judicial authorisation.

  • In the case of mobile telephones, the identifier of the device was also required.

  • In the case of internet, the dynamic and static IP addresses assigned by the internet access provider, the name and address of the user and data necessary to identify the date, time and duration of a communication.
  • In the case of a pre-paid card, data regarding the date and time of the activation of the service also needed to be retained.


Reasons for the invalidity of the Directive

The Court of Justice indicates that the requirements on telecommunications operators imposed by the Directive entails a wide-ranging and particularly serious interference of the fundamental right of individuals to privacy and the protection of their personal data, given that there are no substantive and procedural limits in the Directive regulating and restricting those interferences to what is strictly necessary, thus exceeding the limits of the principle of proportionality.

In fact, the judgment states that “the Directive covers, in a generalised manner, all persons and all means of electronic communication as well as all traffic data without any differentiation, limitation or exception being made in the light of the objective of fighting against terrorism and serious crime.

Consequently, the judgment holds that the said data taken as a whole, what we call Big Data, may provide very precise information concerning the private lives of the persons whose data has been retained, such as the habits of everyday life, permanent or temporary places of residence, the activities carried out in their daily life, when going out or on holiday, the relationships, friends, of those persons and the social environments frequented by them, in short all their life, thoughts, beliefs, feelings, location, and that of their children, current accounts, without prior information provided or consent sought to process that data, basic principles of the fundamental right to the protection of personal data.