Showing posts with label United States. Show all posts
Showing posts with label United States. Show all posts

Friday, 21 October 2016

Brexit: Prospects for data protection

The decision made by the British people in the 23 June 2016 referendum has multiple consequences, many of them legal. Some have already been addressed, but the issue of what Brexit could mean for European citizens’ privacy and data protection rights has been pushed to the background.

The regulatory framework for data protection in the European Union conferred total freedom of circulation on data within the 28 Member States.  The United Kingdom’s exit from the EU, and consequently from that legislative environment, will therefore mean that its citizens will be considered as established in a third country, and issues such as those currently existing with the United States will have to be contended with.  Basically, sending data from any EU country to the UK will constitute an international data transfer, with the legal effects that this entails.
    
Obviously, given the importance of massive data processing for a company from any sector, the UK is not going to remain aloof from its former fellow Member States, since not interacting with the EU in this field would leave it out of the game in a sphere that is vitally important for the economy.   

This situation obviously gives rise to uncertainty -which will have to be cleared up by the British government in the coming months- concerning the decision to be made on the subject of data protection in the island State.

Friday, 15 July 2016

The European Commission launches the EU-U.S. Privacy Shield

On 12 July 2016, the European Commission adopted a new arrangement for international exchanges of data between the United States and the European Union, namely, the “Privacy Shield”.

The need for this new framework arose from the judgment rendered by the CJEU last October in the Schrems case. In its decision, the European Court pointed out the serious deficiencies in the previous “Safe Harbor” arrangement, to the extent that it was ruled invalid. [see our article on Safe Harbor]

In that regard, in February 2016 it was announced that there would be a new framework that would provide the necessary guarantees for the transatlantic flow of EU citizens’ personal data.  Just this month, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés –CNIL-) asked Facebook to stop compiling the data of users who did not have an account with the social media site and to stop transferring that data to the U.S., thus creating a growing awareness of transatlantic data transfers throughout the whole of Europe.   

For this reason, this new arrangement has been in the spotlight in a number of sectors ever since it was conceived.

The final wording of the arrangement seeks to reflect the following principles: 
  • Robust obligations on companies that handle data
  • Transparency and clear safeguards on U.S. government access                
  • Effective protection of individual rights
  • Annual joint review mechanism              

Those principles will be implemented by the following means: U.S. companies handling European citizens’ data will have to register to be on the “Privacy Shield” list and self-certify that they meet the standards set out by the arrangement; there will also be dispute resolution mechanisms that may be accessed by citizens who consider their rights to have been violated within the context of this system; and there will be cooperation between the European Commission and the U.S. Department of Commerce.                                        

The above measures merely seek to ensure an adequate level of protection of the personal data of EU citizens, as well as assurances for U.S. companies which, as market operators, handle that data. 

The adequacy decision is now in force, though U.S. companies will not be able to register to be on the aforementioned list until 1 August 2016. As regards EU citizens, the European Commission has announced that it will be publishing a guide to help get complaints procedures against companies underway.  For the time being, information has been provided in FAQ format along with the press release.

As is typically the case where such momentous issues are concerned, the terms of this new arrangement have been subject to heavy debate.

Figures such as the Euro MP Jan–Philipp Albrecht consider that although the arrangement might, at first glance, appear to provide guarantees, the practical application of its mechanisms could render it meaningless.  He highlights the intricate and complex nature of the rules for legal redress for unauthorised use of citizens’ personal data due to the large number of intermediaries involved, such as arbitration bodies and national authorities.  Also, a number of sectors have pointed out that the wording concerning mass surveillance echoes the “Safe Harbor” framework almost word for word.

It should nevertheless be noted that the “Privacy Shield” has been tweaked throughout the drafting process to accommodate the suggestions and opinions of the many authorities on the subject, such as the Article 29 Working Party, the European Parliament and the European Data Protection Supervisor.  

This provides another tool to promote trade between the European Union and the United States, one that is based on a vision that offers more guarantees as far as citizens’ rights are concerned.




Visit our website: http://www.elzaburu.es/en  

Tuesday, 19 April 2016

U.S. improves Federal Trade Secrets Act, while in Europe …

On 4 April 2016 the U.S. Senate gave its unanimous (yes, unanimous) approval to the Defend Trade Secrets Act (DTSA), amending the Economic Espionage Act (EEA), the aim of which is to strengthen the position of the holders of trade secrets by granting them protection, through federal legislation, comparable to that afforded under trademarks, patents and copyright. The bill now has to go through Congress, where surprises are not to be expected as it would appear that opinion, including that of the White House, is undivided on the question that this is an issue which has a bearing on the economy of the nation and warrants the closest attention.

This new law represents one further advance along the long road that the U.S. has already traveled in the protection of trade secrets. Once case law, with roots in the eighteenth century, set about defining and circumscribing the concept, the States of the Union began adopting laws for the protection of these intangible assets. More case law has been generated unceasingly through to the present day, but the various state laws were subsequently supplemented with a federal law, the Economic Espionage Act, which further harmonized the concept and the fundamental elements in the protection of trade secrets. However, the Economic Espionage Act had certain limitations, as it was only applicable in cases of criminal infringements committed by foreigners. Furthermore, the protection provided did not extend to various aspects of misappropriation of trade secrets.

Under the system laid down in the DTSA, complaints relating to local goods or services will be lodged with a state court, but cases relating to interstate or international commerce may instead be litigated in federal courts. The DTSA sets uniform rules as regards the definition of a trade secret, what is to be considered unlawful, damages and injunctions. It also stipulates that the term for commencing the action shall be three years from the time that the infringement of the rights became known.

In Europe, meanwhile, the Trade Secrets Directive, which was proposed back in 2013 and aroused criticism of a not entirely comprehensible nature in certain quarters, was finally approved by the European Parliament on 14 April 2016, although two more years will still have to go by before it is actually implemented in the legislation of all the Member States.

The comparison between the initiatives taken on the one side of the Atlantic and on the other should lead us to reflect, in this particular matter and in others, on how legislation contributes to the prosperity of nations.


The protection of trade secrets is of major importance for technological development and affects not only companies but also state research institutions. The new directive should provide us with a better legal framework than that hitherto offered by each state individually and should harmonize the protection afforded. However, it will also oblige us to tackle many issues, for the appropriate protection and defence of trade secrets, even before it is transposed into Spanish law. I hope to have the opportunity to speak of that on another occasion in the relatively near future.



Visit our website: http://www.elzaburu.es/en 

Wednesday, 7 October 2015

No Safe Harbour: Sailing in the tempest (Case Maximillian Schrems v Data Protection Commissioner)

The long-awaited decision in Case C-362/14 Maximillian Schrems v Data Protection Commissioner was finally issued on 6 October 2015. Controversial in its findings, this preliminary ruling sheds new light on the ongoing debate regarding the collection, transfer and processing of EU citizens’ data by US companies, and the processing of that data by US intelligence agencies within the framework of the PRISM program.


Background information

Mr. Schrems, an Austrian citizen, has been a Facebook user since 2008. In the case of all users residing in the EU, some or all of the data with which they provide Facebook is transferred from Facebook’s Irish subsidiary to servers located in the United States, where it is processed.

Mr. Schrems lodged a complaint with the Irish supervisory authority (the Data Protection Commissioner) on the grounds that, in light of the revelations made by Edward Snowden in 2013 concerning the activities of the United States intelligence services (in particular, the NSA), the law and practice in force in the United States did not offer sufficient protection against surveillance by the public authorities of data transferred to that country. The Irish supervisory authority rejected the complaint on the basis of the decision of 26 July 2000, which considered that under the “safe harbour scheme” the United States ensured an adequate level of protection of the personal data transferred (known as the Safe Harbour Decision).

Mr. Schrems then filed an appeal with the High Court of Ireland, which considered that the issue prompting his action was closely related to EU law since, according to that High Court, the Safe Harbour Decision did not comply with the principles set forth in the judgments in C-293/12 and C-594/12, EU:C:2014:238.


Preliminary questions submitted to the CJEU

On 17 July 2014, the High Court of Ireland, before which the case had been brought, submitted the following questions to the Court of Justice for a preliminary ruling:

(1)  Whether in the course of determining a complaint which has been made to an independent office holder who has been vested by statute with the functions of administering and enforcing data protection legislation that personal data is being transferred to another third country (in this case, the United States of America) the laws and practices of which, it is claimed, do not contain adequate protections for the data subject, that office holder is absolutely bound by the Community finding to the contrary contained in [Decision 2000/520] having regard to Article 7, Article 8 and Article 47 of [the Charter], the provisions of Article 25(6) of Directive [95/46] notwithstanding?

(2)  Or, alternatively, may and/or must the office holder conduct his or her own investigation of the matter in the light of factual developments in the meantime since that Commission decision was first published?

The Advocate General’s Opinion of 23 September 2015

According to the Opinion of the Advocate General (Yves Bot), a company, by merely having a Safe Harbour certification, would not automatically comply with the European data directive on export requirements.

This argument had already been made in Communication COM(2013) 846 and Communication COM(2013) 847.

As was to be expected, the CJEU followed the arguments put forward by the Advocate General.