ECJ: Privacy Shield invalid

People News /

Is the transfer of personal data to the USA permissible? The European Court of Justice had to address this question.

Background

Under the General Data Protection Regulation (GDPR), personal data may, in principle, only be transferred to a third country if that country ensures an adequate level of protection for the data. However, the GDPR allows the Commission to determine that a third country ensures an adequate level of protection on the basis of its domestic legislation or its international obligations. The EU-US Privacy Shield is an agreement between the EU and the US, on the basis of which the Commission has ultimately determined adequacy.

In the absence of such an adequacy decision, a transfer may only take place if the data exporter established in the EU provides suitable safeguards, which may, amongst other things, be derived from standard contractual clauses drawn up by the Commission, and if the data subjects have enforceable rights and effective legal remedies.

Facts of the case 

The judgment stems from a data protection complaint lodged by an Austrian Facebook user. As with any user resident within the territory of the Union, his personal data was transferred, in whole or in part, by Facebook Ireland to servers belonging to Facebook Inc. in the US, where it was processed. He argued that the US did not guarantee adequate protection for data transferred there and requested that the transfer of his personal data from the EU to the US, carried out by Facebook Ireland on the basis of the standard contractual clauses set out in Decision 2010/877, be suspended or prohibited in future. In the view of the Irish supervisory authority, the handling of the complaint depended to a significant extent on the validity of Decision 2010/87 on standard contractual clauses. It therefore brought proceedings before the Irish High Court, requesting that the court refer the matter to the CJEU for a preliminary ruling. After these proceedings had been initiated, the Commission adopted Decision 2016/1250 on the adequacy of the protection provided by the EU-US Privacy Shield.

In its request for a preliminary ruling, the Irish High Court asked the ECJ, amongst other things, about the validity of both Decision 2010/87 on standard contractual clauses and the Privacy Shield Decision 2016/1250.

The CJEU’s ruling

In its judgment of 16 July 2020, Case C-311/18, the CJEU found that Decision 2010/87 on standard contractual clauses did not infringe the EU Charter of Fundamental Rights and was therefore valid. It declared Decision 2016/1250 on the Privacy Shield, however, to be invalid.

Decision 2010/87 provides for mechanisms which can ensure, in practice, that the level of protection required by EU law is maintained and that transfers of personal data based on such clauses are suspended or prohibited in the event of infringements or where compliance is impossible. Under that decision, the data exporter and the recipient of the transfer must assess in advance whether the required level of protection is maintained in the third country concerned, and the recipient must, where necessary, inform the data exporter that it is unable to comply with the standard contractual clauses. The exporter must then suspend the data transfer and/or withdraw from the contract with the recipient. Consequently, Decision 2010/87 is valid.

Decision 2016/1250 is invalid, as the restrictions on the protection of personal data provided for therein – in the form of a right of access and use by US authorities, under US law, to such data transferred from the EU to that third country – are not equivalent to the requirements of EU law, which must comply with the principle of proportionality. The surveillance programmes based on US legislation are not limited to what is strictly necessary and do not appear to be subject to any restrictions on their implementation. Nor is it apparent that any safeguards exist for individuals potentially covered by these programmes who are not US citizens. Whilst these provisions lay down requirements with which the US authorities must comply when implementing the surveillance programmes in question, they do not confer on the data subjects any rights that can be enforced before the courts against the US authorities.

Nor does the ombudsman mechanism referred to in the Privacy Shield Decision 2016/1250 provide data subjects with a legal remedy before a body offering safeguards that would be substantively equivalent to those required under Union law. Nor is the independence of the ombudsman provided for by that mechanism guaranteed, nor is there any provision for standards empowering the ombudsman to issue binding decisions on the US intelligence services.

Note: This language version has been produced using AI-assisted translation. If you notice anything that could be improved, we would be pleased to receive your feedback.