Data protection for data transferred to the United States: can we trust it?
On 10 July, the European Commission announced that it had adopted a new legal framework once again legalising the transfer of personal data from the European Union to the United States. More recently still, the Norwegian Data Protection Authority took a radical and unprecedented step by prohibiting Meta from carrying out behavioural profiling of Norwegian users for the purpose of targeted advertising. This injunction comes into effect on 4 August and will remain in force for three months. These events merely confirm that the saga surrounding data transfers to the United States is far from over.
A recap of the situation
In light of recent news, we feel it is appropriate to provide a recap of the situation. Under Article 45 of the General Data Protection Regulation (GDPR), data transfers outside the European Economic Area (EEA) are prohibited, unless it can be demonstrated that the transfer falls within a specific situation provided for in that article. The two exceptions most frequently used by companies to justify data transfers outside the EU and the EEA are (1) an adequate level of protection provided by the country of destination and (2) the use of standard contractual clauses (SCCs) between companies transferring data outside the European Economic Area. In the first case, the country of destination must have legislation recognised by the European Commission as offering a level of data protection equivalent to that applied within the European Union. In the second case, the STCs signed between the two entities must be based on the models approved by the European Commission.
With regard to transfers to the United States, and following the invalidation of the Privacy Shield by the Court of Justice of the European Union (CJEU) in 2020, companies can no longer rely on an adequate level of protection to justify such transfers. Indeed, the CJEU ruled that the access to data granted to US intelligence agencies, on the grounds of surveillance, was too broad. As for standard contractual clauses (SCCs), the recipient organisation must still comply with European models. This is not so straightforward to implement, given the requirements set out in these models, which are sometimes irreconcilable with the US approach to data protection.
What’s new?
To fill this legal vacuum, and given the crucial stakes for the digital economy, the European Commission has recently adopted a new piece of legislation. Additional safeguards have been put in place to regulate access to data by US intelligence agencies. From now on, access must not only be justified on the grounds of national security, but must also be limited to what is ‘proportionate’ and ‘necessary’ in order to comply with the provisions of Article 45(3) of the GDPR, which permits the transfer of personal data to a third country. Whilst the intention is laudable, it must nevertheless be acknowledged that these terms, though prominent in the GDPR, still leave considerable room for interpretation.
One new feature of the agreement is that it grants European nationals the right to seek redress if they consider that their personal data has been unlawfully collected by the US authorities. This right to seek redress is accompanied by a right to have such data rectified or erased, as also provided for by the GDPR. Compared with the complete lack of such provisions previously, this progress is to be welcomed. This new version of the text has the merit of seeking, on paper at least, to grant European citizens the same rights as US citizens. Previously, and even when the Privacy Shield was first introduced, if a US company processed European citizens’ data inappropriately, there was no recourse available.
Not quite so simple in practice
However, we feel we should not be too quick to celebrate this progress. Which law do you think will apply? US law, of course. In practice, is a European national really going to go all the way to a US court to assert their rights? In this respect, therefore, this right strikes us as utopian. Furthermore, under both US and Belgian law, a person must have a legal interest to bring legal proceedings. Demonstrating such an interest before a court that is not particularly inclined towards data protection could prove to be a real struggle. Offering rights of redress is all well and good, but being able to enforce them is better still. It seems to us that this globalisation of the US justice system does not truly protect citizens’ rights internationally.
Furthermore, companies that send data to the United States face the same predicament. How will companies – which, as data processors, are responsible for selecting their service providers and ensuring the resulting security – be able to carry out their security audits across the Atlantic? How can a company genuinely enable one of its customers, whose data may have been compromised, to assert their rights before a US court, given that there is no federal data protection legislation?
What about the application of other legal provisions?
We may also question the relationship between the new framework agreement and the Cloud Act. This legislation, in force since 2018 and introduced under the Donald Trump administration, allows US authorities access to all data stored by US companies, regardless of its location. This therefore applies, a fortiori, to all data stored by US companies on European territory. Will the new framework agreement supersede the Cloud Act? Will these two pieces of legislation apply independently of one another? There are still some grey areas. Furthermore, even with this new agreement, how can we be certain that our data will not be accessed by a US company that is not immune to surveillance, despite the safeguards put in place?
Are we heading for a Schrems III ruling?
There is no denying that the new agreement adopted by the Commission is being welcomed as good news by many companies which, regardless of their size, transfer data to the United States on a daily basis. However, in our view, this remains an initial compromise that will need to be developed further. Max Schrems, the Austrian campaigner behind the previous Schrems I and Schrems II cases and rulings, has already announced that he will challenge this new legal framework. We can therefore expect the case to be brought before the Court of Justice of the European Union again by the start of next year. In the meantime, and in these circumstances, we strongly advise you to keep your data within the European Union, under the control of a European entity.