TOTAL: {[ getCartTotalCost() | currencyFilter ]} Update cart for total shopping_basket Checkout

Privacy Perspectives | Untying the global dataflows mess Related reading: The Privacy Advisor's top 10 news stories of 2018

rss_feed
GDPR-Ready_300x250-Ad

One of Harry Houdini's most difficult tricks consisted of escaping from a nail-fastened and rope-bound wooden crate with manacles on his hands and feet, while submerged in New York's East River. That feat is starting to look straightforward when compared to the prospect of lawfully exporting personal data out of the European Union. The restrictions on transfers of data to jurisdictions that do not provide an adequate level of protection have been in place for more than 20 years. And while these restrictions have not prevented the development of the digital economy, judging by this issue's current direction of travel, we could be facing a situation from which not even the great Houdini could escape.

The world of global dataflows radically changed in October 2015 when the Court of Justice of the European Union – influenced by the seriousness of Snowden's disclosures and skillfully persuaded by Max Schrems – established a tough new adequacy test while invalidating the Safe Harbor framework as an adequacy mechanism. Since then, overcoming the limitations that prohibit exporting personal data to countries that do not match the European standards of data protection involves a two-fold exercise:

  • ensuring that the importer of the data applies equivalent data privacy and security measures to those required by European data protection law; and crucially
  • ensuring that the public authorities in the importing jurisdictions – namely government and law enforcement agencies as well as intelligence services – do not have unnecessary, disproportionate and uncontrolled access to such data.

In principle, this is not an unreasonable expectation – after all, the point of the data export restrictions is to protect people's fundamental right to privacy and their personal information. The challenge is the degree to which these two points need to be demonstrated and met. The second element of the test in particular has now become a nearly insurmountable ‎task.

With the Safe Harbor ruling, it became clear that any claim of adequacy must meet the standards of the Charter of Fundamental Rights of the European Union. So when the Privacy Shield was unveiled in February 2016 following two years of negotiations between the European Commission and the U.S. Department of Commerce, the key focus was on the assurances offered by the U.S. government in respect of any potential access to data and its oversight. Shortly afterwards, the Article 29 Working Party issued a detailed statement pointing out the deficiencies of the Privacy Shield in this respect. More recently both the European Parliament and the European Data Protection Supervisor have seen the glass half empty and dismissed the protections and controls of the Privacy Shield as insufficient.

Worryingly, since access to data by public authorities is not an issue on which adequacy decisions have focused in the past, all existing adequacy findings by the European Commission could potentially be at risk if a new Max Schrems decides to target any countries currently deemed to be adequate. And since, according to the CJEU, this aspect of data protection adequacy needs to be present no matter what, any established tools – like standard contractual clauses – used to deploy EU data privacy and security measures may also end up being insufficient to overcome the restrictions on transfers.

This is now in the process of being tested following the Irish Data Protection Commissioner's action requesting the High Court of Ireland to refer the status of standard contractual clauses to the CJEU for a preliminary ruling. It may still take a year or two for the CJEU to rule on this but given the precedent of the Safe Harbor decision, it is not inconceivable that by the time the General Data Protection Regulation comes into force in May 2018, the standard contractual clauses adopted by the European Commission have become unsuitable to legitimise dataflows. The same could of course be true of any legal tool that does not incorporate a legally valid and effective redress mechanism against government access to data.

And then what?

The prospect of a digitally isolated Europe in the 21st century seems unrealistic but this may be a price that European regulators and judges are willing to demand for the sake of protecting fundamental rights. The question right now is what can possibly be done by any organisation that wishes to avoid digital isolation in the absence of a politically perfect solution. Part of the answer may well be persuading the democratic governments of the world to create legal frameworks that enable the levels of control and oversight that the CJEU demands. But more realistically and in the short term, organisations can attempt to complement existing transfer tools with additional protections aimed at limiting disproportionate disclosures of personal data to public authorities.

More than 100 years after Houdini's miraculous escapes, it is still a mystery how he managed to pull them off, but he did. Untying the current mess affecting transfers of personal data from the EU will require similar skills, but it can be done. The trick in this case is to pay attention to what the CJEU has identified as risks to our privacy and address those risks in a sufficiently credible way, so that whatever the uses and disclosures of personal information, our digital freedom is not unjustifiably compromised.

Top image courtesy of Wikipedia

4 Comments

If you want to comment on this post, you need to login.

  • comment Jason Cronk • Jun 3, 2016
    Eduardo, I liked your comment "But more realistically and in the short term, organisations can attempt to complement existing transfer tools with additional protections aimed at limiting disproportionate disclosures of personal data to public authorities."  I might take this to mean something you didn't intend. Putting on my technologist's eyeglasses I see this as on opportunity for using PETs and user controlled encryption keys to basically process or store data in inadequate jurisdictions thereby limiting the potential for disclosure/access by public authorities.
  • comment David Bender • Jun 3, 2016
    Good summary.  A “digitally isolated Europe” might not be an inappropriate result for a region that exalts “privacy über alles,” and marches to the drummer of a court that in its Schrems opinion did not even mention the concept of proportionality that is enshrined in the Charter.
  • comment Stuart Ritchie • Jun 4, 2016
    Eduardo: perhaps someone should do some research on whether the "digital freedoms" and "digital isolation" to which you refer actually are genuine legal (and more importantly cultural) artifacts rather than technological ones - otherwise methodologically we put the cart before the horse every time. Why should international data transfer be culturally necessary in a happily disunited world? There's a fundamental philosophical / constitutional issue here. Short of unitary world government, why should "we" (and what gives "us" the right to) impose the same laws on all nations? And just who gets to decide the content of those laws?
    
    Cutting to the chase, the classic and efficient business solution for businesses who get upset by legal divergence is not to play Chicken Little and wail that foreign governments must pander to irrelevant and narrow economic interests. Instead they can simply decentralize their operations, even if more costly than, say, hiring Chicken Little lobbyists. Especially as efficient decentralization becomes easier than ever before, and lobbyists in this field become increasingly ineffective. 
    
    In any event, every year we enact hundreds if not thousands of laws that pay no regard to current technological feasibility. So legislatures may be lazy, but they're also right: technology generally steps in to fill any gap. Of course PETs will be along to solve most of not all of the operational issues arising from more effective enforcement of the old 1995 EU principles. The sole reason they haven't already done so is that up until the GDPR business has been deprived of economic incentives to preserve rather than to destroy privacy. A few culturally dysfunctional core business models may die: so what? Nothing new there: new models as always will emerge.
    
    @David: nice suggestion - but be careful for what you wish! We may get it. Particularly in this year, not all such isolationist recommendations are coming from the European side of this political pond.
  • comment Amy Roy • Aug 29, 2017
    There are a plethora of conspiracy theories that revolve around how did the greatest illusionist of all time die. Take a look at some of these. 
    https://askopinion.com/how-did-houdini-die