EU Court of Justice invalidates Safe Harbour and the game for thousands US businesses suddenly changes

A hearing at the European Court of Justice (European Court of Justice, 2010)

A hearing at the European Court of Justice (European Court of Justice, 2010)

In what some American media already call a “dramatic judgement”, the European Court of Justice last week changed the course of history for data protection and handling between the EU and the United States. After having declared the “Safe Harbour” data transfer agreement invalid earlier last week, on October 06, the EU’s highest court last Friday urged the EU and the United to shape a new trans-Atlantic data-transfer deal.

A paper monster

The ruling took immediate effect, and surely opened a big hole in the EU-US business legislation and data protection environments. The decision by the European Court of Justice junked a 15-years-old regulation and indeed left some 4,500 US companies, which have previously relied on Safe Harbour, linger in a potential bureaucratic nightmare. To understand why, it is necessary to take a step back and review some data privacy history.

Background

Since 2000, thousands of US companies have relied on Safe Harbour to comply with the “EU Data Protection Directive 95/46/EC” (the “Directive”) on the protection of personal data, and – more practically – to transfer personal data from the EU to the US. Indeed the Safe Harbour has been for fifteen years the “bridge” for thousands of businesses to cope with the many differences between the American and the European regulations. While the United States has a patchwork of various state laws on the privacy topic, the EU has a broad overarching law covering all industry sectors , the “Directive”, which prohibits the transfer of personal data outside of the EU unless there is an “adequate level of protection of the data.”

In order to facilitate business, the two superpowers negotiated a “Safe Harbour” agreement that allowed US companies to process and transfer EU citizens’ personal data only after qualifying for certain rules and principles. The Safe Harbour Framework indeed required adherence to guidance materials and seven basic principles: notice, choice, onward transfer, security, data integrity, access and enforcement. Under Safe Harbor, companies were basically free to transfer personal data from the EU to U.S in compliance with the EU Data Protection Directive and European privacy laws.

The NSA Leaks and the Schrems case

Post the Snowden scandal, more than 2 years ago, things have changed though. Edward Snowden’s National Security Agency leaks indeed showed that European data stored by US companies was not safe from surveillance that would be illegal in Europe, and many regulators, organisations and people started to become dig the matter further.

Maximillian Schrems, an Austrian law student and Facebook user, then argued that the Irish Data Protection Commissioner failed to protect him from mass surveillance by the US NSA. Schrems argued that the actions of many large US firms like Facebook, that basically store all – or at least a vast majority of – their customers data in the USA and then transfer personal data to the NSA as part of the infamous PRISM program, did not provide adequate protection of EU citizens’ data being transferred to third countries.

So the European Court of Justice was asked to investigate and to eventually rule on whether the Safe Harbour Framework was able to sufficiently protect the EU citizen under the EU Data Protection Directive. The court found that the Safe Harbour was “inadequate” to serve its original purpose, and that it did not “satisfy the requirements of the directive”.

The Court’s ruling

“The Court declares the Safe Harbour Decision invalid”, the official document by the Curia stated. “This judgment has the consequence that the Irish supervisory authority is required to examine Mr Schrems’ complaint with all due diligence”, it also declared. The document also cited that “even if the Commission has adopted a decision”, the national supervisory authorities, when dealing with a claim, “must be able to examine, with complete independence, whether the transfer of a person’s data to a third country complies with the requirements laid down by the directive”. Those are heavy words which are destined to change the entire game.

What happens now?

The full impact of this decision is currently hard to see, but for sure the future of cross border data transfers between the EU and US becomes now a big question-mark. By scrapping the Safe Harbour, the European Court of Justice has practically and immediately returned the issue to the hands of regulators in each country: from this moment onwards each EU member nation will decide its own way when it comes to interact with the US on data privacy and handling.

The impact on business

From a business point of view, this could turn into a real nightmare for American firms, as we said. US companies (potentially not only tech firms) that do business in Europe could be requested to keep data locally in each country that they operate in. Moreover, the decision creates new legal risks for companies and surely puts at risk all the bloc’s plans to create a single digital market, because it will jeopardize the region and the possibilities of doing business here by non-EU companies. Indeed now it might happen that one country might block a company’s transfer to the US while the regulator in another gives the green light. Indeed pretty fare from the “unity” dream Commissioners are foreseeing.

“What we need now is to work closely with the Americans to find a solution to get a safe ‘Safe Harbour’, which is in the interest of both Europeans and Americans”, briefly stressed Andrus Ansip, European Commission Vice-President in charge of digital single market. Mr. Ansip also said he would be meeting with businesses next week to discuss practical concerns but urged the EU and the U.S. to continue work towards creating a new Safe Harbour agreement.

A Trans-Atlantic case

Last weeks’ decision once again unveils the many differences between two of the worlds’ pioneers in privacy and data protection laws, which as one can imagine we’ll have huge impacts in the negotiations of trans-Atlantic deals such as TTIP.

It is impossible to determine in detail now the scale of the shock the ruling by the ECJ will have on real economy, but it will for sure add pressure on the ongoing negotiations between the two blocks around data protection, and possibly on all the other matters which are found on the Transatlantic table of negotiations.

Advertising

Advertising

Advertising

Advertising

Advertising

the sting Milestone

Featured Stings

Can we feed everyone without unleashing disaster? Read on

These campaigners want to give a quarter of the UK back to nature

How to build a more resilient and inclusive global system

Stopping antimicrobial resistance would cost just USD 2 per person a year

This one small change could transform education for millions

General Elections in Spain: Twitter organises the first digital debate to empower young people.

How quantum computing could beat climate change

UN ‘comes together in sadness and solidarity’ to honour staff who died on board Ethiopian Airlines flight

How transparency can help the global economy to grow

Human rights experts call for ‘paradigm shift’ on arbitrary detention in Qatar

Draghi reveals how failing banks will be dealt, may cut interest rates soon

Climate change is a disruptor. Here’s how to harness it for innovation

Energy: EU priority projects should be aligned with 2050 climate objectives

Somalis ‘will not be deterred’ by Friday’s terror attacks – UN chief

European Agenda on Migration: Still fragile situation gives no cause for complacency

Trailing the US-EU economic confrontation

The EU Spring Summit set to challenge austerity

Portraits show ‘dignity and humanity’ of Holocaust survivors, 75 years after Auschwitz liberation

UN chief urges ‘active, substantive and meaningful participation’ on International Day of Democracy

What can stop the ‘too big to fail’ bankers from terrorising the world?

3 things you need to know about securing a blockchain

The EU lets the bankers go on rigging the benchmarks

Dozens killed and injured by new airstrikes in western Yemen, UN coordinator condemns ‘outrageous’ toll

Alarm over violent attacks on lawmakers, opposition in Malawi, ahead of elections

“Only through energy policy we can trigger competitiveness”. The Sting live from #EBS2015: Energy Union – When will it happen?

These countries are driving global demand for coal

Disillusioned young people – France thinks it has a solution

DR Congo: Restore internet services as ‘a matter of urgency’, urges UN expert

4 ways sporting events are becoming more sustainable

How to talk to people about mental health – and support one another

There’s a global learning crisis and it’s leaving millions without basic skills

COP22 addresses a strong global pledge to effectively implement the Paris Agreement

Technology is delivering better access to financial services. Here’s how

Why good cybersecurity in business is everyone’s responsibility

More children killed by unsafe water, than bullets, says UNICEF chief

We have to learn to trust Artificial Intelligence. Here’s how

Remarks by High Representative/ Vice-President Federica Mogherini at the press conference following the EU-China Strategic Dialogue

Arrest of three Libyans wanted for grave crimes ‘would send strong and necessary message’ to victims, urges top Prosecutor

UN Envoy urges Burundi leaders to ‘seize opportunities for national unity and peace’

Mediterranean migrant drownings should spur greater action by European countries, urge UN agencies

“A sustainable economy, low-carbon, resource-efficient, resilient and more competitive on the global stage”, EU Commissioner Vella in a Sting Exclusive

Courage of terrorism survivors underlines ‘urgency’ of UN Investigative Team’s work in Iraq

Antibiotics are contaminating the world’s rivers

Main results of European Council of 18/10/2018

New UN report launched to help ratchet up action to combat climate crisis

Is there a drug for every disease?

‘Open, cordial, and frank discussions’ held over future Somalia-UN relationship

OECD presents analysis showing significant impact of proposed international tax reforms

These countries spend the most on education

5 reasons to be more cheerful about the future of the oceans

Measles in Europe: infection rates highest in a decade, says UN health agency

To retire at 65, American millennials need to save almost half their paycheck

A comprehensive strategy for Eurozone’s long term growth gains momentum

Why transparency in drug pricing is more complicated than it seems

Climate Change: A Healthcare Emergency

Europe must remember its past to build its future

Saudi Arabia, China, among 14 nations under UN human rights spotlight: what you need to know

Mainland Europe adopts Germanic cartel business patterns

Monday’s Daily Brief: Independent UN experts on Myanmar, UN chief renounces attacks in US, Libyan airport violence, UN spokesperson on Kashmir, and FAO and Italy on development

7 amazing ways artificial intelligence is used in healthcare

Sri Lanka PM: This is how I will make my country rich by 2025

Italy’s revised budget remains roughly unchanged waiting for Europe’s fury

This is how we make cancer care sustainable and available for all

6 innovative technologies about to transform our infrastructure

More Stings?

Speak your Mind Here

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s