Skip to main content

Doubts around data transfer - use of derogations

 A lot happened since Schrems-II, among others the European Data Protection Board published a FAQ document, a guidance on essential guarantees for surveillance measures     and submitted another guidance, on measures that supplement transfer tools.

Transfer tools are either safeguards which ensure that data subjects enjoy adequate protection of their privacy at the place and in the organisation to where their data are transferred or derogations which enable transfer essentially without adequate protection. I used the term adequate protection and previously the view was that the protection ensured need not be identical with that in the EU. The Schrems II judgment, however, speaks about equivalent protection and this is stronger.

In case the derogations (according to article 49 GDPR) are used, the EDPB is of the view that the last sentence of Article 44 GDPR (All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.) implies that even in this case the protection of the rights and freedoms of the data subject should be maintained as far as possible, i.e. additional safeguards should be applied. The guidance submitted for consultation talk about these safeguards.

Also the EDPB (which issued a guidance about the derogations) and national data protection authorities have taken a very limited view about the applicability of the derogations, practically stating that every derogation except those based on explicit consent, important reasons of public interest (which must be recognised in EU or member state law) and on vital interest as well as transferring data from a register which is intended to provide information to the public and is open at least for any person who can demonstrate a legitimate interest, must be occasional. It adds that even these cases should be exceptional. It is extremely difficult to imagine how transfer necessary for the performance of a contract can be occasional if a contract runs for example over several years.

Also, it is not clear on what the requirement of exceptionality is based. Consent, as well known, must be explicit and specific, thus, the data and the purpose for which consent is given, must be fixed in the consent. So where is the exception? Even if a company transfers a lot of data for processing to its third country subsidiary or mother company or associated company, consent can be asked for all instances.

That's why it was intriguing what I read first in a LinkedIn post, that Judge Thomas von Danwitz, the judge rapporteur of Schrems-II stated on a question from the audience on the Data Protection Day 2021 of the IITR Datenschutz GmbH that the possibilities of Article 49 have not yet been totally worked out ("ausgelotet"). This could be interpreted as it was by a tweet that there are still possibilities to  be exploited which the EDPB and the data protection authorities did not endorse yet (or, in a stronger wording, the possibilities are wider that what the authorities have recognised). A response to this tweet, also confirming the mention of a possible wider interpretation of the cases  when derogations could be applied, nevertheless, states that the interpretation of Mr von Danwitz is in line with the guidance of the data protection autorities. The judge also said, that he did not want to make a definitive statement as it is for the Court to decide. So looking forward to someone brave enough - or forced - to probe it.

Sime commentators referred to the "Data hub" case in France but in my view, this was more about another open question concerning transfers, about which I will talk in another post. The CNIL, however, noted in this case that there is a clear public interest to arrange a transition period and to guarantee the continuity of data hosting health and related uses - this is interesting as it does not name the law where this public interest is recognised, although one could be certainly found. The derogation namely allows only important reasons of public interest recognised in European or member state law as a legal basis of transfer. Note: important resons of public interest and not important public interest. Thus the interest has to be public but not important while the reason has to be important for this public interest.

This leads us to the point which will in my opinion be interpreted more strictly by the Court of Justice: necessity. It is usual practice of the ECJ that necessity is not the same as convenience, the controller must demonstrate that there is no other way (without the transfer) to fulfil the given task. This is also mentioned in the guidance of the EDPB, although formulated differently: simply outsourcing a service is not sufficient to justify transfer. We know that a number of digital services are offered by U.S. companies (mass mailing, surveys, analytics, social media, videoconferencing and on line events etc.) but for some there are European alternatives. Some of these are known, some much less. European alternatives sometimes offer more limited functionality or comfort, but if necessity will be strictly interpreted, additional functionalities can only be a justification for using U.S. service providers only if the additional functionalities offered by them are indeed necessary.

I started to explore European videoconferencing providers, there are several candidates so it will be interesting to see the results.

 


Comments

Popular posts from this blog

Transfer of Personal Data to Third Countries and International Organisations

Legal requirements The GDPR and Regulation (EU) 2018/1725 (the EUDPR) have changed somewhat the rules concerning transfer of personal data to jurisdictions which are not considered to provide adequate protection of personal data. On one hand the conditions are clearer, on the other hand, new types of safeguards have been introduced. It has to be noted, that there are two possible situations: transfer from a European Institution as controller to another controller and transfer to a processor. At the moment these cases are mostly treated together, although there are some differences. One safeguard which is common between the old and new rules is the use of standard contractual clauses approved by the European Commission (the only change is that the approval procedure has been set within the framework of Comitology, namely the investigation procedure) and the EDPS can also adopt contractual clauses but these also have to be approved by the Commission under the same procedure

How to prepare for the new GDPR?

If you are completely complying with the "old" data protection rules, you do need have to do a lot about your existing operations processing personal data. Some of the rules were, however open to interpretation and thus some "cutting corners" has been made impossible, like implicit consent. The new "right to be forgotten" also applies immediately to all processing (if there is a request, of course) where the retention was defined too liberally. Different national rules which you followed may be too lenient or too stict so at least a review of what you do amd how you do it is indispensable. Documentation also has to be completed, the "privacy by design" and "privacy by default" concepts and the obligation for data protection impact assessment, however, applies only to newly starting or significantly changed processing. So what about consent? First of all, it has to be noted that - contrary to what you can read sometimes - it is n

Why is there no article about transmission of data to EU controllers in the GDPR?

There is an article, number 9, in the data protection regulation for EU institutions (Regulation (EU) 2018/1725, called EUDPR). The transmission to other EU institutions or to another controller within the same institution is, however, only subject to recital 21. In the GDPR , even the recitals do not mention transmission of personal data to other European organisations. Of course, the use of processors is regulated in both acts, but not the transmission to another controller. It can be concluded that the transmission to entities under the same legislation is not covered while transmission from EU institutions to entities under a regulation which has a wider scope, is. The reason is clear: protection by the EUDPR is intended to be stricter. For example, EU institutions are not allowed to process data based on legitimate interest. Therefore transmission to another controller, who may process data based on legal bases unavailable for EU institutions, is restricted to cases where the sam