Notes

← Back to home

A collection of fragments of understanding in the pursuit of deeper questions.

Data Protection

Antitrust, Consumer or Privacy Policy? ... Or all of them? Separate EU rules converge around the creation of a thriving internal market and the protection of the individual

  • Competition Law strives to ensure the efficiency of the internal market and the welfare of and choice available to consumer.
  • Consumer Protection Law aims to ensure truthful and accurate information when making choices.
  • Data Protection Law seek to ensure that individuals can control their own personal data.

What is Privacy?

  • The right to be "let alone" (Warren and Brandeis, 1890).
  • The right to protect oneself against unwanted information or advertising, appropriation of name or image, or any other kind of unwanted intrusion (Prosser, 1960).
  • A human/fundamental right (Bloustein, 1964).

What is Data Protection?

  • A set of rules granting individuals the "rights to control their personal data"(Westin, 1967); the way in which their personal data are collected and used (Stigler, 1980) and ... in summary, the right to control their analogical and digital identities entirely (Sweeney, 2002).
  • Also, a human/fundamental right.

What is Personal Data?

image59

Personal Data: An Evolving Category Personal Data are the data that identify or are able to identify natural persons, and that can provide details on, for example:

  • Their features and characteristics;
  • Their habits;
  • Their lifestyle;
  • Their personal relationship;
  • Their states of health;
  • Their economic conditions.

Some traditional examples of personal data By tradition, we consider:

  • Identification Data, those data that allow direct documentation, such as names and surnames, or personal images;
  • Sensitive Data, those data that can reveal racial and ethnic origins, religious beliefs, the state of health, sexual life, philosophical or political opinions, membership in parties, trade unions, associations or other organizations of religious, philosophical, or political nature;
  • Judicial Data, those data that can reveal the existence of certain judicial measures subject to registration in the judicial register or the status of defendant or suspect.

Most recent examples of personal data With the evolution of new technologies, other personal data have taken on a significant role, such as;

  • Localization Data, those data that provide information on frequented places and travel;
  • Biometric Data, such as fingerprints, topography of the hand or the characteristics of the handwritten signature;
  • Online Data, such as IP address and cookies or email addresses. For example, think that who, without the consent of the addressees involved, uses email addresses for sending general/advertising emails (so-called spamming) violates their privacy and violates data protection rules, even if the spammer found the emails addresses on the web.

Why we need to discuss Data Protection

  • The privacy issue is not new.
  • What is new is the ability to collect, store, and analyze a mass of personal data in real time without human intervention (e.g. the profiling of Google and Facebook).

Thus,

  • Today the collection and analysis of personal data can affect individuals in their identities and effective freedom to express their thoughts, their personality, their choices.
  • Why and How?
    • Because individuals may be associated with profiles that condition their behaviors;
    • Because those profiles could be wrong;
    • Because those profiles may reveal some details that individuals would prefer to hide ... Or that individuals do not even know.

Focus: Data Protection in the EU

  • From Directive 95/46 to Regulation 2016/279
  • GDPR, General Data Protection Regulation - from the 25^th^ May 2018 is directly applied in every Member State of the EU.

Technical words to better understand the GDPR

  • The Data Subject is the individual whose data are processed.
  • The Data Controller is who determines the purposes and means of the processing of personal data.
  • The Data Processor is who processes personal data on behalf of the controller.
  • The Processing means any operation or set of operations which is performed on personal data by both automated and non-automated means. For example, the collection of data, their recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction ...

GDPR: Main Rules Personal data shall be:

  • processed lawfully, fairly and in a transparent manner in relation to the data subject ('lawfulness, fairness and transparency');
  • collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes ('purpose limitation');
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimization');
  • accurate and, where necessary, kept up to date ('accuracy');
  • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed ('time limitation');
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage ('integrity and confidentiality').

In particular, according to Article 7, Processing is Lawful if the Data Subject has given consent to the processing of his or her personal data for specific purposes.

The key factor: Consent Consent is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she - by a statement or by a clear affirmative action - signifies agreement to the processing of personal data relating to him or her.

Which means:

  • Free, Specific, Informed
    • A service cannot be conditioned to consent (this is not considered freely given).
    • Tacit or presumed consent (e.g. to pre-checked boxes on a form) is not allowed.
  • Revocable, with the same ease with which it was provided.
  • Unequivocable, inaction cannot constitute consensus.
  • Explicit for sensitive data.
  • Demonstrable (the written form is not required, even if this is a way to configure the unequivocal consent and its being explicit").
  • Minors' Consent only from 16 years onward; before: consent of the parents or of those who take their place.

Exception to the Consent Principle

  • When processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
    • The contract is sufficient (and no consent is required) when the processing of data is linked to an activity essential for its fulfillment (e.g. to manage the user in a contract for the supply of gas or electricity).
    • The contract (and consensus) is not sufficient if the collected data are used for other purposes (e.g. the company offering the supply wants to advertise its other services).

Further Exceptions to the Principle of Consent

  • Processing is necessary for compliance with a legal obligation to which the controller is subject;
  • Processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

(Some) of the rights of data subjects

  • Right of Access. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and the following information: Why? What? Where? For how long? How?
  • Rights of Rectification and Erasure. The data subject has the right to request the controller to modify, correct or update, the data concerning him/her.
  • Right to be Forgotten. The data subject has the right to obtain from the controller the cancellation of the PD that concern him without unjustified delay in some cases, including:
    • Personal data are no longer necessary with respect to the purposes for which they were collected or otherwise processed.
    • The data subject revokes the consent on which the treatment is based.
    • The data subject opposes the processing and there is no further legitimate reason to proceed with the processing.
    • Personal data have been processed unlawfully.

Before the right there was the case: Garcia vs Google Spain

"This right is born as an evolution of the principle established in Google Spain, a ruling of the European Court of Justice whereby the Court affirmed that the right of a person to obtain the de-indicization of a link related to a piece of news concerning that person when that piece of news no longer had public interest."

  • Data Portability. This right to receive from the controller, the personal data concerning him/her so that they can be transmitted to another data controller. This right serves to guarantee the transfer of data from one online service to another:
    • Individuals' greater control over their data.
    • Greater competition between companies and therefore promoting innovation and the development of new services.

There are restrictions on the exercise of these rights (e.g. national security, defense, prevention and repression of crimes, public security).

When does the GDPR apply?

  • Processing of PD is carried out by a controller/processor established within the EU, that is, by a controller/processor who performs an economic activity through a permanent organization which is established within the EU.
  • Processing of PD is carried out by a controller/processor established outside the EU, but the processing activities are related to:
    • The offering of goods or services to data subjects living in EU; or
    • The monitoring of data subjects' behaviour taking place within EU. Indeed, GDPR applies outside the EU.

Data transfer to non-EU countries The expansions of international trade and the spread of online platforms has made data flows to non-EU countries increasingly common and frequent. Therefore, to ensure an adequate level of safety: conditions for a data transfer to third countries to be carried out. In particular, there are three ways whereby data can be transferred outside the EU in a safe way ... companies can rely on:

  • Standard Contractual Clauses (SCC).
    • The European Commission has developed standard contractual clauses to allow the safe transfer of personal data to non-EU countries.
    • In everyday life, the exporter of data, incorporating the text of these SCC in the contract used for the transfer, ensures that the data will be processed in accordance with the principles established in European legislation also in the third country of destination.
    • The Data Controllers can prepare further and diverse ad hoc contractual clauses to be submitted to the Supervisory Authorities. An essential element is, however, the possibility for the interested parties to exercise their rights.
  • Binding Corporate Rules (BCR).
    • These rules allow transfers to non-EU countries only among companies belonging to the same group.
    • They consist of a series of contractual clauses that dictate binding principles for all the companies belonging to the group, in line with the GDPR and which ensure an adequate level of protection.
    • Before being implemented, the BCR must be examined and approved by the supervisory authority.
  • Ad hoc decisions.
    • In the absence of SCC and BCR, the data transfer to non-EU countries is eligible if it established that the third country guarantees a data protection level appropriate to the EU one.
    • To assess such adequacy, it is necessary to examine different aspects of the would-be processing: i.e. the nature of the data, the purpose of the processing, the possibility that such data will pass into other countries before reaching the destination country, the security measures adopted ... and so on.
    • The requirement of adequacy, rather than that of strict equivalence, gives more leeway to ensure a comparable level of data protection... Think, for example, to international agreements, such as that between the US and the EU.

The EU - US International Agreements for Data Transfer

  • In 2000, EU and US concluded an initial agreement (so-called Safe Harbor) to allow and regulate the transfer of data of European citizens to the United States.
  • In October 2015, the EU Court of Justice in the Schrems case declared Safe Harbor invalid.
  • In July 2016, the European Commission created the so-called Privacy Shield, which is the new agreement regulating the transfer of. Data between the EU and the US.
  • In July 2020, the EU Court of Justice in the Schrems II case declared the Privacy Shield invalid.

The Schrems Case The facts

  • On 25 June 2013, Mr. Schrems - a user of the Facebook - asked the Ireland Privacy Commissioner to exercise its statutory powers by prohibiting Facebook Ireland from transferring his personal data to the United States.
  • He contended that in the US the privacy law and practice did not ensure adequate protection of personal data against the surveillance activities that were engaged in US by the public authorities (after Snowden).
  • The Commissioner rejected the complaint as unfounded.
  • Mr. Schrems brought an appeal before the High Court challenging the decision of the Commissioner.
  • The High Court found that the electronic surveillance and interception of personal data transferred from the EU to the US serve necessary and indispensable objectives in the US public interest.
  • However, Snowden case showed a "significant over-reach" on the part of the NSA.
  • Specifically, the right to respect for private life would be rendered meaningless if the State authorities were authorized to access electronic communications on a casual and generalized basis without any objective justification based on considerations of national security or the prevention of crime that are specific to the individual concerned and without those practices being accompanied by appropriate and verifiable safeguards.
  • Therefore, the High Court referred to the Court of Justice of the EU (CJEU).

The Holding of the CJEU

  • The Commission may adopt a decision - such as the so called Safe Harbour with the US - that said that a third country ensures an adequate level of protection.
  • And until such decision is declared invalid by the Court of Justice, the Member States and their independent supervisory authorities cannot adopt measures contrary to that decision.
  • However, such decision cannot prevent persons whose personal data has been or could be transferred to a third country from lodging with the national supervisory authorities a claim.
  • And in such a case the national supervisory authorities must be able to examine, with complete independence, whether the transfer of that data complies with the requirements laid down by the directive.
  • Thus, National privacy authorities can intervene!
  • Furthermore, the Safe-Harbor is Invalid.
  • In EU, any law affecting privacy for national security reasons must lay down clear and precise rules governing the scope and application of a measure and imposing minimum safeguards, so that the persons whose personal data is concerned have sufficient guarantees enabling their data to be effectively protected against the risk of abuse and against any unlawful access and use of that data.
  • On the contrary, in the US the legislation permit the public authorities to have access on a generalized basis to the content of electronic communications and does not provide for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or obtain the rectification or erasure of such data.
  • Thus, the US practice does not ensure an adequate level of protection by reason of its domestic law.

After the Schrems I Case The US and EU achieved another agreement, the so-called Privacy Shield which set forth:

  • Stricter obligations for companies operating in the United States and processing personal data of European citizens.
  • Controls and sanctions by the FTC (the Federal Trade Commission) for the US companies violating the conditions of the agreement.
  • A clear prohibition of indiscriminate mass surveillance by public authorities on personal data transferred to the United States!

But this is not the end The Schrems II Case (2020) The EU Court of Justice:

  • Invalidates the EU - US Privacy Shield Framework, as it does not satisfy the requirements that are required under EU law and it does not grant subjects actionable rights before the courts against the US authorities.
  • But concludes that the standard contractual clauses issued by the European Commission for the transfer of personal data to data processors established outside of the EU are valid.

The recap on the EU - US scenario

  • 2010 Safe Harbor
    • In 2016 declared invalid in Schrems I by the CJEU.
  • 2016 Privacy Shield
    • In 2020 Privacy Shield is declared invalid by the CJEU in Schrems II.
  • SCC are still valid.

To conclude: what has changed with the GDPR? Main Novelties:

  • New conditions for lawful processing.
  • Greater rights for data subjects.
  • Exacerbation of pecuniary sanctions (now: up to 20.000.000 euros; for companies, up to 4% of their yearly sales).
  • Extension of the territorial scope of EU privacy legislation.