A collection of fragments of understanding in the pursuit of deeper questions.
Art. 25, Directive 95/46/EC (What happens when data is transferred to a country which is not member of the European Union, in order to regulate these differences, the EU Directive introduced some mechanisms allowing the transfer of the Data, the most important option is to rely on the Adequacy decision, a decision approved by the European Commission, by which the competent body afford adequate level of protection, which vary on the nature of the data. The Directive introduced some criterion to evaluate the adequacy of the level of protection).
(In the U.S. there is no federal legislation regarding data-trasnfer, there was only a registry in which companies transferring data had to self-certificate the conditions they were using. In 2000 EU needed something more specific than Directive of 95, due to a huge increase of data transportation. The EU Commission adopted the "Safe Harbour" decision, which was a validation of the self-certification mechanism in use in the U.S.)
Safe Harbour 2000/520/EC: Commission Decision on the adequacy of the protection provided by the safe harbor privacy principles.
Safe Harbour: mechanism of self-certification. Intended for U.S. organizations that process personal data collected in the EU, the Safe Harbor Principles are designed to assist eligible organizations to comply with the EU Data Protection Directive and maintain the privacy and integrity of that data. U.S. companies can opt into the program (I.e. self-certify) as long as they adhere to the 7 principles and 15 frequently asked questions.
(The growing complexity of digital companies in 15 years, made the self-certification method obsolete.
During NSA scandal, a student questioned the security of personal data transferred to the U.S. according to the "Safe Harbour". Data Protection authority said that the mechanism was enough but, the High Court of Ireland started doubting too, therefore it asked to clarification to the Court of Justice and the invalidation of the mechanism on the basis of a violation of Art. 7 and 8 of the Charter, the decision and reasoning of he Court of Justice follows...)
Schrems Case (2015) Schrems asked the DPC to prohibit Facebook Ireland from transferring his personal data to the US. He contended that the law and practice in force in the US did not ensure adequate protection of the personal data against the surveillance activities that were engaged in there by the public authorities.
The DPC rejected the complaint. The High Court held that the mass and undifferentiated accessing of personal data is contrary to the principle of proportionality and the fundamental values protected by the Irish Constitution.
However, the case concerns the implementation of EU law as referred to in Article 51 of the Charter and that the legality of the decision at issue in the main proceedings must therefore be assessed in the light of EU law. According to the High Court, Decision 2000/520 does not satisfy the requirements flowing both from Articles 7 and 8 of the Charter.
Advocate General Bot **"**Article 28 of Directive 95/46/EC, read in light of Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that the existence of a decision adopted by the European Commission on the basis of Article 25(6) does not have the effect of preventing a national supervisory authority from investigating a complaint alleging that a third country does not ensure an adequate level of protection of the personal data transferred and, where appropriate, from suspending the transfer of that data".
**"**Commission Decision 2000/520/EC of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the safe harbour privacy principles and related frequently asked questions issued by the Department of Commerce of the United States of America is invalid".
Court of Justice **"**Until the Commission decision is declared invalid by the Court, the Member States and their organs, which include their independent supervisory authorities, admittedly cannot adopt measures contrary to that decision. Measures of the EU institutions are in principle presumed to be lawful and accordingly produce legal effects until such time as they are withdrawn, annulled in an action for annulment or declared invalid following a reference for a preliminary ruling or a plea of illegality. However, a Commission decision adopted pursuant to Article 25(6) of Directive 95/46, such as Decision 2000/520, cannot prevent persons whose personal data have been or could be transferred to a third country from lodging with the national supervisory authorities a claim concerning the protection of their rights and freedoms in regard to the processing of that data. A decision of that nature cannot eliminate or reduce the powers expressly accorded to the national supervisory authorities by Article 8(3) of the Charter and Article 28 of the directive". **"**Neither Article 25(2) of Directive 95/46 nor any other provision of the directive contains a definition of the concept of an adequate level of protection. In particular, Article 25(2) does no more than state that the adequacy of the level of protection afforded by a third country 'shall be assessed in the light of all the circumstances surrounding a data transfer operation or set of data transfer operations' and lists, on a non-exhaustive basis, the circumstances to which consideration must be given carrying out such an assessment"
(No binding definition of "adequate", is a flexible definition on purpose. The general purpose of Directive is to ensure a high level of protection of data. Then the Court starts making some reasonings regarding the level of protection of data abroad, and agree on the fact that data cannot be protected as in Europe, but can be meant as requiring an essentially equivalent level of protection)(Adequacy doesn't mean identity, but an essentially equal level of protection, therefore there is a sort of manipulation and interpretation of the word adequacy from the Court).
"Article 25(6) of Directive 95/46 implements the express obligation laid down in Article 8(1) of the Charter to protect personal data and is intended to ensure that the high level of that protection continues where personal data is transferred to a third country ...
The word 'adequate' in Article 25(6) of Directive 95/46 admittedly signifies that a third country cannot be required to ensure a level of protection identical to that guaranteed in the EU legal order. However, as the Advocate General has observed in point 141 of his Opinion, the term 'adequate level of protection' must be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union by virtue of Directive 95/46 read in the light of the Charter. If there were no such requirement, the objective referred to in the previous paragraph of the present judgment would be disregarded".
(Even if the legal norms applicable in the third country are different from EU, those norms must prove, in practice an essentially equivalent level of protection to that guaranteed within the European Union).
"Even though the means to which the third country has recourse for the purpose of ensuring a level of protection may differ from those employed within the European Union those means must nevertheless prove, in practice, effective in order to ensure protection essentially equivalent to that guaranteed within the European Union.
Also, in the light of the fact that the level of protection ensured by a third country is liable to change, it is incumbent upon the Commission, after it has adopted a decision to check periodically whether the finding relating to the adequacy of the level of protection ensured by the third country is still factually and legally justified. Such a check is required, in any event, when evidence gives rise to a doubt in that regard".
(Since the technology is changing, the Court said that there must be a regular check from the European Commission whether the finding relating to the adequacy of the level of protection ensured by the third country is still factually and legally justified. On both sides, if EU Law changes either third countries' law changes).
"Decision 2000/520 lays down that 'national security, public interest, or law enforcement requirements' have primacy over the safe harbour principles, primacy pursuant to which self-certified US organisations receiving personal data from the EU are bound to disregard those principles without limitation where they conflict with those requirements and therefore prove incompatible with them.
In addition, it does not contain any finding regarding the existence, in the US, of rules intended to limit any interference with the fundamental rights of the persons whose data is transferred from the EU, interference which the State entities of that country would be authorised to engage in when they pursue legitimate objectives, such as national security. Nor does Decision 2000/520 refer to the existence of effective legal protection against interference of that kind".
(The EU Court wanted the data to be safe also from the government's interference).
"Legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life, as guaranteed by Article 7 of the Charter. Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter".
Therefore Decision 2000/520 is invalid. (October 2015) (What happened the day after?)
Transfer of Personal Data to Third Countries
The following are alternatives
Binding Corporate Rules are rules that can be equalized internal policies adopted by multinational group of companies which define its global policy with regard to the international transfers of personal data within the same corporate group to entities located in countries which do not provide an adequate level of protection. (They require a long time to be approved and enter in function). Furthermore, no transfer can be made on this basis outside the group.
Standard Contractual Clauses are set of clauses (approved by the EU Commission) that can be adopted in the agreements between different subjects, however they are quite rigid.
Data Subject Consent
The aftermath of the Schrems Judgment The Judicial Redress Act affords persons whose data are shared by EU and other countries with US law enforcement agencies for the purpose of investigating, detecting, or prosecuting criminal offenses - including citizens of EU Member States - access to civil remedies for certain violations of those protections, and access to court proceedings in which those remedies can be pursued.
Privacy Shield In 2016, the Privacy Shield substituted the Safe Harbour mechanism. "While the US and the EU share the goal of enhancing privacy protection, the US takes a different approach to privacy from that taken by the EU. The US uses a sectoral approach that relies on a mix of legislation, regulation, and self-regulation. Given those differences and to provide organizations in the US with a reliable mechanism for personal data transfers to the US from the EU while ensuring that EU data subjects continue to benefit from effective safeguards and protection as required by European legislation with respect to the processing of their personal data when they have been transferred to non-EU countries, the Department of Commerce is issuing these Privacy Shield Principles".