Data Transfers

Data Transfers
In 2013, Edward Snowden publicly disclosed that US Intelligence Agencies have access to the personal data of European users via surveillance programs such as PRISM or Upstream. These disclosed documents also listed a number of companies that are providing data to the US government for surveillance programs, including Apple, Microsoft, Facebook, Google and Yahoo. Following the Snowden disclosures, Max Schrems filed a complaint against Facebook Ireland Ltd before the Irish Data Protection Commissioner (DPC), arguing that Facebook may not transfer his personal data to the US anymore, given that Facebook USA has to provide that data to the US secret services without adequate protection.

After lengthy back and forth between the DPC, Facebook and Max Schrems, the case was referenced to the Court of Justice of the European Union (CJEU). In a groundbreaking judgment in 2015 the CJEU declared the first legal instrument (“Safe Harbor”) invalid. In 2019, the CJEU also declared “Privacy Shield” (the successor of Safe Harbor) invalid and highlighted that Facebook may also not use “Standard Contractual Clauses”, which was another type of transfer mechanism.

At its core, there is a fundamental conflict between US surveillance laws (which demand surveillance of non-US persons) and European data protection laws (which requires privacy protections), that can only be overcome by a common standard for privacy protections, no matter the citizenship. Until such time, it is unlikely that the matter will be resolved.

More information on EU-US Data Transfers

In this project, noyb

  • filed 101 model complaints against companies that are still transferring data to the US after invalidation of Privacy Shield in July 2020,
  • is providing information for EU companies on how to comply with the ruling and informing users about their options to stop data transfers to the US,
  • is prompting the Irish Data Protection Commissioner, the responsible authority for Facebook, to enforce the judgment and stop Facebook’s data transfers to the US,
  • is actively preparing to challenge any upcoming new EU-US data transfer deal that is not based on any substantial change of US laws and practices and
  • advocates for a long-term solution, based on an agreement among democratic countries, which limits surveillance of private individuals (no matter the citizenship), unless common thresholds (such as probable cause and a judicial approval) are met.

Case Controller DPA Status Duration
C029-44 netdoktor.at GmbH DSB (Austria) Pending (4 years and more) Filed:
Closed:
(2 years 7 months)
C029-45 CZECH NEWS CENTER a.s. DSB (Austria), UOOU (Czech Republic) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-46 oe24 GmbH DSB (Austria) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-47 POMO Media Group sro DSB (Austria), UOOU (Czech Republic) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-48 Politis DSB (Austria), Commissioner (Cyprus) Partly Won Filed:
(4 years 3 months ago)
C029-49 Cyprus Football Association DSB (Austria), Commissioner (Cyprus) Partly Won Filed:
(4 years 3 months ago)
C029-5 Syn DSB (Austria), Persónuvernd (Island) Other Outcome Filed:
(4 years 3 months ago)
C029-50 CYPRUS NEWS AGENCY DSB (Austria), Commissioner (Cyprus) Partly Won Filed:
(4 years 3 months ago)
C029-51 DYO DEKA EDITORIAL SA (lifo) DSB (Austria), HDPA (Greece) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-52 FIRST ISSUE SA DSB (Austria), HDPA (Greece) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-53 iefimerida DSB (Austria), HDPA (Greece) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-54 Scrooge SA DSB (Austria), HDPA (Greece) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-55 Liechtenstein Marketing Datenschutzstelle (Liechtenstein) Withdrawn (Complied) Filed:
(4 years 3 months ago)
C029-56 Incrementum AG Datenschutzstelle (Liechtenstein) Withdrawn (Complied) Filed:
Closed:
(2 weeks)
C029-57 Universität Liechtenstein Datenschutzstelle (Liechtenstein) Withdrawn (Complied) Filed:
Closed:
(4 weeks)
C029-58 RTÉ Head Office DPC (Ireland) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-59 Allied Irish Banks DPC (Ireland) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-6 DV DSB (Austria), Persónuvernd (Island) Other Outcome Filed:
(4 years 3 months ago)
C029-60 UCD DPC (Ireland) Pending (4 years and more) Filed:
(4 years 3 months ago)
C029-61 Vacaciones eDreams S.L. AEPD (Spain) Pending (4 years and more) Filed:
(4 years 3 months ago)

Share

Related articles