In 2013, Edward Snowden publicly disclosed that US Intelligence Agencies have access to the personal data of European users via surveillance programs such as PRISM or Upstream. These disclosed documents also listed a number of companies that are providing data to the US government for surveillance programs, including Apple, Microsoft, Facebook, Google and Yahoo. Following the Snowden disclosures, Max Schrems filed a complaint against Facebook Ireland Ltd before the Irish Data Protection Commissioner (DPC), arguing that Facebook may not transfer his personal data to the US anymore, given that Facebook USA has to provide that data to the US secret services without adequate protection.
After lengthy back and forth between the DPC, Facebook and Max Schrems, the case was referenced to the Court of Justice of the European Union (CJEU). In a groundbreaking judgment in 2015 the CJEU declared the first legal instrument (“Safe Harbor”) invalid. In 2019, the CJEU also declared “Privacy Shield” (the successor of Safe Harbor) invalid and highlighted that Facebook may also not use “Standard Contractual Clauses”, which was another type of transfer mechanism.
At its core, there is a fundamental conflict between US surveillance laws (which demand surveillance of non-US persons) and European data protection laws (which requires privacy protections), that can only be overcome by a common standard for privacy protections, no matter the citizenship. Until such time, it is unlikely that the matter will be resolved.
More information on EU-US Data Transfers
More information on EU-US Data Transfers
In this project, noyb
- filed 101 model complaints against companies that are still transferring data to the US after invalidation of Privacy Shield in July 2020,
- is providing information for EU companies on how to comply with the ruling and informing users about their options to stop data transfers to the US,
- is prompting the Irish Data Protection Commissioner, the responsible authority for Facebook, to enforce the judgment and stop Facebook’s data transfers to the US,
- is actively preparing to challenge any upcoming new EU-US data transfer deal that is not based on any substantial change of US laws and practices and
- advocates for a long-term solution, based on an agreement among democratic countries, which limits surveillance of private individuals (no matter the citizenship), unless common thresholds (such as probable cause and a judicial approval) are met.
Case | Controller Sort descending | DPA | Status | Duration |
---|---|---|---|---|
C029-80 | 24.hu | DSB (Austria), NAIH (Hungary) | Other Outcome | Filed:
(4 years 1 month ago) |
C029-77 | 24sata.hr | DSB (Austria), AZOP (Croatia) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-63 | Airbnb Ireland UC | DPC (Ireland), AEPD (Spain) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-86 | Airbnb Ireland UC | DSB (Austria), DPC (Ireland) | Withdrawn (Other Reason) | Filed:
(4 years 1 month ago) |
C029-65 | Airbnb Ireland UC | DPC (Ireland), IDPC (Malta) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-70 | Airbnb Ireland UC | DPC (Ireland), Garante per la protezione dei dati personali (Italy) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-20 | Allepal OÜ | DSB (Austria), AKI (Estonia) | Won | Filed:
(4 years 1 month ago) |
C029-59 | Allied Irish Banks | DPC (Ireland) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-42 | Auchan E-commerce France | CNIL (France) | Other Outcome | Filed:
(4 years 1 month ago) |
C029-98 | Banque et Caisse d'Epargne de l'Etat | CNPD (Luxembourg) | Other Outcome | Filed:
Closed: (1 year 7 months) |
C029-97 | Big Bang, d.o.o. | DSB (Austria), IP (Slovenia) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-87 | BoligPortal | DSB (Austria), Datatilsynet (Denmark) | Partly Won | Filed:
(4 years 1 month ago) |
C029-13 | bpost SA | APD/GBA (Belgium) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-73 | bradva.bg | CPDP (Bulgaria) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-31 | Caffeina Media Ltd | Garante per la protezione dei dati personali (Italy) | Won | Filed:
Closed: (1 year 10 months) |
C029-66 | CareerJet Limited | IDPC (Malta) | Other Outcome | Filed:
(4 years 1 month ago) |
C029-4 | CDON AB (formarly: Qliro Group AB) | DSB (Austria), IMY (Sweden) | Won | Filed:
(4 years 1 month ago) |
C029-93 | Chefkoch GmbH | LDI (North Rhine-Westphalia), HmbBfDI (Hamburg) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-88 | CinemaxX Danmark A/S | DSB (Austria), Datatilsynet (Denmark) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |
C029-14 | Concept Multimedia Belgium sa - IPM | APD/GBA (Belgium) | Pending (4 years and more) | Filed:
(4 years 1 month ago) |