Данные и приватность · 1 июля 2024 · 6 мин чтения

Transfer of personal data from the EU to the US

Personal data (hereinafter referred to as PD) are transferred from the EU to companies in the US, including to support international trade (e.g. airline services) and labor market needs (e.g. hiring an EU professional in the US). As a general rule, PD from the EU may be transferred to countries providing adequate PD protection, which may be recognized by European Commission decisions or ensured by

Из выпуска мониторинга No. 7, July 2024 · выпуск целиком, PDF · на сайте Института Гайдара

Personal data (hereinafter referred to as PD) are transferred from the EU to companies in the US, including to support international trade (e.g. airline services) and labor market needs (e.g. hiring an EU professional in the US). As a general rule, PD from the EU may be transferred to countries providing adequate PD protection, which may be recognized by European Commission decisions or ensured by certain instruments, such as standard contractual clauses (signed by the companies transferring1 and receiving PD). As the US PD regulation is less stringent than in the EU, the US was not considered by default to have adequate PD protection. The European Commission's decisions on the adequacy of protection of PD in the US facilitate their cross-border transfer.

Among the documents that formed the basis for the European Commission's decisions on the adequacy of protection is the EU-US Data Privacy Framework. In July 2024, the European Council for Data Protection published2 clarifications to these provisions , specifying technical aspects of PD transfer (e.g., transfer of PD to companies that are subsidiaries of those that have adhered to the framework, obligation to inform data subjects about recipients of data in the US).

The European Commission's decision on the adequacy of US PD protection under the Framework provisions, was issued in July 2023, however, 2 decisions of the European Commission similar in form and meaning (the3 Safe Harbor Principles Decision of 2000 and4 the Privacy Shield Decision of 2016 ) were previously in force), which were recognized5 invalid by the EU Court under cases Schrems I (2015) and Schrems II (2020).

The Safe Harbor, Privacy Shield and Data Privacy Frameworks are based on the principles of information, accountability in onward transmission, security of transmission,6 data integrity, etc. There are slight differences in the “safe harbor” and “privacy shield” principles. The latter is broader, e.g. in terms of liability when transferring PD for processing to7 contractors and in what cases and what must be notified to PD subjects, including the requirement to disclose PD in response to lawful requests from authorities to ensure national security rights of PD subjects.

Another difference between the three European Commission decisions under consideration is the mechanisms for protecting the rights of PD subjects. Thus, in the case of Schrems I (which overturned the safe harbor decision), the EU Court of Justice ruled that the safe harbor principles (2000) provide insufficient legal protection for PD subjects. Therefore, as part of the next solution, the privacy shield, an ombudsman function was provided, so that EU authorities could submit requests on behalf of subjects of PD transferred from the EU using ombudsman in case US intelligence poses risks of a PD violation (e.g., mass collection of PD).

The European Commission's decisions based on the safe harbor and privacy shield principles were invalidated by the EU Court of Justice for the following reasons:

1) disproportionate access by US intelligence agencies to Europeans' PD (e.g., mass collection of PD under the US Foreign Intelligence Surveillance Act);

2) lack of effective legal protection from interference by US government agencies. However, the introduction of the ombudsman function did not affect the effectiveness of legal protection, as he is not, actually, a court.

A decision of the European Commission on the adequacy of protection provided by standard contractual clauses (include, for example, obligations of the data exporter and importer with respect to each other and data8 subjects) adopted in 2010 , in the Schrems II case has not been overturned in the court because these provisions, while not binding on9 third-country authorities, including the US , nevertheless, ensure that transfer of PD to a third country is suspended/prohibited if the recipient does not or cannot comply with their protection.

It is worth noting that the decision of the European Commission on the 2023 Data Privacy Framework was taken after the US signed Executive Order No. 14086 in 2022 to strengthen security safeguards in intelligence10 activities , in order to limit disproportionate US intelligence access to European PD. The difference between this solution and the previous two is the introduction of a two-tiered11 mechanism in the US for consideration of the complaints submitted by PD subjects, whose data were transferred from the EU to the US, with regard to their collection and use by the intelligence:

• - at Level 1, complaints are handled by an official (as opposed to an ombudsman - in the intelligence community, not within the US State Department);

• - at level 2, complaints are handled by a specially created data protection supervisory court, to which a level 1 decision can be appealed. This is intended to strengthen protection against intelligence interference.

These measures are criticized as formal: proportionality is subject to value judgments, and independence, transparency and the impartiality of the data protection supervisory court is challenged because data subjects do not have direct access to it. In this respect, Mr. Schrems prepares for the next hearing in the EU12 Court. Moreover, both the EU and the US are interested in having a valid decision on the adequacy of the PD protection in the US: for both parties it reduces costs in foreign trade transactions.

Russia’s experience

In Russia, according to item 2 Article 12 of the PD Law, the Roskomnadzor has approved the list of countries providing adequate protection of the PD subjects rights: 8913 countries , including all 27 EU countries,14 however, there is no US in this list. This means that PD cannot be transferred to the US until Roskomnadzor decides to allow the transfer. Operators have the right to transfer personal data to the countries on the list before the notification of cross-border data transfer is considered by the authorized body, and to other countries as a result of such consideration.

The approach of the Russian Federation is more rigorous than in the EU, where the transfer of personal data to third countries is allowed without authorization of the supervisory authority even in the lack of a decision on the adequacy of protection in these countries (for example, based on binding corporate rules or the consent of the subject of personal data after being informed of the risks). Whether it provides greater protection for PD depends on the scrutiny by the competent authority of the conditions in notices of cross-border data transfers.

  1. In the absence of such decisions and instruments, PD may be transferred from the EU to third countries as an exception: for example, with the expressed consent of the PD subject after being informed of the risks.
  2. https://www.edpb.europa.eu/system/files/2024-07/edpb_dpf_faq-for-businesses_en.pdf
  3. https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj
  4. The decision means that adequacy of data protection is ensured by the Data Privacy Framework, i.e. it applies only to US companies that have declared compliance with this framework and are therefore listed by the US Department of Commerce, and not to the US as a whole. The same is true for the safe harbor and privacy shield principles.
  5. https://eur-lex.europa.eu/eli/dec/2000/520/oj
  6. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%3AOJ.L_.2016.207.01.0001.01.ENG
  7. Court of Justice of the European Union (CJEU).
  8. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62014CJ0362
  9. https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:62018CJ0311
  10. Note that this did not create a legal vacuum, as the European Commission's decision on standard contractual clauses (2010, see below) remained in force.
  11. . There are 7 of them: information, selection, accountability in further transfer; security, data integrity and target limitation; access of subjects; defense of rights, enforcement and liability. Principles are published by the U.S. Department of Commerce and are accompanied by negotiations between the EU and the U.S. on the conditions (which also include mechanisms for implementing the principles) on which the adequacy of data protection can be recognized, i.e. the European Commission's decisions are not unilateral.
  12. For example, Facebook transfers users’ data from the EU to its servers in the US; if Facebook in the US conditionally hires company A for processing of these data, then, company A is a contractor.
  13. https://eur-lex.europa.eu/eli/dec/2010/87/oj
  14. Unlike the decisions discussed above, this decision focuses on the transfer of PD to all third countries, but the Schrems II case involved transfer of PD specifically to the United States.
  15. https://www.federalregister.gov/documents/2022/10/14/2022-22531/enhancing-safeguards-for-united-states-signals-intelligence-activities
  16. https://ec.europa.eu/commission/presscorner/detail/en/qanda_23_3752
  17. https://noyb.eu/en/european-commission-gives-eu-us-data-transfers-third-round-cjeu

From the monitoring issue No. 7, July 2024. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также