Hiển thị các bài đăng có nhãn data protection Regulation. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn data protection Regulation. Hiển thị tất cả bài đăng

Thứ Tư, 11 tháng 3, 2015

When super-regulators fight: the ‘one-stop shop’ in the proposed Data Protection Regulation



Steve Peers

A guilty pleasure for fans of superhero comic books is the moment when our heroes pause in their valiant efforts to save the public from the nefarious plans of the supervillains – and start beating the hell out of each other instead. This is usually triggered by some trivial difference of opinion, perhaps concerning a continuity error or intellectual property rights.

Similarly, the EU vests its hopes for the effective enforcement of data protection law upon national data protection authorities (DPAs): the superheroes of the data protection world. They have considerable powers under the current data protection Directive, and the proposed Regulation would also give them more powers. But what if they disagree with each other? There’s nothing in the current legislation to settle this problem, which gives each DPA the power to regulate actions on its own territory without addressing the obvious complications that result in a digital age, when many forms of processing of personal data (most obviously via the Internet) take place across borders.  

To deal with this problem, the Commission proposal contains a conflict rule to determine who is the lead regulator in cross-border cases, with the possibility that a ‘European Data Protection Board’ or the Commission itself can issue an opinion on the issue. This has been dubbed the ‘one-stop shop’ rule. However, due to legal concerns, both the Council (which is about to adopt its position on this part of the proposed Regulation: see the draft text here), and the European Parliament (EP), which has already adopted its position on the entire text, propose instead that the Board must be able to make binding decisions to settle disputes.

So this is set to become one of the most significant innovations of the new legislation. Let’s take a look at what the future rules will likely say about the role of national DPAs, the one-stop-shop process and the powers of the Board.

National data protection authorities

The current Directive already provides for the existence of DPAs, and insists that they must exercise their powers in ‘complete independence’. CJEU case law (discussed here) has set out a very strong interpretation of this notion, ruling that Germany, Austria and Hungary breached it, because they provided for too much accountability to national parliaments (Germany), failed to separate the DPA from the ordinary civil service (Austria) and defenestrated the DPA boss before his normal term of office expired (Hungary).

The proposed Regulation would retain and elaborate upon this concept, and the Council and EP agree with most of the Commission’s suggestions. Admittedly, the DPAs have to be appointed by public authorities in the first place: after all, their powers don’t stem from being bitten by a radioactive spider, or orphaned in a bat-infested back alley. The Council would amend the proposal so that they don’t have to be appointed by the government or parliament, but could instead be appointed by the head of state or independent body. Only the last alternative would fully ensure their independence from the outset (although who appoints the ‘independent body’?)

Three points of concern here. First, the proposal would usefully require the national DPAs to be adequately funded. That is easier said than done, for most DPAs complain of an absence of sufficient funding. For instance, the Irish DPA occupies a small office next to a corner shop – but purports to regulate (among many other things) all of Facebook’s activities in the EU.  Secondly, the Council would remove the proposed rule requiring that DPAs be independent ‘beyond doubt’ when they are appointed; but DPAs should not be a resting ground for political hacks and bagmen. Thirdly, the Council would remove most of the details concerning the loss of office of DPAs, retaining only the minimum rule of four years in office. As the termination of the Hungarian DPA showed, it’s hard to exercise your powers independently if you constantly fear that there may be Kryptonite in your coffee.

As for the powers of the DPAs, the Regulation would strengthen and elaborate upon their current advisory and enforcement roles. In particular, the current powers to investigate, intervene and engage in legal proceedings would be fleshed out, by adding powers concerning audits, access to the premises of the controller and processor, ordering compliance with a data subject’s request, the suspension of data flows, or the imposition of fines.  

But with these great powers will come only limited accountability. DPAs will have to publish an annual public report (and the EP even wants to weaken this obligation). But that’s the only way that their decisions can be controlled, unless a cross-border complication means that other DPAs, or the European Data Protection Board (a sort of uber-DPA) gain jurisdiction, as discussed below. Otherwise, the only bodies which can watch these watchmen are the courts.

Settling disputes

Although the Commission is often accused of favouring over-centralisation in the EU, its proposed model for a ‘one-stop-shop’ was highly decentralised. Where a data processor or controller was established in the EU in more than one Member State, the supervisory authority of the ‘main establishment’ would have competence to regulate all that controller’s or processor’s activity in all Member States. There would be new rules on cooperation between supervisory authorities, in particular as regards mutual assistance (each DPA would usually have to comply with requests from another DPA) and joint operations.

In several cases, however, a DPA would have had to send a draft measure to the European Data Protection Board for its opinion. In particular, this would have applied to measures regulating processing concerning ‘offering of goods or services to data subjects in several Member States, or monitoring of their behaviour’, or which would ‘substantially affect’ the free movement of data. Following the Board’s opinion, the Commission could give its opinion, and then could ultimately adopt a binding measure if necessary. A decision of any supervisory authority is enforceable in all Member States, except where that DPA breaches the consultation rules, in which case its decision isn’t valid.

However, the Council and EP both agree to strip the Commission of all dispute settlement powers, and to confer binding powers on the Board instead. In the Council’s version, the DPA of the main establishment or single establishment of the controller or processor would not be the sole authority, but only the lead supervisory authority for transnational processing. Even then, each national supervisory authority would be competent to deal with an issue which only concerned an establishment in its State, or ‘substantially affects data subjects only in’ that State, unless the lead DPA decided to step in.

There’s a complex process for trying to reach a consensus on a decision between the lead DPA and the other DPAs involved. But in the event of a dispute between them, as regards the content of a draft decision, or who is the lead DPA in the first place, or where the procedures aren’t followed, then the European Data Protection Board can adopt a binding decision.  The Council would remove the rules on enforceability and unenforceability of DPA decisions, but the EP wants to strengthen them. In the event of disputes about the Board’s decisions, the preamble sets out detailed rules on whether litigation would take place before the national or EU courts.

The European Data Protection Board

It isn’t spelled out in the main text of the proposed Regulation, but the future Board is clearly a super-powered version of the current ‘Article 29 working party’, an advisory body which is (like the future Board) made up of members of the national DPAs. That working party can give opinions on national data protection law, data protection in the EU and third countries, the amendment of the Directive and codes of conduct. It has indeed issued many such opinions, which can be found on its website. They are interesting documents which fascinate data protection specialists, but which have not yet had any direct impact on the interpretation of the law by the CJEU. In the Commission’s proposal, the working party would be renamed and it would have more advisory powers, but its essential role would not change.

However, this puny body is about to be transformed at the behest of the Council and EP, which would both confer significant powers upon it as regards dispute settlement (discussed above), along with a longer list of advisory powers. The Council would also take the logical step of defining the Board as a ‘body’ of the EU, with express legal personality.

Finally, it should be noted that the future European Data Protection Boardshould not be confused with the current European Data Protection Supervisor (EDPS) – although I suspect that this warning will be in vain for many years to come. The EDPS is created by separate legislation, and has the role of enforcing data protection law against the EU’s institutions and other bodies, as well as advising on the development of EU data protection law. Its role in the new Regulation will be very limited. The Commission wants it to have a seat and a deputy chair post on the Board, but the Council rejects the first suggestion (relegating the EDPS to an observer role instead) and both the Council and the EP reject the second one. The EDPS will provide the Board’s secretariat, but the Council wants to build a firewall between the two administrations. In effect, while both the Board and the EDPS will have a significant role in the EU’s data protection architecture, there will be almost no crossover between them – rather like comic books produced by competing publishers.

Conclusion

It is certainly necessary for the EU to ensure that DPAs have effective powers to ensure the application of data protection law. Although it will still be possible for individuals to bring legal action directly against data processors or controllers (under other parts of the Regulation, which the Council has not yet agreed), DPAs remain the principal method of enforcing the rules. However, the draft legislation does not fully address the key practical question of sufficient ensuring resources for DPAs, and there is also not enough protection against dismissal or for the initial independence of DPA staff in the Council’s draft position.  

As for settlement of disputes, the Commission’s idea of a lead DPA having full jurisdiction was fairly attractive, although apparently it was torpedoed by the objections of the Council’s legal service. The replacement system is comparatively convoluted, and it has one key weakness – the absence of procedural rights for the original complainant before the Board. Also, it leaves intact greater possibilities of multiple DPAs acting as regards the same data processor or controller, with resulting greater complications for data subjects, DPAs and data processors and controllers alike. It will probably take some time (and possibly even litigation) before the new system will be working effectively. Furthermore, the Council’s removal of the rules about the unenforceability of DPA decisions which are taken in contravention of the rules could lead to complications in the event of rebellious DPAs. Finally, the existence of parallel bodies with similar names (the Board and the EDPS) may be unavoidable, but it unlikely to help public understanding of the EU’s data protection system.

Thứ Hai, 9 tháng 3, 2015

Basic data protection principles in the proposed Data Protection Regulation: Back to the Future?




Steve Peers

So far, 2015 is not like the Back to the Future movies promised it would be like. In particular, there are no hoverboards (drones are a poor substitute). Moreover, instead of agreeing a data protection framework fully fit for 2015, the Council is probably about to agree that the key principles of the law should remain as they were in 1995 – which might as well be 1985 (or even 1955) in terms of technology law.

Background

The negotiations on the EU’s proposed General Data Protection Regulation finally seem to be nearing the final stretch, as far as the Council is concerned. Member States’ ministers in the Council seem likely to agree later this week on two more parts of the proposed Regulation: on basic principles of data protection (text here) and on supervisory authorities, including the idea of a ‘one-stop shop’ for data protection supervision (text here).

Previously they had agreed on three other parts of the Regulation, namely rules on: territorial scope and external relations (see discussion here); public-interest exceptions (see here); and the roles of data controllers and processors (see here; see particularly the discussion of the ‘privacy seals’ rules here). (For full consolidated text of everything the Council has agreed to date, see here). If the proposed texts on principles and data protection authorities are indeed agreed this week, the Council mainly only has to agree on the scope and definitions in the Regulation, along with the rights of data subjects, such as the right to be forgotten (see discussion of the proposed text on that issue here), and related individual remedies.

This blog post focusses on the issue of basic data protection principles. The Commission’s proposalsuggested some fairly modest changes to these basic rules as compared to the current data protection Directive, although the European Parliament (EP) would like to go further than the Commission (see its position here). However, the Council’s position would entail very modest changes indeed to the status quo. For this aspect of data protection law, if the Council has its way, the EU’s lengthy legislative reform journey would end up much where it originally started.

Details

Currently, the data protection Directive begins with a clause (Article 5) which appears to give the Member States a great deal of discretion in how to apply the Directive. The CJEU effectively sidelined that clause in its ASNEFjudgment, emphasising instead the need for uniform interpretation of the Directive. The new Regulation would suppress this clause entirely, but the Council in particular wants to reintroduce a number of specific provisions referring back to national law. So in some respects, the current Directive resembles a Regulation already – but conversely, the future Regulation will continue to resemble a Directive. 

The basic principles of data protection as proposed and (nearly) agreed by the EU institutions are similar to the current Directive: fair and lawful processing; purpose limitation; data minimisation; accuracy; and storage minimisation. The changes would concern: the addition of ‘transparency’; some express protection for archiving or other scientific purposes; and the insertion of data security (by both the EP and the Council). The EP also suggests that the effective protection of rights should be listed as one of the principles. This is a useful suggestion, since although it might seem at first sight that such effective protection is a procedural, not a substantive rule, in the field of data protection it is necessary to ensure that procedural rights are built in to the system (the so-called ‘privacy by design’). An example would be a social network that makes it easy to complain that the user’s privacy has been violated.

Next, the proposal sets out the grounds for processing personal data, again based on the current Directive: consent; contract; compliance with a legal obligation; vital interests of the data subject; public interest or official authority; or legitimate interest of the controller or a third party, subject to an override for the privacy of the data subject. The latter rule is particularly important for the private sector, in the absence of consent or a contract, and the case law points in different directions. In ASNEF, the CJEU ruled that Member States restricted direct marketing companies too much in the interests of consumers, but in Google Spain(discussed here) it ruled that the privacy interests of those named in search results overrode Google’s financial interests as regards its search engine.

The rules would be amended to: refer to consent for specific purposes; extend to the vital interests of another person (according to the Council); and consider the interests of children as regards the ‘legitimate interests’ clause. (The Commission proposal, agreed by the EP, defines a child as anyone under 18; the Council has not agreed this definition yet). Also, the Commission would like to remove the possibility that the legitimate interests of third parties are a ground for processing, but the EP and Council both want to keep this. However, the EP wants to add an important new proviso that such private interests are linked to the ‘reasonable expectations’ of the data subject.  The Council also wants to retain the current rule that consent must be ‘unambiguous’, while the EP and Commission want to delete this adjective.

Furthermore, the institutions differ greatly on what happens if the purpose of data processing is changed. The Commission proposes that changing the purpose should be acceptable on any of the grounds for the initial processing of the data, except for the legitimate interests of the controller. The Council wants to allow a change of purpose for any of the grounds for the initial processing, including the legitimate interests of the controller; while the EP does not want to provide expressly for any incompatible processing at all. The Council’s position in particular would turn the purpose limitation principle into the very smallest of figleaves.

One of the most significant changes in the new rules would be a definition of consent (the CJEU has not yet been asked to clarify this concept under the current Directive). All the institutions agree that the data controller would have to prove consent. The Council’s version would add some very useful rules requiring the data controller to use plain language, while the EP would specify that the relevant contractual terms would be void. The institutions also agree that there should be an express power for the data subject to withdraw consent, although it’s arguable that such a power already exists implicitly under the current rules. Finally, the Commission wants a new clause that would reject the possibility of consent if there is a ‘significant imbalance’ between the data subject and the data controller, and the EP wants to disapply contract terms which are unnecessary for supplying a service. However, the Council rejects entirely the idea that the Regulation should protect Davids from Goliaths.

The other significant change would be a specific rule on children. The Commission proposes that information society services must get the consent of the parents of children under 13. This broadly reflects social networks’ practice of either requiring consent or not permitting younger children to join their network (as we know, this is not fully effective in practice). But the Council version, if agreed, will refer instead to national laws on contract, removing the reference to a particular age. For its part, the EP would broaden the scope of the clause to refer to all supply of goods and services, and would also add a very useful ‘plain language’ clause. Unfortunately, none of the EU institutions propose an amendment which would enormously improve the lives of parents across Europe: an EU-wide hour-long daily limit on children playing Minecraft.

Next, the proposed Regulation keeps largely intact the supposed prohibition on processing so-called sensitive personal data, namely data on racial origin, political opinions, religious beliefs, trade union membership and health or sex life. All institutions agree to add ‘genetic data’ to this list. The EP and Commission also want to add criminal convictions, but the Council wants to retain the current separate rule on this type of data. Furthermore, the EP wants to add sexual orientation, gender identity and biometric data to the list.

The ‘prohibition’ on processing such data is a legal fiction, since both the current rules and the proposed Regulation allow it to be processed on a number of grounds. In fact, the Council will likely agree to extend those grounds, to include social security and social protection, judicial activities, public health and archiving. The Council also wants to retain the current rule that consent by the data subject must be ‘explicit’, while the EP wants to add the possibility of processing based on a contract.

Finally, both the EP and the Council want to strengthen the current rule providing that the data controller is not obliged to obtain further data on the excuse that it has to identify the data subject in order to apply data protection law.

Comments

In summary, the Council’s likely version of the future Regulation would only differ from the current Regulation as regards: new principles of transparency and security; a new definition of consent; a largely cosmetic clause on children’s consent (since it refers back to national law); and a small extension of the list of sensitive data, coupled with a bigger list of exceptions to the prohibition on processing that data.

For its part, the EP would: add a new principle of effective exercise of rights; adjust the balance of interests between the data subject and data controller; limit incompatible further processing; curtail questionable contract terms; strengthen children’s rights; and widen the scope of the concept of sensitive data.

Despite all the fuss made over the proposed new legislation, the Council’s changes would amount to a very marginal change in the rules. (To be fair, though, there would be bigger changes in some other areas of data protection law, such as the new ‘one-stop-shop’ rules).  In particular, there are manifold protections for research-related activities in the Council version of the text: the end is clearly not as nigh for research as many advocates of it have been predicting. The key differences between the EP and the Council concern the balance between corporate interests and individual privacy rights, where it seems that companies have successfully lobbied the Council to make no significant changes, while privacy NGOs have convinced the EP to argue for modest improvements in individual rights. The forthcoming negotiations between the EP and the Council on the final version of the Regulation will determine whether the new rules will genuinely be different, or will merely amount to old cookies in new jars.  

 

Thứ Tư, 15 tháng 10, 2014

The proposed General Data Protection Regulation: suggested amendments to the definition of personal data


Douwe Korff, Professor of International Law
I.                    Background

In a recent judgment (discussed previously on this blog) the third chamber of the CJEU has ruled that the concept of "personal data" in the 1995 data protection (DP) directive is limited to data directly relating to a person, and does not include legal analyses in the file on the person, on which the state (NL) relied in taking its decisions in relation to that person (Joined Cases C-141/12 and C-372/12). I believe the Court’s restriction of the concept is wrong and contrary to the intended purpose of data protection; and should be corrected in the new General Data Protection Regulation.

First of all, the Court based itself on the, in my opinion erroneous, view that the 1995 EC DP Directive was solely aimed at protecting privacy. In particular, it felt that the right of data subjects to access to their personal data should not extend to a legal analysis of their case, contained in a file on them, because (in the Court’s view) such an analyses “is not in itself liable to be the subject of a check of its accuracy by [a data subject]”, and data subjects should not be able to use data protection to seek a rectification of such an analysis (cf. para. 44 of the judgment).

Secondly, the Court also relied on the fact that data of the kind at issue in the joined cases was administrative data held by a public authority and, drawing a parallel with EU regulations on privacy and access to documents, held that access to the legal analysis should be addressed under the latter rules rather than the former. This failed to take into account the fact that the EU rules referred to apply only to public (i.e., EU) bodies, whereas the 1995 DP Directive applies also, and in indeed especially, to private-sector bodies (in particular companies) that are not subject to public-sector rules on access to administrative data.

The Court’s judgment, in sum, seriously limits the concept of personal data and the right of access to one’s personal data, and thus seriously limits the application of the entire EU data protection regime. It leaves individuals with seriously less rights in respect of data on them (or relating to them, or used to take decisions on them, or that affect them) than was previously thought.

Specifically,the judgment runs directly counter to the authoritative 2007 Article 29 Working Party (WP) Opinion on the concept of personal data (Opinion 4/2007, WP136, of 20 June 2007). This first of all noted that the purpose of data protection is not limited to a narrow concept of privacy – as is indeed also clear from the fact that data protection is guaranteed in the Charter of Fundamental Rights (CFR) as a separate right, sui generis, from the right to private life/privacy (data protection is guaranteed in Article 8 CFR; Privacy in Article 7 CFR). Astonishingly, given that the WP29 is expressly charged with providing guidance on the interpretation and application of the 1995 DP Directive, the Court did not even mention either the Working Party or this specific opinion.

In the opinion, the Working Party discussed four elements of the definition, from which it deduces the appropriate criteria for determining whether data should be regarded as personal data within the meaning of the directive. They can be paraphrased as follows:

-                      The first element: “any information”:

The WP concludes that these words indicate that the concept of personal data should be interpreted broadly, and not limited to matters relating to a person’s private and family life stricto senso (as has wrongly been done in the UK under the Durant decision, and as appears to also underpin the Court’s judgment). It also covers information in any form, including documents, photographs, videos, audio and biometric data, body tissues and DNA.

-                      The second element: “relating to”:

In general terms, information can be considered to “relate” to an individual when it is about that individual. However, data about “things” can also be personal data, if the object in question is closely associated with a specific individual (e.g., mobile phone location data). This is of increasing importance in the era of the Internet of Things. Important in relation to the CJEU judgment, the WP29 adds the following consideration, with reference to an earlier opinion, on radio frequency identification (RFID) tags, WP105 of 19 January 2005 (original italics and bold; underlining added):

In the context of discussions on the data protection issues raised by RFID tags, the Working Party noted that "data relates to an individual if it refers to the identity, characteristics or behaviour of an individual or if such information is used to determine or influence the way in which that person is treated or evaluated."
...
[I]n order to consider that the data “relate” to an individual, a "content" element OR a "purpose" element OR a "result" element should be present.
The “content” element is present in those cases where - corresponding to the most obvious and common understanding in a society of the word "relate" - information is given about a particular person, regardless of any purpose on the side of the data controller or of a third party, or the impact of that information on the data subject.
...
Also a "purpose" element can be responsible for the fact that information "relates" to a certain person. That “purpose” element can be considered to exist when the data are used or are likely to be used, taking into account all the circumstances surrounding the precise case, with the purpose to evaluate, treat in a certain way or influence the status or behaviour of an individual.
...
A third kind of 'relating' to specific persons arises when a "result" element is present. Despite the absence of a "content" or "purpose" element, data can be considered to "relate" to an individual because their use is likely to have an impact on a certain person's rights and interests, taking into account all the circumstances surrounding the precise case. It should be noted that it is not necessary that the potential result be a major impact. It is sufficient if the individual may be treated differently from other persons as a result of the processing of such data.
...
These three elements (content, purpose, result) must be considered as alternative conditions, and not as cumulative ones. In particular, where the content element is present, there is no need for the other elements to be present to consider that the information relates to the individual. A corollary of this is that the same piece of information may relate to different individuals at the same time, depending on what element is present with regard to each one. The same information may relate to individual Titius because of the "content" element (the data is clearly about Titius), AND to Gaius because of the "purpose" element (it will be used in order to treat Gaius in a certain way) AND to Sempronius because of the "result" element (it is likely to have an impact on the rights and interests of Sempronius). This means also that it is not necessary that the data "focuses" on someone in order to consider that it relates to him. ...
The “legal analyses” that the CJEU ruled were not personal data are clearly covered by the above: they are the very basis on which the data subjects in questions (asylum seekers) were “treated” and “evaluated”. To apply the reasoning of the Working Party: they determine whether Titius should be treated the same way as Gaius or not; and they may also have an impact on the rights and interests of Sempronius.
This is also crucially important in relation to “profiles”. Under the judgment, states and companies could argue that individuals should also not have a right to challenge the accuracy of a profile, any more than the accuracy of a legal analysis; and that, indeed, they are not entitled to be provided on demand with the elements used in the creation of a profile. After all, a profile, by definition, is also based on an abstract analysis of facts and assumptions not specifically related to the data subject – although both are of course used in relation to the data subject, and determine the way he or she is treated.
In my opinion, the above is the most dangerous limitation flowing from the Court’s judgment.
-                      The third element: “identified or identifiable”:
Although this issue did not arise in the CJEU cases, it is still crucial, in particular in relation to the ever-increasing and ever-more-widely-available massive sets of “Big Data”. In the opinion of the WP, the core issue is whether a person is, or can be, singled out from the data, whether by name or not. A name sometimes suffices for this, but often not, while a photograph or an identity number often does allow such singling out even if no other details of the person are known. In relation to pseudonymised or supposedly anonymised data, the WP concluded (with reference to the recitals in the 1995 directive) that the central issue is whether the person can be identified (singled out), whether by the data controller or by any other person, “taking account of all the means likely reasonably to be used either by the controller or by any other person to identify that individual.”
-                      The fourth element: “natural person”:
In principle, personal data are data relating to identified or identifiable living individuals. There are some issues relating to data on deceased persons and unborn children: these can often still (also) relate to living individuals, in the way discussed above, and would then still be personal data in relation to those latter individuals. Data on legal entities can sometimes also, similarly, relate to living individuals associated with those entities. Also, in some contexts some data protection rights are expressly extended to legal persons (companies etc.) per se, in particular under the so-called “e-Privacy Directive”. But that is a special case. This too, however, was not an issue relevant to the CJEU judgment.

Until the CJEU judgment, it could be assumed that as long as the General Data Protection Regulation used the same definition of personal data as the 1995 DP Directive, the above elements and criteria could simply be read into the new instrument.

However, the judgment could result in the definition in the GDPR being read in accordance with the Court’s restricted views, rather than in line with the WP29 guidance.

In my opinion, if the EU wishes to retain a strong European data protection framework, as is often asserted, it is essential that the GDPR expressly (if of course briefly) endorses the WP29 view of the issue, rather than the CJEU’s one.

Below, I suggest amendments to the definition of the concept of personal data in the GDPR that would achieve that (some further amendments should be made to the recitals).
II.                  Proposed amendments to the GDPR
As can be seen from the Annexes, with the different definitions of personal data and data subject in the Commission text of the GDPR and in the amended version of the Regulation adopted by the EP (and with the corresponding definitions in the current 1995 DP Directive), the definitions all say in essence that:

'personal data' means any information relating to a data subject (with ‘data subject’ then defined as “an identified or identifiable natural person”), or:
'personal data' means any information relating to an identified or identifiable natural person -
which comes to the same thing (and is in accordance with the current directive).

The EP text adds clarification on when a person can be regarded as “identifiable”, on the lines of the views of the Article 29 Working Party (drawing on a recital in the current directive); and more specific provisions on “pseudonymous data” and “encrypted data”.

However, neither text adds clarification on the question of when data can be said to “relate” to a (natural, living) persons – which is the issue so badly dealt with in the CJEU judgment.

I propose that the definition of “personal data” in the GDPR be expanded to expressly clarify the question of when data can be said to “relate” to a person, by drawing on the guidance of the Article 29 Working Party set out above; and by also expressly clarifying that “profiles” always “relate” to any person to whom they may be applied. Specifically, I propose that an additional paragraph be added to Article 2(2), spelling out that:

“data relate to a person if they are about that person, or about an object linked to that person; or if the data are used or are likely to be used for the purpose of evaluating that person, or to treat that person in a certain way or influence the status or behaviour of that person; or if the use of the data is likely to have an impact on that person's rights and interests. Profiles resulting from ‘profiling’ as defined in [Article 20 in the Commission text/Article 4(3a) of the EP text] by their nature relate to any person to whom they may be applied.”

The Annexes indicate more specifically how such an amendment could be incorporated into the current (Commission and EP) texts of the Regulation.


Annex I

PROPOSED AMENDMENTS TO ARTICLE 4 OF THE GENERAL DATA PROTECTION REGULATION:

(Added or amended text in bold)

The proposed amendments if applied to the Commission text:

(1)        'data subject' means an identified natural person or a natural person who can be identified, directly or indirectly, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;

(2)        'personal data' means any information relating to a data subject;

(2a)      data relate to a person if they are about that person, or about an object linked to that person; or if the data are used or are likely to be used for the purpose of evaluating that person, or to treat that person in a certain way or influence the status or behaviour of that person; or if the use of the data is likely to have an impact on that person's rights and interests. Profiles resulting from ‘profiling’ as defined in Article 20 by their nature relate to any person to whom they may be applied.

The proposed amendments if applied to the EP text:

(2)        'personal data' means any information relating to an identified or identifiable natural person ('data subject');

(2a)      an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, unique identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social or gender identity of that person;

(2b)     data relate to a person if they are about that person, or about an object linked to that person; or if the data are used or are likely to be used for the purpose of evaluating that person, or to treat that person in a certain way or influence the status or behaviour of that person; or if the use of the data is likely to have an impact on that person's rights and interests. Profiles resulting from ‘profiling’ as defined in paragraph (3a) by their nature relate to any person to whom they may be applied.

(2c) 'pseudonymous data' means personal data that cannot be attributed to a specific data subject without the use of additional information, as long as such additional information is kept separately and subject to technical and organisational measures to ensure non-attribution;

(2d)‘encrypted data’ means personal data, which through technological protection measures is rendered unintelligible to any person who is not authorised to access it;

NB: The actual Commission and EP texts are set out in Annex II


Annex II 

The definition of “personal data” in the original Commission text of the GDPR and in the amended version of the Regulation adopted by the European Parliament:

Text proposed by the Commission
Amendment
Definitions
Definitions
For the purposes of this Regulation:
For the purposes of this Regulation:
(1) 'data subject' means an identified natural person or a natural person who can be identified, directly or indirectly, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;

(2) 'personal data' means any information relating to a data subject;
(2) 'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, unique identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social or gender identity of that person;

(2a) 'pseudonymous data' means personal data that cannot be attributed to a specific data subject without the use of additional information, as long as such additional information is kept separately and subject to technical and organisational measures to ensure non-attribution;

(2b) ‘encrypted data’ means personal data, which through technological protection measures is rendered unintelligible to any person who is not authorised to access it;

Cf. the following definition in the current 1995 DP Directive:
(a) 'personal data 'shall mean any information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;

Thứ Sáu, 3 tháng 10, 2014

WARNING: THE EU COUNCIL IS TRYING TO UNDERMINE PRIVACY SEALS (and through this, the General Data Protection Regulation)


Douwe Korff, Professor of International Law, Associate of Oxford Martin School, University of Oxford, and Visiting Fellow, Yale University (Information Society Project). He helped to establish the European Privacy Seal (EuroPriSe) scheme discussed in the text.

I.                   Introduction

Some people, including myself, believe that good privacy seals, managed by the right bodies, can make a serious contribution to high-level data protection – while bad seals, issued by bodies that are more interested in providing fig-leaves and making money, can seriously harm data protection. The arrangements for data protection certification in the new General Data Protection Regulation (hereafter: “the regulation”) are therefore important. The original draft of the regulation, issued by the Commission in January 2012, merely said that certification schemes should be “encouraged” (although it provided for some EU-level harmonisation of the frameworks).

The European Parliament’s amended text is much more ambitious in this regard and, if adopted, would make certification schemes both more integrated with the general data protection regime and stronger, also in terms of ensuring that no seals could be issued in one Member State that would undermine data protection in other Member States.

However, the text set out in an EU Council document dated 26 September 2014 and just leaked, shows that the Member States are trying to undermine the good proposals of Parliament.

At II, I first briefly set out the problems with European privacy seal schemes under the current rules. Next, at III, I analyse the relevant provisions in the different versions of the regulation, adopted by the Commission, Parliament and the Council. Finally, at IV, I conclude that if the Council text were to be adopted, the provisions on seals could become a Trojan Horse that could seriously undermine the in principle strong data protection regime in the regulation (pace other watering-down attempts by the Council). This note thus seeks to sound a warning to those involved in the upcoming trilateral negotiations on the regulation text, not to allow such a dangerous scheme (or rather, an ill-defined miscellany of schemes) to slip in.

II.                Data protection seals and the 1995 Data Protection Directive

There is no explicit provision on data protection- or privacy seals or certification schemes in the main EC data protection directive (Directive 95/46/EC, hereafter “the directive”), although other self-regulatory mechanisms, such as codes of conduct and contractual arrangements are encouraged under it (see Art. 27 re codes; Art. 26(2) re “appropriate contractual clauses”). Nevertheless, the European Commission has in practice encouraged the establishment of seals, in particular by supporting the establishment of the “European Privacy Seal” (EuroPriSe) scheme under an “e-TEN” programme; this was until recently operated by the data protection authority of the German Land of Schleswig-Holstein, the Independent Centre for Privacy Protection (or ULD after its German initials), but has recently been passed on to a private German company, 2B.[1]The French data protection authority, CNIL, has also established a certification scheme, under which controllers can certify that they meet certain CNIL-specified criteria (but so far only in relation to privacy training, data protection audit, and one product: cloud computing).[2]

This is not the place to evaluate these, or other, existing data protection- or privacy certification/seal systems.[3]Suffice it to note that these schemes are limited in their potential by three factors in particular:

-                      because the directive is still implemented in greatly divergent ways in the Member States, a seal that certifies compliance with the standards set out in the directive (such as EuroPriSe) cannot guarantee that the certified product or service also complies with all the idiosyncracies of all the 30-odd national laws (some of which, in some respects, are not in accordance with the directive); while a seal that certifies compliance with one national law (such as the CNIL’s Labels) does not guarantee compliance with the other laws (or necessarily with the directive);

-                      the current European rules do not afford seal holders any significant commercial advantage, beyond demonstrating that a company is serious about its data protection compliance;[4]and

-                      serious seals (like EuroPriSe) are quite expensive in terms of costs of experts in particular, and highly demanding in time and effort on the part of the seal applicant.

Because of these factors, the uptake on the EuroPriSe and CNIL-seals has been very limited and, indeed, disappointing.[5]

In short: privacy seals/certification schemes have the potential to reduce regulatory and enforcement burdens on supervisory authorities, build consumer- and business-to-business trust and confidence through better information and greater transparency and reliable assurances from competent, respected bodies, and facilitate trade (e.g., by providing the kinds of safeguards and guarantees that the legal rules require in certain respects, but do not always spell out, e.g., as regards processors, data transfers, or cloud computing). However, to date that potential has not been realised.
III.              Data protection seals and the draft General Data Protection Regulation

The adoption of a regulation to replace the directive will ameliorate the first of the above-mentioned problems by its very nature: in stead of 30-odd still widely varying national laws transposing the directive in different ways and to different extents, there will now, at least in theory, be one set of directly applicable rules, set out in the regulation. However, the regulation is still replete with quite vague terms (“fair”, “adequate”, “necessary”, etc.), and many terms, including core definitions (such as “personal [=identifiable] data”), still require interpretation and can be applied in different ways in different contexts. It is therefore absolutely crucial, and commendable, that the regulation contains a mechanism to ensure close cooperation and mutual assistance between the national data protection authorities (and between them and the newly-to-be-created European Data Protection Board), and a “consistency mechanism” through which the DPAs and the Commission can object to interpretations and applications of the provisions in the regulation by other DPAs with which they disagree, ultimately resulting in a binding central ruling that must be adhered to by all.[6]In my opinion, the aim of the regulation – ensuring true and full real harmonisation – stands or falls with these mechanisms.

This ought to also apply to seals, if they are to have any real effect – a fortiori in relation to seals that might be granted to products or services that are offered (by European or non-European controllers) to European citizens and consumers: it should not be possible for a seal to be issued in one country for such a product, supposedly certifying that the product meets the requirements of the regulation, without the other countries (and  the other countries’ DPAs) agreeing that that certification is justified. Rather, data protection seals should either be issued at the European level, through a central European body (at least for products and services that are offered in more than one Member State, e.g., online), or seals that may be offered at the national level should be subject to the cooperation- and consistency mechanisms (again at least when they relate to products offered in several EU states or online).

However, the consistency mechanism in particular can only be invoked in relation to “measures” adopted by DPAs that have “legal effects” (Art. 58(2), initial sentence). As we shall see, this has important implications in relation to seals.

I will now discuss to what extent this is reflected in the different versions of the regulation.

Certification in the Commission text

As already noted, the European Commission published the text of the proposed General Data Protection Regulation (GDPR) in January 2012.[7]This text essentially merely requires the Member States and the Commission to “encourage, in particular at European level, the establishment of data protection certification mechanisms and of data protection seals and marks, allowing data subjects to quickly assess the level of data protection provided by controllers and processors.” (Art. 39(1) Commission text), although it also envisages the adoption, by the Commission, of “delegated acts” at some future time, “for the purpose of further specifying the criteria and requirements for [these] data protection certification mechanisms” (Art. 39(2)); and the issuing by the Commission of “technical standards for certification mechanisms and data protection seals and marks and mechanisms to promote and recognize certification mechanisms and data protection seals and marks” (Art. 39(3)).

The Commission text does not mention any specific, concrete, legally binding consequences of the awarding of seals: as under the current schemes, all they do under this text would be to provide some general assurance of compliance. Seals would not amount to a finding of compliance with any “legal effect”. The delegated acts and further specifications relating to seals, just mentioned, would, it would appear, not be able to create such effects.

The “encouragements” and arrangements envisaged in the Commission text thus fall considerable short of the sort of certification/seal schemes I mentioned earlier, that would be subject to cooperation and consistency mechanisms.

Certification in the EP text

The LIBE Commitee of the European Parliament agreed on an amended text in October 2013,[8]and this text was adopted in March this year by the Parliament as a whole.[9]The EP text significantly amends the proposal in respect of certification schemes, and strengthens the seals.

The amended version of the Regulation adopted by the European Parliament thus, first of all, stipulates that seals must be issued DPAs:[10]

Any controller or processor may request any supervisory authority in the Union, for a reasonable fee taking into account the administrative costs, to certify that the processing of personal data is performed in compliance with this Regulation, in particular with the principles set out in Article 5, 23 and 30, the obligations of the controller and the processor, and the data subject’s rights.

(Article 39(1a) in the Consolidated LIBE version of the Regulation, emphasis added)

This is not affected by the stipulation that the basic evaluations needed for the seals may be left to third-party accredited experts or “auditors” (Art. 39(1d) of the EP text): under the EP text, the seals will still have to be issued by the DPAs, i.e., the DPAs must at least double-check or certify the evaluation reports of the auditors (similar to the way in which the Schleswig-Holstein DPA, ULD, has until recently certified the European Privacy Seals). This is expressly reaffirmed in the final sentence of Article 39(1d):

The final certification shall be provided by the supervisory authority.

This is important because, secondly, under the EP text, seals would also have legal effects in some regards:

-                 a seal will be able to “demonstrate” that a processor offers “sufficient guarantees” in relation to the processing the processor is asked to undertake, to allow the controller to enlist the processor’s services in compliance with Article 26(1) (see Art. 26(3a) of the EP text);

-                 in relation of a data transfer to a country without adequate data protection, a seal that covers the relevant processing by both the controller (the EU-based data exporter) and the recipient (the data importer in the third country) will in itself provide “appropriate safeguards” in respect of the protection of the data; and processing covered by a seal would thus be allowed without further ado.

In other words, under the EP text, a processor who has been issued with a seal could not be held to be lacking in “sufficient guarantees” (at least in respect of the processing for which the seal was issued, if that did not cover the processor’s operations generally), as long as the processor complied with the conditions etc. provided for and assessed in the certification process; and transfers of data for which a seal has been issued could not be held to be in breach of the in-principle prohibition on transfers, now contained in Article 42 of the regulation (unless of course the parties failed to meet the conditions etc. provided for and assessed in the certification process). The seals envisaged in the EP text would thus clearly offer concrete legal benefits to seal-holders.

The EP text adds that:

The supervisory authorities and the European Data Protection Board shall cooperate under the consistency mechanism pursuant to Article 57 to guarantee a harmonised data protection certification mechanism including harmonised fees within the Union.”

(Article 39(1c) EP text);

and that

The Commission shall be empowered to adopt, after requesting an opinion of the European Data Protection Board and consulting with stakeholders, in particular industry and non-governmental organisations, delegated acts in accordance with Article 86 for the purpose of further specifying the criteria and requirements for the data protection certification mechanisms referred to in paragraph 1-1h, including requirements for accreditation of auditors, conditions for granting and withdrawal, and requirements for recognition within the Union and in third countries. These delegated acts shall confer enforceable rights on data subjects.

(Article 39(3) EP text)

However, as the wording of these provisions make clear, these harmonising measures relate only to the parameters and technical details of the certification scheme (similar to the stipulations in the Commission text, although the EP text rightly allows for better input from the EDPS and other stakeholders).

It is therefore important to note that under the EP text the actual issuing of a seal by a DPA would constitute an administrative act of such an authority: the issuing of seals is part of each DPA’s brief to implement and apply the Regulation within their jurisdiction (cf. Art. 53(1)(ia) of the EP text).

This in turn will mean that the cooperation- and consistency mechanisms set out in Chapter VII of the regulation will apply to the issuing of individual seals. The EP text indeed amends the provisions on these mechanisms and distinguishes between cooperation in individual cases (Arts. 54a, 55 and 56 EP text), consistency in matters of general application (Art. 58 EP text), and consistency in individual cases (Art. 58a EP text). This results in the following scheme:

-                 In deciding on whether to issue a seal in relation to processing by a controller who is established in more than one Member State, or who processes personal data on residents of more than one Member State – i.e., in relation to any cross-border operating company, including especially companies offering products and services throughout the EU (and beyond) over the Internet – there will be a need to first establish who is the “lead authority”; and next, that lead authority will be required to consult “all other competent supervisory authorities” on whether or not a seal should be issued (cf. Art. 54a(1) and (2) of the EP text). Those other authorities must then provide “mutual assistance” as required (Art. 55); and the DPAs may decide to deal with the matter through a “joint operation” (Art. 56);

-                 At the request of any DPA, the EDPB can issue an opinion on which DPA should be regarded as the lead authority; and in the end, the EDPB can decide the matter (Art. 54(3) and (3a) EP text);

-                 Moreover, since (as just shown) under the EP text seals will carry certain legal effects, in particular in relation to processors and data transfers, the issuing of a seal will constitute a “measure intended to produce legal effects within the meaning of Article 54a”. Consequently, in such cases – i.e., in casu, in relation to seals applied for by cross-border-operating companies and Internet-based companies – the “consistency mechanism” provided for in Article 58a of the EP text comes into play. Under this mechanism, the relevant lead authority must inform the other DPAs of the intended measure – i.e., of his intention to issue a seal for such a company – and the other DPAs can then refer the matter to the newly-to-be-created European Data Protection Board, if they have “serious objections” to the measure, i.e., to the seal being awarded to the company, service or product in question.

Clearly, the seals envisaged in the EP text are much more serious and carry much more weight than the largely unspecified ones that the Commission text “encourages”, in particular in relation to cross-border-operating and/or online companies (including non-EU companies): a seal issued under the EP text to such companies, either without objection from any other DPAs than the seal-issuing “lead authority”, or after having gone through the consistency mechanism and having been found to be in accordance with the regulation, clearly has strong legitimacy throughout the EU/EEA: it will truly demonstrate full compliance with the regulation, throught the EU/EEA, and it will have the stipulated legal effects throughout the EU/EEA.

The seals envisaged in the EP text thus address all the issues mentioned earlier that have to data hampered certification schemes:

-                 They would convincingly certify compliance with the fully harmonised rules in the regulation; and this would be accepted, or would have to be accepted, by all DPAs (either because they did not object to the seal being issued after having been notified of the intended awarding of the seal, or because the issuing of the seal was ruled to be in accordance with the regulation under the consistency mechanism);

-                 The seal would bestow clear and valuable legal and commercial benefits on the seal-holder; and

-                 This would warrant the costs and effort involved in obtaining the seal.

Moreover, I believe that such “heavy” seals, thus seriously embedded in the harmonised EU rules, would offer true assurances to citizens and business, and seriously positively contribute to ensuring data protection at a high level.

In my opinion, the EP text in this regard thus promises important benefits to business and consumers alike.

Certification in the Council text

On 26 September 2014, a Council document was produced by the Council data protection committee, DAPIX, that dealt with the chapter in the regulation dealing (inter alia) with certification schemes (Chapter IV).[11]This internal, restricted (“Limité) but quickly leaked document contains specific texts for the relevant provisions on seals in the regulation.

Essentially, they show that the Council wants to reject the EP proposals for a strong system of harmonised, consistent data protection seals with real effects, and to revert back to the vague promisses of “encouragement” in the Commission text – if anything watering the system down even further.

Thus, first of all, the Council text, like the Commission text, merely calls upon the Member States and the Commission to “encourage” the establishment of data protection certification schemes (while adding the EDPB to the addressees for this call) (Art. 39(1) Council text). The only difference is that Council text calls for this to be done “in particular at Union level”, where  the Commission text referred to “in particular at European level” (idem). Thus, the Council wants to remove the EP stipulation that DPAs must (“shall”) implement certification (cf. Art. 52(1)(ja) EP text).

Secondly, under the Council text seals may be issued eitherby a DPA or by another “certification body” approved by an official national accreditation body (such as the UK Accreditation Service, UKAS).[12]In other words, under the Council text, certification schemes could be essentially almost completely “out-sourced” to a body other than the national DPA, as long as the body was accredited (i.e., meeting appropriate organisational and management and financial requirements) and met any specific requirements laid down by the DPA (but the assessment of which would also be left to the accreditation body). Specifically, although the relevant DPA would be “provide[d] ... with the reasons for granting or withdrawing [a] requested certification” (Art. 39(5) Council text), in countries that opted for such an out-sourced scheme, the seal would be issued by the accredited certification body, and not by the DPA.

Not suprisingly, under such a scheme, the DPA would not in any way be bound by the assessment of the certification body that the assessed product or service meets the requirements of the regulation: see Article 39(2) Council text, which expressly stipulates that:

A certification ... is without prejudice to the tasks and powers of the [competent] supervisory authority.

There is a suggestion to the contrary in Article 39(1) of the Council text, where this says that

seals or marks may also be established for the purpose of demonstrating the existence of appropriate safeguards provided by controllers or processors that are not subject to this Regulation (emphasis added)

As we have seen, under the EP text, seals can indeed “demonstrate”, in a legally binding way, that certain requirements of the regulation are met.

However, under the Council text, seals would not have any such real effects. Rather, seals could just be taken into account in assessing compliance. As the Council text puts it explicity in relation to a variety of issues, in identical terms, “An approved certification mechanism pursuant to Article 39 may be used as an element to demonstrate compliance” with relevant requirements such as: compliance with a code of conduct (Art. 22(2b) Council text); compliance with privacy-by-design and –default requirements (Art. 23(2a)); with the requirement of processors to offer “sufficient guarantees” (Art. 26(2aa)); with data security requirements (Art. 30(2a)); and presumably with requirements relating to data transfers to countries without adequate protection (but the relevant provisions are not covered by the Council document).

The point to be made here is that allowing seals to be taken into account in this way, as an “element” in a wider assessment, means that the seals by themselves alone are not seen as “demonstrating” the matter in question. In other words, although they may have some legal weight, they do not in themselves have any “legal effects”.

For both reasons – the seals not being issued by a DPA, and the seals not having legal effects – the issuing of seals under the Council text would not constitute an administrative act with legal effects on the part of the DPA in countries that choose this option (as the UK in particular appears to want to do).

Consequently, the issuing of seals in such countries would not be subject to either the cooperation or the consistency mechanisms in the regulation. The DPAs would not have to inform other DPAs of the fact that they were asked to issue a seal in relation to a controller offering products or services also in other Member States (or online), or processing personal data on data subjects in other Member States; they would not have to consider whether they would be the appropriate (lead) authority to deal with such a request; they would not have to ask for, let alone heed, the views of other DPAs on the issuing of the seal; and they could not be made to deal with the proposed issuing of a seal to such a company under the consistency mechanism; the decision could not be overruled from Brussels.

Yet at the same time, in spite of such seals not having any formal standing, in practice the DPA in the country in question (who was after all informed of the reasons for granting the seal, by a body appointed by that DPA itself) would be unlikely to take enforcement action against a company with the seal, as long as the company adhered to the conditions etc. set out in the seal.

IV.             Conclusions

The above analyses of the different versions of the regulation shows two clearly opposed views of certification schemes. On the one hand, the European Parliament wants to introduce a strong certification scheme, operated by the DPAs within a harmonised EU framework. Seals would be given real, important legal effects, of real benefit to companies – but (in particular in respect of cross-border-operating or online companies, including non-EU ones) only if they were subject to close scrutiny by all the EU DPAs, and the EDPB, and if it were agreed between them, or decided under the consistency mechanism at the highest [Brussels] level that it was appropriate to issue the seal in the particular instance. Such seals would therefore also offer real assurances to consumers nd citizens.

By contrast, the Council would allow Member States to either opt for relatively strong seals issued by DPAs (such as the French Labels), orfor an almost completely out-sourced certification scheme under which seals would be issued by an accredited certification body separate from the DPA (and not subject to directions from the DPA, other than in terms of general guidance). The out-sourced seals would have no formal legal effect – but would also by-pass all European cooperation and consistency mechanisms. Yet they would still in practice largely exempt the companies that were awarded such seals from enforcement action by the DPA in question (as long as they complied with the conditions etc. set out in the seals).

In my opinion, a certification scheme allowing the latter kinds of seals would introduce a Trojan Horse into the new EU data protection regime. International companies, including the so-called “Internet giants” (Microsoft, Google, Yahoo, Facebook, Twitter, etc.) could – and almost certainly would, just as now – pick and choose to apply for seals in EU states in which they would hope to be given relatively lax treatment; where they feel they can relatively easily obtain a seal – from an out-sourced body. The DPAs in other countries would not be asked to give their views; they could not challenge the issuing of the seal (indeed, even the DPA in the country in question would only be informed of the issuing of the seal and the reasons for it). Yet they would then of course rely on the seal, or seals, they obtained to argue that their operations are fully compliant with the regulation. DPAs in other Member States, and the EU bodies concerned (including the Commission) would probably be less inclined to pursue such companies in such circumstances for non-compliance.

I would urge those who are going to be involved in the upcoming trilateral negotiations over the final text of the regulation and who take data protection to heart, to reject the Council text and support the EP one in respect of certification schemes.

That is not to say that some compromises are impossible. For instance, a Member State could still largely outsource a certification system to an accredited certification body (so as to avoid imposing further burdens on its DPA), yet retain the advantages of the EP scheme, if it left the final decision on each seal to its DPA, acting on the “recommendation” of the certification body. That way, it would still be the DPA that took the decision. If at the same time, such a seal would be given the effect of demonstrating compliance in certain contexts (rather than just being allowed to be an “element” in evidence), that would mean that the cooperation and consistency mechanisms would still come into play – which will ensure that appropriately high-level pan-EU scrutiny would be applied, in particular to cross-border and online companies. I hope this note will stimulate that debate.



[2]               See: http://www.cnil.fr/linstitution/labels-cnil/
[3]               A report of an EU-commissioned study into privacy seals (Service Contract Number: 258065) is due out shortly. This also discusses the myriad of other, generally more limited schemes in Europe, and the (generally weak) non-European schemes.
[4]               By contrast, the data protection law of the small German Land of Schleswig-Holstein expressly allows public authorities to give preferences to products and services which have been granted the local (Schleswig-Holstein) seal by the local data protection authority (ULD). ULD has issued more than 80 such local seals, including several to Microsoft, see: https://www.datenschutzzentrum.de/guetesiegel/register.htm
[5]               According to its 2012 annual report, CNIL had received 25 seal applications and had issued 10 seals (as at 15 February 2013; no later data available). EuroPriSe has issued 31 seals (not counting re-certifications) (last checked 01 October 2014).
[6]               See Chapter VII of the draft regulation.
[10]             Article 39(2a) adds that “The European Data Protection Board may on its own initiative certify that a data protection-enhancing technical standard is compliant with this Regulation.” But this only applies to “technical standards”, not to seals for products or services.
[11]             Presidency Note to COREPER, Brussels, 26 September 2014 (original: English), institutional file number 2012/0011(COD), document number 12312/3/14REV3 (hereafter referred to as the “Council text”),
The document also deals with important other issues addressed in Chapter Iv of the regulation, including data protection by design and default, joint controllers, data security, data breach notification, data protection impact assessments and prior consultation, in-house data protection officers, but these are not discussed here.
[12]             See: http://www.ukas.com/The Council text refers more specifically to “the National Accreditation Body named in accordance with Regulation (EC) 765/2008 of the European parliament and the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products in compliance with EN-ISO/IEC 17065/2012 and with the additional requirements established by [the DPA of the Member State in question].” (Art. 39a(1)(b) Council text).