Hiển thị các bài đăng có nhãn data protection supervisors. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn data protection supervisors. Hiển thị tất cả bài đăng

Thứ Tư, 11 tháng 3, 2015

When super-regulators fight: the ‘one-stop shop’ in the proposed Data Protection Regulation



Steve Peers

A guilty pleasure for fans of superhero comic books is the moment when our heroes pause in their valiant efforts to save the public from the nefarious plans of the supervillains – and start beating the hell out of each other instead. This is usually triggered by some trivial difference of opinion, perhaps concerning a continuity error or intellectual property rights.

Similarly, the EU vests its hopes for the effective enforcement of data protection law upon national data protection authorities (DPAs): the superheroes of the data protection world. They have considerable powers under the current data protection Directive, and the proposed Regulation would also give them more powers. But what if they disagree with each other? There’s nothing in the current legislation to settle this problem, which gives each DPA the power to regulate actions on its own territory without addressing the obvious complications that result in a digital age, when many forms of processing of personal data (most obviously via the Internet) take place across borders.  

To deal with this problem, the Commission proposal contains a conflict rule to determine who is the lead regulator in cross-border cases, with the possibility that a ‘European Data Protection Board’ or the Commission itself can issue an opinion on the issue. This has been dubbed the ‘one-stop shop’ rule. However, due to legal concerns, both the Council (which is about to adopt its position on this part of the proposed Regulation: see the draft text here), and the European Parliament (EP), which has already adopted its position on the entire text, propose instead that the Board must be able to make binding decisions to settle disputes.

So this is set to become one of the most significant innovations of the new legislation. Let’s take a look at what the future rules will likely say about the role of national DPAs, the one-stop-shop process and the powers of the Board.

National data protection authorities

The current Directive already provides for the existence of DPAs, and insists that they must exercise their powers in ‘complete independence’. CJEU case law (discussed here) has set out a very strong interpretation of this notion, ruling that Germany, Austria and Hungary breached it, because they provided for too much accountability to national parliaments (Germany), failed to separate the DPA from the ordinary civil service (Austria) and defenestrated the DPA boss before his normal term of office expired (Hungary).

The proposed Regulation would retain and elaborate upon this concept, and the Council and EP agree with most of the Commission’s suggestions. Admittedly, the DPAs have to be appointed by public authorities in the first place: after all, their powers don’t stem from being bitten by a radioactive spider, or orphaned in a bat-infested back alley. The Council would amend the proposal so that they don’t have to be appointed by the government or parliament, but could instead be appointed by the head of state or independent body. Only the last alternative would fully ensure their independence from the outset (although who appoints the ‘independent body’?)

Three points of concern here. First, the proposal would usefully require the national DPAs to be adequately funded. That is easier said than done, for most DPAs complain of an absence of sufficient funding. For instance, the Irish DPA occupies a small office next to a corner shop – but purports to regulate (among many other things) all of Facebook’s activities in the EU.  Secondly, the Council would remove the proposed rule requiring that DPAs be independent ‘beyond doubt’ when they are appointed; but DPAs should not be a resting ground for political hacks and bagmen. Thirdly, the Council would remove most of the details concerning the loss of office of DPAs, retaining only the minimum rule of four years in office. As the termination of the Hungarian DPA showed, it’s hard to exercise your powers independently if you constantly fear that there may be Kryptonite in your coffee.

As for the powers of the DPAs, the Regulation would strengthen and elaborate upon their current advisory and enforcement roles. In particular, the current powers to investigate, intervene and engage in legal proceedings would be fleshed out, by adding powers concerning audits, access to the premises of the controller and processor, ordering compliance with a data subject’s request, the suspension of data flows, or the imposition of fines.  

But with these great powers will come only limited accountability. DPAs will have to publish an annual public report (and the EP even wants to weaken this obligation). But that’s the only way that their decisions can be controlled, unless a cross-border complication means that other DPAs, or the European Data Protection Board (a sort of uber-DPA) gain jurisdiction, as discussed below. Otherwise, the only bodies which can watch these watchmen are the courts.

Settling disputes

Although the Commission is often accused of favouring over-centralisation in the EU, its proposed model for a ‘one-stop-shop’ was highly decentralised. Where a data processor or controller was established in the EU in more than one Member State, the supervisory authority of the ‘main establishment’ would have competence to regulate all that controller’s or processor’s activity in all Member States. There would be new rules on cooperation between supervisory authorities, in particular as regards mutual assistance (each DPA would usually have to comply with requests from another DPA) and joint operations.

In several cases, however, a DPA would have had to send a draft measure to the European Data Protection Board for its opinion. In particular, this would have applied to measures regulating processing concerning ‘offering of goods or services to data subjects in several Member States, or monitoring of their behaviour’, or which would ‘substantially affect’ the free movement of data. Following the Board’s opinion, the Commission could give its opinion, and then could ultimately adopt a binding measure if necessary. A decision of any supervisory authority is enforceable in all Member States, except where that DPA breaches the consultation rules, in which case its decision isn’t valid.

However, the Council and EP both agree to strip the Commission of all dispute settlement powers, and to confer binding powers on the Board instead. In the Council’s version, the DPA of the main establishment or single establishment of the controller or processor would not be the sole authority, but only the lead supervisory authority for transnational processing. Even then, each national supervisory authority would be competent to deal with an issue which only concerned an establishment in its State, or ‘substantially affects data subjects only in’ that State, unless the lead DPA decided to step in.

There’s a complex process for trying to reach a consensus on a decision between the lead DPA and the other DPAs involved. But in the event of a dispute between them, as regards the content of a draft decision, or who is the lead DPA in the first place, or where the procedures aren’t followed, then the European Data Protection Board can adopt a binding decision.  The Council would remove the rules on enforceability and unenforceability of DPA decisions, but the EP wants to strengthen them. In the event of disputes about the Board’s decisions, the preamble sets out detailed rules on whether litigation would take place before the national or EU courts.

The European Data Protection Board

It isn’t spelled out in the main text of the proposed Regulation, but the future Board is clearly a super-powered version of the current ‘Article 29 working party’, an advisory body which is (like the future Board) made up of members of the national DPAs. That working party can give opinions on national data protection law, data protection in the EU and third countries, the amendment of the Directive and codes of conduct. It has indeed issued many such opinions, which can be found on its website. They are interesting documents which fascinate data protection specialists, but which have not yet had any direct impact on the interpretation of the law by the CJEU. In the Commission’s proposal, the working party would be renamed and it would have more advisory powers, but its essential role would not change.

However, this puny body is about to be transformed at the behest of the Council and EP, which would both confer significant powers upon it as regards dispute settlement (discussed above), along with a longer list of advisory powers. The Council would also take the logical step of defining the Board as a ‘body’ of the EU, with express legal personality.

Finally, it should be noted that the future European Data Protection Boardshould not be confused with the current European Data Protection Supervisor (EDPS) – although I suspect that this warning will be in vain for many years to come. The EDPS is created by separate legislation, and has the role of enforcing data protection law against the EU’s institutions and other bodies, as well as advising on the development of EU data protection law. Its role in the new Regulation will be very limited. The Commission wants it to have a seat and a deputy chair post on the Board, but the Council rejects the first suggestion (relegating the EDPS to an observer role instead) and both the Council and the EP reject the second one. The EDPS will provide the Board’s secretariat, but the Council wants to build a firewall between the two administrations. In effect, while both the Board and the EDPS will have a significant role in the EU’s data protection architecture, there will be almost no crossover between them – rather like comic books produced by competing publishers.

Conclusion

It is certainly necessary for the EU to ensure that DPAs have effective powers to ensure the application of data protection law. Although it will still be possible for individuals to bring legal action directly against data processors or controllers (under other parts of the Regulation, which the Council has not yet agreed), DPAs remain the principal method of enforcing the rules. However, the draft legislation does not fully address the key practical question of sufficient ensuring resources for DPAs, and there is also not enough protection against dismissal or for the initial independence of DPA staff in the Council’s draft position.  

As for settlement of disputes, the Commission’s idea of a lead DPA having full jurisdiction was fairly attractive, although apparently it was torpedoed by the objections of the Council’s legal service. The replacement system is comparatively convoluted, and it has one key weakness – the absence of procedural rights for the original complainant before the Board. Also, it leaves intact greater possibilities of multiple DPAs acting as regards the same data processor or controller, with resulting greater complications for data subjects, DPAs and data processors and controllers alike. It will probably take some time (and possibly even litigation) before the new system will be working effectively. Furthermore, the Council’s removal of the rules about the unenforceability of DPA decisions which are taken in contravention of the rules could lead to complications in the event of rebellious DPAs. Finally, the existence of parallel bodies with similar names (the Board and the EDPS) may be unavoidable, but it unlikely to help public understanding of the EU’s data protection system.

Thứ Tư, 18 tháng 6, 2014

Europe v Facebook: the beginning of the end for NSA spying on EU citizens?




Steve Peers

Since the revelations about the extent of spying by the American National Security Agency (NSA) revealed by Edward Snowden, doubts have increased about the adequacy of the data protection regime in the United States, in particular as regards its impact on EU citizens, who are subject to the more favourable regime established by the Data Protection Directive. One aspect of these doubts concerns the ability of the NSA to examine the content of communications processed by social media companies based in the USA, such as Facebook.

Today’s decision by the Irish High Court to send questions in the ‘Europe v Facebook’ case to the CJEU raises the possibility that the NSA’s access to EU citizens’ personal data might soon come to an end. But it’s not clear if the CJEU will address the most essential issues directly, because the case raises a number of complex legal issues that need to be examined in more detail.

As a starting point, the basic legal regime governing transfers to Facebook is the ‘Safe Harbour’ system, which takes the form of a Commission Decision finding that all American companies certifying their participation in a system for complying with basic data protection principles maintain an ‘adequate’ level of data protection. This is one of the ‘adequacy decisions’ that the Commission can make pursuant to the rules on the data protection Directive on transfers of personal data outside the EU (see further my recent blog post on the planned reforms to this system). Despite the doubts arising from the Snowden revelations, the Commission’s most recent report on the Safe Harbour system did not suggest that the system should be 

Not everyone accepts these assertions, however. An Austrian citizen, Mr. Schrems, complained about the transfer of his personal data as a Facebook user pursuant to the Safe Harbour rules to the Irish data protection authority, which was competent in this matter because Facebook has a subsidiary in Ireland. The national authority argued that it could not take a decision on this complaint, because it was bound by the Commission’s decision. Moreover, it argued that the complaint was ‘frivolous’.

Mr. Schrems then challenged the authority’s decision before the Irish High Court. In its ruling today, the national judge therefore decided to send a question to the CJEU. Essentially, the question is whether the national data protection authority is bound by the Commission’s Decision, and whether that authority can conduct its own examination.

The first obvious question in this case is whether the American system infringes EU data protection law. Basing itself on the recent Digital Rights judgment of the CJEU, in which that Court ruled that the EU’s data retention Directive was invalid, the national court clearly believes that it does. While acknowledging the important anti-terrorist objectives of the law, the judge, when examining national constitutional law states that it is ‘very difficult’ to see how such mass surveillance ‘could pass any proportionality test or survive any constitutional scrutiny’. Indeed, such surveillance has ‘gloomy echoes’ of the mass surveillance carried out in ‘totalitarian states such as the [East Germany] of Ulbricht and Honeker’.

The judge equally believes that the US system is a violation of EU law, with no adequate or accessible safeguards available to EU citizens, and no consideration of EU law issues built in to the review process that does exist.

Is this analysis correct? There are two fundamental issues here which the national court doesn’t consider: the scope of the data protection directive, and the derogations from that Directive. On the question of scope, the CJEU previously found in its Passenger Name Records (PNR) judgment that the EU/US agreement which provided for the transfer of data from airlines to the US authorities was outside the scope of the data protection Directive, because it regulated essentially only the activities of law enforcement authorities, and the Directive does not apply to the ‘processing of personal data…in the course of an activity which falls outside the scope’ of EU law, such as…public security, defence, State security…and…criminal law’. On the other hand, the CJEU ruled that the data retention directive was correctly based on the EU’s internal market powers, since it essentially regulated the activity of private industry, albeit for public security objectives. While in this case, it might be argued that the Americanlaw in question falls within the first type of law, the Safe Harbour agreement clearly falls within the second. So it is a sort of hybrid question, but on balance the issue falls within the scope of the Directive, since the measure at issue is essentially the Safe Harbour agreement.

Secondly, the external transfer rules in the EU Directive do not refer expressly to the issue of derogations from data protection rights on public security grounds. Yet presumably some such derogations can exist, given that the Directive itself provides for public security derogations as regards the standard EU rules. Surely the security exceptions applied by third countries don’t have to be exactly the sameas those applied by the Directive. But some form of minimum standard must apply. For the reasons set out by the national judge, however, there is a strong argument that the US rules fall below the standard of anything which the EU can accept as ‘adequate’.  

Because the national judge takes these two issues for granted, there is no question sent to the CJEU on whether the American regime is either within the scope of the Directive, or violates the minimum standards of adequacy which the EU can accept as regards third states. But both these issues are absolutely essential in the debate over the post-Snowden relationship between the US and EU. It would therefore be desirable if the CJEU addressed them nonetheless.

Next, another problematic issue here is which set of EU data protection rules should apply: the external transfer rules, or the more stringent standard rules? The national court, along with the data protection authority, applies the external transfer rules, given Facebook’s certification under the Safe Harbour system. However, it is doubtful whether this is correct.

As is well known, in the recent Google Spain judgment, the CJEU ruled that the standard rules applied to Google’s search engine function, given that it had an ‘establishment’ in Spain, according to the Court’s interpretation of the rules. As I then argued on this blog, it probably follows from that judgment that the standard rules apply at least to some social networks like Facebook. In any event, the issue will arise again when the revised jurisdiction and external transfer rules, mentioned above, apply.  However, the complainant and the national court assume that the external transfer rules apply. Perhaps the CJEU should also examine this issue of its own motion.

Another problematic issue is the question of how to challenge the inadequacy of data protection in practice in the US, which is the subject of the only question sent to the CJEU. The Safe Harbour agreement addresses this point directly, since it allows national data protection authorities to suspend data transfers as regards an individual company, in accordance with existing national law, if either the US government or the US enforcement system has found a violation of that agreement, or if:

there is a substantial likelihood that the Principles are being violated; there is a reasonable basis for believing that the enforcement mechanism concerned is not taking or will not take adequate and timely steps to settle the case at issue; the continuing transfer would create an imminent risk of grave harm to data subjects; and the competent authorities in the Member State have made reasonable efforts under the circumstances to provide the organisation with notice and an opportunity to respond.

However, Irish national law does not provide for such a system, but simply sets out an irrebutable presumption that the Commission’s adequacy decision is sufficient. This rule may well have played a part in convincing Facebook and the subsidiaries of other US companies to set up in Ireland in the first place.
The challenge argued that the national data protection authority nevertheless had to exercise such powers, and so the national judge asked only whether this was possible. Logically, there can be only one answer, by extension from the NS judgment: Member States cannot create an irrebutable presumption that prevents the exercise of Charter rights, so the national data protection authority must have the powers in question.

In the alternative, or arguably additionally, it must be possible to challenge the validity of the Commission’s adequacy decision in the national courts, which would then have an obligation, if they thought that challenge was well-founded, to send questions on that point to the CJEU. (See the Foto-Frost judgment).

The next problematic issue is the role of the national constitutional protection for human rights. Clearly the national judge believes that the American system breaches the protection for the right to privacy guaranteed in the Irish constitution. Nevertheless, the national court proceeds to examine the issue primarily from the perspective of EU law. So if the CJEU rules against the challenge to the American law on the merits, or does not address those merits for procedural reasons, should the national court proceed to apply Irish law?

In principle, national constitutional law cannot apply here, since EU law, as the national court recognises, has extensively harmonised this issue. This means that, according to the Melloni judgment of the CJEU, only the EU’s human rights standards, in the form of the Charter, can apply. National constitutional standards cannot. But national courts in Ireland (and elsewhere) might be unwilling to accept that outcome.

National law would only apply if the CJEU rules that this issue falls entirely outside the scopeof the Directive, as discussed above. If, on the other hand, the processing falls within a public security derogationfrom the Directive, the EU Charter would apply, by analogy with the CJEU’s recent judgment in Pfleger (discussed here), in which it ruled that the Charter applies to national derogations from EU free movement law. This parallels the argument (discussed here) that national data retention law falls within the scope of EU law, following the Digital Rights judgment, because it is a derogation from the EU’s e-privacy Directive.

Finally, the consequences of any future finding by the national data protection authority that transfers under the Safe Harbour decision must be suspended as regards Facebook must be considered. Assuming that the US had not changed its law in the meantime, Facebook would have a dilemma: should it comply with its US legal obligations, or face the suspension of transfers of data from Europe? Possibly it could avoid this dilemma by ensuring that it only processed EU residents’ data within the EU, potentially avoiding the scope of US law. But this might be expensive, and in any event the US might seek to extend the scope of its law to cover such cases. These issues would inevitably arise for other major US companies as well.

Any real prospect that Facebook transfers from the EU might be blocked would cause a major earthquake in EU/US relations, making the concerns about the recent Google Spainjudgment look like a minor tremor. It may be that the only solution is for the US to take more seriously its ongoing discussions with the EU on data protection issues, with a view to reaching a solution that reconciles its security concerns with the basic principles of privacy protection.



Barnard & Peers: chapter 9 

Thứ Ba, 13 tháng 5, 2014

The CJEU's Google Spain judgment: failing to balance privacy and freedom of expression



By Steve Peers

The EU’s data protection Directive was adopted in 1995, when the Internet was in its infancy, and most or all Internet household names did not exist. In particular, the first version of the code for Google search engines was first written the following year, and the company was officially founded in September 1998 – shortly before Member States’ deadline to implement the Directive.

Yet, pending the completion of negotiations for a controversial revision of the Directive proposed by the Commission, this legislation remains applicable to the Internet as it has developed since. Many years of controversy as to whether (and if so, how) the Directive applies to key elements of the Web, such as social networks, search engines and cookies have culminated today in the CJEU’s judgment in GoogleSpain, which concerns search engines.

The background to the case, as further explained by Lorna Woods, concerns a Spanish citizen who no longer wanted an old newspaper report on his financial history (concerning social security debts) to be available via Google. Of course, the mere fact that he has brought this legal challenge likely means that that the details of his financial history will become known even more widely – much as many thousands of EU law students have memorised the name of Mr. Stauder, who similarly brought a legal challenge with a view to keeping his financial difficulties private, resulting in the first CJEU judgment on the role of human rights in EU law.

The Court’s judgment

The CJEU addressed four key issues in its judgment: (a) the material scope of the Directive, ie whether it applies to search engines; (b) the territorial scope of the Directive, ie whether it applies to Google Spain, given that the parent company is based in Silicon Valley; (c) the responsibility of search engine operators; and (d) the concept of the ‘right to be forgotten’, ie the right of an individual to insist (in this case) that his or her history be removed from accessibility via a search engine. The details of the Court’s ruling have been summarised by Lorna Woods, but I will repeat some key points here in order to put the following analysis into context.  

Material scope

Does the Directive apply to search engines? The CJEU said yes.  The information at issue was undoubtedly ‘personal data’, and placing it on a website was ‘processing’. A search engine was processing personal data, even though it originated from third parties, because (using the definition in the Directive) it ‘collects’ data from the Internet, then ‘retrieves’, ‘stores’ and ‘discloses’ it. It was irrelevant that the material had been published elsewhere and not altered by Google, as the CJEU had already ruled in the Satamedia case (in the context of tax information published on CD-ROM). Moreover the definition of ‘processing’ does not require that the data be altered.

A second – and perhaps more important point – was whether Google was a ‘controller’ of the data, with the result that it has liability for the data processing.  Again the key issue was Google’s use of data already published elsewhere. The Advocate-General had concluded from this that Google was not a data controller – but the CJEU reached the opposite conclusion. On this point, the Court, ruling that there must be a ‘broad definition of the concept’ of a ‘controller’, distinguished between the original publication of the data and its processing by a search engine: Google undoubtedly controlled the latter activity, by means of its control over the search process. One is unavoidably reminded of the Machiavellian search-engine billionaire who frequently appears on episodes of The Good Wife – although of course he is nothing like the executives of Google.

In particular, the Court ruled that the activities of search engines make information available to people who would not have found it on the original web page, and provides a ‘detailed profile of the data subject’, and so have a much greater impact on the right to privacy than the original website publication.

Territorial scope

Does the Directive apply to search engine companies based in California, with a subsidiary in Spain? The national court suggested three grounds on which this might be the case: the ‘establishment’ in the territory; the ‘use of equipment’ in the territory (as regards crawlers or robots, the possible storage of data and the use of domain names); or the default application of the EU Charter of Fundamental Rights.

The Court found that Google Spain was ‘established’ in the territory, and therefore the data protection Directive, in the form implemented by Spain, applied. It was not necessary to rule on the other possibilities as regards the scope of the Directive, which are very significant in the context of the Internet, so those issues remain open. It should be noted, however, that in light of the objectives of the Directive, the rules on its scope ‘cannot be interpreted restrictively’, and that it had ‘a particularly broad territorial scope’.

Why was Google Spain established there, even though it did not carry out any search engine activities? The CJEU said that it was sufficient that the company carried out advertisingactivities, these being linked to the well-known business model of Google (selling advertising which was relevant to search engine results).

Responsibility of search engine operators

The CJEU ruled that search engine operators are responsible, distinct from the original web page publishers, for removing information on data subjects from search engine results, even where the publication on the original pages might be lawful. It confirmed that the right to demand rectification, erasure or blocking of data did not apply only where the data was inaccurate or inaccurate, but also where the processing was unlawful for any other reason, including non-compliance with any other ground in the Directive relating to data quality or criteria for data processing, or in the context of the right to object to data processing on ‘compelling legitimate grounds’.

This meant that data subjects could request that search engines delete personal data from their search results, and complain to the courts or data protection supervisory authorities if they refused.  As for Article 7(f) of the Directive, which provides that one ground for processing data (where there was no contract, legal obligation, public interest requirement or consent by the data subject) was the ‘legitimate interests of the controller’, this was a case where (as Article 7(f) provides) those interests were ‘overridden’ by the rights of the data subject.

There has to be a balancing of rights in such cases – including the public right to freedom of expression – but in light of the ease of obtaining information on data subjects, and the ‘ubiquitous’ nature of the ‘detailed profile’ that results from search engine results, the huge impact on the right to privacy ‘cannot be justified by merely the economic interest’ of the search engine operator. The public interest in the information was only relevant where the data subject played a role in public life.

In light of the greater impact of search engine results on the right to privacy, search engines are not only subject to a separate application of the balancing test, but a more stringent application of that test – meaning that the information might remain available on the original website, even if it was blocked from the search engine results. The CJEU states that search engines cannot rely on the ‘journalistic’ exception from the Directive.

The ‘right to be forgotten’

Finally, the CJEU accepts the arguments that the Directive’s requirements that personal data must be retained for limited periods, only for as long as it is relevant, amounts to a form of ‘right to be forgotten’ (although the Court does not say that such a right exists as such). While it leaves it to the national court to apply such a right to the facts of this case, the Court clearly guides the national court to the conclusion that the data subject’s rights have been violated.

Comments

The essential problem with this judgment is that the CJEU concerns itself so much with enforcing the right to privacy, that it forgot that other rights are also applicable.

As regards the right to privacy, the Court’s analysis is convincing. Of course, information on a named person’s financial affairs is ‘personal data’, and it has long been established that prior publication is irrelevant in this regard – a particularly important point for search engines. Equally, the Court had previously ruled (convincingly) in the Lindqvist judgment that placing data online is a form of ‘data processing’. 

While it is less obvious that Google is a ‘data controller’, given that it does not control the original publication of the data, the Court’s conclusion that search engines are data controllers is ultimately convincing, given the additional processing that results from the use of a search engine, along with the enormous added value that a search engine brings for anyone who seeks to find that data. In this sense, Google is a victim of its own success.

Similarly, as regards the territorial scope of the Directive, it would be remarkable if Google, having established a subsidiary and domain name in Spain and sought to sell advertising there, would not be regarded as being ‘established’ in that country. The sale of advertising in connection with free searches is, of course, the key element of Google’s business model (leaving aside the many other companies, such as YouTube and Blogger, that Google has acquired over the years), and making money is surely one of the ‘activities’ of any business that aims to make profits.

The separate liability of Google as a ‘data controller’ obviously justifies the Court’s conclusion that it might, in appropriate cases, be required to take down material from its search engine results that infringes the data protection directive. This is most obviously relevant where that data is inaccurate or libellous, but that is not the case here, where the personal data is simply embarrassing.

So, in the absence of another legitimate ground for processing (which will normally be the case as regards search engines), the case ultimately turns on the balancing of interests between the data subject, the search engine and other Internet users. And here is where the Court’s reasoning goes awry.

In its previous judgment in ASNEF, the Court ruled that Spanish law failed to apply the correct balance between data subjects and direct marketing companies, because by banning any use of personal data which was not already public, it implicitly did not give enough weight to the company’s right to carry on a business. But here the Court makes no reference to that right, even though Google’s methods are as central to its business model as the use of private personal data is for direct marketers. Indeed, Google’s highly targeted advertising (not as such an issue in this case) is itself obviously a form of direct marketing.

Also in ASNEF, the Court criticised the Spanish law for its automaticity, because it failed to weigh up the interests of companies and data subjects in individual cases. But in Google Spain, it is the Court which sets out an automatic test: the economic interest of the search engine is overridden if the individual is not a public figure.

The interests of other Internet users are only briefly mentioned, even though Article 7(f) requires only a balancing of interests between not only as between the data controller (ie, the search engine in this case) and the data subject, but also as regards third parties to whom the data are disclosed, ie the general public. Oddly, the Court does not expressly refer to the Charter right to freedom of expression (it’s in Article 11 of the Charter), and does not expressly link its statements about the balancing test to the case law of the European Court of Human Rights on the best way to balance privacy and freedom of expression.

Furthermore, unlike in ASNEF, the Court makes no mention of Article 52 of the Charter (the provision dealing with limitation of Charter rights, including in the interest of protecting other rights, which also requires consistent interpretation with the ECHR). It should also be noted that, in deciding the key freedom of expression issue itself, the Court has departed from its prior approach (in Satamedia and Lindqvist, for instance) of leaving it to the national courts to decide on this issue.

The Court’s dismissal of the journalistic exception also contradicts its willingness to agree, in Satamedia, that merely sending personal tax data by text message to nosy neighbours could constitute ‘journalism’. Here, of course, it is not Google which is the journalist; but Google is a crucial intermediaryfor journalists. If journalism can consist of sending out tax information by text message, it could also equally consist of commenting (for whatever reason, and in whatever forum) on an individual’s past financial problems. And there is no reason why the passage of time should count against the exercise of the right of freedom of expression – although that factor should be relevant, as the Court says, as regards the right to privacy.

Consequences of the judgment

Obviously, today’s judgment only concerns search engines, but it may have broader relevance than that.  Its relevance to social networks will soon be considered in another post on this blog. For search engines, those which are less successful than Google might not have an ‘establishment’ within the meaning of this judgment, which raises the question of whether they would otherwise have an establishment, use equipment on the territory, or can be covered due to the Charter.

More broadly, any non-EU company with a subsidiary selling advertising in an EU Member State in connection with its Internet services must obviously be regarded as covered by the data protection Directive by analogy with this judgment, without prejudice to those broader possibilities.

As for those search engines which do fall within the scope of the judgment, most obviously Google, it seems that their legal obligations are considerably greater than what they had thought them to be. They must respond to individual complaints that the personal data which can be found about that individual is simply too old to be relevant any more, whether it is accurate or not, and they can be challenged before the courts or a supervisory authority if they do not comply.  In fact, an individual could also take action to this end before a supervisory authority.

Could a supervisory authority act of its own motion to enforce this judgment? Probably not, because the rights at issue in this case are triggered by individual complaints. Some people assiduously search Google to see what results they can find on themselves; in this context, I should point out that I am not the same ‘Steve Peers’ from Essex who has been convicted for non-payment of council tax. But others are unaware of, or don’t care about, or couldn’t be bothered to challenge, or are positively thrilled about, the existence of old information about them which can be found by means of using Google.

So not everyone who might conceivably be embarrassed by such old information will complain to Google, but a considerable number are likely to do so. Google’s liability extends to responding to such individuals, but not to completely changing the way it processes personal data in the absence of such complaints. 

Interesting questions may arise, however, as regards the interpretation of the rules set out in the judgment: what exactly is a public figure, and how long has to pass before personal data is no longer relevant? For instance, a job applicant can certainly object to Google if its search results include pictures of her dancing drunkenly on a table in 1998. But she could hardly argue that a record of last night’s debauchery must be 'forgotten'  already - even if she cannot remember it herself. 

Such disputes may well prove an opportunity to argue that the remit of this judgment is narrower than it first appears, or even to request (which any national court can do) that the Court reverse at least some aspects of its judgment. For now, however, the CJEU has established a potentially far-reaching right to be forgotten, with possible significant impacts at least on the activity of search engines. While in the Lindqvist judgment, the Court was keen to ensure that the data protection Directive was adapted to the reality of the Internet, in Google Spain it seems to demand that the Internet should rather be adapted to the Directive. 

As for the initiative to amend the Directive (to be replaced by a general data protection Regulation), this judgment might speed that process up, since Internet companies now have an incentive to use the process as an opportunity to limit their liability compared to what it would otherwise be - rather than (before the judgment) an interest in slowing the process down, in order to avoid an increase in that liability. Time will tell what the result of that negotiation will be.


Barnard & Peers: chapter 9

Thứ Tư, 9 tháng 4, 2014

The CJEU confirms the independence of data protection authorities



Steve Peers

Yesterday’s second judgment on data protection is not quite as important as the first, but is very interesting nonetheless. In Commission v Hungary, the CJEU built upon its prior rulings in Commission v Germany and Commission v Austria, as regards the independence of data protection authorities. But implicitly the judgment has rather broader resonance than that.

Background

The EU’s data protection Directive requires data protection authorities to be set up to enforce the rules in the Directive, alongside the possibility of individual court actions. Since the Directive applies to the public and private sectors, and the data protection authorities form part of the public sector, there is an implicit risk that the authorities might be reluctant to challenge the government or the governing parties’ private sector allies, or could otherwise be ‘captured’ by the sectors of industry most impacted by data protection law. To avoid this possibility, the Directive requires Member States to ensure that data protection authorities act ‘with complete independence’.

In Commission v Germany, the CJEU ruled that Germany infringed this rule by providing for too much parliamentary accountability for the data protection authorities. In Commission v Austria, the Member State concerned had breached the law because the data protection authority formally was part of the civil service, giving rise to a possible appearance of partiality.

The judgment

The latest judgment concerned a different issue. Hungary had replaced the individual data protection supervisor with a supervisory board, and had cut short the term of the supervisor when the new board was set up.

In the Court’s view, Hungary had infringed the Directive. As in the Austrian case, the national rules could lead to a situation of ‘prior compliance’ with the government’s wishes (or what might often be called ‘self-censorship’). Here that would result from the threat of early termination of the supervisor’s (or now the supervisory board’s) term.

So, while Member States are free to have different rules on the composition of national data protection authorities, and free to change those rules, any significant changes had to provide for transitional periods to avoid compromising the independence of those authorities.

Comments

The Court’s judgment is unsurprising, in light of its prior case-law. The prospect of early termination of a term of office of a 'independent' supervisor is bound to give rise to the appearance of partiality, if not actual self-censorship. The supervisor concerned might even have doubts about the government's willingness to employ him or her in another job after the termination of the term of office. A government could even put pressure on the private sector not to hire that individual. In any event, the private sector may judge that it is unwise to hire a person who appears not to be in the government's favour.

More broadly, the judgment should also be seen as part of a broader concern about the rule of law in Hungary. This judgment is just one of several actions which the Commission brought, or threatened to bring, due to concerns about possible interference with the central bank, the judiciary and the data protection authorities in that state.

Previously, the Hungarian rules on retirement of judges – which would have entailed a big reduction in the retirement age for current judges, followed by a later retirement age for their replacements – were criticised by the Court of Justice, on the grounds that this would breach the EU’s framework equality Directive as regards age discrimination. The apparent intent to ‘pack the courts’ via this route was not discussed as such by the CJEU, although the Court’s judges were surely aware of it.

Moreover, the Commission had begun proceedings regarding the independence of the Hungarian central bank, and dropped them due to changes in Hungarian legislation. It had also threatened to bring separate proceedings relating to the independence of the judiciary generally, due to the risk that EU law cannot be properly applied unless judges are impartial. While that argument is sound in principle (whether it is true of Hungary is a separate question), ultimately the Commission decided that a non-judicial approach was better suited to dealing with such situations, and released its recent communication on the rule of law in the EU instead.

It seems as though the CJEU is also determined to follow a cautious path politically. Neither yesterday’s judgment nor the earlier judgment on judicial retirement makes any reference to the broader context. Furthermore, it hardly seems coincidental that yesterday’s judgment came after, not before, last weekend’s election, which saw the current government returned to power. A judgment like this one shows both the strengths and the weaknesses of EU law when fundamental questions like these are raised. 


Barnard & Peers: chapter 9