Saturday, 25 June 2022

The Proposed Data Reform Bill


 








Jane Lambert

In my article Consultation on Changing the Data Protection Laws (12 Sept 2021), I discussed the consultation on changing the data protection laws. According to the consultation outcome, Data: a new direction - government response to consultation of 23 June 2022, the government received 2,924 responses, 684 by email and 2,240 via a survey platform. It also attended over 40 round tables with academia, tech and industry bodies, and consumer rights groups.  The consultation outcome lists the organizations in Annex B, summarized the responses in the consultation outcome and set out the government's legislative intentions in the light of the responses on each issue in Annex A.

In a recent press release, the Department for Digital, Culture, Media and Sport outlined a new Data Reform Bill.  That Bill is intended to reduce the administrative burden on businesses in order to encourage more innovative uses of personal data for research, facilitate trade and save businesses up to £10 billion over the next 10 years. An example given by the press release is that an independent pharmacist will no longer have to recruit an independent data protection officer to comply with the data protection legislation provided that it can manage risks effectively.  The Bill will also increase penalties for nuisance calls and other serious breaches of the Privacy and Electronic Communications (EC Directive) Regulations 2003 and reorganize the Information Commissioner's Office. 

The proposals have been welcomed by John Edwards, the recently appointed Information Commissioner, in a Statement in response to the government’s announcement on the upcoming Data Reform Bill which was published on 16 June 2022.   His predecessor contributed to the consultation (see Response to DCMSconsultation “Data: anew direction” 6 Oct 2021).

I shall return to this topic once the bill is published.  Anyone wishing to discuss this article or its subject matter may call me on 020 7404 5252 during office hours or send me a message through my contact form.

Sunday, 13 February 2022

Privacy and Electronic Communications - Leave.EU Group Ltd v The Information Commissioner

EU-Austritt (47521165961).svg
Author Mrmw Public Domain CCO 1.0









Jane Lambert

Court of Appeal (Sir Geoffrey Vos, Master of the Rolls, Lord Justice Lewison and Lady Justice Asplin) Leave.EU Group Ltd & Anor v The Information Commissioner [2022] EWCA Civ 109 (8 Feb 2022)

On 1 Feb 2020, the Information Commissioner issued a monetary penalty notice for £45,000 against Leave.EU Group Ltd. under s.55A of the Data Protection Act 1998 and an assessment notice under s.146 of the Data Protection Act 2018.  She issued those notices because Leave.EU Group Ltd. had sent email newsletters to some of its supporters that contained unsolicited marketing material relating to Eldon Insurance Services Ltd.   It appears that Eldon Insurance Services Ltd is now known as Somerset Bridge Insurance Services Ltd.

Leave.EU and Eldon appealed unsuccessfully to the First-Tier Tribunal (General Regulatory Chamber) (see Leave.EU Group Limited Eldon Insurance Services Limited v The Information Commissioner 2020 WL 01140646). They appealed to the Upper Tribunal which upheld the First-Tier Tribunal (see Leave.EU Group Limited and another v The Information Commissioner [2021] UKUT 26 (AAC)).  With the Upper Tribunal's permission, they appealed to the Court of Appeal.  On 1 Feb 2022, when the appeal was due to be heard, the Information Commissioner's legal representatives turned up at court but there was nobody from Leave.EU.

The Court asked the Information Commissioner's counsel what they should do. He replied that the Court could either dismiss the appeal for non-prosecution or decide the appeal on the Commissioner's oral and written submissions and Leave.EU's skeleton argument. The Commissioner was neutral as to the course that the Court should adopt but her counsel emphasized the importance of the issues under appeal. The Court decided (i) that it would not be just or appropriate to hear the substantive appeal in the absence of Leave.EU, (ii) that the Court was satisfied that Leave.EU was aware of the appeal hearing and had decided not to attend, and (iii) the appeal should be dismissed and that it would give its reasons in writing later.

The Information Commissioner and the tribunals below had found that Leave.EU and Eldon had contravened art 13 (1) of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) OJ L 201, 31.7.2002, p. 37–47. Leave.EU has appealed on the following grounds:
"First it contended that paragraph 22 did not prohibit the inclusion of any direct marketing information in an email which was otherwise solicited and not sent for direct marketing purposes, such as the political newsletters in this case. Secondly, Leave.EU contended that the FTT was wrong to hold that the subscribers had not freely consented to receive marketing information from Eldon, since they had consented to receive such material as Leave.EU felt might interest its subscribers. Thirdly, Leave.EU contended that the Information Commissioner ought to be regarded as having been required to give reasons for her decision, despite the absence of a statutory requirement to do so."

In its reasoned judgment which was delivered on 8 Feb 2022, The Master of the Rolls described those issues as "important and in some respects novel" at para [19]. He was satisfied that the Court had power to hear the appeal in the absence of the appellant under CPR 52.20 and rule 38 of the Tribunal Procedure (Upper Tribunal) Rules 2008 as well as its inherent jurisdiction but thought it undesirable in the circumstances of this case to try to decide such important questions at the level of the Court of Appeal without full oral argument.

Lord Justice Lewison and Lady Justice Asplin agreed.

According to the Commissioner's counsel, Eldon had been sold to a third party on 31 Jan 2022 who had consented to judgment and reached an agreement with the Commissioner (see her Statement on an agreement reached between Somerset Bridge Insurance Services Limited and the ICO of 1 Feb 2022). The solicitors who had acted for both appellants had applied to come off the record a few days earlier. The Court had tried to communicate with Leave.EU's sole director but he did not respond to its approaches.

The failure of Leave.EU to take any steps in the appeal in the days leading up to the hearing is regrettable.  As Sir Geoffrey Vos noted at [19] an appropriately qualified panel of the Court of Appeal had been ready to hear this case for many months.  The issues upon which the Court had been asked to decide are likely to concern other parties and cases of this kind do not come before the Court of Appeal often. 

Anyone wishing to discuss this article or the procedural or standard issues may call me on 020 7404 5252 during normal business hours or send me a message through my contact form.

Tuesday, 11 January 2022

Information Rights - Driver v Information Commissioner

Ramsgate Sands in 1854
Artist William Frith 

 













First Tier Tribunal (General Regulatory Chamber) (Upper Tribunal Judge Rintoul, J Randall and Raz Edwards) Driver v Information Commissioner and another [2021] UKFTT 2017-0218 (GRC)

In his preface to the white paper Your Right to Know (Cm 3818), the then Prime Minister, Tony Blair, introduced his government's proposals for a Freedom of Information Bill as one of several important constitutional reforms.  Others included the Human Rights Bill,  devolution statutes for Scotland and Wales and the Data Protection Act 1998.  The government's intention was to redefine its relationship with the governed.

S.1 (1) of the Freedom of Information Act 2000 states that:
"Any person making a request for information to a public authority is entitled—
(a) to be informed in writing by the public authority whether it holds information of the description specified in the request, and
(b) if that is the case, to have that information communicated to him."

However, those rights are subject to several exceptions pursuant to s.1 (2) and s.2 (1), (2) and (3) (g) of the Act. One of those exceptions is s.41:

"(1) Information is exempt information if—
(a) it was obtained by the public authority from any other person (including another public authority), and
(b) the disclosure of the information to the public (otherwise than under this Act) by the public authority holding it would constitute a breach of confidence actionable by that or any other person.
(2)  The duty to confirm or deny does not arise if, or to the extent that, the confirmation or denial that would have to be given to comply with section 1 (1) (a) would (apart from this Act) constitute an actionable breach of confidence."
In Higher Education Funding Council for England v Information Commissioner and another (unreported, 13 Jan 2010). the Information Tribunal held that a public authority seeking to rely on that exception would have to show that the disclosure would be likely to give rise to a successful action for breach of confidence:
“Our conclusion on this part of the case, therefore, is that the HEFCE must establish that disclosure would expose it to the risk of a breach of confidence claim which, on a balance of probabilities, would succeed. This includes considering whether the public authority would have a defence to the claim.  Establishing that such a claim would be arguable is not sufficient to bring the exemption into play.”

An example of such a claim was  Driver v Information Commissioner and another   [2021] UKFTT 2017_0218 (GRC).

The information in question was the identity of certain claimants and the amounts paid to each of them in an out of court settlement with a local authority that had banned the transport of live animals through its port in contravention of EU law.  Those claimants had successfully challenged the ban in the Chancery Division on the grounds that it breached art 35 of the Treaty on the Functioning of the European Union.  They subsequently claimed damages for losses occasioned by the ban.  

 A local resident who had opposed live animal exports asked the authority for the above information under s.1 (1) of the Freedom of Information Act 2000. The authority declined on the ground that disclosure of that information would be an actionable breach of confidence. The resident asked the Information Commissioner to intervene.  The Commissioner sided with the local authority.  The resident appealed successfully against the Commissioner's decision to the General Regulatory Tribunal.  The Tribunal held that s.41 did not apply because the withheld information had not been obtained by the local authority (see Driver v Information Commissioner and another [2017] UKFTT 2017_0040 (GRC)).  The Information Commissioner appealed to the Upper Tribunal which allowed the appeal and remitted the case to a differently constituted first instance tribunal (see Information Commissioner v Driver and another [2020] UKUT 333 (AAC)). The Upper Tribunal directed the new tribunal to proceed on the basis that the threshold condition in s.41 (1) (a) of the Act had been satisfied.  That is to say, the claimants’ names constituted information obtained by the public authority from another person.

In the remitted proceedings the tribunal took as its starting point the following passage from the judgment of Mr Justice Megarry (as he then was) in Coco v A N Clark (Engineers) Ltd [1968] FSR 415:

"In my judgment, three elements are normally required if, apart from contract, a case of breach of confidence is to succeed. First, the information itself, in the words of Lord Greene, M.R. in the Saltman case on page 215, must “have the necessary quality of confidence about it”. Secondly, that information must have been imparted in circumstances importing an obligation of confidence. Thirdly, there must be an unauthorised use of that information to the detriment of the party communicating it. I must briefly examine each of these requirements in turn."

The tribunal was satisfied that the information in question was passed to the local authority in the course of negotiations for compensation. The object of those negotiations was to achieve an out of court settlement.  At para [33] of its decision it said:

"There are good reasons of public policy why such negotiations are conducted with an expectation of confidentiality, not least of which is to encourage parties to settle disputes without the need to go to court. These negotiations were, we accept, carried out on a without prejudice basis. That, in turn, prevents the parties from revealing later what was discussed. The corollary of that is to impose a duty of confidentiality as, otherwise, the basis of without prejudice communications would be undermined. We find that is so irrespective of the fact that there was no express agreement to keep matters confidential; that was not necessary given the nature of the negotiations."

The resident had submitted that the information was not confidential because the identities of the claimants were well known.  They may have been witnesses in previous litigation.  Their names, photographs and videos had been circulated over the internet. That was true but what that evidence did not do was "identify with any certainty any entity, real or corporate, as having been in receipt of compensation or, importantly, the amount paid to each."  Accordingly, the confidential nature of the information had been retained and the obligation of confidence had not been waived.  The tribunal was satisfied that the information had "the necessary quality of confidence about it" and had been "transmitted in circumstances importing an obligation of confidence."

Turning to the question of detriment, the tribunal said at [42]:

"We consider that there is a detriment in the disclosure of withheld material in that the material was supplied on the basis that it was to be kept confidential. The parties clearly proceeded on that basis. The fact that they had done so, and had suffered loss, is something that they wished not to be known."

The tribunal reminded itself that its role was to consider only if it was more likely than not that a court would find a breach of confidence. Given the particular circumstances in which the information had been imparted and the relationship of trust that that would have been created, the disclosure of the information to the resident would have met the detriment requirement.

The tribunal acknowledged that there are circumstances in which the public interest outeights the obligation of confidence.  In this case, there was a significant weight to be attached to the public interest in keeping confidential negotiations undertaken on a without prejudice basis. All the parties who had entered into those negotiations did so on the assumption that they would be kept confidential. It was an assumption they were rightly entitled to hold.  The tribunal accepted that the public was entitled to know how its money was spent and to whom, but the amount of the settlement and the reason for entering it was already in the public domain.  There was no need to disclose more.  The tribunal concluded at [51] that the withheld material was exempted information by operation of s.41.

Anyone wishing to discuss this article may call me on 020 7404 5252 or send me a message through my contact form.

Sunday, 12 September 2021

Consultation on Changing the Data Protection Laws


 








Jane Lambert

In his press release of 26 Aug 2021 which I discussed in Dowden's Data Protection Plans on 27 Aug 2021, Oliver Dowden MP, Secretary of State for Digital, Culture, Media and Sport, announced a consultation on changes to the UK's data protection laws.  That consultation was launched on 10 Sept 2021 with the publication of the consultation document, Data: a New DirectionResponses must be submitted by 19 Nov 2021.

The consultation document is 146 pages long and is divided into an introduction, 5 chapters. a page on whom the Department for Digital, Culture. Media and Sport ("DCMA")  is seeking to consult, how to respond and what happens next and a privacy notice.  DCMS states that it is keen to hear from "a representative cross section of society, ensuring diversity and inclusion", It believes that the consultation will have particular relevance to 

  • Individuals 
  • Start-ups and small businesses 
  • Technology companies and data-driven or data-rich companies 
  • Investors in technology and data-driven or data-rich companies 
  • Civil society organisations focused on consumer rights, digital rights, privacy and data protection 
  • Academics, and research and policy organisations with a particular interest in the role of data in the economy and society, or as data controllers in their own right 
  • Organizations involved in international data standards, regulation, and governance 
  • Law firms and other professional business services.
Respondents are urged to use the DCMS's online survey platform but responses can also be submitted by email or post.  The DCMS will publish its response in due course.

The 5 chapters are as follows:
  • Chapter 1- Reducing barriers to responsible innovation
  • Chapter 2 - Reducing burdens on businesses and delivering better outcomes for people
  • Chapter 3 - Boosting trade and reducing barriers to data flows
  • Chapter 4 - Delivering better public services, and 
  • Chapter 5 - Reform of the Information Commissioner's Office.
The reason for reducing barriers to responsible innovation are set out in para 30:

"The government has heard from stakeholders that elements of the law can create barriers to responsible innovation. Some definitions are unclear and lack explanatory case law or regulatory guidance that could take years to develop; organisations may choose not to use data as fully as they could owing to unfounded concerns about legality. For example, the rules for some organisations to use and to re-use personal data for research are difficult to navigate, despite the public being generally in favour of their personal data being used for scientific research that can deliver real benefits to society.5 The government has also heard evidence that uncertainty about when different lawful grounds for processing personal data should be used has led to an overreliance on seeking consent from individuals. This creates an unnecessary burden for consumers as well as for organisations. Finally, the increasing adoption and potential of new data-driven technologies is dependent on clear and consistent rules about the use of personal data."

The criticism of the present system is contained in para 139:

"The current legislation is based on a model that prescribes a series of activities and controls that organisations must adopt in order to be considered compliant. Although a key goal of the EU's GDPR was to create a regime that focussed on the accountability of organisations, the current model, in practice, tends towards a ‘box-ticking’ compliance regime, rather than one which encourages a proactive and systemic approach, and risks undermining the intentions of the principle of accountability."

One of those burdens is said to be subject access requests.  It is said that organizations have difficulty in processing such requests and with the threshold for making requests.  One of the solutions canvassed by the DCMS is the reintroduction of a fee for subject access requests and that is one of the proposals on which the Department is consulting. 

On "Boosting trade and reducing barriers to data flows" the DCMS explains at 240:

"Recent legal developments, including the Schrems II judgment, have made it more difficult for UK data exporters to transfer personal data overseas (see explanatory box below). The invalidation of the Privacy Shield by this judgment was particularly disruptive given the volume of trade it supported and the very many small and medium-sized businesses that were relying on it. Outside of the European Union, the UK has an opportunity to consider both the impact of this judgment on its transfers regime and how best to support international data flows in the future."

Data protection law became horrendously complex with the adoption of the General Data Protection Regulation and the implementation of the Law Enforcement Directive by the Data Protection Act 2018 on 25 May 2018.  Brexit has greatly exacerbated that complexity.   A snapshot of the current law since the expiry of the transition or implementation period on 31 Dec 2020 is set out in The Data Protection Legislation which I published on 28 Aug 2021.

Anyone wishing to discuss this article or any of its contents can call me on 020 7404 5252 during normal office hours or send me a message through my contact form at other times.

Friday, 27 August 2021

Dowden's Data Protection Plans


Jane Lambert

In the last few months, this government has made one ambitious promise after another. In his foreword to Global Britain in a competitive age, the Prime Minister wrote that his government's aim is for the UK to become a science and tech superpower by 2030 (see NIPC Brexit 19 March 2021). In his foreword to the UK Innovation Strategy Leading the future by creating it Kwasi Kwarteng, Secretary of State for Business, said that the UK would in science and technology what it is in finance (see UK Innovation Strategy, NIPC Inventors Club 12 Aug 2021). With similar hyperbole, Oliver Dowden, Secretary of State for Culture, Media and Sport has announced "a world-leading data regime" by "forging new global partnerships and designing our own common sense data laws" (see UK unveils post-Brexit global data plans to boost growth, increase trade and improve healthcare DCMS press release 26 Aug 2021).

The Press Release

Mr Dowden's press release makes three announcements:
  • an intention to negotiate "data adequacy partnerships" with Australia, Colombia, the Dubai International Financial Centre, Singapore, South Korea and the USA;
  • the appointment of John Edwards, the New Zealand Privacy Commissioner, as the next Information Commissioner; and 
  • a consultation on changes to the UK's data protection laws "to break down barriers to innovative and responsible uses of data so it can boost growth, especially for startups and small firms, speed up scientific discoveries and improve public services."
Data Protection Legislation 

On 25 May 2018, the General Data Protection Regulation ("GDPR") came into force across the European Union including the UK.  Art 94 of the GDPR repealed Directive 95/46/EC which had been implemented in the UK by the Data Protection Act 1998.  As it was a regulation of the European Council and Parliament, the GDPR took effect automatically.  The UK Parliament enacted the Data Protection Act 2018 which repealed the Data Protection Act 1998, supplemented the GDPR and applied a broadly equivalent regime to certain types of processing to which the GDPR did not apply.  

When the UK left the EU on 31 Jan 2020, the GDPR remained in force in the UK during the transition or implementation period that ended on 31 Dec 2020 pursuant to art 127 of the withdrawal agreement.  At the end of the transition period, the GDPR was incorporated into English, Welsh, Scots and Northern Irish law by s.3 (1) of the European Union  (Withdrawal) Act 2018.  Reg 3 and Sched. 1 of The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019 No 418) amended the provisions of the GDPR that have been incorporated into domestic law.   Reg 4 and Sched 2 of those regulations amended the Data Protection Act 2018.  

Transfer of Data Abroad

A fundamental principle of all data protection laws is that personal data should not be transferred abroad without adequate safeguards for its protection.  Art 44 of the GDPR provides:
"Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation."

One of the conditions on which personal data may be transferred overseas is set out in art 45 (1):

"A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation."

The decision of whether a third country provides adequate protection depends on a number of elements set out in art 45 (2).   The Commission has already made an adequacy decision in favour of the UK by its Decision of  26 June 2021 which I discussed in Commission Adequacy Decisions on 29 June 2021.  

Amendments to Art 45

Para 38 (2) of  Sched 1 of  The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 changed art 45 (1) of the GDPR to:
"A transfer of personal data to a third country or an international organisation may take place where it is based on adequacy regulations (see section 17A of the 2018 Act) ”. Such a transfer shall not require any specific authorisation."

Para 38 (3) of that Sched deleted most o the rest of the article.  Para 23 of Sched 2 inserted new sections 17A, 17B and 17C into the Data Protection Act 2018.  Those new sections contain new provisions for determining the adequacy of other countries' protection of personal data.  These include the power to make regulations.    

Para 42  of Sched 2 inserted new sections 74A and 74B into the Data Protection Act 2018,   These provide for the transfer abroad of data not covered by the GDPR in accordance with the above-mentioned regulations.   S.74A (4) of the Act is in substantially the same terms as art 45 (2) of the GDPR.

"Adequacy Partnerships"

The pairing of the noun "partnership" with the adjective "adequacy" suggests that adequacy decisions could depend on reciprocity and commercial advantage rather than the criteria in art 45 (1).   The press release reinforces that impression:
"The government believes it can unlock more trade and innovation by reducing unnecessary barriers and burdens on international data transfers, thereby opening up global markets to UK businesses. In turn this will help give UK customers faster, cheaper and more reliable products and services from around the world."

 Those concerns are at least partially allayed by the "Test for Adequacy" section of the guidance note International data transfers: building trust, delivering growth and firing up innovation published on 26 Aug 2021.  On paper, at least, the test for adequacy is objective and not dissimilar to the test in art 45 (2) of the GDPR. 

Risk of Losing the European Commission Adequacy Finding

A problem of seeking adequacy partnerships with countries operating very different regimes for protecting personal data is that the Commission could revoke its decision on the adequacy of protection in the UK under art 3 (4). That paragraph provides:

"Where the Commission has indications that an adequate level of protection is no longer ensured, the Commission shall inform the competent United Kingdom authorities and may suspend, repeal or amend this Decision."
Such a situation could arise if data were to flow without restriction from the EU to the UK and then from the UK to the USA but not directly from the EU to the  USA.   It would be unfortunate if the UK jeopardized its status in the European Economic Area in a quest for more distant and generally smaller markets overseas. 

Consultation

There is as yet no green paper or consultation on changing the law.   The only indication of what the government has in mind at this stage is that it believes improved data sharing could help deliver more agile, effective and efficient public services and help make the UK a science and technology superpower.   

Further Information

Anyone wishing to discuss this article or data protection generally my call me on 020 7404 5252 during office hours or send me a message through my contact form.

Tuesday, 29 June 2021

Commission Adequacy Decision

European Commission
Author EmDee Licence CC BY-SA 4.0  Source Wikipedia Commons

 









Jane Lambert

The uninterrupted exchange of personal data across borders is vital for the financial and other service industries. As I noted in Another Data Protection Act! "You're joking! Not another one!" - A Short History of Data Protection Legislation in the UK 23 Sept 2017 NIPC Law, it was restrictions on the transfer of personal data from countries that had enacted data protection legislation rather than the Younger and Lindop reports that prompted Parliament to enact the first Data Protection Act in 1984. Until 23:00 on 31 Dec 2020 businesses in the UK could rely on art 1 (3) of the General Data Protection Regulation (Regulation (EU) 2016/679 which provides that the free movement of personal data within the European Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. That was because EU law continued to apply to the UK between 23:00 on 31 Jan and 23:00 on 31 Dec 2020 pursuant to art 127 (1) of the agreement by which the UK withdrew from the EU.

Upon the expiry of that period, the United Kingdom became a "third country" for the purposes of art 44 of the GDPR.  That article provides:

"Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined."

Art 45 (1), however, provides:

"A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation."
The rest of that article sets out the criteria by which the Commission can make such a decision and the procedure for reaching it.

By a decision dated 28 June 2021 (Commission Implementing Decision of 28.6.2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom (C(2021) 4800 final)), the Commission has decided that for the purposes of art 45 of the GDPR the UK ensures an adequate level of protection for personal data transferred within the scope of the GDPR from the EU to the UK. The decision consists of 93 pages almost all of which are recitals setting out the Commission's reasons.  The decision on adequacy is contained in art 1 (1).  Art 3 (1) of the Decision requires the Commission to "monitor the application of the legal framework upon which this Decision is based, including the conditions under which onward transfers are carried out, individual rights are exercised and United Kingdom public authorities have access to data transferred on the basis of this Decision, with a view to assessing whether the United Kingdom continues to ensure an adequate level of protection within the meaning of Article 1." The Commission has power under art 3 (4) to suspend, repeal or amend the decision where it has indications that an adequate level of protection is no longer ensured.  It can also suspend, repeal or amend the decision under art 3 (5) if a lack of cooperation of the UK government prevents the Commission from determining whether the finding in art 1 (1) is affected.   The decision shall expire on 27 June 2025, unless extended in accordance with art 93 (2) of the GDPR.

Art 1 (2) of the decision makes clear that it does not cover personal data that is transferred for purposes of UK immigration control or that otherwise falls within the scope of the exemption from certain data subject rights for purposes of the maintenance of effective immigration control pursuant to para 4 (1) of Sched. 2 to the Data Protection Act 2018.  Art 2 (2) (d) of the GDPR states that the regulation does not apply to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.   Such processing is regulated by the Law Enforcement Directive (Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA). 

Art 35 (1) of the directive imposes the following obligation upon EU member states:

"Member States shall provide for any transfer by competent authorities of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation including for onward transfers to another third country or international organisation to take place, subject to compliance with the national provisions adopted pursuant to other provisions of this Directive, only where the conditions laid down in this Chapter are met, namely:
(a) the transfer is necessary for the purposes set out in Article 1 (1);
(b) the personal data are transferred to a controller in a third country or international organisation that is an authority competent for the purposes referred to in Article 1 (1);
(c) where personal data are transmitted or made available from another Member State, that Member State has given its prior authorisation to the transfer in accordance with its national law;
(d) the Commission has adopted an adequacy decision pursuant to Article 36, or, in the absence of such a decision, appropriate safeguards have been provided or exist pursuant to Article 37, or, in the absence of an adequacy decision pursuant to Article 36 and of appropriate safeguards in accordance with Article 37, derogations for specific situations apply pursuant to Article 38; and
(e)  in the case of an onward transfer to another third country or international organisation, the competent authority that carried out the original transfer or another competent authority of the same Member State authorises the onward transfer, after taking into due account all relevant factors, including the seriousness of the criminal offence, the purpose for which the personal data was originally transferred and the level of personal data protection in the third country or an international organisation to which personal data are onward transferred."
Art 36 of the Law Enforcement Directive is very similar to art 45 of the GDPR.  By Commission Implementing Decision of 28.6.2021 pursuant to Directive (EU), 2016/680 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom (C(2021) 4801 final) the Commission found that the UK ensures an adequate level of protection for personal data transferred from the EU to UK public authorities responsible for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties for the purposes of art 36. The decision requires the Commission to monitor the UK government's compliance with the legal framework and enables the Commission to suspend, repeal or amend the decision in the event of non-compliance or non-cooperation.  Subject to that provision, the decision also remains in force until 27 June 2025.

In an ICO statement in response to the EU Commission’s announcement on the approval of the UK’s adequacy, the Information Commissioner said:
“This is a positive result for UK businesses and organisations.
Approved adequacy means that businesses can continue to receive data from the EU without having to ake any changes to their data protection practices.
Adequacy is the best outcome as it means organisations can carry on with data protection as usual. And people will continue to enjoy the protections that their data will be used fairly, lawfully and transparently.
The result is also a testament to the strength of the UK’s data protection regime.”

Anyone wishing to discuss this article or data protection generally my call me on 020 7404 5252 during office hours or send me a message through my contact form. 

Saturday, 25 July 2020

Schrems II (Transfers of Data to the USA) Data Protection Commissioner v Facebook Ireland Ltd and Another

Damien Slattery / CC BY-SA (https://creativecommons.org/licenses/by-sa/3.0)






































Jane Lambert

Court of Justice of the European Union (K. Lenaerts, President, R. Silva de Lapuerta, Vice-President, A. Arabadjiev, A. Prechal, M. Vilaras, M. Safjan, S. Rodin, P.G. Xuereb, L.S. Rossi and I. Jarukaitis, Presidents of Chambers, M. Ilešič, T. von Danwitz (Rapporteur), and D. Šváby, Judges)  Case C‑311/18, Data Protection Commissioner v Facebook Ireland Ltd and another [2020] EUECJ C-311/18, EU:C:2020:559, ECLI:EU:C:2020:559 

This was a request for a preliminary ruling by Ms Justice Costello of the High Court of Ireland pursuant to art 267 of the Treaty on the Functioning of the European Union.  The request came at the behest of the Data Protection Commissioner of the Republic of Ireland.  The Commissioner had been asked by one Maximilian Schrems ("Mr Schrems") to require Facebook Ireland Ltd. ("Facebook") to cease or suspend transfers of personal data of which Mr Schrems was the data subject to Facebook's holding company in the United States where it could be intercepted and processed by US security and intelligence services without any legal redress.

The SCC Decisions
The Commissioner believed that she could not perform her task without a ruling of the validity of three Commission Decisions (referred to collectively as the "SCC Descirions") setting conditions for the transfer of personal data to the USA as a result of the Court of Justice's decision in Case C‑362/14, Schrems v Data Protection Commissioner  EU:C:2015:650, ECLI:EU:C:2015:650, [2016] QB 527, [2015] EUECJ C-362/14, [2016] 2 CMLR 2, [2016] 2 WLR 873, [2016] CEC 647, [2015] WLR(D) 403.  The Commissioner invited the Irish High Court either to make a finding on the validity of the SCC Decisions on its own initiative or to refer the question of their validity to Luxembourg under art 267 TFEU.

The Reference
In The Data Protection Commissioner v Facebook Ireland Limited and another [2017] IEHC 545, Ms Justice Costello found grounds for believing that the SCC Decisions were invalid. It was in her view extremely important for there to be uniformity on the issue throughout the European Union. On that basis, she believed that a reference was necessary and appropriate. Her ladyship delivered her order for a reference to the parties on 12 April 2018 whereupon Facebook Ireland appealed her decision to make a reference and applied for a stay of the reference pending their appeal.   Ms Justice Costello heard and rejected Facebook Ireland's application for a stay in Data Protection Commissioner v Facebook Ireland Ltd and another [2018] IEHC 236 (2 May 2018).

The Questions
The questions that Ms Justice Costlello referred to the Court of Justice were set out at paragraph [68] of the Court's judgment in Case C‑311/18, Data Protection Commissioner v Facebook Ireland Ltd [2020] EUECJ C-311/18, EU:C:2020:559, ECLI:EU:C:2020:559:
"(1) In circumstances in which personal data is transferred by a private company from a European Union (EU) Member State to a private company in a third country for a commercial purpose pursuant to [the SCC Decision] and may be further processed in the third country by its authorities for purposes of national security but also for purposes of law enforcement and the conduct of the foreign affairs of the third country, does EU law (including the Charter) apply to the transfer of the data notwithstanding the provisions of Article 4 (2) TEU in relation to national security and the provisions of the first indent of Article 3 (2) of Directive [95/46] in relation to public security, defence and State security?
(2)
 (a) In determining whether there is a violation of the rights of an individual through the transfer of data from the [European Union] to a third country under the [SCC Decision] where it may be further processed for national security purposes, is the relevant comparator for the purposes of [Directive 95/46]:
(i) the Charter, the EU Treaty, the FEU Treaty, [Directive 95/46], the [European Convention for the Protection of Human Rights and Fundamental Freedoms, signed at Rome on 4 November 1950] (or any other provision of EU law); or
(ii) the national laws of one or more Member States?
(b) If the relevant comparator is (ii), are the practices in the context of national security in one or more Member States also to be included in the comparator?
(3) When assessing whether a third country ensures the level of protection required by EU law to personal data transferred to that country for the purposes of Article 26 of [Directive 95/46], ought the level of protection in the third country be assessed by reference to:
(a) the applicable rules in the third country resulting from its domestic law or international commitments, and the practice designed to ensure compliance with those rules, to include the professional rules and security measures which are complied with in the third country; or
(b) the rules referred to in (a) together with such administrative, regulatory and compliance practices and policy safeguards, procedures, protocols, oversight mechanisms and non-judicial remedies as are in place in the third country?
(4) Given the facts found by the High Court in relation to US law, if personal data is transferred from the European Union to the United States under [the SCC Decision] does this violate the rights of individuals under Articles 7 and/or 8 of the Charter?
(5) Given the facts found by the High Court in relation to US law, if personal data is transferred from the European Union to the United States under [the SCC Decision]:
(a) does the level of protection afforded by the United States respect the essence of an individual’s right to a judicial remedy for breach of his or her data privacy rights guaranteed by Article 47 of the Charter?
If the answer to Question 5(a) is in the affirmative:
(b) are the limitations imposed by US law on an individual’s right to a judicial remedy in the context of US national security proportionate within the meaning of Article 52 of the Charter and do not exceed what is necessary in a democratic society for national security purposes?
(6)
 (a) What is the level of protection required to be afforded to personal data transferred to a third country pursuant to standard contractual clauses adopted in accordance with a decision of the Commission under Article 26(4) [of Directive 95/46] in light of the provisions of [Directive 95/46] and in particular Articles 25 and 26 read in the light of the Charter?
(b) What are the matters to be taken into account in assessing whether the level of protection afforded to data transferred to a third country under [the SCC Decision] satisfies the requirements of [Directive 95/46] and the Charter?
(7) Does the fact that the standard contractual clauses apply as between the data exporter and the data importer and do not bind the national authorities of a third country who may require the data importer to make available to its security services for further processing the personal data transferred pursuant to the clauses provided for in [the SCC Decision] preclude the clauses from adducing adequate safeguards as envisaged by Article 26(2) of [Directive 95/46]?
(8) If a third country data importer is subject to surveillance laws that in the view of a data protection authority conflict with the [standard contractual clauses] or Article 25 and 26 of [Directive 95/46] and/or the Charter, is a data protection authority required to use its enforcement powers under Article 28(3) of [Directive 95/46] to suspend data flows or is the exercise of those powers limited to exceptional cases only, in light of recital 11 of [the SCC Decision], or can a data protection authority use its discretion not to suspend data flows?
(9)
 (a) For the purposes of Article 25(6) of [Directive 95/46], does [the Privacy Shield Decision] constitute a finding of general application binding on data protection authorities and the courts of the Member States to the effect that the United States ensures an adequate level of protection within the meaning of Article 25(2) of [Directive 95/46] by reason of its domestic law or of the international commitments it has entered into?
(b) If it does not, what relevance, if any, does the Privacy Shield Decision have in the assessment conducted into the adequacy of the safeguards provided to data transferred to the United States which is transferred pursuant to the [SCC Decision]?
(10) Given the findings of the High Court in relation to US law, does the provision of the Privacy Shield ombudsperson under Annex A to Annex III to the Privacy Shield Decision when taken in conjunction with the existing regime in the United States ensure that the US provides a remedy to data subjects whose personal data is transferred to the United States under the [SCC Decision] that is compatible with Article 47 of the Charter]?
(11) Does the [SCC Decision] violate Articles 7, 8 and/or 47 of the Charter?’
Admissibility
The admissibility of the reference was challenged by Facebook and the British and German governments. Facebook argued that the reference served no useful purpose as the Data Protection Directive (Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data OJ L 281, 23.11.1995, p. 31–50) had been repealed by the General Data Protection Regulation ("GDPR") (Regulation (EU)  2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) OJ 4.5.2016 L119/1). The Court noted that the Directive was in force when the reference was made and the relevant articles of the Directive had been substantially reproduced in the GDPR. The German government contended that the Commissioner had not expressed an opinion but only doubts on the validity of the SCC Decisions and that the referring court had not made a finding on whether or not Mr Schrems had consented to the data transfer.  The British government submitted that there had been no finding that the transfer of data had been made in reliance on the SCC Decisions. The Court rejected both governments' contentions finding that the request for the preliminary reference had been well-founded.

The First Question
The Court reformulated the first question as follows at paragraph [80]:

"By its first question, the referring court wishes to know, in essence, whether Article 2 (1) and Article 2 (2) (a), (b) and (d) of the GDPR, read in conjunction with Article 4 (2) TEU, must be interpreted as meaning that that regulation applies to the transfer of personal data by an economic operator established in a Member State to another economic operator established in a third country, in circumstances where, at the time of that transfer or thereafter, that data is liable to be processed by the authorities of that third country for the purposes of public security, defence and State security."

Art 2 (1) of the GDPR provides:
"This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system."
However, art 2 (2) limits the scope of art 2 (1):
"This Regulation does not apply to the processing of personal data:
(a)  in the course of an activity which falls outside the scope of Union law;
(b)  by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;
(c)  ................
(d) by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security."
 Art 4 (2) of the Treaty on European Union provides:
"The Union shall respect the equality of Member States before the Treaties as well as their national identities, inherent in their fundamental structures, political and constitutional, inclusive of regional and local self-government. It shall respect their essential State functions, including ensuring the territorial integrity of the State, maintaining law and order and safeguarding national security. In particular, national security remains the sole responsibility of each Member State."
The Court held that art 4 (2) applies only to member states of the EU and not to non-member states such as the USA.   None of the limitations of art 2 (2) applies to Facebook. It concluded at paragraph [89]:
"the answer to the first question is that Article 2 (1) and (2) of the GDPR must be interpreted as meaning that that regulation applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State to another economic operator established in a third country, irrespective of whether, at the time of that transfer or thereafter, that data is liable to be processed by the authorities of the third country in question for the purposes of public security, defence and State security."
The Second, Third and Sixth Questions
The Court took the second, third and sixth questions together:
"[90] By its second, third and sixth questions, the referring court seeks clarification from the Court, in essence, on the level of protection required by Article 46 (1) and Article 46 (2) (c) of the GDPR in respect of a transfer of personal data to a third country based on standard data protection clauses. In particular, the referring court asks the Court to specify which factors need to be taken into consideration for the purpose of determining whether that level of protection is ensured in the context of such a transfer." 
Art 46 (1) and (2) (c) of the GDPR are as follows:
"(1) In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.
(2) The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by
.............................
(c)  standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93 (2)......"
In the absence of an adequacy decision under art 45 (3) GDPR, the Court held that a controller or processor may transfer personal data to a third country only if the controller or processor has provided ‘appropriate safeguards’, and on the condition that ‘enforceable data subject rights and effective legal remedies for data subjects’ are available. These can be provided by contract unless public authorities in the recipient country can override those contracts.   Consequently, the answer to the second, third and sixth questions is that art  46 (1) and art 46 (2) (c) GDPR must be interpreted as meaning that the appropriate safeguards, enforceable rights and effective legal remedies required by those provisions must ensure that data subjects whose personal data are transferred to a third country pursuant to standard data protection clauses are afforded a level of protection essentially equivalent to that guaranteed within the European Union by that regulation, read in the light of the Charter of Fundamental Rights of the European Union ("the Charter").

The Eighth Question
The Court interpreted the Irish High Cour's eighth question as follows:
"By its eighth question, the referring court wishes to know, in essence, whether Article 58 (2) (f) and (j) of the GDPR must be interpreted as meaning that the competent supervisory authority is required to suspend or prohibit a transfer of personal data to a third country pursuant to standard data protection clauses adopted by the Commission, if, in the view of that supervisory authority, those clauses are not or cannot be complied with in that third country and the protection of the data transferred that is required by EU law, in particular by Articles 45 and 46 of the GDPR and by the Charter, cannot be ensured, or as meaning that the exercise of those powers is limited to exceptional cases."
Art 58 (2) (f) and (j) of the GDPR are as follows:

"Each supervisory authority shall have all of the following corrective powers:
.............
(f) to impose a temporary or definitive limitation including a ban on processing;
.............
(j) to order the suspension of data flows to a recipient in a third country or to an international organisation."
Arts 45 and 46 provide safeguards for the transfer of data outside the EU. 

The Court observed that supervisory authorities have to enforce compliance with the GDPR in accordance with the Charter. They have to take particular care with transfers of data outside the EU and be diligent in dealing with data subjects' complaints.  It answered the eighth question as follows:
"In the light of the foregoing considerations, the answer to the eighth question is that Article 58 (2) (f) and (j) of the GDPR must be interpreted as meaning that, unless there is a valid Commission adequacy decision, the competent supervisory authority is required to suspend or prohibit a transfer of data to a third country pursuant to standard data protection clauses adopted by the Commission, if, in the view of that supervisory authority and in the light of all the circumstances of that transfer, those clauses are not or cannot be complied with in that third country and the protection of the data transferred that is required by EU law, in particular by Articles 45 and 46 of the GDPR and by the Charter, cannot be ensured by other means, where the controller or a processor has not itself suspended or put an end to the transfer."

The Seventh and Eleventh Questions
The Court took the seventh and eleventh questions together and interpreted them as follows:
"By its 7th and 11th questions, which it is appropriate to consider together, the referring court seeks clarification from the Court, in essence, on the validity of the SCC Decision in the light of Articles 7, 8 and 47 of the Charter."
The SCC Decision was Commission Decision of 15 June 2001 on standard contractual clauses for the transfer of personal data to third countries, under Directive 95/46/EC (OJ L 181, 4.7.2001, p. 19–31). It has been modified by Commission Decision of 27 December 2004 amending Decision 2001/497/EC as regards the introduction of an alternative set of standard contractual clauses for the transfer of personal data to third countries (notified under document number C(2004) 5271)Text with EEA relevance (OJ L 385, 29.12.2004, p. 74–84) and Commission Decision of 5 February 2010 on standard contractual clauses for the transfer of personal data to processors established in third countries under Directive 95/46/EC of the European Parliament and of the Council (notified under document C(2010) 593) (Text with EEA relevance) (OJ L 39, 12.2.2010, p. 5–18). The three Decisions are referred to collectively as the SCC Decisions.

The Court noted that art 1 of the SCC Decision provides that the standard data protection clauses set out in its annexe are considered to offer adequate safeguards with respect to the protection of the privacy and fundamental rights and freedoms of individuals in accordance with the requirements of art 26 (2) of the Data Protection Directive and now arts 46 (1) and 46 (2) (c) of the GDPR. Those clauses bind the recipient of a data transfer in a country outside the EU but not the public authorities of that country.  However, the clauses impose contractual obligations on both the controller and processor in the EU and the recipient of the data not to transfer data if the contractual safeguards cannot be guaranteed.   In the light of all of the foregoing considerations, the Court answered the 7th and 11th questions as follows:  "examination of the SCC Decision in the light of Articles 7, 8 and 47 of the Charter has disclosed nothing to affect the validity of that decision."

The Fourth, Fifth, Ninth and Tenth Questions
The Court interpreted those questions as follows at paragraph [150] of its judgment:
"By its ninth question, the referring court wishes to know, in essence, whether and to what extent findings in the Privacy Shield Decision to the effect that the United States ensures an adequate level of protection are binding on the supervisory authority of a Member State. By its 4th, 5th and 10th questions, that court asks, in essence, whether, in view of its own findings on US law, the transfer to that third country of personal data pursuant to the standard data protection clauses in the annex to the SCC Decision breaches the rights enshrined in Articles 7, 8 and 47 of the Charter and asks the Court, in particular, whether the introduction of the ombudsperson referred to in Annex III to the Privacy Shield Decision is compatible with Article 47 of the Charter."
The Privacy Shield Decision is Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the EU-U.S. Privacy Shield (notified under document C(2016) 4176) (Text with EEA relevance) C/2016/4176  (OJ L 207, 1.8.2016, p. 1–112).  This decision was made after the Data Protection Commissioner began her action in the Irish High Court. It is relevant to the proceedings because Facebook relies on the Privacy Shield Decision and alleges that it is binding on the Commissioner. The Court considered the provisions of the Decision and whether they provided adequate safeguards for data subjects.   It concluded that they did not and determined at [201] that the Privacy Shield Decision was invalid.

Further Proceedings
It is to be assumed that the Data Protection Commissioner's action will now be relisted for a  further hearing in the Irish High Court.  Irish readers are asked whether the relisted proceedings can be taken by Ms Justice Costello as she now sits in the Court of Appeal.

Further Information
Anyone wishing to discuss this case or data protection generally may call my clerk on 07986 948267 or send me a message through my contact page.