14 ms·
The full ruling is available here: http://www.politico.eu/wp-content/uploads/2015/10/schrems-judgment.pdf http://www.politico.eu/wp-content/uploads/2015/10/schr
by A_Beer_Clinked 11y ago
The full ruling is available here:
http://www.politico.eu/wp-content/uploads/2015/10/schrems-judgment.pdf http://www.politico.eu/wp-content/uploads/2015/10/schrems-ju...
These bit jumped out at me:
>Furthermore, national security, public interest and law enforcement
requirements of the United States prevail over the safe harbour scheme, so that United States
undertakings are bound to disregard, without limitation, the protective rules laid down by that
scheme where they conflict with such requirements. The United States safe harbour scheme
thus enables interference, by United States public authorities, with the fundamental rights of
persons, and the Commission decision does not refer either to the existence, in the United States,
of rules intended to limit any such interference or to the existence of effective legal protection
against the interference.
>This judgment has the consequence that the Irish supervisory authority is required to examine Mr Schrems’
complaint with all due diligence and, at the conclusion of its investigation, is to decide
whether, pursuant to the directive, transfer of the data of Facebook’s European subscribers
to the United States should be suspended on the ground that that country does not afford
an adequate level of protection of personal data.
My reading (not a legal expert) is that data residency is the important bit here. Which in my view is a small step but not sufficient.
- armada651 11y agoI think it means a lot more than just data residency. Without the safe harbor agreement you can no longer avoid EU privacy regulations by storing the data in the US. This means that a lot of US companies are now exposed to EU privacy regulations where previously they only had to account for US privacy regulations. The US privacy regulations are no longer considered compatible with the EU privacy regulations. That has much more impact than just data residency.
- cm2187 11y agoWhat I am curious about is how do we define "doing business in the EU"? If I am american, create a blog stored in the US, and allow users to register an account to comment on the blog, am I doing business in the EU if a EU person creates an account or are my visitors more akin to foreign tourists visiting a US shop in the US and therefore outside the reach of EU regulation? In the financial sector, the extra-territoriality of US laws has been a problem for decades. Securities issued in the EU, by EU entities and marketed to EU investors end up having some language referring to which US regulation they fall under out of fear that a US person will end up buying it, and the US applying their laws and regulations.
- nolok 11y ago> What I am curious about is how do we define "doing business in the EU"? If I am american, create a blog stored in the US, and allow users to register an account to comment on the blog, am I doing business in the EU if a EU person creates an account or are my visitors more akin to foreign tourists visiting a US shop in the US and therefore outside the reach of EU regulation? De facto, it's when you take money from EU customers and/or have an official office in some EU country.
- cm2187 11y agoso a non profit wouldn't require to follow EU regulations on personal data?
- nolok 11y agoNote that I said "de facto", not "de jure". Nobody would bother suing a non profit that doesn't have EU offices unless you were very large and/or very prominent and/or doing something really nefarious about the data you have. And even then, suing an US company with no EU standing in front of an EU court from an EU citizen complaint is far from easy. The same reason that if, say, Texas introduce a law that says everyone commenting on a texan website needs to be polite and I post a comment with some name calling, suing me as someone not from Texas nor the US would not be very doable, even though I technically infringe on that law.
- pjc50 11y agosuing me as someone not from Texas nor the US would not be very doable It's been done: https://blogs.ch.cam.ac.uk/pmr/2010/11/21/english-libels-laws-are-used-to-suppress-scientific-debate-please-get-them-changed/ https://blogs.ch.cam.ac.uk/pmr/2010/11/21/english-libels-law... The libel situation has slightly improved since then.
- mattlutze 11y agoTo wit, non-profit doesn't mean "doesn't take in money." IIRC, it means that the organization doesn't distribute surplus income (profit) to shareholders. So, a non-profit that took monies from EU citizens I think would still possibly be affected, unless there's EU laws that make non-profits a different class of business subject do different laws.
- throwaway7767 11y agoThe end of the article makes it sound like just adding a clause to the terms & conditions saying the user agrees to his data being stored in the US would be enough to bypass this. They just can't assume they have that right under safe harbour. Hopefully they'll restrict that and require a higher threshold for consent than someone clicking "I agree" to 100 pages of dense legalese.
- 7952 11y ago>> require a higher threshold for consent than someone clicking "I agree" to 100 pages of dense legalese. You could just add it to the cookie permission widget!
- richmarr 11y ago> Without the safe harbor agreement you can no longer avoid EU privacy regulations by storing the data in the US. Maybe I'm missing something here. My understanding is that the Safe Harbour agreement wasn't a mechanism for US companies to avoid EU data protection regulations... it was a certification that they did comply with EU data protection (particularly in situations where that data was transmitted outside the EU). Now it's gone, EU customer data held by US companies will be governed by national data protection laws instead, so may end up having to be stored within the EU. > The US privacy regulations are no longer considered compatible with the EU privacy regulations I don't think they ever were, which is why the Safe Harbour needed to exist in the first place.
- flexie 11y agoNo, you are more or less right. The general rule is that personal data may only be transferred to organizations in third countries such as the US if they comply with the EU rules on data protection. See chapter IV of the data protection directive: http://eur-lex.europa.eu/legal-content/en/ALL/?uri=CELEX:31995L0046 http://eur-lex.europa.eu/legal-content/en/ALL/?uri=CELEX:319... In order to avoid that each EU member state would have to approve Google, Microsoft etc. one by one, the safe harbour framework was set up to let US companies self certify that they complied with the rules: "In order to bridge these differences and provide a streamlined and cost-effective means for U.S. organizations to satisfy the Directive’s “adequacy” requirement, the U.S. Department of Commerce in consultation with the European Commission developed a "safe harbor" framework. The U.S.-EU Safe Harbor Framework, which was approved by the EU in 2000, is an important way for U.S. organizations to avoid experiencing interruptions in their business dealings with the EU or facing prosecution by EU member state authorities under EU member state privacy laws. Self-certifying to the U.S.-EU Safe Harbor Framework will ensure that EU organizations know that your organization provides "adequate" privacy protection, as defined by the Directive." http://www.export.gov/safeharbor/eu/eg_main_018476.asp http://www.export.gov/safeharbor/eu/eg_main_018476.asp That was obviously a broken system, partially because the certified companies didn't live up to the EU standards, partially because the US government violated the rules systematically through CIA, NSA etc. The fault here is really European as much as American. By relying on the wolf to guard the sheep we very much had it coming.
- WhoBeI 11y agoUS privacy regulations where not considered compatible with EU ones before the ruling either. The agreement was that US companies sign a list with the US Dept. of Commerce that they considered themselves in compliance with EU regulations when handling EU citizen data and that would give legal immunity to them and their subsidiaries in the EU. This ruling means that EU countries are now allowed to check if they are lying or not.
- kuschku 11y agoThis is going to be funny. Time to sue every website that includes Google Analytics today. As, obviously, this ruling means no one – not even your website – may give out my data to US entities, including Google. So any type of tracking like that is now illegal. IANAL.
- lwyr 11y agoThat's the press release, which is a good summary, but not the actual judgment. The judgment is available at: http://curia.europa.eu/juris/documents.jsf?num=C-362/14 http://curia.europa.eu/juris/documents.jsf?num=C-362/14
- junto 11y agoDid anyone else notice the following as a distinct bias? Max Schrems, an Austrian lawyer and privacy activist, has done everything he can over the last several years to be a thorn in Facebook’s side. My alternative perspective: Max Schrems, an Austrian lawyer and privacy activist, has done everything he can over the last several years to protect the rights of European citizens whose privacy has been abused and invaded by US firms.