5 ms·
Privacy shield was one framework (now invalid, as parent notes) among a few. FB is dependent on standard contractual clauses which are generally valid (per sch
by zonethundery 6y ago
Privacy shield was one framework (now invalid, as parent notes) among a few. FB is dependent on standard contractual clauses which are generally valid (per schrems ii) but potentially invalid if the recipient is subject to FISA 702 warrants. Schrems ii put the burden of making that validity determination on member states' data protection authorities.
The Irish DPC didn't want to make this decision (for reasons), kicking the can to the CJEU, which eventually resolved Schrems II and remanded the decision on FB's SCC's back to the DPC.
- broeng 6y agoYes, it will be interesting to follow the SCC's (Standard Contractual Clauses). But, even though they were upheld, it is still up to the data exporter to guerantee before every transfer, that the SCC will provide an "essentially equivalent" protection to that offerend in the EU with GDPR for instance. It will also be dependant on all circumstances of the SCC whether the protections offered by it is enough, for instance if the receiving end could be compelled by the government, for instance, to hand over the data. It is hard to imagine a SCC that could provide "essentially equivalent" protection if the other end is an American company, given the authority the US government can exert over it.
- zonethundery 6y agoI mostly agree- its very hard to imagine any SCC for a communication service/social network surviving this kind of complaint. Not so sure about other kinds of things.