1. The global economy imperatives
The movements of personal data to and from countries outside the E.U. are paramount in the context of a global economy relying heavily on international cooperation and commercial ties across-nations. Nevertheless, the importance of such transfers being recognized, the increased risk to the protection of personal data exposed to international exchanges cannot be ignored either. The GDPR aims to mitigate such risks by setting-up appropriate safeguards to protect personal data disseminated beyond the E.U. borders, into the so-called inadequate jurisdictions.
According to the 2nd paragraph of Recital 101 of the GDPR: “The increase in such flows has raised new challenges and concerns regarding the protection of personal data. However, when personal data are transferred from the Union to controllers, processors, or other recipients in third countries (…), the level of protection of natural persons ensured in the Union by this Regulation should not be undermined, including in cases of onward transfers of personal data from the third country (…) to controllers, processors in the same or another third country (…).”
The GDPR is therefore, without prejudice to transfers of personal data beyond the E.U. borders, facilitating them if certain legal requirements are complied with. The imposition of such legal requirements is justified by the need to ensure that the individuals whose personal data are subjected to cross border data transfers continue to benefit the same rights and the same level of protection as they enjoy in the E.U.
In other words, as the E.U. advisory bodies already posited, the GDPR was adopted to serve a dual-purpose: facilitating the free flow of personal data within the E.U., while preserving the fundamental rights and freedoms of individuals, particularly their right to the protection of personal data.
2. E.U. guardrails for cross-border data transfers
The introduction of legal guardrails for cross-border data transfers from the E.U. to other jurisdictions spurs continuous debates both in support or against. On one hand, some U.S. multinationals argue that the legislation in this matter should be more liberal with fewer requirements on cross-border data transfer, allowing for greater freedom. On the other hand, the E.U. institutions are acting with a protectionist mindset or, I would argue, in pursuit of judicial pragmatism.
The result of all the energy spent on cross-border data transfers since the adoption of GDPR has been the successful promotion of two Court of Justice of the E.U. (CJEU) law cases, where previous adequacy decisions regarding the U.S. have been abolished one by one. I would argue that the invalidation of Safe Harbour and Privacy Shield by the CJEU took place in this context, as opposed to being a purely philosophically or politically motivated decisions, as some are positing.
Edward Snowden’s revelations about the use of large-scale programs for monitoring the Internet and telephone conversations by the U.S. intelligence services played a seminal role in that and from that moment on. Of course, there is much more than the Snowden’s case, if we only think about the never-ending delay of the U.S. Congress in adopting a comprehensive privacy law that would create equal data protection rights for all Americans and all data on the American soil.
The Snowden disclosures shed light on numerous global surveillance programs, predominantly run by the NSA and the Five Eyes Intelligence Alliance, which includes New Zealand, the U.K., and Canada.
In response to Snowden actions, Maximilian Schrems filed a complaint with the Irish Data Protection Commissioner challenging Facebook Ireland’s transfer of his personal data to the U.S., alleging that it exposed his data to U.S. surveillance in violation of EU law. Schrems’ complaint was rooted in the principle embedded in EU data protection law, emphasizing that personal data subject to EU standards must be treated equivalently when exported or not exported at all. This principle was reinforced by Recital 116 of the GDPR, highlighting the increased risk to individuals’ data protection rights when data moves across borders.
Initially assuming Facebook relied on the EU-US Safe Harbor Decision, Schrems later discovered Facebook’s use of Standard Contractual Clauses (SCCs) for data transfers. Despite this revelation, the Irish Data Protection Commissioner, considering Schrems’ complaint frivolous, argued its inability to prohibit transfers if Facebook relied on Safe Harbor. Schrems contested this stance in Irish courts, ultimately leading to the CJEU’s Schrems I decision in 2015, which invalidated Safe Harbor. However, the Commissioner informed Schrems post-decision that Facebook used SCCs, prompting Schrems to amend his complaint accordingly.
The European Commission’s accelerated discussions with the U.S. Department of Commerce resulted in the Privacy Shield Decision, aimed at facilitating U.S.-E.U. data transfers. However, the Irish Commissioner’s investigation into Facebook’s transfers and US surveillance found the protection inadequate under E.U. law. Despite Facebook’s arguments regarding national security exclusions and the validity of the Privacy Shield, Schrems maintained that the Privacy Shield misrepresented U.S. surveillance laws and lacked authority to interpret SCCs. The case eventually made its way to the CJEU through the Irish High Court, culminating in the Schrems II judgment.
3. Safeguardingthe E.U. cross-border data transfers
In the aftermath of the CJEU Decision 2016/1250 in Case C-311/18 invalidating the Privacy Shield or better known as Schrems 2 judgment, the European Data Protection Board (EDPB) has released Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data.
The Recommendations comprises, among others, of a 6-steps roadmap for data exporters to verify, on a case-by-case basis and, where appropriate, in collaboration with the importers, if the law or practice of the third country impinges on the effectiveness of the appropriate safeguards contained in the Article 46 of the GDPR. Organisations relying on standard data protection clauses, binding corporate rules, codes of conduct or certification mechanisms must:
- Map all transfers of personal data to third countries and verify if they are adequate, relevant, and limited to what is necessary in relation to their purposes.
- Verify the transfer tool relied upon.
- Assess if there is anything in the law and/or practices in force in the third country that may impinge on the effectiveness of the appropriate safeguards of the transfer tools relied upon, in the context of the specific transfer.
- If needed, identify and adopt supplementary measures that are necessary to bring the level of protection of the data transferred up to the EU standard of essential equivalence.
- Take any formal procedural steps the adoption of the supplementary measure may require.
- Re-evaluate at appropriate intervals the level of protection afforded to the personal data transferred to third countries and monitor if there have been or there will be any developments that may affect it.
The third step is commonly known as a Transfer Impact Assessment (TIA). A TIA must be conducted by data exporters, with the assistance of the data importer, prior to any transfer relying on the appropriate safeguards listed in Article 46 of the GDPR. If the country of destination is covered by an adequacy decision, the exporter is not subject to this obligation. The same applies if the transfer is carried out based on one of the derogations listed in Article 49 of the GDPR.
Carrying a TIA is not a trivial exercise, which is why some Data Protection Authorities and legal experts alike have proposed templates and roadmaps to scoping the exercise from different angles. For example, the French Data Protection Authority (CNIL) has elaborated a Practical Guide in line with the Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data which was adopted on 18 June 2021.
The CNIL Practical Guide advises that, before undergoing a TIA exercise, the exporters should weight into five aspects, as follows:
- The data subject to transfer constitutes personal data according to the provisions of Article 4(1) of the GDPR
- A data transfers takes place according to Guidelines 05/2021 on the interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR.
- Exporter and importer acting capacity (i.e., controllers, joint controllers, processors)
- Minimizing the volume of the data subject to transfer or anonymizing the data
- The possibility to transfer the data to an adequate country.
On the other hand, the U.K. Data Protection Authority, the infamous Information Commissioner’s Office (ICO) proposed a Transfer Risk Assessment (TRA). The ICO interprets the word “impact” as “risk” and therefore, proposes a risk assessment. In other words, according to ICO, depending on the quantifiable risk of the processing activity and its risk score, the transfer can be “permitted” or “not permitted”.
This is a deviation from both the EDPB and CNIL approach which, on the contrary, interprets the CJEU Judgment in Case C-311/18 as imposing an obligation on businesses to conduct an effectiveness assessment with regards to the transfer tool employed for transferring data to inadequate jurisdictions. Therefore, the word “impact” must be read, according to the CJEU, EDPB and CNIL interpretation, considering the consequences that specific legal context might have on the “effectiveness” of contractual commitments and their standing to provide for an “essentially equivalent level of protection” in the country of destination of the data.
In other words, according to the CJEU, EDPB and CNIL interpretation, impact/s on the level of the essentially equivalent protection must be mended through supplementary measures, if possible. If not possible, even in the case of a theoretical or residual risk to the essentially equivalent level of protection of the data and individuals, the transfer must be suspended or halted.
Independent of these differences in approaches, a TIA exercise should gauge at least the following aspects:
- Applicable legislation for the protection of personal data.
- Laws or practices affecting the effectiveness of the transfer tool.
- Any rule of law shortcomings that would impinge on data subject possibility to appeal against an illegal access to data.
- Importer potential to be subject to a request for access or a direct access to the data.
4. Conclusion
The timing of Edward Snowden’s revelations proved pivotal in the landscape of privacy and data protection law. Just a year earlier, the European Commission had introduced the EU General Data Protection Regulation (GDPR), which was undergoing extensive debate and reforms, still a few years from its eventual adoption. Concurrently, the EU-U.S. Safe Harbor Framework remained operational. Notably, Maximilian Schrems was on the cusp of filing his complaint with the Irish Data Protection Commission, a move that would eventually lead to the invalidation of the Safe Harbor and subsequently of Privacy Shield by the Court of Justice of the European Union and imposition of transfers assessments or TIAs.
The objective of a TIA is to assess whether the importers in third countries will be able to respect obligations committed to in transfer engagements they will sign up for, in view of the legislation and practices of the third country, especially as they amount to the potential access to personal data by public authorities of the third country, and to document this assessment.
If necessary, the TIA must assess whether supplementary measures would allow to fill-in gaps ascertained and to ensure a level of protection essentially equivalent with the one prescribed in the EU data protection legislation.
At Wrangu, we have a legal team on top of privacy and data protection combined with technical experts to deliver privacy solutions like Privacy Hub which includes a TIA module. Download our brochure or schedule a call to see how we can help solve your privacy needs.