Schrems II and Brexit

4 Steps to Take Before the End of the Transition Period

While the U.K. formally left the European Union on January 31, 2020, nearly all E.U. law continues to apply in the U.K. including the “Schrems II” decision. For the moment, this means U.K. organisations may continue to transfer data from the E.U. to the U.K. and vice versa.

However, the decision of the Court of Justice of the European Union (CJEU) creates a layer of complexity for Data Protection Officers preparing for the end of the transition period on December 31, 2020.

For the U.K. the big question is whether the European Commission will give an “adequacy decision,” and whether the decision will be finalised before December 31. Without an “adequacy decision” organisations will have to put in place one of the alternative mechanisms to transfer data from the E.U. to the U.K. to remain in compliance.

Wrangu’s Privacy Hub can help with your privacy and data protection concerns and assist your organization with multi-regulation support.

In this blog you will find the highlights of the decision, an analysis of whether the U.K. will get an adequacy decision, and 4 steps to prepare for the end of the transition period.

What Happened in Schrems II?

In “Schrems II” the CJEU invalidated the Privacy Shield agreement between the E.U. and the United States. The Privacy Shield served as the “adequacy decision” allowing data transfers from the E.U. to the U.S. The result raises concerns for E.U.-U.K. data transfers as the end of transition period looms. Without an adequacy decision the U.K. would be considered a “third country” meaning that data transfers would need additional safeguards.

Read more about how the decision affects E.U. – U.S. data transfers.

Will the U.K. Get an Adequacy Decision?

Up until “Schrems II” it seemed likely the U.K. would be granted an adequacy decision as the 2018 Data Protection Act implemented much of GDPR into domestic law. However, the Court’s decision raises 3 key concerns

  1. The U.K.’s relationship with the United States. The two countries are negotiating a data transfer agreement and the United States is seeking unrestricted data flows. This raises concerns for the E.U. about “onward transfers” of E.U. citizen data from the U.K. to the U.S.
  2. The U.K.’s national security and surveillance apparatus. Given the “Schrems II” decision turned on U.S. government surveillance, an “adequacy decision” is further complicated by the U.K.’s national security and surveillance apparatus. Specifically, the broad powers to intercept communications and access data under the Investigatory Powers Act of 2016.
  3. Despite best intentions, there might not be enough time. The fastest time to adopt an “adequacy decision” is eighteen months, but the process can take up to five years. Even a positive decision could be later revoked by the Commission or invalidated by the CJEU.

The U.K. is caught between the proverbial rock and a hard place given its own surveillance practices, its desire for autonomy on data protection laws, and the desire for the free flow of information.

The uncertainty created by “Schrems II” means that organisations transferring data to the U.K. should prepare for the possibility that the U.K. will not secure an “adequacy decision” and should consider alternative mechanisms to legitimize data transfers from the E.U.

4 Steps to Prepare for the End of the Transition Period

  1. Map and Analyse Data Flows that involve transfers of personal data from the E.U. to the U.K.
  2. Consider Alternative Transfer Mechanisms

    (i)  Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs): To evaluate whether SCCs or BCRs may be relied on organisations must determine, on a case by case basis, that adequate protection equivalent to the GDPR is observed in the country where the data is to be transferred.

    For existing BCRs, the European Data Protection Board (EDPB) released an information note stating organisations in the U.K. need to get BCRs reapproved designating a supervisory authority in the E.U. as the U.K. supervisory authority will no longer qualify as competent after the transition period.

    (ii) Article 49 Derogations
    The European Data Protection Board (EDPB) made clear in its 2018 guidelines that Article 49 derogations apply where there are no other transfer mechanisms available. The derogations serve as an exception from the general rule and should not be considered a standard solution.

  3. Appoint an E.U. based Representative: If your organisation is based in the U.K. and does not have an E.U. establishment, Article 27 of GDPR requires non-E.U. companies appoint an E.U. based representative to act as their European point of contact for individuals and local data protection authorities.

  4. Consider Data Privacy Management Software to deliver efficiency, transparency, and risk reduction across all activities.

We will continue to monitor developments and share our analysis with you. Learn more about how Wrangu’s Privacy Hub can help with your privacy and data protection concerns and assist your organisation with multi-regulation support including US Privacy Laws, EU (GDPR), Brazil (LGPD), Turkey (LPPD), and others.

Author