TwitterDeutsche Version
GDPR
Judgement

ECJ Ruling on Schrems II

ECJ Decision C-311/18, Schrems II
Datum16. July 2020

Data protection activist Max Schrems has achieved another victory before the European Court of Justice. Back in 2015, Schrems had already succeeded in having the European Court of Justice rule that the Safe Harbor Agreement—the predecessor to the Privacy Shield—was invalid.

In its ruling in Case C-311/18, the European Court of Justice declares the Decision 2016/1250 of the European Commission on the Privacy Shield as invalid. The Court of Justice finds that the requirements of national security, the public interest, and compliance with U.S. law are given priority over the protection against interference with the fundamental rights of individuals whose data is transferred to the United States. The surveillance programs based on U.S. law are not limited to the extent necessary. Data subjects who are not U.S. citizens have no judicially enforceable rights under the Privacy Shield provisions applicable to government agencies. Furthermore, the Court finds that the Ombudsman is not independent and cannot issue binding decisions against U.S. intelligence agencies.

The validity of Decision 2010/87 &on standard contractual clauses is not called into question; however, the requirements set forth in the GDPR regarding appropriate safeguards, enforceable rights, and effective remedies must be interpreted such that the level of protection is equivalent to that of the GDPR. The level of protection must be assessed on the basis of the contractual agreements between the data exporter and the recipient in the third country, as well as the access rights of the third country’s authorities. Supervisory authorities are obligated to &suspend or prohibit the transfer of personal data to a third country if they believe that the Standard Contractual Clauses are not being complied with or cannot be complied with in that country, and that the protection of the data cannot be guaranteed. Data controllers must now thoroughly examine the national laws of the third country. This applies in particular to laws and regulations that grant supervisory powers to authorities. Target companies in the third country are also required to notify the data controller in the EU if the high level of data protection cannot be met.

Organizations that transfer data to third countries for which no adequacy decision exists face major challenges as a result of the CJEU’s ruling.  In particular, data transfers to the U.S. will henceforth entail high risks unless valid consent has been obtained from the data subjects. Relying on standard contractual clauses instead of the Privacy Shield will, at best, buy time until the supervisory authorities prohibit the transfer. In many cases, lawful data transfers are likely to fail simply because the data exporter will be unable to demonstrate that the recipient company is complying with the requirements. 

 

 

Sources