Article 45 GDPR: Difference between revisions

From GDPRhub
 
(4 intermediate revisions by 2 users not shown)
Line 185: Line 185:


==Legal Text==
==Legal Text==
<br /><center>'''Article 45 - Transfers on the basis of an adequacy decision'''</center><br />
<br /><center>'''Article 45 - Transfers on the basis of an adequacy decision'''</center>


<span id="1">1.  A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.</span>
<span id="1">1.  A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.</span>
Line 221: Line 221:


==Commentary==
==Commentary==
Article 45 GDPR refers to the complex issue of international data transfers. The huge amounts of data transferred from the EU to third countries created the necessity to adopt provisions that could ensure the implementation of precautionary measures to protect the transfers. The level of protection that should be achieved is promoted and delimitated in Chapter V of the GDPR. Chapter V of the GDPR creates a three-tiered structure for legal bases for international data transfers, with adequacy decisions being at the top, appropriate safeguards at the middle and negotiations at the bottom.<ref>''Kuner'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 45 GDPR, p. 774 (Oxford University Press 2020).</ref>  
Article 45 GDPR refers to the complex issue of international data transfers. The huge amounts of data transferred from the EU to third countries created the necessity to adopt provisions that could ensure the implementation of precautionary measures to protect the transfers. The level of protection that should be achieved is promoted and delimited in Chapter V of the GDPR. Chapter V of the GDPR creates a three-tiered structure for legal bases for international data transfers, with adequacy decisions being at the top, appropriate safeguards in the middle, and negotiations at the bottom.<ref>''Kuner'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 45 GDPR, p. 774 (Oxford University Press 2020).</ref> On the basis of Art. 45 GDPR, the European Commission (Commission) has the power to determine whether a country outside the EU offers an adequate, "''essentially equivalent''" level of data protection than the EU. Adequacy means that the rules implemented in the third countries or international organisations are effective in practice.<ref>WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, p. 3 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]).</ref> The Commission has so far recognised the following countries as providing adequate protection by means of '''adequacy decisions''<nowiki/>': Andorra, Argentina, Canada (only commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom (under the GDPR and the LED) and Uruguay. These decisions entail that personal data can be transferred from the EU (as well as Norway, Liechtenstein and Iceland) to these third countries without additional safeguards, that these transfers will be assimilated to intra-EU transmissions of data.<ref>The  adequacy decisions which are currently adopted can be found [https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en here].</ref>
 
On the basis of Art. 45 GDPR the European Commission has the power to determine, whether a country outside the EU offers an adequate, "essentially equivalent" level of data protection with the EU. Adequacy means that the rules implemented in the third countries or international organisations are effective in practice<ref>WP29, Adequacy Referential, WP 254 rev.01, 28 November 2017, p. 3 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]).</ref>. The European Commission has so far recognised the following countries as providing adequate protection by means of 'adequacy decisions': Andorra, Argentina, Canada (only commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland and Uruguay. The current adequacy decisions can be found [https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en here].
 
===(1) Adequacy Decision===
===(1) Adequacy Decision===
Under Article 45 GDPR, a transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. The expression 'adequate level of protection' means that the third country, by virtue of its national legislation or international obligations, ensures a level of protection of freedoms and fundamental rights which is ''<nowiki/>'essentially equivalent''' to the one guaranteed in the Union in the light of the Charter.<ref>CJEU, C-311/18, Facebook Ireland and Schrems, ECLI:EU:C:2020:559, 16 July 2020, margin number 94. The WP29 adhered to this interpretation, further stating that the third country's rules must comply with a "core" of principles relating both to the content of data protection rules and their enforcement, based on the GDPR, the Charter of Fundamental Rights of the European Union (CFR) and other relevant international instruments, such as Council of Europe Convention 108. See, WP29, Adequacy Referential, WP 254 rev.01, 28 November 2017, p. 4 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]).</ref> Although the resources used by a third country may differ from those used in the EU, they must nevertheless prove to be effective in practice.<ref>For example, a regulation based on voluntary commitment is not excluded from the outset. However, effective monitoring and control mechanisms will then have to be put in place in the third country to identify and punish in practice any breaches of rules guaranteeing the protection of fundamental rights, in particular the right to respect for privacy and the right to the protection of personal data. See, ''Zerdick'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 6 (Beck 2018, 2nd ed.) (accessed 3 March 2022).</ref> The main consequence of the adequacy decision is that, if it is adopted, the transfer "''shall not require any specific authorisation''".
Under Article 45 GDPR, a transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question, ensures an adequate level of protection. The expression '<nowiki/>''adequate level of protection''<nowiki/>' means that the recipient,  by virtue of its national legislation or international obligations, ensures a level of protection of freedoms and fundamental rights which is ''<nowiki/>'essentially equivalent''' to the one guaranteed in the Union in the light of the Charter.<ref>CJEU, Case C-311/18, ''Facebook Ireland and Schrems'', 16 July 2020, margin number 94 (available [https://curia.europa.eu/juris/document/document.jsf?text=&docid=228677&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=2603508 here]). The WP29 adhered to this interpretation, further stating that the third country's rules must comply with a "core" of principles relating both to the content of data protection rules and their enforcement, based on the GDPR, the Charter of Fundamental Rights of the European Union (CFR) and other relevant international instruments, such as Council of Europe Convention 108. See, WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, p. 3 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]).</ref> Although the resources used by a third country may differ from those used in the EU, they must nevertheless prove to be equally effective in practice.<ref>For example, a regulation based on voluntary commitment is not excluded from the outset. However, effective monitoring and control mechanisms will then have to be put in place in the third country to identify and punish in practice any breaches of rules guaranteeing the protection of fundamental rights, in particular the right to respect for privacy and the right to the protection of personal data. See, ''Zerdick'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 6 (C.H. Beck 2018, 2nd Edition).</ref> The main consequence of the adequacy decision is that, if it is adopted, the transfer "''shall not require any specific authorisation''".


===(2) Criteria for the Adequacy Decision===
===(2) Criteria for the Adequacy Decision===
Article 45(2) GDPR sets out a number of criteria that the European Commission must take into account while considering the adoption of an adequacy decision. This list is not exhaustive<ref>''Zerdick'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 7 (Beck 2018, 2nd ed.) (accessed 3 March 2022).</ref> and includes the following elements: (a) the rule of law, respect for human rights and fundamental freedoms, relevant legislation, as well as the implementation of such legislation, data protection rules and security measures, including rules for the onward transfer of personal data to another third country, case-law, as well as effective and enforceable data subject rights and effective administrative and judicial redress for the data subjects whose personal data are being transferred; (b) the existence and effective functioning of one or more independent supervisory authorities in the third country, including adequate enforcement powers; and (c) the international commitments the third country or international organisation concerned has entered into, in particular in relation to the protection of personal data.
Article 45(2) GDPR sets out a number of criteria that the Commission must take into account while considering the adequacy of a third country or an international organisation. This list is not exhaustive<ref>''Zerdick'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 6 (C.H. Beck 2018, 2nd Edition).</ref> and includes at least the following elements:  


The criteria listed above are intended as a guide and should not be understood in an overly restrictive sense. This means that the third country does not have to implement the identical measures of protection provided by the EU in order for their data protection system to be deemed adequate.<ref>The fundamental different ideas on the protection of personal data among the different states, in combination with the economic policy and entrepreneurial freedoms promoted by the EU, leave space for adaptation for the third countries. It must also be noted that, an adequacy decision cannot regulate the exchange of data for the purpose of national security or the common foreign and security policy. See, European Commission, Decision on on the adequate protection of personal data contained in the Passenger Name Record of air passengers transferred to the United States, 2004/535/EG, 14 May 2004, repealed by the CJEU, Parliament v Council, C-317/04 and C-318/04, 30 May 2006 (available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-318/04 here]); see Philipp, Öffentlichkeit bei Ratsentscheidungen gefordert, in EuZW, Volume 17 (2006), p. 357.</ref> However, certain elements of the European order must always be respected. In particular, from a substantive perspective, a third country’s or international organisation’s system must contain at least the following basic content: (i) Rules on basic data protection concepts and/or principles should exist; (ii) Grounds for lawful and fair processing for legitimate purposes should be set in a sufficiently clear manner; (iii) The principled of purpose limitation, (iv) data quality and proportionality, (v) data retention, (vi) security and confidentiality, and (vii) transparency should be recognized; the data subject should have at least the (viii) the right of access, rectification, erasure and objection, (ix) restrictions on onward transfers are foreseen. The necessary guarantees are not limited to those of a substantial nature. Indeed, the European authorities have clarified that an adequate level of protection cannot be guaranteed without at least the following elements: (i) the presence of at least one independent, impartial, properly funded supervisory authority with investigative powers; (ii) the existence of a data protection system that is shared and known by controllers and data subjects; (iii) an accountability system for controllers; and, finally, (iv) the existence of effective administrative and judicial redress, including for compensation for damages as a result of the unlawful processing of his/her personal data.<ref>WP29, Adequacy Referential, WP 254 rev.01, 28 November 2017, pp. 5-6 (available here).</ref>
==== (a) Rule of Law ====
In assessing the adequacy of a third country or international organisation, the Commission shall take into account, among others, the rule of law, respect for human rights and fundamental freedoms, relevant legislation and its implemenation, data protection rules and security measures(including rules for the onward transfer of personal data to another third country), case-law, effective and enforceable data subject rights, as well as effective administrative and judicial redress for the data subjects whose personal data are being transferred. These criteria assume a minimum level of human rights and fundamental freedoms. Third countries or international organisations must ensure minimum of interference with fundamental rights by providing guarantees for law enforcement and national security access to data. On this topic, the Article 29 Working Party (WP29) has also identified four essential guarantees: (i) processing should be based on clear, precise and accessible rules (legal basis); (ii) necessity and proportionality with regards to legitimate objectives pursued need to be demonstrated; (iii) the processing has to be subject to independent oversight; and (iv) effective remedies need to be available to the individuals. Although these were actually originated from the jurisprudence of the Court of Justice of the European Union (CJEU) and the European Court of Human Rights (ECHR) in the field of surveillance, the WP29 considers that these four guarantees also apply and need to be respected by all third countries for access to data for national security or law enforcement purposes, in order to be considered adequate.<ref>The clarification is probably made following the Snowden revelations on mass surveillance by the US government. See, WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, p. 9 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]).</ref>  


The WP29 has also identified four essential guarantees reflecting the jurisprudence of the CJEU and the ECHR in the field of surveillance. In particular, (i) Processing should be based on clear, precise and accessible rules (legal basis); (ii) Necessity and proportionality with regards to legitimate objectives pursued need to be demonstrated; (iii) The processing has to be subject to independent oversight; and (iv) Effective remedies need to be available to the individuals.<ref>WP29, Adequacy Referential, WP 254 rev.01, 28 November 2017, p. 9 (available here).</ref>
==== (b) Independent Supervisory Authorities ====
====Schrems I and II====
The Commission will have to ponder the existence and effective functioning of one or more independent DPAs in the third country, including adequate enforcement powers. The independent and effective DPAs shall be mandated to monitor the respect of the third-country or intra-organisational data protection rules. The authorities should also advise data subjects and cooperate with the DPAs of the Member States.<ref>''Towfigh and Ulrich,'' in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 12 (C.H. Beck 2018, 2nd Edition).</ref>  


===== Facts =====
==== (c) International Obligations ====
Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid.
Finally, the international commitments the third country or international organisation concerned has entered into should be taken into consideration, in particular those related to the protection of personal data. This criterion is intended to verify that the international commitments in question do not conflict with the criteria listed above. On the other hand, the presence of international agreements that promote or facilitate the implementation of a more efficient personal data protection system must be positively taken into account.<ref>''Towfigh and Ulrich,'' in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 13 (C.H. Beck 2018, 2nd Edition).</ref>


In its judgment on October 6<sup>th</sup> 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC.
====Essential elements====
The criteria listed above are intended as a guide and should not be understood in an overly restrictive sense. This means that the third country does not have to implement the identical measures of protection provided by the EU in order for their data protection system to be deemed adequate.The fundamental different ideas on the protection of personal data among the different states, in combination with the economic policy and entrepreneurial freedoms promoted by the EU, leave space for adaptation for the third countries. It must also be noted that, an adequacy decision cannot regulate the exchange of data for the purpose of national security or the common foreign and security policy.<ref>See, European Commission, Decision on on the adequate protection of personal data contained in the Passenger Name Record of air passengers transferred to the United States, 2004/535/EG, 14 May 2004, repealed by the CJEU, Joined Cases C-317/04 and C-318/04, ''Parliament v Council'', 30 May 2006 (available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-318/04 here]); also see ''Philipp'', Öffentlichkeit bei Ratsentscheidungen gefordert, in EuZW, Volume 17 (2006), p. 357.</ref>


In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1<sup>st</sup> 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Articles 7, 8, and 47 of the Charter. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4<sup>th</sup> 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU.
That said, certain elements of the European order must always be respected. In particular, from a substantive perspective, a third country or international organisation’s system must contain at least the following basic content: (i) rules on basic data protection concepts and/or principles should exist; (ii) grounds for lawful and fair processing for legitimate purposes should be set in a sufficiently clear manner; (iii) the principle of purpose limitation; (iv) data quality and proportionality; (v) data retention; (vi) security and confidentiality; (vii) transparency should be recognized; (viii) the data subject should have at least the right of access, rectification, erasure and objection; and (ix) restrictions on onward transfers are foreseen.  


In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISC approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data ''without'' ensuring a level of protection that was essentially equivalent to that which was guaranteed by Articles 7 and 8 of the Charter. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable.
The necessary guarantees are not limited to those of a substantial nature. Indeed, the European authorities have clarified that an adequate level of protection cannot be guaranteed without at least the following elements: (i) the presence of at least one independent, impartial, properly funded DPA with investigative powers; (ii) the existence of a data protection system that is shared and known by controllers and data subjects; (iii) an accountability system for controllers; and, finally, (iv) the existence of effective administrative and judicial redress, including compensation for damages as a result of the unlawful processing of  personal data<span lang="EN-GB">Article 45 GDPR refers to the complex issue of
international data transfers. The huge amounts of data transferred from the EU
to third countries created the necessity to adopt provisions that could ensure
the implementation of precautionary measures to protect the transfers. The
level of protection that should be achieved is promoted and delimited in
Chapter V of the GDPR. Chapter V of the GDPR creates a three-tiered structure
for legal bases for international data transfers, with adequacy decisions being
at the top, appropriate safeguards in the middle, and negotiations at the
bottom.</span>.<ref>WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, pp. 7-8 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]).</ref>


Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data.<ref>The request for a preliminary ruling referred eleven questions to the Court of Justice. The topics covered in these questions were as follows: the applicability of EU law to data transfers made for commercial purposes, but further processed for national security and law enforcement purposes; the relevant legislation for determining whether there has been a violation of individual rights; how to assess the level of protection in a third country; whether data transfers to the US violate the Charter; whether the level of protection offered in the US respects or limits an individual’s right to a judicial remedy; what level of protection is required to be afforded to personal data that is transferred under SCCs; whether the SCCs can even be adequate as safeguards given they do not bind national authorities; whether there is an obligation to suspend data flows if a data importer is subject to surveillance law; what the relevance of the Privacy Shield decision is with regards to assessing safeguards; whether the presence of an ombudsperson can ensure that the US provides an effective remedy to data subjects; whether the SCCs violate the Charter.</ref>
==== Article 45 and Schrems II ====
Although the CJEU judgement [[CJEU - C-311/18 - Schrems II|C-311/18 (Schrems II)]] invalidated the Commission Decision 2016/1250 (EU-US Privacy Shield), but affirmed the validity of standard contractual clauses (SCCs), providing that they include effective mechanisms to ensure compliance in practice with the “''essentially equivalent''” level of protection guaranteed by the GDPR to EU citizens. Below is the summarised version of this judgement.


===== Holding =====
===== Facts =====
The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes.
Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid.  


Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country.
In its judgment on October 6<sup>th</sup> 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC.  


The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were ''not'' circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services.
In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1<sup>st</sup> 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Articles 7, 8, and 47 of the Charter. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4<sup>th</sup> 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU.  


Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid. The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means.
In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data ''without'' ensuring a level of protection that was essentially equivalent to that which was guaranteed by Articles 7 and 8 of the Charter. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable.  


Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify ''prior'' to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.
Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data.
===== Holding =====
The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes.  


====Procedure====
Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country.  
The process in order to adopt an adequacy decision requires<ref>European Commission, Adequacy decisions (accessed on 19 August 2021, available [https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en here]).</ref> a submission of a proposal from the European Commission, an opinion from the European Data Protection Board (EDPB), an approval from representatives of EU countries and finally the adoption of the decision by the European Commission. The significance of the decision is easy to be understood due to its effect. After the adoption of a decision personal data can flow from the EEA to a third country without the requirement of further safeguards needed.<ref>Data Protection Commission, Transfers of Personal Data to Third Countries or International Organisations (accessed on 19 August 2021, available [https://www.dataprotection.ie/en/organisations/international-transfers/transfers-personal-data-third-countries-or-international-organisations here]).</ref>


The Commission can issue adequacy decisions for any country that is not an EU Member State or party to the EEA, or as the article provides a decision can be issued for an international organisation.  So far, as it was mentioned above, the Commission has issued adequacy decisions for a number of countries such as: Andorra, Argentina, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, Switzerland and Uruguay, while a partial adequacy decision has been issued for Canada.<ref>Office Of The Data Protection Ombudsman, Transfers on the basis of an adequacy decision (accessed on 19 August 2021, available [https://tietosuoja.fi/en/transfers-on-the-basis-of-an-adequacy-decision here]).</ref> Adequacy talks were concluded with South Korea on 30 march 2021.  
The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were ''not'' circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services.  


====Time of validity====
Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid.
Adequacy decisions have to be reviewed at least every four years while they can be repealed, amended, or suspended without a retroactive effect, when the third country or the organisation no longer ensures an adequate level of protection. The absence of a retroactive effect departures from EU law and avoids the disappearance of an EU act from the legal order from the date of entering into force (ex tunc). <ref>''Lenaerts'', ''Maselis'',''Gutman'', EU Procedural Law, locations 18058 -18065 (Oxford University Press 2014).</ref> Following the amendment or the repeal, the Commission has to enter into consultations with the third country or the international organisation in order to remedy the situation.<ref>''Kuner'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 45 GDPR, p. 789 (Oxford University Press 2020).</ref> All decisions concerning adequacy must be published in the official journal of the EU.
====Content====
An adequacy decision must contain a number of specific elements.<ref>''Kuner'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 45 GDPR, p. 785 (Oxford University Press 2020).</ref> More precisely, it must contains at least:


1. A statement that the third country or the international organisation ensures adequate protection through its domestic law and regulations.  
The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means. Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify ''prior'' to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.
===(3) Adoption of the Adequacy Decision===
According to Article 45(3) GDPR, after assessing the adequacy of the level of protection of a third country<ref>Or a territory or one or more specified sectors within a third country, or an international organisation.</ref> under paragraph 2, the Commission may decide to adopt an adequacy decision by means of an implementing act. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the DPAor authorities referred to in point (b) of paragraph 2 of this provision. The implementing act shall also provide for a mechanism for a periodic review, which should be carried out at least every four years,  taking into account all relevant developments in the third country or international organisation.<ref>This is intended to force the Commission to regularly review its adequacy decisions and to counter possible changes in the data protection situation in a third country, for example through legislative changes. See, ''Towfigh and Ulrich,'' in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 19 (C.H. Beck 2018, 2nd Edition).</ref> The implementing act shall be adopted in accordance with the examination procedure referred to in [[Article 93 GDPR|Article 93(2) GDPR]]. The process in order to adopt an adequacy decision requires the submission of a proposal from the Commission, a non-binding opinion from the European Data Protection Board (EDPB), an approval from representatives of EU countries, and finally, the adoption of the decision by the Commission. The significance of the decision is easily understood due to its effect. After the adoption of a decision, personal data can flow from the EEA to a third country without the requirement of further safeguards.<ref>DPC, ‘Transfers of Personal Data to Third Countries or International Organisations’ (available [https://www.dataprotection.ie/en/organisations/international-transfers/transfers-personal-data-third-countries-or-international-organisations here]) (accessed on 28 April 2022).</ref> The Commission can issue adequacy decisions for any country that is not an EU Member State or party to the EEA, a territory or one or more specified sectors within one of these countries, as well as an international organisation, as this provision establishes. As mentioned beforehand, so far, the Commission has issued adequacy decisions for the following countries: Andorra, Argentina, Canada (only commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, Republic of Korea , Switzerland, United Kingdom (under the GDPR and the LED) and Uruguay.<ref>Office Of The Data Protection Ombudsman, Transfers on the basis of an adequacy decision (available [https://tietosuoja.fi/en/transfers-on-the-basis-of-an-adequacy-decision here]) (accessed on 28 April 2022).</ref>
===(4) Monitoring of Developments in the third Country===
Under Article 45(4) GDPR, following the adoption of an adequacy decision, the Commission must regularly examine whether the functioning of an adequacy decision is still correct, both objectively and legally. In any event, such an examination is necessary where there are indications which give rise to doubts in that regard.  This continuous adequacy monitoring also requires dialogue with the authorities of the third country concerned. The Commission may also continue to do so with the support of the EDPB in accordance with Article 70(1)(b) GDPR.<ref>''Zerdick'', in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 22 (C.H. Beck 2018, 2nd Edition).</ref>


2. The territorial and sectoral application of the decision (Article 45(3) GDPR).
===(5) Repeal, Amendment or Suspension of the Adequacy Decision===
According to Article 45(5) GDPR, the continued monitoring referred to in paragraph 3, or other information which has come to light, may demonstrate that the third country does not ensure the essentially equivalent level of protection referred to in paragraph 2, and that the initial adequacy decision is therefore no longer accurate. In such circumstances, the Commission is required, to the extent necessary, to repeal, amend, or suspend the initial decision by means of implementing acts without retro-active effects.<ref>The absence of a retroactive effect departures from EU law and avoids the disappearance of an EU act from the legal order from the date of entering into force (ex tunc). See, ''Lenaerts'', ''Maselis'',''Gutman'', EU Procedural Law, locations 18058 -18065 (Oxford University Press 2014).</ref> The decision-making procedure referred to in Article 93(2) GDPR shall apply unless there are urgency elements requiring an immediate decision. In that case, the procedure provided for in Article 93(3) GDPR shall apply. This allows the Commission to react on short notice, where appropriate, to changes in circumstances within the third country or the international organisation, and to amend the adequacy decision. Whether there is a duly justified case must be decided on a case-by-case basis.<ref>''Towfigh and Ulrich,'' in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 21 (C.H. Beck 2018, 2nd Edition).</ref>


3. A mechanism for periodic review.
=== (6) Mandatory Consultation following the Decision under Paragraph 5 ===
Article 45(6) GDPR establishes that following the repeal, amendment or suspension decision under paragraph 5, the Commission has to enter into consultations with the third country or the international organisation in order to remedy the situation.<ref>''Kuner'', in Kuner Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 45 GDPR, p. 789 (Oxford University Press 2020).</ref> The aim of the negotiations with the Commission is to encourage the third country or international organisation to raise the level of protection of personal data again and to bring it closer to European standards.


4. Identification of the supervisory authority or of authorities holding the responsibility for ensuring and enforcing compliance with the data protection rules (Article 45(2)(b) GDPR and Article 45(2)(3) GDPR).  
=== (7) Transfers in case of Repeal, Amendment or Suspension of the Adequacy Decision ===
Article 45(7) GDPR clarifies that in case the Commission withdraws a previous decision or, in more limited terms, suspends or amends it, transfers can nevertheless take place according to the other instruments provided for in Articles 46-49 of the GDPR (e.g. SCCs or binding corporate rules). The provision expresses a general principle, and applies not only to the case provided for in paragraph 5, but also in cases where an adequacy decision has not been previously adopted.


Additionally, the WP29 has also highlighted the mechanisms that the data protection system, the third country or the international organisation must contain: A supervisory authority, a data protection system that ensures a good level of compliance, providing support and help to data subjects in the exercise of their rights and redress mechanisms, accountability.<ref>''Kuner'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 45 GDPR, p. 789 (Oxford University Press 2020).</ref> Also in line with Article 45 (2)(a) GDPR third countries must ensure the minimum of interference with fundamental rights by providing guarantees for law enforcement and national security access: Clear, precise and accessible rules for data processing. necessity and proportionality must be demonstrated with regards to the legitimate objectives pursued, the processing must be subject to independent oversight, effective remedies must be available to individuals. <ref>WP29, Adequacy Referential, WP 254 rev.01, 28 November 2017, p. 9 (available [https://ec.europa.eu/newsroom/article29/redirection/document/57550 here]). </ref>
=== (8) Adequacy Decisions shall be Published ===
According to Article 45(8) GDPR, the Commission's adequacy decision for third countries, their territories and specific sectors, as well as for international organisations,  must be published in the Official Journal of the European Union, as well as on the Commission's website.<ref>Previous adequacy decisions of the Commission available [https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en here].</ref>  


====Enforcement====
=== (9) Continued Validity ===
As regards the enforcement of Article 45 GDPR, it was also stated in Schrems II judgement (para. 63), that an individual must be able to make a claim to a DPA contesting the compatibility of a data transfer based on an adequacy decision with the protection of privacy and fundamental rights, and the DPA must examine the claim with all due diligence.
Article 45(9) GDPR establishes that decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this provision.
----
----
==Decisions==
==Decisions==

Latest revision as of 14:58, 28 April 2022

Article 45 - General principle for transfers
Gdpricon.png
Chapter 10: Delegated and implementing acts

Legal Text


Article 45 - Transfers on the basis of an adequacy decision

1. A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.

2. When assessing the adequacy of the level of protection, the Commission shall, in particular, take account of the following elements:

(a) the rule of law, respect for human rights and fundamental freedoms, relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, as well as the implementation of such legislation, data protection rules, professional rules and security measures, including rules for the onward transfer of personal data to another third country or international organisation which are complied with in that country or international organisation, case-law, as well as effective and enforceable data subject rights and effective administrative and judicial redress for the data subjects whose personal data are being transferred;
(b) the existence and effective functioning of one or more independent supervisory authorities in the third country or to which an international organisation is subject, with responsibility for ensuring and enforcing compliance with the data protection rules, including adequate enforcement powers, for assisting and advising the data subjects in exercising their rights and for cooperation with the supervisory authorities of the Member States; and
(c) the international commitments the third country or international organisation concerned has entered into, or other obligations arising from legally binding conventions or instruments as well as from its participation in multilateral or regional systems, in particular in relation to the protection of personal data.

3. The Commission, after assessing the adequacy of the level of protection, may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article. The implementing act shall provide for a mechanism for a periodic review, at least every four years, which shall take into account all relevant developments in the third country or international organisation. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the supervisory authority or authorities referred to in point (b) of paragraph 2 of this Article. The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93(2).

4. The Commission shall, on an ongoing basis, monitor developments in third countries and international organisations that could affect the functioning of decisions adopted pursuant to paragraph 3 of this Article and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC.

5. The Commission shall, where available information reveals, in particular following the review referred to in paragraph 3 of this Article, that a third country, a territory or one or more specified sectors within a third country, or an international organisation no longer ensures an adequate level of protection within the meaning of paragraph 2 of this Article, to the extent necessary, repeal, amend or suspend the decision referred to in paragraph 3 of this Article by means of implementing acts without retro-active effect. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).

On duly justified imperative grounds of urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93(3).

6. The Commission shall enter into consultations with the third country or international organisation with a view to remedying the situation giving rise to the decision made pursuant to paragraph 5.

7. A decision pursuant to paragraph 5 of this Article is without prejudice to transfers of personal data to the third country, a territory or one or more specified sectors within that third country, or the international organisation in question pursuant to Articles 46 to 49.

8. The Commission shall publish in the Official Journal of the European Union and on its website a list of the third countries, territories and specified sectors within a third country and international organisations for which it has decided that an adequate level of protection is or is no longer ensured.

9. Decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this Article.

Relevant Recitals

Recital 103: Adequacy Decisions
The Commission may decide with effect for the entire Union that a third country, a territory or specified sector within a third country, or an international organisation, offers an adequate level of data protection, thus providing legal certainty and uniformity throughout the Union as regards the third country or international organisation which is considered to provide such level of protection. In such cases, transfers of personal data to that third country or international organisation may take place without the need to obtain any further authorisation. The Commission may also decide, having given notice and a full statement setting out the reasons to the third country or international organisation, to revoke such a decision.

Recital 104: Assessment Criteria for Adequacy Decisions
In line with the fundamental values on which the Union is founded, in particular the protection of human rights, the Commission should, in its assessment of the third country, or of a territory or specified sector within a third country, take into account how a particular third country respects the rule of law, access to justice as well as international human rights norms and standards and its general and sectoral law, including legislation concerning public security, defence and national security as well as public order and criminal law. The adoption of an adequacy decision with regard to a territory or a specified sector in a third country should take into account clear and objective criteria, such as specific processing activities and the scope of applicable legal standards and legislation in force in the third country. The third country should offer guarantees ensuring an adequate level of protection essentially equivalent to that ensured within the Union, in particular where personal data are processed in one or several specific sectors. In particular, the third country should ensure effective independent data protection supervision and should provide for cooperation mechanisms with the Member States' data protection authorities, and the data subjects should be provided with effective and enforceable rights and effective administrative and judicial redress.

Recital 105: Considering International Obligations for Adequacy Decision
Apart from the international commitments the third country or international organisation has entered into, the Commission should take account of obligations arising from the third country's or international organisation's participation in multilateral or regional systems in particular in relation to the protection of personal data, as well as the implementation of such obligations. In particular, the third country's accession to the Council of Europe Convention of 28 January 1981 for the Protection of Individuals with regard to the Automatic Processing of Personal Data and its Additional Protocol should be taken into account. The Commission should consult the Board when assessing the level of protection in third countries or international organisations.

Recital 106: Monitoring the Functioning of Adequacy Decisions
The Commission should monitor the functioning of decisions on the level of protection in a third country, a territory or specified sector within a third country, or an international organisation, and monitor the functioning of decisions adopted on the basis of Article 25(6) or Article 26(4) of Directive 95/46/EC. In its adequacy decisions, the Commission should provide for a periodic review mechanism of their functioning. That periodic review should be conducted in consultation with the third country or international organisation in question and take into account all relevant developments in the third country or international organisation. For the purposes of monitoring and of carrying out the periodic reviews, the Commission should take into consideration the views and findings of the European Parliament and of the Council as well as of other relevant bodies and sources. The Commission should evaluate, within a reasonable time, the functioning of the latter decisions and report any relevant findings to the Committee within the meaning of Regulation (EU) No 182/2011 of the European Parliament and of the Council as established under this Regulation, to the European Parliament and to the Council.

Recital 107: Obligations when a Adequate Level of Data Protection is No Longer Ensured
The Commission may recognise that a third country, a territory or a specified sector within a third country, or an international organisation no longer ensures an adequate level of data protection. Consequently the transfer of personal data to that third country or international organisation should be prohibited, unless the requirements in this Regulation relating to transfers subject to appropriate safeguards, including binding corporate rules, and derogations for specific situations are fulfilled. In that case, provision should be made for consultations between the Commission and such third countries or international organisations. The Commission should, in a timely manner, inform the third country or international organisation of the reasons and enter into consultations with it in order to remedy the situation.

Commentary

Article 45 GDPR refers to the complex issue of international data transfers. The huge amounts of data transferred from the EU to third countries created the necessity to adopt provisions that could ensure the implementation of precautionary measures to protect the transfers. The level of protection that should be achieved is promoted and delimited in Chapter V of the GDPR. Chapter V of the GDPR creates a three-tiered structure for legal bases for international data transfers, with adequacy decisions being at the top, appropriate safeguards in the middle, and negotiations at the bottom.[1] On the basis of Art. 45 GDPR, the European Commission (Commission) has the power to determine whether a country outside the EU offers an adequate, "essentially equivalent" level of data protection than the EU. Adequacy means that the rules implemented in the third countries or international organisations are effective in practice.[2] The Commission has so far recognised the following countries as providing adequate protection by means of 'adequacy decisions': Andorra, Argentina, Canada (only commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom (under the GDPR and the LED) and Uruguay. These decisions entail that personal data can be transferred from the EU (as well as Norway, Liechtenstein and Iceland) to these third countries without additional safeguards, that these transfers will be assimilated to intra-EU transmissions of data.[3]

(1) Adequacy Decision

Under Article 45 GDPR, a transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question, ensures an adequate level of protection. The expression 'adequate level of protection' means that the recipient,  by virtue of its national legislation or international obligations, ensures a level of protection of freedoms and fundamental rights which is 'essentially equivalent' to the one guaranteed in the Union in the light of the Charter.[4] Although the resources used by a third country may differ from those used in the EU, they must nevertheless prove to be equally effective in practice.[5] The main consequence of the adequacy decision is that, if it is adopted, the transfer "shall not require any specific authorisation".

(2) Criteria for the Adequacy Decision

Article 45(2) GDPR sets out a number of criteria that the Commission must take into account while considering the adequacy of a third country or an international organisation. This list is not exhaustive[6] and includes at least the following elements:

(a) Rule of Law

In assessing the adequacy of a third country or international organisation, the Commission shall take into account, among others, the rule of law, respect for human rights and fundamental freedoms, relevant legislation and its implemenation, data protection rules and security measures(including rules for the onward transfer of personal data to another third country), case-law, effective and enforceable data subject rights, as well as effective administrative and judicial redress for the data subjects whose personal data are being transferred. These criteria assume a minimum level of human rights and fundamental freedoms. Third countries or international organisations must ensure minimum of interference with fundamental rights by providing guarantees for law enforcement and national security access to data. On this topic, the Article 29 Working Party (WP29) has also identified four essential guarantees: (i) processing should be based on clear, precise and accessible rules (legal basis); (ii) necessity and proportionality with regards to legitimate objectives pursued need to be demonstrated; (iii) the processing has to be subject to independent oversight; and (iv) effective remedies need to be available to the individuals. Although these were actually originated from the jurisprudence of the Court of Justice of the European Union (CJEU) and the European Court of Human Rights (ECHR) in the field of surveillance, the WP29 considers that these four guarantees also apply and need to be respected by all third countries for access to data for national security or law enforcement purposes, in order to be considered adequate.[7]

(b) Independent Supervisory Authorities

The Commission will have to ponder the existence and effective functioning of one or more independent DPAs in the third country, including adequate enforcement powers. The independent and effective DPAs shall be mandated to monitor the respect of the third-country or intra-organisational data protection rules. The authorities should also advise data subjects and cooperate with the DPAs of the Member States.[8]

(c) International Obligations

Finally, the international commitments the third country or international organisation concerned has entered into should be taken into consideration, in particular those related to the protection of personal data. This criterion is intended to verify that the international commitments in question do not conflict with the criteria listed above. On the other hand, the presence of international agreements that promote or facilitate the implementation of a more efficient personal data protection system must be positively taken into account.[9]

Essential elements

The criteria listed above are intended as a guide and should not be understood in an overly restrictive sense. This means that the third country does not have to implement the identical measures of protection provided by the EU in order for their data protection system to be deemed adequate.The fundamental different ideas on the protection of personal data among the different states, in combination with the economic policy and entrepreneurial freedoms promoted by the EU, leave space for adaptation for the third countries. It must also be noted that, an adequacy decision cannot regulate the exchange of data for the purpose of national security or the common foreign and security policy.[10]

That said, certain elements of the European order must always be respected. In particular, from a substantive perspective, a third country or international organisation’s system must contain at least the following basic content: (i) rules on basic data protection concepts and/or principles should exist; (ii) grounds for lawful and fair processing for legitimate purposes should be set in a sufficiently clear manner; (iii) the principle of purpose limitation; (iv) data quality and proportionality; (v) data retention; (vi) security and confidentiality; (vii) transparency should be recognized; (viii) the data subject should have at least the right of access, rectification, erasure and objection; and (ix) restrictions on onward transfers are foreseen.

The necessary guarantees are not limited to those of a substantial nature. Indeed, the European authorities have clarified that an adequate level of protection cannot be guaranteed without at least the following elements: (i) the presence of at least one independent, impartial, properly funded DPA with investigative powers; (ii) the existence of a data protection system that is shared and known by controllers and data subjects; (iii) an accountability system for controllers; and, finally, (iv) the existence of effective administrative and judicial redress, including compensation for damages as a result of the unlawful processing of  personal dataArticle 45 GDPR refers to the complex issue of international data transfers. The huge amounts of data transferred from the EU to third countries created the necessity to adopt provisions that could ensure the implementation of precautionary measures to protect the transfers. The level of protection that should be achieved is promoted and delimited in Chapter V of the GDPR. Chapter V of the GDPR creates a three-tiered structure for legal bases for international data transfers, with adequacy decisions being at the top, appropriate safeguards in the middle, and negotiations at the bottom..[11]

Article 45 and Schrems II

Although the CJEU judgement C-311/18 (Schrems II) invalidated the Commission Decision 2016/1250 (EU-US Privacy Shield), but affirmed the validity of standard contractual clauses (SCCs), providing that they include effective mechanisms to ensure compliance in practice with the “essentially equivalent” level of protection guaranteed by the GDPR to EU citizens. Below is the summarised version of this judgement.

Facts

Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid.

In its judgment on October 6th 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC.

In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1st 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Articles 7, 8, and 47 of the Charter. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4th 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU.

In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data without ensuring a level of protection that was essentially equivalent to that which was guaranteed by Articles 7 and 8 of the Charter. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable.

Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data.

Holding

The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes.

Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country.

The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were not circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services.

Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid.

The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means. Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify prior to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.

(3) Adoption of the Adequacy Decision

According to Article 45(3) GDPR, after assessing the adequacy of the level of protection of a third country[12] under paragraph 2, the Commission may decide to adopt an adequacy decision by means of an implementing act. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the DPAor authorities referred to in point (b) of paragraph 2 of this provision. The implementing act shall also provide for a mechanism for a periodic review, which should be carried out at least every four years,  taking into account all relevant developments in the third country or international organisation.[13] The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93(2) GDPR. The process in order to adopt an adequacy decision requires the submission of a proposal from the Commission, a non-binding opinion from the European Data Protection Board (EDPB), an approval from representatives of EU countries, and finally, the adoption of the decision by the Commission. The significance of the decision is easily understood due to its effect. After the adoption of a decision, personal data can flow from the EEA to a third country without the requirement of further safeguards.[14] The Commission can issue adequacy decisions for any country that is not an EU Member State or party to the EEA, a territory or one or more specified sectors within one of these countries, as well as an international organisation, as this provision establishes. As mentioned beforehand, so far, the Commission has issued adequacy decisions for the following countries: Andorra, Argentina, Canada (only commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, Republic of Korea , Switzerland, United Kingdom (under the GDPR and the LED) and Uruguay.[15]

(4) Monitoring of Developments in the third Country

Under Article 45(4) GDPR, following the adoption of an adequacy decision, the Commission must regularly examine whether the functioning of an adequacy decision is still correct, both objectively and legally. In any event, such an examination is necessary where there are indications which give rise to doubts in that regard.  This continuous adequacy monitoring also requires dialogue with the authorities of the third country concerned. The Commission may also continue to do so with the support of the EDPB in accordance with Article 70(1)(b) GDPR.[16]

(5) Repeal, Amendment or Suspension of the Adequacy Decision

According to Article 45(5) GDPR, the continued monitoring referred to in paragraph 3, or other information which has come to light, may demonstrate that the third country does not ensure the essentially equivalent level of protection referred to in paragraph 2, and that the initial adequacy decision is therefore no longer accurate. In such circumstances, the Commission is required, to the extent necessary, to repeal, amend, or suspend the initial decision by means of implementing acts without retro-active effects.[17] The decision-making procedure referred to in Article 93(2) GDPR shall apply unless there are urgency elements requiring an immediate decision. In that case, the procedure provided for in Article 93(3) GDPR shall apply. This allows the Commission to react on short notice, where appropriate, to changes in circumstances within the third country or the international organisation, and to amend the adequacy decision. Whether there is a duly justified case must be decided on a case-by-case basis.[18]

(6) Mandatory Consultation following the Decision under Paragraph 5

Article 45(6) GDPR establishes that following the repeal, amendment or suspension decision under paragraph 5, the Commission has to enter into consultations with the third country or the international organisation in order to remedy the situation.[19] The aim of the negotiations with the Commission is to encourage the third country or international organisation to raise the level of protection of personal data again and to bring it closer to European standards.

(7) Transfers in case of Repeal, Amendment or Suspension of the Adequacy Decision

Article 45(7) GDPR clarifies that in case the Commission withdraws a previous decision or, in more limited terms, suspends or amends it, transfers can nevertheless take place according to the other instruments provided for in Articles 46-49 of the GDPR (e.g. SCCs or binding corporate rules). The provision expresses a general principle, and applies not only to the case provided for in paragraph 5, but also in cases where an adequacy decision has not been previously adopted.

(8) Adequacy Decisions shall be Published

According to Article 45(8) GDPR, the Commission's adequacy decision for third countries, their territories and specific sectors, as well as for international organisations,  must be published in the Official Journal of the European Union, as well as on the Commission's website.[20]

(9) Continued Validity

Article 45(9) GDPR establishes that decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this provision.


Decisions

→ You can find all related decisions in Category:Article 45 GDPR

References

  1. Kuner, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 45 GDPR, p. 774 (Oxford University Press 2020).
  2. WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, p. 3 (available here).
  3. The  adequacy decisions which are currently adopted can be found here.
  4. CJEU, Case C-311/18, Facebook Ireland and Schrems, 16 July 2020, margin number 94 (available here). The WP29 adhered to this interpretation, further stating that the third country's rules must comply with a "core" of principles relating both to the content of data protection rules and their enforcement, based on the GDPR, the Charter of Fundamental Rights of the European Union (CFR) and other relevant international instruments, such as Council of Europe Convention 108. See, WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, p. 3 (available here).
  5. For example, a regulation based on voluntary commitment is not excluded from the outset. However, effective monitoring and control mechanisms will then have to be put in place in the third country to identify and punish in practice any breaches of rules guaranteeing the protection of fundamental rights, in particular the right to respect for privacy and the right to the protection of personal data. See, Zerdick, in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 6 (C.H. Beck 2018, 2nd Edition).
  6. Zerdick, in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 6 (C.H. Beck 2018, 2nd Edition).
  7. The clarification is probably made following the Snowden revelations on mass surveillance by the US government. See, WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, p. 9 (available here).
  8. Towfigh and Ulrich, in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 12 (C.H. Beck 2018, 2nd Edition).
  9. Towfigh and Ulrich, in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 13 (C.H. Beck 2018, 2nd Edition).
  10. See, European Commission, Decision on on the adequate protection of personal data contained in the Passenger Name Record of air passengers transferred to the United States, 2004/535/EG, 14 May 2004, repealed by the CJEU, Joined Cases C-317/04 and C-318/04, Parliament v Council, 30 May 2006 (available here); also see Philipp, Öffentlichkeit bei Ratsentscheidungen gefordert, in EuZW, Volume 17 (2006), p. 357.
  11. WP29, ‘Adequacy Referential’, 18/EN WP 254 rev.01, 6 February 2018, pp. 7-8 (available here).
  12. Or a territory or one or more specified sectors within a third country, or an international organisation.
  13. This is intended to force the Commission to regularly review its adequacy decisions and to counter possible changes in the data protection situation in a third country, for example through legislative changes. See, Towfigh and Ulrich, in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 19 (C.H. Beck 2018, 2nd Edition).
  14. DPC, ‘Transfers of Personal Data to Third Countries or International Organisations’ (available here) (accessed on 28 April 2022).
  15. Office Of The Data Protection Ombudsman, Transfers on the basis of an adequacy decision (available here) (accessed on 28 April 2022).
  16. Zerdick, in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 45 GDPR, margin number 22 (C.H. Beck 2018, 2nd Edition).
  17. The absence of a retroactive effect departures from EU law and avoids the disappearance of an EU act from the legal order from the date of entering into force (ex tunc). See, Lenaerts, Maselis,Gutman, EU Procedural Law, locations 18058 -18065 (Oxford University Press 2014).
  18. Towfigh and Ulrich, in Sydow, Europäische Datenschutzgrundverordnung, Article 45 GDPR, margin number 21 (C.H. Beck 2018, 2nd Edition).
  19. Kuner, in Kuner Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 45 GDPR, p. 789 (Oxford University Press 2020).
  20. Previous adequacy decisions of the Commission available here.