New European, U.S. data transfer pact agreed
reuters.com
reuters.com
With the current situation, it’s impossible to create a treaty complying with EU privacy law. (This is a personal opinion, not legal advice).
Otherwise, you could equally argue that is is not possible for the EU to create a treaty that complies with American law.
It seems that the more likely route would involve pressuring the EU's judicial systems to interpret that charter more favorably.
There's pockets of the people who seem to want to leave the EU, but I suspect that's more driven by xenophobia/racism than privacy legislation.
You're looking at it backwards: established interests that hate scrutiny (mostly on "socialist" work regulations, product quality regulations etc) are driving xenophobic sentiment to engineer an EU exit that would ensure they're firmly back in the driving seat at the national level. It's similar to the US "southern strategy" that recruited religious folks to the cause of Big Business, separating them from their working-class interests. "Divide and rule" is still one of the best strategies you can employ.
That's not true.
Under the Data Protection Directive the Commission, acting alone, can do this.
Article 25(6):
"The Commission may find, in accordance with the procedure referred to in Article 31 (2), that a third country ensures an adequate level of protection within the meaning of paragraph 2 of this Article, by reason of its domestic law or of the international commitments it has entered into, particularly upon conclusion of the negotiations referred to in paragraph 5, for the protection of the private lives and basic freedoms and rights of individuals.
Member States shall take the measures necessary to comply with the Commission's decision."
>The pact is so vague about the protection of European citizens that there's a good chance that the European Court of Justice won't accept it
I'd go as far as saying it's almost certain.
If I understood it, the situation got a bit better last years as the parliament has a bit more power now - but I don't know the mechanics.
Disclaimer: This is only my uninformed understanding as an EU citizen.
It's actually not too different from how governments are elected in many countries.
The Schrems case stemmed from the fact the the Irish DPA refused to investigate Facebook's transatlantic data transfer because Safe Harbor was in place. Schrems challenged that decision in the Irish High Court, the HC then referred the case to the CJEU which declared the agreement to be invalid because it violated the Charter of Fundamental Rights.
As an EU citizen, I have suddenly become quite fond of the court institution. It seems to be the only thing in the union that seems occasionally to work as it should. Commission feels outright autocratic when it comes to down issues like this.
The parliament most of the time also acts quite sensible.
They are a relic of the pre-Parliament structure, when stuff got done with treaties and agreements, and should simply be dropped in favour of simple Parliamentary rule. The problem is that turkeys don't vote for Christmas, so national-government apparatchiks will never willingly renounce their power.
It's one of the many states of empasse the current EU structure finds itself stuck into, and it won't be solved by this or that state leaving.
wat?
Americans give so much data to companies.
There is zero chance this would stand up if it was taken to the European Court of Justice, they'd laugh it out of the room just like they did with Safe Harbor.
http://europa.eu/rapid/press-release_IP-16-216_en.htm
This one reads like a big fat nothing. So it's the FTC who will be monitoring if the US companies treat EU citizens' privacy well? Yeah, what could possibly go wrong? It's not like the FTC hasn't already been virtually impotent in punishing privacy violations from US with small fines and "20 year privacy monitoring", which is about the same as credit rating agencies giving big banks AAA ratings in 2008.
EDIT: Oh wait, it's actually the Department of Commerce - only the most corporate-friendly agency in the U.S - the one that will be doing the monitoring. Lovely.
The fix for Safe Harbor was negotiated with Department of Commerce who has no authority to talk about reforming this policy.
Options were
1. Immediately end the ability of US based digital companies to do business in Europe
2. Cave completely and have a few months of normalcy before Europe Commission kills the deal.
This treaty: it must be ratified by Congress in order for it to be considered accepted by the EC. Under the U.S. Constitution, this means it would carry the full force of the law. The Commerce Department wouldn't bear the weight of enforcement.
FISA §702: limits collection to targeted non-U.S. persons of foreign intelligence interest at borders (Upstream) and submission of NSLs to U.S. organizations for data on non-U.S. persons. The Privacy Shield agreement only prohibits mass surveillance.
EO12333 does not apply since that collection occurs outside of the United States, and would not be in the jurisdiction of this agreement.
> Department of Commerce who has no authority to talk about reforming this policy.
No, this agreement was made at the behest of the Senate Committee on Commerce, Science, and Transportation [1]. Since this will be ratified by the Senate, it will carry the full weight of the law.
[1] http://www.commerce.senate.gov/public/index.cfm/pressrelease...
This agreement was made at the request of senators.
Under the U.S. Constitution, all foreign treaties must be ratified by the Senate. This will carry the full weight of the law.
Nothing to see here, walk on...
The regulators wouldn't restrict data transfer - the existing Directive does. The question is not whether the Data Protection agencies can or not restrict data transfers, but whether the courts consider that this new agreement allows companies to comply with the Directive.
" The word 'password' on a computer screen is magnified with a magnifying glass in this picture illustration taken in Berlin May 21, 2013. "
Because that somehow represents a data transfer pact between the EC and the US? I thought that was meant to be a scare-picture of 'hackers'...?
and the "European Commission may be issuing a round-trip to Luxembourg": http://europe-v-facebook.org/PS_update.pdf by @maxschrems