Bachelor Thesis an Analysis of the EU Data Protection Policy and The
Total Page:16
File Type:pdf, Size:1020Kb
Bachelor Thesis An analysis of the EU data protection policy and the significance of the Maximillian Schrems case July 2019 words:18190 Harpo Vogelsang (s1834371) Faculty of Behavioural management and Social Science Public Governance across Borders First Supervisor: Dr. Claudio Matera Second Supervisor: Prof. Dr. Ramses A. Wessel Abstract The transfer of personal data from EU citizens to third countries requires an adequate level of data protection. In 2013, the revelations by Edward Snowden about mass surveillance practices by US intelligence services attracted a lot of attention. Subsequently, the Austrian privacy activist Maximillian Schrems did not believe that an adequate level of protection of his personal data transferred to the US could be longer guaranteed. Thus, he demanded the suspension of the transfer of his data to the US. The following trial went through all judicial instances, before the European Court of Justice. Ultimately, the Court supported Schrems opinion, declaring the legal basis for the transfer of personal data from the EU to the US invalid. The judgement and its underlying principles directly challenged the EU data protection frame work. Since the judgement in 2015, the Data Protection Directive got replaced by the General Data Protection Regulation and the Commission has announced further policy changes. The purpose of this study is to answer the research question: To what extent do the EU data protection policies reflect the principles upheld in the judgement of the Schrems case? Therefore, a systematic overview of the European data protection framework is given. Initially, the framework before the trial is presented. Afterwards, the judgement and its underlying principles are analyzed. Finally, the current framework and upcoming changes are depicted and the significance of the Schrems case for these legal developments is evaluated. Table of Content 3 1. Introduction.......................................................................................................................... 1 1.1 Research design ................................................................................................................... 4 1.2 Scientific and social relevance............................................................................................ 5 2. The EU data protection framework before 2015..................................................................... 6 2.1 The Data Protection Directive .................................................................................................. 9 2.2 The Safe Harbor Agreement ............................................................................................. 12 2.3 The ePrivacy Directive ....................................................................................................... 14 2.4 Conclusion of the Chapter ................................................................................................. 17 3. The Schrems Case ............................................................................................................... 18 3.1 Background .......................................................................................................................... 18 3.2 The Trial ............................................................................................................................... 21 3.3 The Judgement ................................................................................................................... 22 3.4 Conclusion of the Chapter ................................................................................................. 24 4. The EU data protection framework after 2015 ..................................................................... 25 4.1 The Privacy Shield .............................................................................................................. 27 4.2 The GDPR ........................................................................................................................... 30 4.2.2 Obligations for data controllers and processors ........................................................... 33 4.2.3 Application and enforcement .......................................................................................... 36 4.2.4 Data transfer to third countries ....................................................................................... 37 4.3 The ePrivacy Regulation ......................................................................................................... 38 4.3 Conclusion of the Chapter ................................................................................................. 41 5. Conclusion .......................................................................................................................... 42 6. References .......................................................................................................................... 45 Abbreviations CFR Charter of Fundamental Rights of the European Union CFSP Common Foreign and Security Policy DOC US Department of Commerce DPA Data Protection Authority DPC Data Protection Commissioner DPD Data Protection Directive ECJ European Court of Justice EDPB European Data Protection Board ePD ePrivacy Directive ePR ePrivacy Regulation FTC Federal Trade Commission GDPR General Data Protection Directive NSA National Security Agency OECD Organization for Economic Cooperation and Development OTT Over-the-top services UDHR Universal Declaration of Human Rights Introduction 1. Introduction With the rise of new communication technologies in the past decades the discussion about data protection and privacy received more attention. Especially the handling of personal data by big technology companies concern a growing number of people. They fear the misuse of new and existing technologies while the complexity of the issue gets more confusing. Thus, policy makers were required to enable laws, which protect the privacy of the citizens. In regard to the EU, the first legislation concerning this topic was the Data Protection Directive (DPD). It was applicable from 1994 until 2018, when it got replaced by the General Data Protection Directive (GDPR). In this time period information technologies experienced a rapid growth, today they are indispensable in virtually every aspect of modern life and with recent innovations like self-driving cars, virtual assistants or the internet of things there is no end in sight for this development. However, with new technologies new problems and challenges emerged, on the one hand companies began to collect data from their customers, e.g. for advertisement or personalized services, which led some economists to rate the potential of data so high that they call it “the oil of the 21st century”. On the other hand governments started collecting data of their citizens in the name of security (The Economist, 2017). But, the right to privacy is enshrined in Article 12 of the Universal Declaration of Human Rights (UDHR): “No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks”. Given the fact that the UDHR is not legally binding to states or persons, other legally binding laws such as the DPD or the GDPR are necessary to ensure that this right is not violated and personal data gets exploited. However, it is almost impossible for the lawmakers to keep up with the enormous pace of evolving technologies and the resulting new possibilities to collect personal data (Moses, 2007, pp. 247). Hence, data protection regulations needed to be adapted gradually, often after scandals which gained public attention and lead to demands by privacy activist and Non- Governmental Organizations. In this process the EU took a leading role in the protection of privacy rights, setting today a global standard (Carnevale, 2018). This 1 Introduction paper is going to examine this legal development of data protection legislation in the EU. The DPD’s aims were to protect the rights and freedoms of people while processing personal data as well as to regulate data processing within the EU and data transfers to third countries (Art. 1 DPD). Accordingly, data transfers to third countries were only allowed if third countries guaranteed an “adequate level of protection” (Art. 25 DPD). In the year 2000, the European Commission made the decision, that the United States principles of data protection did comply with the EU Directive, this decision is commonly known as Safe Harbor decision. However, in the following years big (American) technology companies like Google or Facebook were continuously covered in the news, due to controversial practices regarding privacy and data protection. In 2010, after a Wall Street Journal report, Facebook admitted that its most popular game applications shared private user data and contact details of friends with external companies, which used the data for advertisement. According to the American newspaper the data breach affected tens of millions of users, even those who had activated Facebook's strictest privacy settings (Steel & Fowler, 2010). Another example for a violation of privacy rights became public in 2011 when security researchers discovered a hidden file inside Apples mobile devices which stored a complete collection of locations visited by their user in the past year (Arthur, 2011a). In the aftermath, Google and Microsoft had to