- The ECJ states that national data protection supervisory authorities are authorized and independent to examine transfers of personal data to third countries.
- Commission Decision 2000/520 (Safe Harbor) is invalid because it does not guarantee a level of data protection equivalent to Union law and effective legal protection.
- Exceptions for national security or public interests may only limit data protection to what is absolutely necessary; comprehensive access violates fundamental rights.
The Judgment of the ECJ in the case of Schrems of October 6, 2015:
Binding of data protection supervisory authorities:
36 In those circumstances, the High Court decided to stay the proceedings and refer the following questions to the Court for a preliminary ruling:
1. is a independent officerwhich is entrusted by law with the administration and enforcement of data protection legislation, when examining a complaint lodged with it that personal data were being transferred to a third country (in this case, the United States of America) whose law and practice did not ensure adequate protection of the data subjects, in the light of Articles 7, 8 and 47 of the Charter, without prejudice to the provisions of Article 25(6) of Directive 95/46, absolutely bound by the Union’s finding to the contrary in Decision 2000/520?
(2) Or, instead, may and/or shall the officer consider in light of factual developments that have occurred since the Commission first published its decision, conduct its own investigations into this matter?
The ECJ’s response:
47 Since the national supervisory authorities are required by Article 8(3) of the Charter and Article 28 of Directive 95/46 to monitor compliance with the Union rules on the protection of individuals with regard to the processing of personal data, it is each of them has the power to verify that a transfer of personal data from its Member State to a third country complies with the requirements laid down in Directive 95/46.
[…]50 For the purpose of monitoring transfers of personal data to third countries by reference to the level of protection of those data in the third country concerned, Article 25 of Directive 95/46 imposes a number of obligations on the Member States and the Commission. In particular, according to this article, as the Advocate General pointed out in n. 86 of his Opinion, the Determination of whether a third country ensures an adequate level of protection to be made by both the Member States and the Commission.
[…]52 As long as the Commission’s decision has not been annulled by the Court of Justice, the Member States and their bodies, which include their independent supervisory bodies, may, thus not take any measures contrary to this Decisionsuch as legal acts establishing with binding effect that the third country to which the decision relates does not ensure an adequate level of protection. Indeed, the acts of the Union institutions are in principle subject to a presumption of legality […].
53 A Commission decision adopted pursuant to Article 25(6) of Directive 95/46, such as Decision 2000/520 may not, however, prevent persons whose personal data have been or may be transferred to a third country from making a submission within the meaning of Article 28(4) of the Directive to the national supervisory authorities for the protection of the rights and freedoms concerning those persons with regard to the processing of such data. Similarly, as the Advocate General has pointed out, in particular in points 61, 93 and 116 of his Opinion, such a decision may not affect the powers conferred on the national supervisory authorities by Article 8(3) of the Charter and by Article 28 of Directive neither eliminate nor limit the powers explicitly granted.
[…]
57 Rather, Article 28 of Directive 95/46 applies by its very nature to any processing of personal data. Therefore, even if the Commission has taken a decision under Article 25(6) of the Directive, when a person approaches the national supervisory authorities with a request for the protection of his or her rights and freedoms with regard to the processing of his or her personal data, the national supervisory authorities must be able to examine in complete independencewhether the transmission of these data complies with the requirements set out in the Directive.
[…]61 Nevertheless the Court of Justice alone is competent to declare the invalidity of an act of European Union law such as a Commission decision adopted under Article 25(6) of Directive 95/46, the exclusivity of this jurisdiction being intended to guarantee legal certainty by ensuring the uniform application of Union law […].
62 Although national courts are entitled to review the validity of a Union act such as a Commission decision adopted under Article 25(6) of Directive 95/46, they do not have the power themselves to find that such an act is invalid […]. A fortiori, when examining a submission within the meaning of Article 28(4) of the Directive concerning the compatibility of a Commission decision taken pursuant to Article 25(6) of the Directive with the protection of privacy and of the freedoms and fundamental rights of individuals, the national supervisory authorities are not themselves empowered to declare that such a decision is invalid..
[…]
64 If the supervisory authority concludes that the argument on which such a submission is based is unfounded and therefore rejects the submission, the person from whom the submission originated must, in accordance with the second subparagraph of Article 28(3) of Directive 95/46 in the light of Article 47 of the Charter have recourse to the courtsso that it can challenge such a decision adversely affecting it before the national courts. In view of the case-law cited in paragraphs 61 and 62 of the present judgment these courts must stay the proceedings and submit to the Court of Justice a reference for a preliminary ruling on validity, if they consider that one or more of the grounds for invalidity raised by the parties or, as the case may be, examined ex officio, are valid (see, to that effect, T & L Sugars and Sidul Açúcares v Commission, C‑456/13 P, EU:C:2015:284, paragraph 48 and the case-law cited therein).
On the validity of Decision 2000/520 (Recognition of adequacy:
[…]73 It is true that the word ‘adequate’ in Article 25(6) of Directive 95/46 implies that it cannot be required that a third country guarantee a level of protection identical to that guaranteed by the Union legal order. However, as the Advocate General stated in point 141 of his Opinion, the term ‘adequate level of protection’ must be understood as meaning that it is required that the third country effectively ensures, by virtue of its national legislation or international obligations, a level of protection of freedoms and fundamental rights equivalent in substance to that guaranteed in the Union by virtue of Directive 95/46 in the light of the Charter. Indeed, without such a requirement, the objective mentioned in the preceding paragraph would be disregarded. Moreover, the high level of protection guaranteed by Directive 95/46 in the light of the Charter could easily be circumvented by transferring personal data from the Union to third countries for processing.
[…]75 In these circumstances, the Commission has an obligation when considering the level of protection afforded by a third country, assess the content of the rules in force in that country resulting from its domestic legislation or international obligations, as well as the practices used to ensure compliance with those rules, whereby according to Art. 25 (2) of Directive 95/46 it must take into account all circumstances that play a role in a transfer of personal data to a third country.
76 Similarly, in view of the fact that the level of protection afforded by a third country may be subject to change, it is for the Commission, following the adoption of a decision pursuant to Article 25(6) of Directive 95/46 in check at regular intervalswhether the finding on the adequacy of the level of protection provided by the third country in question is still justified in factual and legal terms. Such an examination is required in any case if there are indications that raise doubts about this.
77 Moreover, as the Advocate General pointed out in points 134 and 135 of his Opinion, when examining the validity of a Commission decision adopted under Article 25(6) of Directive 95/46, the following must be taken into account also to take into account circumstances that have arisen after the adoption of this decision.
[…]81 Even if the recourse of a third country to a Self certification system as such does not violate the requirement in Art. 25(6) of Directive 95/46 that an adequate level of protection must be ensured in the third country concerned “by reason of its domestic law or international obligations,” the reliability of such a system with respect to this requirement rests substantially on the Creation of effective monitoring and control mechanisms, which make it possible to identify and sanction in practice any violations of rules ensuring the protection of fundamental rights, in particular the right to respect for privacy and the right to the protection of personal data.
82 In the present case, the safe harbor principles set forth in paragraph 2 of Annex I to Decision 2000/520 are “intended solely for use by U.S. organizations that receive personal data from the European Union to qualify for the ’safe harbor’ and the resulting presumption of ‘adequacy’ of data protection.” Thus, these Principles apply only to self-certified U.S. organizations that receive personal data from the Union, Without requiring compliance with the aforementioned principles by the U.S. authorities.
[…]84 In addition, according to paragraph 4 of Annex I to Decision 2000/520, the application of the above principles may be limited, inter alia, “in so far as. Requirements of national security, public interest or the implementation of laws must be taken into account”, as well as “by statutory law, state regulatory statute, or case law creating inconsistent obligations or express authorizations, provided that the organization, in exercising those authorizations, can demonstrate that noncompliance with the principles was limited to the extent that compliance with overriding legitimate interests required by that same authorization.”
[…]86 Decision 2000/520 thus gives priority to the “Needs of national security, public interest, or enforcement of laws” given priority over “safe harbor” principles; by virtue of this precedence, self-certified U.S. organizations receiving personal information from the Union are required, without limitation, to disregard the safe harbor principles if they conflict with, and are therefore found to be inconsistent with, those requirements.
87 In view of their general character therefore, the exception in paragraph 4 of Annex I to Decision 2000/520 allows interference with the fundamental rights of individuals whose personal data are or may be transferred from the Union to the United States on the basis of requirements of national security, public interest or United States law. For the purposes of determining the existence of an interference with the fundamental right to respect for private life, it is not relevant whether the privacy information in question is of a sensitive nature or whether the individuals concerned might suffer prejudice as a result of the interference ([…]).
[…]89 In addition, Decision 2000/520. does not contain a finding on the existence of effective judicial protection against such interference. As the Advocate General pointed out in points 204 to 206 of his Opinion, the private arbitration mechanisms and the proceedings before the Federal Trade Commission, whose powers, described in particular in FAQ 11 in Annex II to the Decision, are limited to commercial disputes, relate to compliance by American undertakings with the safe harbor principles and cannot be used in the context of disputes concerning the legality of interference with fundamental rights resulting from measures of State origin.
90 Moreover, the above analysis of Decision 2000/520 is confirmed by the Commission’s own assessment of the factual situation resulting from the implementation of that decision. It states, in particular, in paragraphs 2 and 3.2 of Communication COM(2013) 846 final and in paragraphs 7.1, 7.2 and 8 of Communication COM(2013) 847 final, reproduced respectively in paragraphs 13 to 16 and in paragraphs 22, 23 and 25 of the present judgment, the Commission found that the U.S. authorities were able to access and process the personal data transferred from the Member States to the United States in a manner that was incompatible with the objectives of their transfer, in particular, and went beyond what was strictly necessary and proportionate to protect national security. Similarly, the Commission found that it was there were no administrative or judicial remedies for the persons concernedwhich allowed them to have access to the data concerning them and, if necessary, to obtain its rectification or deletion.
91 With regard to the level of protection of freedoms and fundamental rights guaranteed within the Union, it should be noted that a Union rule which provides for a Interference with the fundamental rights guaranteed by Articles 7 and 8 of the Charter contains, in accordance with the settled case law of the Court of Justice must provide clear and precise rules on the scope and application of a measure and establish minimum requirements so that individuals whose personal data are concerned have sufficient safeguards to ensure effective protection of their data against risks of misuse and against any unauthorized access to or use of such data. The requirement to have such safeguards is all the more significant when the personal data are processed automatically and there is a significant risk of unauthorized access to them (Digital Rights Ireland and Others, C‑293/12 and C‑594/12, EU:C:2014:238, paras 54 and 55 and the case law cited therein).
92 Moreover, the protection of the fundamental right to respect for private life at Union level requires, above all, that the Limit exceptions to the protection of personal data and its restrictions to what is absolutely necessary (Digital Rights Ireland and Others, C‑293/12 and C‑594/12, EU:C:2014:238, para. 52 and the case law cited therein).
93 Not limited to what is absolutely necessary is a provision that generally the storage of all personal data of all personswhose data have been transferred from the Union to the United States, Without any differentiation, limitation or exception to be carried out on the basis of the objective pursued and Without providing an objective criterionwhich makes it possible to limit the access of the authorities to the data and their subsequent use to very specific, strictly limited purposes that are capable of justifying the interference associated both with the access to these data and with their use ([…]).
94 Specifically, violates a regulation that allows authorities to, generally access the content of electronic communications, the essence of the fundamental right to respect for private life guaranteed by Article 7 of the Charter ([…]).
95 Similarly, a regulation that does not provide for the possibility for the citizen to obtain, by means of a judicial remedy, access to personal data concerning him or to obtain their rectification or erasure, the essence of the fundamental right to effective judicial protection enshrined in Article 47 of the Charter. Indeed, under Article 47(1) of the Charter, any person whose rights or freedoms guaranteed by Union law have been infringed shall have the right to an effective remedy before a tribunal, in accordance with the conditions laid down in that article. In this respect, the very existence of effective judicial review serving to ensure compliance with Union law is inherent in the nature of a State governed by the rule of law ([…]).
[…]98 Therefore, without it being necessary to examine the content of the safe harbor principles, it must be concluded that Article 1 of Decision 2000/520 violates the requirements set forth in Article 25(6) of Directive 95/46 in light of the Charter and is invalid for that reason.
[…] 106 Based on the above considerations, it must be concluded that Decision 2000/520 is invalid.