Take-Aways (AI)
  • The ECJ sta­tes that natio­nal data pro­tec­tion super­vi­so­ry aut­ho­ri­ties are aut­ho­ri­zed and inde­pen­dent to exami­ne trans­fers of per­so­nal data to third countries.
  • Com­mis­si­on Decis­i­on 2000/520 (Safe Har­bor) is inva­lid becau­se it does not gua­ran­tee a level of data pro­tec­tion equi­va­lent to Uni­on law and effec­ti­ve legal protection.
  • Excep­ti­ons for natio­nal secu­ri­ty or public inte­rests may only limit data pro­tec­tion to what is abso­lut­e­ly neces­sa­ry; com­pre­hen­si­ve access vio­la­tes fun­da­men­tal rights.

The Judgment of the ECJ in the case of Schrems of Octo­ber 6, 2015:

Bin­ding of data pro­tec­tion super­vi­so­ry authorities:

36 In tho­se cir­cum­stances, the High Court deci­ded to stay the pro­ce­e­dings and refer the fol­lo­wing que­sti­ons to the Court for a preli­mi­na­ry ruling:

1. is a inde­pen­dent offi­cerwhich is ent­ru­sted by law with the admi­ni­stra­ti­on and enforce­ment of data pro­tec­tion legis­la­ti­on, when exami­ning a com­plaint lodged with it that per­so­nal data were being trans­fer­red to a third coun­try (in this case, the United Sta­tes of Ame­ri­ca) who­se law and prac­ti­ce did not ensu­re ade­qua­te pro­tec­tion of the data sub­jects, in the light of Artic­les 7, 8 and 47 of the Char­ter, wit­hout pre­ju­di­ce to the pro­vi­si­ons of Artic­le 25(6) of Direc­ti­ve 95/46, abso­lut­e­ly bound by the Union’s fin­ding to the con­tra­ry in Decis­i­on 2000/520?
(2) Or, instead, may and/or shall the offi­cer con­sider in light of fac­tu­al deve­lo­p­ments that have occur­red sin­ce the Com­mis­si­on first published its decis­i­on, con­duct its own inve­sti­ga­ti­ons into this mat­ter?

The ECJ’s response:

47 Sin­ce the natio­nal super­vi­so­ry aut­ho­ri­ties are requi­red by Artic­le 8(3) of the Char­ter and Artic­le 28 of Direc­ti­ve 95/46 to moni­tor com­pli­ance with the Uni­on rules on the pro­tec­tion of indi­vi­du­als with regard to the pro­ce­s­sing of per­so­nal data, it is each of them has the power to veri­fy that a trans­fer of per­so­nal data from its Mem­ber Sta­te to a third coun­try com­plies with the requi­re­ments laid down in Direc­ti­ve 95/46.

[…]

50 For the pur­po­se of moni­to­ring trans­fers of per­so­nal data to third count­ries by refe­rence to the level of pro­tec­tion of tho­se data in the third coun­try con­cer­ned, Artic­le 25 of Direc­ti­ve 95/46 impo­ses a num­ber of obli­ga­ti­ons on the Mem­ber Sta­tes and the Com­mis­si­on. In par­ti­cu­lar, accor­ding to this artic­le, as the Advo­ca­te Gene­ral poin­ted out in n. 86 of his Opi­ni­on, the Deter­mi­na­ti­on of whe­ther a third coun­try ensu­res an ade­qua­te level of pro­tec­tion to be made by both the Mem­ber Sta­tes and the Com­mis­si­on.

[…]

52 As long as the Commission’s decis­i­on has not been annul­led by the Court of Justi­ce, the Mem­ber Sta­tes and their bodies, which include their inde­pen­dent super­vi­so­ry bodies, may, thus not take any mea­su­res con­tra­ry to this Decis­i­onsuch as legal acts estab­li­shing with bin­ding effect that the third coun­try to which the decis­i­on rela­tes does not ensu­re an ade­qua­te level of pro­tec­tion. Inde­ed, the acts of the Uni­on insti­tu­ti­ons are in prin­ci­ple sub­ject to a pre­sump­ti­on of legality […].

53 A Com­mis­si­on decis­i­on adopted pur­su­ant to Artic­le 25(6) of Direc­ti­ve 95/46, such as Decis­i­on 2000/520 may not, howe­ver, pre­vent per­sons who­se per­so­nal data have been or may be trans­fer­red to a third coun­try from making a sub­mis­si­on within the mea­ning of Artic­le 28(4) of the Direc­ti­ve to the natio­nal super­vi­so­ry aut­ho­ri­ties for the pro­tec­tion of the rights and free­doms con­cer­ning tho­se per­sons with regard to the pro­ce­s­sing of such data. Simi­lar­ly, as the Advo­ca­te Gene­ral has poin­ted out, in par­ti­cu­lar in points 61, 93 and 116 of his Opi­ni­on, such a decis­i­on may not affect the powers con­fer­red on the natio­nal super­vi­so­ry aut­ho­ri­ties by Artic­le 8(3) of the Char­ter and by Artic­le 28 of Direc­ti­ve neither eli­mi­na­te nor limit the powers expli­ci­t­ly gran­ted.

[…]

57 Rather, Artic­le 28 of Direc­ti­ve 95/46 applies by its very natu­re to any pro­ce­s­sing of per­so­nal data. The­r­e­fo­re, even if the Com­mis­si­on has taken a decis­i­on under Artic­le 25(6) of the Direc­ti­ve, when a per­son approa­ches the natio­nal super­vi­so­ry aut­ho­ri­ties with a request for the pro­tec­tion of his or her rights and free­doms with regard to the pro­ce­s­sing of his or her per­so­nal data, the natio­nal super­vi­so­ry aut­ho­ri­ties must be able to exami­ne in com­ple­te inde­pen­dencewhe­ther the trans­mis­si­on of the­se data com­plies with the requi­re­ments set out in the Directive.

[…]

61 Nevert­hel­ess the Court of Justi­ce alo­ne is com­pe­tent to decla­re the inva­li­di­ty of an act of Euro­pean Uni­on law such as a Com­mis­si­on decis­i­on adopted under Artic­le 25(6) of Direc­ti­ve 95/46, the exclu­si­vi­ty of this juris­dic­tion being inten­ded to gua­ran­tee legal cer­tain­ty by ensu­ring the uni­form appli­ca­ti­on of Uni­on law […].

62 Alt­hough natio­nal courts are entit­led to review the vali­di­ty of a Uni­on act such as a Com­mis­si­on decis­i­on adopted under Artic­le 25(6) of Direc­ti­ve 95/46, they do not have the power them­sel­ves to find that such an act is inva­lid […]. A for­tio­ri, when exami­ning a sub­mis­si­on within the mea­ning of Artic­le 28(4) of the Direc­ti­ve con­cer­ning the com­pa­ti­bi­li­ty of a Com­mis­si­on decis­i­on taken pur­su­ant to Artic­le 25(6) of the Direc­ti­ve with the pro­tec­tion of pri­va­cy and of the free­doms and fun­da­men­tal rights of indi­vi­du­als, the natio­nal super­vi­so­ry aut­ho­ri­ties are not them­sel­ves empowered to decla­re that such a decis­i­on is inva­lid..

[…]

64 If the super­vi­so­ry aut­ho­ri­ty con­clu­des that the argu­ment on which such a sub­mis­si­on is based is unfoun­ded and the­r­e­fo­re rejects the sub­mis­si­on, the per­son from whom the sub­mis­si­on ori­gi­na­ted must, in accordance with the second sub­pa­ra­graph of Artic­le 28(3) of Direc­ti­ve 95/46 in the light of Artic­le 47 of the Char­ter have recour­se to the courtsso that it can chall­enge such a decis­i­on adver­se­ly affec­ting it befo­re the natio­nal courts. In view of the case-law cited in para­graphs 61 and 62 of the pre­sent judgment the­se courts must stay the pro­ce­e­dings and sub­mit to the Court of Justi­ce a refe­rence for a preli­mi­na­ry ruling on vali­di­ty, if they con­sider that one or more of the grounds for inva­li­di­ty rai­sed by the par­ties or, as the case may be, exami­ned ex offi­cio, are valid (see, to that effect, T & L Sug­ars and Sidul Açú­ca­res v Com­mis­si­on, C‑456/13 P, EU:C:2015:284, para­graph 48 and the case-law cited therein).

On the vali­di­ty of Decis­i­on 2000/520 (Reco­gni­ti­on of adequacy:

[…]

73 It is true that the word ‘ade­qua­te’ in Artic­le 25(6) of Direc­ti­ve 95/46 implies that it can­not be requi­red that a third coun­try gua­ran­tee a level of pro­tec­tion iden­ti­cal to that gua­ran­teed by the Uni­on legal order. Howe­ver, as the Advo­ca­te Gene­ral sta­ted in point 141 of his Opi­ni­on, the term ‘ade­qua­te level of pro­tec­tion’ must be under­s­tood as mea­ning that it is requi­red that the third coun­try effec­tively ensu­res, by vir­tue of its natio­nal legis­la­ti­on or inter­na­tio­nal obli­ga­ti­ons, a level of pro­tec­tion of free­doms and fun­da­men­tal rights equi­va­lent in sub­stance to that gua­ran­teed in the Uni­on by vir­tue of Direc­ti­ve 95/46 in the light of the Char­ter. Inde­ed, wit­hout such a requi­re­ment, the objec­ti­ve men­tio­ned in the pre­ce­ding para­graph would be dis­re­gard­ed. Moreo­ver, the high level of pro­tec­tion gua­ran­teed by Direc­ti­ve 95/46 in the light of the Char­ter could easi­ly be cir­cum­ven­ted by trans­fer­ring per­so­nal data from the Uni­on to third count­ries for processing.

[…]

75 In the­se cir­cum­stances, the Com­mis­si­on has an obli­ga­ti­on when con­side­ring the level of pro­tec­tion affor­ded by a third coun­try, assess the con­tent of the rules in force in that coun­try resul­ting from its dome­stic legis­la­ti­on or inter­na­tio­nal obli­ga­ti­ons, as well as the prac­ti­ces used to ensu­re com­pli­ance with tho­se rules, wher­eby accor­ding to Art. 25 (2) of Direc­ti­ve 95/46 it must take into account all cir­cum­stances that play a role in a trans­fer of per­so­nal data to a third country.

76 Simi­lar­ly, in view of the fact that the level of pro­tec­tion affor­ded by a third coun­try may be sub­ject to chan­ge, it is for the Com­mis­si­on, fol­lo­wing the adop­ti­on of a decis­i­on pur­su­ant to Artic­le 25(6) of Direc­ti­ve 95/46 in check at regu­lar inter­valswhe­ther the fin­ding on the ade­qua­cy of the level of pro­tec­tion pro­vi­ded by the third coun­try in que­sti­on is still justi­fi­ed in fac­tu­al and legal terms. Such an exami­na­ti­on is requi­red in any case if the­re are indi­ca­ti­ons that rai­se doubts about this.

77 Moreo­ver, as the Advo­ca­te Gene­ral poin­ted out in points 134 and 135 of his Opi­ni­on, when exami­ning the vali­di­ty of a Com­mis­si­on decis­i­on adopted under Artic­le 25(6) of Direc­ti­ve 95/46, the fol­lo­wing must be taken into account also to take into account cir­cum­stances that have ari­sen after the adop­ti­on of this decis­i­on.

[…]

81 Even if the recour­se of a third coun­try to a Self cer­ti­fi­ca­ti­on system as such does not vio­la­te the requi­re­ment in Art. 25(6) of Direc­ti­ve 95/46 that an ade­qua­te level of pro­tec­tion must be ensu­red in the third coun­try con­cer­ned “by rea­son of its dome­stic law or inter­na­tio­nal obli­ga­ti­ons,” the relia­bi­li­ty of such a system with respect to this requi­re­ment rests sub­stan­ti­al­ly on the Crea­ti­on of effec­ti­ve moni­to­ring and con­trol mecha­nisms, which make it pos­si­ble to iden­ti­fy and sanc­tion in prac­ti­ce any vio­la­ti­ons of rules ensu­ring the pro­tec­tion of fun­da­men­tal rights, in par­ti­cu­lar the right to respect for pri­va­cy and the right to the pro­tec­tion of per­so­nal data.

82 In the pre­sent case, the safe har­bor prin­ci­ples set forth in para­graph 2 of Annex I to Decis­i­on 2000/520 are “inten­ded sole­ly for use by U.S. orga­nizati­ons that recei­ve per­so­nal data from the Euro­pean Uni­on to qua­li­fy for the ’safe har­bor’ and the resul­ting pre­sump­ti­on of ‘ade­qua­cy’ of data pro­tec­tion.” Thus, the­se Prin­ci­ples app­ly only to self-cer­ti­fi­ed U.S. orga­nizati­ons that recei­ve per­so­nal data from the Uni­on, Wit­hout requi­ring com­pli­ance with the afo­re­men­tio­ned prin­ci­ples by the U.S. aut­ho­ri­ties.

[…]

84 In addi­ti­on, accor­ding to para­graph 4 of Annex I to Decis­i­on 2000/520, the appli­ca­ti­on of the abo­ve prin­ci­ples may be limi­t­ed, inter alia, “in so far as. Requi­re­ments of natio­nal secu­ri­ty, public inte­rest or the imple­men­ta­ti­on of laws must be taken into account”, as well as “by sta­tu­to­ry law, sta­te regu­la­to­ry sta­tu­te, or case law crea­ting incon­si­stent obli­ga­ti­ons or express aut­ho­rizati­ons, pro­vi­ded that the orga­nizati­on, in exer­cis­ing tho­se aut­ho­rizati­ons, can demon­stra­te that non­com­pli­ance with the prin­ci­ples was limi­t­ed to the ext­ent that com­pli­ance with over­ri­ding legi­ti­ma­te inte­rests requi­red by that same authorization.”

[…]

86 Decis­i­on 2000/520 thus gives prio­ri­ty to the “Needs of natio­nal secu­ri­ty, public inte­rest, or enforce­ment of laws” given prio­ri­ty over “safe har­bor” prin­ci­ples; by vir­tue of this pre­ce­dence, self-cer­ti­fi­ed U.S. orga­nizati­ons recei­ving per­so­nal infor­ma­ti­on from the Uni­on are requi­red, wit­hout limi­ta­ti­on, to dis­re­gard the safe har­bor prin­ci­ples if they con­flict with, and are the­r­e­fo­re found to be incon­si­stent with, tho­se requirements.

87 In view of their gene­ral cha­rac­ter the­r­e­fo­re, the excep­ti­on in para­graph 4 of Annex I to Decis­i­on 2000/520 allo­ws inter­fe­rence with the fun­da­men­tal rights of indi­vi­du­als who­se per­so­nal data are or may be trans­fer­red from the Uni­on to the United Sta­tes on the basis of requi­re­ments of natio­nal secu­ri­ty, public inte­rest or United Sta­tes law. For the pur­po­ses of deter­mi­ning the exi­stence of an inter­fe­rence with the fun­da­men­tal right to respect for pri­va­te life, it is not rele­vant whe­ther the pri­va­cy infor­ma­ti­on in que­sti­on is of a sen­si­ti­ve natu­re or whe­ther the indi­vi­du­als con­cer­ned might suf­fer pre­ju­di­ce as a result of the interference ([…]).

[…]

89 In addi­ti­on, Decis­i­on 2000/520. does not con­tain a fin­ding on the exi­stence of effec­ti­ve judi­cial pro­tec­tion against such inter­fe­rence. As the Advo­ca­te Gene­ral poin­ted out in points 204 to 206 of his Opi­ni­on, the pri­va­te arbi­tra­ti­on mecha­nisms and the pro­ce­e­dings befo­re the Fede­ral Trade Com­mis­si­on, who­se powers, descri­bed in par­ti­cu­lar in FAQ 11 in Annex II to the Decis­i­on, are limi­t­ed to com­mer­cial dis­pu­tes, rela­te to com­pli­ance by Ame­ri­can under­ta­kings with the safe har­bor prin­ci­ples and can­not be used in the con­text of dis­pu­tes con­cer­ning the lega­li­ty of inter­fe­rence with fun­da­men­tal rights resul­ting from mea­su­res of Sta­te origin.

90 Moreo­ver, the abo­ve ana­ly­sis of Decis­i­on 2000/520 is con­firm­ed by the Commission’s own assess­ment of the fac­tu­al situa­ti­on resul­ting from the imple­men­ta­ti­on of that decis­i­on. It sta­tes, in par­ti­cu­lar, in para­graphs 2 and 3.2 of Com­mu­ni­ca­ti­on COM(2013) 846 final and in para­graphs 7.1, 7.2 and 8 of Com­mu­ni­ca­ti­on COM(2013) 847 final, repro­du­ced respec­tively in para­graphs 13 to 16 and in para­graphs 22, 23 and 25 of the pre­sent judgment, the Com­mis­si­on found that the U.S. aut­ho­ri­ties were able to access and pro­cess the per­so­nal data trans­fer­red from the Mem­ber Sta­tes to the United Sta­tes in a man­ner that was incom­pa­ti­ble with the objec­ti­ves of their trans­fer, in par­ti­cu­lar, and went bey­ond what was strict­ly neces­sa­ry and pro­por­tio­na­te to pro­tect natio­nal secu­ri­ty. Simi­lar­ly, the Com­mis­si­on found that it was the­re were no admi­ni­stra­ti­ve or judi­cial reme­dies for the per­sons con­cer­nedwhich allo­wed them to have access to the data con­cer­ning them and, if neces­sa­ry, to obtain its rec­ti­fi­ca­ti­on or deletion.

91 With regard to the level of pro­tec­tion of free­doms and fun­da­men­tal rights gua­ran­teed within the Uni­on, it should be noted that a Uni­on rule which pro­vi­des for a Inter­fe­rence with the fun­da­men­tal rights gua­ran­teed by Artic­les 7 and 8 of the Char­ter con­ta­ins, in accordance with the sett­led case law of the Court of Justi­ce must pro­vi­de clear and pre­cise rules on the scope and appli­ca­ti­on of a mea­su­re and estab­lish mini­mum requi­re­ments so that indi­vi­du­als who­se per­so­nal data are con­cer­ned have suf­fi­ci­ent safe­guards to ensu­re effec­ti­ve pro­tec­tion of their data against risks of misu­se and against any unaut­ho­ri­zed access to or use of such data. The requi­re­ment to have such safe­guards is all the more signi­fi­cant when the per­so­nal data are pro­ce­s­sed auto­ma­ti­cal­ly and the­re is a signi­fi­cant risk of unaut­ho­ri­zed access to them (Digi­tal Rights Ire­land and Others, C‑293/12 and C‑594/12, EU:C:2014:238, paras 54 and 55 and the case law cited therein).

92 Moreo­ver, the pro­tec­tion of the fun­da­men­tal right to respect for pri­va­te life at Uni­on level requi­res, abo­ve all, that the Limit excep­ti­ons to the pro­tec­tion of per­so­nal data and its rest­ric­tions to what is abso­lut­e­ly neces­sa­ry (Digi­tal Rights Ire­land and Others, C‑293/12 and C‑594/12, EU:C:2014:238, para. 52 and the case law cited therein).

93 Not limi­t­ed to what is abso­lut­e­ly neces­sa­ry is a pro­vi­si­on that gene­ral­ly the sto­rage of all per­so­nal data of all per­sonswho­se data have been trans­fer­red from the Uni­on to the United Sta­tes, Wit­hout any dif­fe­ren­tia­ti­on, limi­ta­ti­on or excep­ti­on to be car­ri­ed out on the basis of the objec­ti­ve pur­sued and Wit­hout pro­vi­ding an objec­ti­ve cri­ter­ionwhich makes it pos­si­ble to limit the access of the aut­ho­ri­ties to the data and their sub­se­quent use to very spe­ci­fic, strict­ly limi­t­ed pur­po­ses that are capa­ble of justi­fy­ing the inter­fe­rence asso­cia­ted both with the access to the­se data and with their use ([…]).

94 Spe­ci­fi­cal­ly, vio­la­tes a regu­la­ti­on that allo­ws aut­ho­ri­ties to, gene­ral­ly access the con­tent of elec­tro­nic com­mu­ni­ca­ti­ons, the essence of the fun­da­men­tal right to respect for pri­va­te life gua­ran­teed by Artic­le 7 of the Charter ([…]).

95 Simi­lar­ly, a regu­la­ti­on that does not pro­vi­de for the pos­si­bi­li­ty for the citi­zen to obtain, by means of a judi­cial reme­dy, access to per­so­nal data con­cer­ning him or to obtain their rec­ti­fi­ca­ti­on or era­su­re, the essence of the fun­da­men­tal right to effec­ti­ve judi­cial pro­tec­tion enshri­ned in Artic­le 47 of the Char­ter. Inde­ed, under Artic­le 47(1) of the Char­ter, any per­son who­se rights or free­doms gua­ran­teed by Uni­on law have been inf­rin­ged shall have the right to an effec­ti­ve reme­dy befo­re a tri­bu­nal, in accordance with the con­di­ti­ons laid down in that artic­le. In this respect, the very exi­stence of effec­ti­ve judi­cial review ser­ving to ensu­re com­pli­ance with Uni­on law is inher­ent in the natu­re of a Sta­te gover­ned by the rule of law ([…]).

[…]

98 The­r­e­fo­re, wit­hout it being neces­sa­ry to exami­ne the con­tent of the safe har­bor prin­ci­ples, it must be con­clu­ded that Artic­le 1 of Decis­i­on 2000/520 vio­la­tes the requi­re­ments set forth in Artic­le 25(6) of Direc­ti­ve 95/46 in light of the Char­ter and is inva­lid for that reason.

[…] 106 Based on the abo­ve con­side­ra­ti­ons, it must be con­clu­ded that Decis­i­on 2000/520 is invalid.