Take-Aways (AI)
  • David Rosen­thal pro­vi­des struc­tu­red forms for the risk assess­ment of per­so­nal data trans­fers abroad.
  • Forms record local lawful access rights, pro­vi­der mea­su­res and allow TIAs for the USA, Rus­sia, Chi­na and India.
  • Aut­ho­ri­ties use, accept or cri­ti­ci­ze the method; deba­te about risk-based approach ver­sus zero risk remains.
  • Rosen­thal published exten­si­ve FAQs on the method in order to objec­ti­fy the dis­cus­sion and explain US sur­veil­lan­ce law.

David Rosen­thal is known to have made available seve­ral forms that sup­port risk assess­ments rela­ted to trans­fers of per­so­nal infor­ma­ti­on abroad (see rela­ted here).

So far it is the fol­lo­wing forms, in logi­cal order:

  • Sur­vey of local law with refe­rence to Lawful Access.Becau­se the access risk depends on local law (apart from the cir­cum­stances of the trans­fer and the tech­ni­cal and orga­nizatio­nal pro­tec­tion mea­su­res taken), the rele­vant local law must be known and, in par­ti­cu­lar, a distinc­tion must be made bet­ween legal bases which satis­fy the prin­ci­ples of the rule of law and which are the­r­e­fo­re unpro­ble­ma­tic in terms of data pro­tec­tion law, and pro­be­ma­tic legal bases. A form is pro­vi­ded for this pur­po­se, with which this right can be queried in a struc­tu­red man­ner. Cor­re­spon­ding sur­veys are alre­a­dy available for India, Ser­bia, nor­t­hern Mace­do­nia and Koso­vo. Excel.
  • Sur­vey of the mea­su­res of a US-Pro­vi­ders: The access risk also depends on what mea­su­res an invol­ved US pro­vi­der has taken. A form is also pro­vi­ded for this → same Excel
  • TIA under the EU SCC – this is based on local law, as men­tio­ned, and checks the access risk against this back­ground. The form con­ta­ins seve­ral sheets with dif­fe­rent use cases under U.S. law, i.e., in the case of a trans­mis­si­on to the U.S., and TIAs for Rus­sia, Chi­na, and India, in addi­ti­on to ins­truc­tions on how to com­ple­te → same Excel
  • a sim­pli­fi­ed TIA for simp­ler cases → same Excel
  • TIA for secrets: In con­trast to data pro­tec­tion law, sec­re­cy pro­vi­si­ons pro­hi­bit dis­clo­sure – depen­ding on the direc­tion of pro­tec­tion and the cir­cum­stances – even to aut­ho­ri­ties of count­ries with an ade­qua­te level of pro­tec­tion and not only under pro­ble­ma­tic law, but under any local law. The exami­na­ti­on is the­r­e­fo­re broa­der and deeper than the exami­na­ti­on under data pro­tec­tion law alo­ne. A sepa­ra­te form exists for this pur­po­se → Excel

The IAPP has published two forms by David Rosen­thal, the TIA for the SCC and the TIA for secrets.

The­se forms serve

  • first to sur­vey the law, becau­se wit­hout this step, a TIA can­not be meaningful for a par­ti­cu­lar coun­try, i.e., it can­not be exami­ned whe­ther the fac­tu­al requi­re­ments are met and whe­ther bar­riers or excep­ti­ons apply;
  • the coll­ec­tion of the tech­ni­cal facts from the pro­vi­der – this is a part of the assess­ment, in com­bi­na­ti­on with own mea­su­res; and
  • the struc­tu­red and docu­men­ted assess­ment of the risk that access is pos­si­ble in accordance with local law and the orga­nizatio­nal and tech­ni­cal frame­work conditions.

The forms are wide­ly used. Among other things, this has led to the fact that various Aut­ho­ri­ties have more or less dealt with it. Publicly known:

  • the FDPIC in the SUVA case – cri­ti­cal remarks wit­hout conclusion;
  • the Zurich Govern­ment Coun­cil – Use of the form as stan­dard, max 10% pro­ba­bi­li­ty accept­ed as suf­fi­ci­ent­ly low;
  • the data pro­tec­tion aut­ho­ri­ties of the Can­ton of Basel-Stadt – use of the forms in a spe­ci­fic case accepted;
  • the public prosecutor’s office of the Can­ton of Basel City – method sui­ta­ble for the out­sour­cing decis­i­on under the offi­ci­al and pro­fes­sio­nal secrecy;
  • the Danish Data Pro­tec­tion Super­vi­so­ry Aut­ho­ri­ty – Cri­ti­cism of the form (alt­hough it is not known in what form the form has been used);
  • the Dutch Mini­stry of Justi­ce in con­nec­tion with the use of Micro­soft Teams, One­Dri­ve, Share­point and Azu­re AD – con­duc­ting a TIA based on the Rosen­thal form); cf. here.

Other comm­ents are available but not publicly known.

Aut­ho­ri­ties have thus part­ly used the form them­sel­ves, part­ly accept­ed it, and part­ly cri­ti­ci­zed it. The lat­ter is against the back­ground of the well-known deba­te about the risk-based approach vs. zero-risk approach. Howe­ver, not all aut­ho­ri­ties have taken a clo­ser look at the mat­ter. David Rosen­thal has taken this as an oppor­tu­ni­ty, publish exten­si­ve FAQs about his methodwhich, among other things, com­ment in detail on U.S. sur­veil­lan­ce law:

Let’s hope that the FAQ will help to objec­ti­fy the dis­cus­sion – that would be urgen­tly necessary.

It is undis­pu­ted that data pro­tec­tion law gene­ral­ly fol­lows a risk-based approach, no less than other rights that regu­la­te the hand­ling of risks. Any other approach would not only be absurd, but uncon­sti­tu­tio­nal, if one thinks of the gene­ral pre­re­qui­si­tes for inter­ven­ti­on, at least accor­ding to the Swiss Fede­ral Con­sti­tu­ti­on, and of the pro­tec­ti­ve direc­tion of Artic­le 13 (2) BV.

What this means for trans­fers abroad, howe­ver, is debata­ble. Howe­ver, the­re is often no distinc­tion bet­ween the que­sti­on of which rights are pro­ble­ma­tic in the afo­re­men­tio­ned sen­se, when the­se rights may app­ly, and how the risks are to be asses­sed and dealt with if they do app­ly. One can­not, howe­ver, sub­sti­tu­te a dis­cus­sion of local law by rejec­ting a risk-based approach a priori.