- David Rosenthal provides structured forms for the risk assessment of personal data transfers abroad.
- Forms record local lawful access rights, provider measures and allow TIAs for the USA, Russia, China and India.
- Authorities use, accept or criticize the method; debate about risk-based approach versus zero risk remains.
- Rosenthal published extensive FAQs on the method in order to objectify the discussion and explain US surveillance law.
David Rosenthal is known to have made available several forms that support risk assessments related to transfers of personal information abroad (see related here).
So far it is the following forms, in logical order:
- Survey of local law with reference to Lawful Access.Because the access risk depends on local law (apart from the circumstances of the transfer and the technical and organizational protection measures taken), the relevant local law must be known and, in particular, a distinction must be made between legal bases which satisfy the principles of the rule of law and which are therefore unproblematic in terms of data protection law, and probematic legal bases. A form is provided for this purpose, with which this right can be queried in a structured manner. Corresponding surveys are already available for India, Serbia, northern Macedonia and Kosovo. Excel.
- Survey of the measures of a US-Providers: The access risk also depends on what measures an involved US provider has taken. A form is also provided for this → same Excel
- TIA under the EU SCC – this is based on local law, as mentioned, and checks the access risk against this background. The form contains several sheets with different use cases under U.S. law, i.e., in the case of a transmission to the U.S., and TIAs for Russia, China, and India, in addition to instructions on how to complete → same Excel
- a simplified TIA for simpler cases → same Excel
- TIA for secrets: In contrast to data protection law, secrecy provisions prohibit disclosure – depending on the direction of protection and the circumstances – even to authorities of countries with an adequate level of protection and not only under problematic law, but under any local law. The examination is therefore broader and deeper than the examination under data protection law alone. A separate form exists for this purpose → Excel
The IAPP has published two forms by David Rosenthal, the TIA for the SCC and the TIA for secrets.
These forms serve
- first to survey the law, because without this step, a TIA cannot be meaningful for a particular country, i.e., it cannot be examined whether the factual requirements are met and whether barriers or exceptions apply;
- the collection of the technical facts from the provider – this is a part of the assessment, in combination with own measures; and
- the structured and documented assessment of the risk that access is possible in accordance with local law and the organizational and technical framework conditions.
The forms are widely used. Among other things, this has led to the fact that various Authorities have more or less dealt with it. Publicly known:
- the FDPIC in the SUVA case – critical remarks without conclusion;
- the Zurich Government Council – Use of the form as standard, max 10% probability accepted as sufficiently low;
- the data protection authorities of the Canton of Basel-Stadt – use of the forms in a specific case accepted;
- the public prosecutor’s office of the Canton of Basel City – method suitable for the outsourcing decision under the official and professional secrecy;
- the Danish Data Protection Supervisory Authority – Criticism of the form (although it is not known in what form the form has been used);
- the Dutch Ministry of Justice in connection with the use of Microsoft Teams, OneDrive, Sharepoint and Azure AD – conducting a TIA based on the Rosenthal form); cf. here.
Other comments are available but not publicly known.
Authorities have thus partly used the form themselves, partly accepted it, and partly criticized it. The latter is against the background of the well-known debate about the risk-based approach vs. zero-risk approach. However, not all authorities have taken a closer look at the matter. David Rosenthal has taken this as an opportunity, publish extensive FAQs about his methodwhich, among other things, comment in detail on U.S. surveillance law:
Let’s hope that the FAQ will help to objectify the discussion – that would be urgently necessary.
It is undisputed that data protection law generally follows a risk-based approach, no less than other rights that regulate the handling of risks. Any other approach would not only be absurd, but unconstitutional, if one thinks of the general prerequisites for intervention, at least according to the Swiss Federal Constitution, and of the protective direction of Article 13 (2) BV.
What this means for transfers abroad, however, is debatable. However, there is often no distinction between the question of which rights are problematic in the aforementioned sense, when these rights may apply, and how the risks are to be assessed and dealt with if they do apply. One cannot, however, substitute a discussion of local law by rejecting a risk-based approach a priori.