{"id":3676,"date":"2021-02-19T15:18:13","date_gmt":"2021-02-19T21:18:13","guid":{"rendered":"http:\/\/blogs.luc.edu\/compliance\/?p=3676"},"modified":"2021-02-19T15:18:13","modified_gmt":"2021-02-19T21:18:13","slug":"relax-after-gdprs-schrems-ii-some-companies-transferring-personal-data-from-the-eu-to-the-us-may-actually-have-less-challenges-than-you-thought","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=3676","title":{"rendered":"Relax, After GDPR\u2019s Schrems II, Some Companies Transferring Personal Data from the EU to the US May Actually Have Less Challenges Than You Thought"},"content":{"rendered":"<p><span style=\"font-family: 'times new roman', times, serif\"><em>Richard Horton<\/em><\/span><br \/>\n<span style=\"font-family: 'times new roman', times, serif\"><em>Associate Editor<\/em><\/span><br \/>\n<span style=\"font-family: 'times new roman', times, serif\"><em>Loyola University Chicago School of Law, LLM 2021<\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">On December 12, 2020, the European Commission (the \u201cEC\u201d) issued a highly anticipated <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\">draft of newly revised standard contractual clauses<\/a> (\u201cnew SCCs\u201d) that may be used by European Union-based companies to safeguard data transfers of personal data to third countries, such as the US, in compliance with <a href=\"https:\/\/gdpr-info.eu\/art-46-gdpr\/\">GDPR Art. 46(1)<\/a>. The release comes at a decidedly inopportune time as it follows on the heels of the Court of Justice of the European Union\u2019s (CJEU) <a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=228677&amp;pageIndex=0&amp;doclang=en\"><em>Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems<\/em><\/a> (\u201c<em>Schrems II\u201d<\/em>) decision which casts serious doubt on the adequacy of SCCs <em>alone<\/em> to safeguard against the \u201chigh-risks\u201d involved in EU to US data transfers. And for many data protection experts, the language of the revised SCCs only adds to the confusion, raising even more questions. But one question in particular seems to be prominent among others\u2014for transfers to importers, directly subject to GDPR, are SCCs really necessary?<\/span><!--more--><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>The prevailing question on the scope of Art. 46(1)<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Upon its release, the draft of the new SCCs has been subject to <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\/feedback?p_id=14543795\">public comment<\/a> from the privacy and data protection world, allowing corporations, advocates, attorneys, practitioners, academics, policy experts, and regulators to officially have their say. The step is required under EU law before a final version of the new SCCs can be finalized and adopted by the EC.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">At its closing, the EC received nearly <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\/feedback?p_id=14543795\">150 comments to its website<\/a> during the less than 30-day comment period. The comments reflect a wide variety of concerns ranging from the <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\/F1306021\">trivial<\/a>\u2014&#8221;we strongly suggest that they should be [re-]named \u2018[s]tandard data protection clauses\u2019,\u201d to the more <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\/F1306021\">thoughtful and substantive<\/a>\u2014\u201dthere is an effort to fill the gaps in the GDPR and to comply with the Schrems II judgement, but the new SCCs overshoot the mark and disproportionately complicate the transfer\u2026\u201d<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Also weighing in on the new SCCs are, the influential data protection authorities, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) with their <a href=\"https:\/\/edpb.europa.eu\/sites\/edpb\/files\/files\/file1\/edpb_edps_jointopinion_202102_art46sccs_en.pdf\">joint opinion<\/a> published on January 15, 2021 (\u201cJoint Opinion\u201d). The Joint Opinion outlined a number of critiques of the new SCCs and the accompanying Implementing Decision and provided recommendations for revisions, pursuant to their responsibility to provide feedback under EUDPR.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Although framed differently, <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\/F1306018\">ICANN<\/a>, <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\/F1306007\">Noyb<\/a>, <a href=\"https:\/\/edpb.europa.eu\/sites\/edpb\/files\/files\/file1\/edpb_edps_jointopinion_202102_art46sccs_en.pdf\">EDPB\/EDPS<\/a>, and several other commenters seem to all raise a single common question. Essentially, they ask whether GDPR\u2019s Art. 46 appropriate safeguards are even necessary for data transfers to importers in third countries that are already subject to GDPR. Commenters point to the language of <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries\">Art. 1(1) of the EC\u2019s Implementing Decision<\/a>, which formally adopts the new SCCs. The provision seems to imply this position by stating \u201c[t]he standard contractual clauses set out in the Annex are considered to provide appropriate safeguards within the meaning of Article 46(1) and (2)(c) of Regulation (EU) 2016\/679 for the transfer of personal data from a controller or processor subject to Regulation (EU) 2016\/679 (data exporter) <em>to a controller or (sub-) processor not subject to Regulation (EU) 2016\/679 (data importer)<\/em>.\u201d<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">The widely accepted interpretation of GDPR Art. 46 has been that <em>all<\/em> data transfers to an importer, established in a third country without an adequacy decision, are subject to the mandatory safeguards. For example, when Company A, a controller-exporter based in the EU, transfers data to Company B, a processor-importer based in the US, Company A must implement appropriate safeguards such as SCCs, binding corporate rules, a code of conduct, or an approved certification program. However, if the EC\u2019s legislative intent was to exclude Company B from these burdensome requirements when Company B is directly subject to GDPR, then a large number of data transfers may <em>now<\/em> be completed with far less compliance challenges. Thus, entities that are subject to GDPR may be considered as \u201cexempt\u201d regardless of their third country location, for purposes of Art. 46 requirements.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">How might Company B be directly subject to GDPR? <a href=\"https:\/\/gdpr-info.eu\/art-3-gdpr\/\">Art. 3(2)<\/a> provides that GDPR has extraterritorial application <em>only<\/em> to controllers and processors, that are established outside of the EU, where the particular data processing activity \u201c<a href=\"https:\/\/gdpr-info.eu\/art-3-gdpr\/\">targets<\/a>\u201d individuals in the EU. Because a large percentage of data processing activities that involve EU residents\u2019 personal data are in some way directed towards EU residents, this exception could affect a substantial percentage of the total number of third country data transfers.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">The EDPB and EDPS, as proponents of greater privacy protections, <a href=\"https:\/\/edpb.europa.eu\/sites\/edpb\/files\/files\/file1\/edpb_edps_jointopinion_202102_art46sccs_en.pdf\">called out the shocking implication<\/a>, but also gratuitously provided the EC with a safe route for <a href=\"https:\/\/edpb.europa.eu\/sites\/edpb\/files\/files\/file1\/edpb_edps_jointopinion_202102_art46sccs_en.pdf\">walking it back<\/a>. The Joint Opinion asks the EC if it merely intended the provision to define the scope of the SCCs themselves, or whether it was, in fact, intended more broadly to define the scope of \u201cthe notion of transfers\u201d in general. The implications of the latter would undoubtedly be tremendous.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>The case for excluding importers, directly subject to GDPR, from Art. 46(1)<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Until the EC decides to address this particular question and provide a definitive answer, the privacy and data protection world must attempt to answer this question for itself. Clearly, it\u2019s easy to avoid the risks and assume that the statement did not mean what it seems to mean. The safest route forward is to continue to implement Art. 46 safeguards for <em>all<\/em> third country data transfers. But for those transfers where the safeguards present a hurdle that is far too great to overcome, companies must at least consider whether this interpretation is reasonable and if it can be substantiated.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><a href=\"https:\/\/gdpr-info.eu\/recitals\/no-108\/\">Recital 108<\/a> of GDPR provides that measures to compensate for the lack of data protection in a third country should be determined with the goal of compliance with the data protection requirements, and rights of data subjects, in the EU. Further, the CJEU requires that third country data protection standards be \u201c<a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=228677&amp;pageIndex=0&amp;doclang=en\">essentially equivalent<\/a>\u201d to that of EU law to support a finding that an EC adequacy decision is valid. Thus, the safeguards enumerated in Art. 46 and the adequacy decisions of Art. 45 essentially function as means to subject third country-based importers to the same data protection requirements imposed on controllers and processors under GDPR. Therefore, it may be reasonably argued that data transfers to US importers directly subject to GDPR can justifiably be excluded from the additional safeguards required under Art. 46(1).<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On December 12, 2020, the European Commission (the \u201cEC\u201d) issued a highly anticipated draft of newly revised standard contractual clauses (\u201cnew SCCs\u201d) that may be used by European Union-based companies to safeguard data transfers of personal data to third countries, such as the US, in compliance with GDPR Art. 46(1). The release comes at a decidedly inopportune time as it follows on the heels of the Court of Justice of the European Union\u2019s (CJEU) Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (\u201cSchrems II\u201d) decision which casts serious doubt on the adequacy of SCCs alone to safeguard against the \u201chigh-risks\u201d involved in EU to US data transfers. And for many data protection experts, the language of the revised SCCs only adds to the confusion, raising even more questions. But one question in particular seems to be prominent among others\u2014for transfers to importers, directly subject to GDPR, are SCCs really necessary?<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[473,571,575,1205,1622,1623],"class_list":["post-3676","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-compliance-program","tag-data-privacy","tag-data-security","tag-journal-of-regulatory-compliance","tag-privacy","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/3676","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3676"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/3676\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3676"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3676"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3676"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}