One year after its launch, the Privacy Shield mechanism continues to offer an adequate level of protection for European citizens' data transferred for commercial reasons to companies in the United States. However, its implementation could be improved, the European Commission states in its first annual report on the functioning of the mechanism, published on Wednesday 18 October.
Overall, the report stresses that the American authorities have created the necessary structures and procedures in place to ensure the smooth functioning of the mechanism, particularly the handling of complaints. So far, no individual complaints have been submitted to the 28 national data protection authorities and very few have been made on the American side, a senior European official reports.
The functioning of the certification procedure has also been deemed satisfactory. More than 2,400 businesses are now certified by the American Trade Department, which is more than in the ten years its predecessor, Safe Harbour, was in place, the European Commissioner for Justice, Vera Jourova, told the press.
On the access of the American public authorities to data of a personal nature for national security reasons, the report states that the necessary guarantees set in place by the US are still in force.
According to the information available to the Commission, between January and June 2016, the American giant Facebook received between 500 and 999 requests for access to personal data by the supervisory authorities, concerning between 13,000 and 13,499 user accounts. In relation to the total number of users, nearly 2 billion, the number of accounts involved in government requests for access to personal data is is very low, the European institutions stresses.
Recommendations for the future of the system. To improve its implementation of Privacy Shield, the Commission expects a more proactive and regular monitoring by the American side of whether businesses are meeting their obligations.
The EU also hopes that the protection for non-American nationals set out in presidential directive 28 will feature clearly in section 702 of the American law on foreign intelligence surveillance (FISA), which is currently being reformed. With regard to this, the Commissioner said that she was in close touch with members of the American Congress and anticipated a response from them by the end of the year.
On the controversial issue of the permanent ombudsman, the Commission reiterated its calls for one to be appointed as soon as possible, as well as filling the vacant posts on the American Privacy and Civil Liberties Council, but does not suggest any timeframes.
For its part, the Commission undertakes to do more to raise awareness among European citizens of how they can exercise their rights in the framework of this mechanism, particularly in terms of making complaints.
According to the same senior official, the success of Privacy Shield could be extended to other trade partners of the EU, such as Japan, with which a free-trade deal is soon to be finalised. Furthermore, Tokyo has just adopted an act on data protection which takes much of its inspiration from European standards.
However, this success may already have been called into question by the Court of Justice of the EU, which may be called upon to examine the appropriateness of the protection of European data in another context. In early October, the Irish High Court asked the European Court to take position on the possibility for the Irish data protection authority to suspend or ban the transfer of personal data of Facebook Ireland users to the US on the grounds of insufficient privacy guarantees (see EUROPE 11875). Acknowledging this as a first challenge, the Commissioner nonetheless said that she remained confident as to the Court's future verdict.
An initial assessment that has not convinced BEUC. Following the three days of meetings between the European and American authorities on this evaluation in Washington at the end of September (see EUROPE 11867), several stakeholders remain uneasy over the collection and use of the data of European citizens by American intelligence agencies (see EUROPE 11865).
Approached by EUROPE for comment after the publication of the report, the European Consumer Organisation (BEUC) said that most of the gaps revealed by the European data protection authorities last year had not been filled and that other important elements of the agreement are not even in place. The organisation therefore feels that concluding that the mechanism “works well” is “rather remarkable”.
The report must now be put to the European Parliament and Council, but also to the 'article 29' working group of the data protection authorities. The Commission's unilateral report will also be submitted to the American authorities. (Original version in French by Marion Fontana)