European Commission

On January 10, 2017, the European Commission unveiled the “last major Digital Single Market initiatives” addressing Europe’s digital future.  These initiatives comprise the following:

  • A proposal for a Regulation on Privacy and Electronic Communications (E-Privacy Regulation) (see our post here);
  • A Communication on “Building a European Data Economy” (see


Continue Reading European Commission Unveils Data Economy Package: International Data Transfers

On January 10, 2017, the European Commission unveiled the “last major Digital Single Market initiatives” addressing Europe’s digital future.  These initiatives comprise the following:

  • A proposal for a Regulation on Privacy and Electronic Communications (E-Privacy Regulation) (see our post here);
  • A Communication on “Building a European Data Economy”; and
  • A Communication on exchanging and protecting personal data in a globalized world (see our post here).

(There is also a proposal for a Regulation on data protection rules applying to European institutions which InsidePrivacy is not reporting on.)

This post summarizes the Commission’s Communication on “Building a European Data Economy” (formerly referred to as the “Free Flow of Data Initiative”).

Background

The Data Protection Directive, and soon the GDPR, provides the foundation for the free flow of personal data throughout the EU.  However, Member States have imposed data localization restrictions for various reasons (e.g., in relation to patient health records, for auditing or law enforcement requirements).  In addition, the GDPR and Data Protection Directive only provide for the free flow of data within the EU in relation to personal data, not non-personal data.

The Communication sets out to address these data localization requirements and transfer barriers.  In addition, the Commission uses the document to address “emerging issues” that the Commission believes could lead to problems in the growing European “data economy” (a loose term that refers to the growing network of industrial data, machine-generated data related to the Internet of Things, and data pools generated by and for autonomous machinery, self-driving cars, and machine learning tools).”
Continue Reading European Commission Unveils Data Economy Package: “Building a European Data Economy”

On January 10, 2017, the European Commission unveiled the “last major Digital Single Market initiatives” addressing Europe’s digital future.  These initiatives comprise the following:

  • A proposal for a Regulation on Privacy and Electronic Communications (E-Privacy Regulation) ;
  • A Communication on “Building a European Data Economy” (see our post here); and
  • A Communication on exchanging and protecting personal data in a globalized world (see our post here).

(There is also a proposal for a Regulation on data protection rules applying to European institutions which InsidePrivacy is not reporting on.)

This post summarizes the proposal for an E-Privacy Regulation.

E-Privacy

The existing E-Privacy Directive 2002/58/EC sets out specific privacy-related rules for telecommunications, marketing, and digital services that “particularise and complement” those in the Data Protection Directive.  However, following the enactment of the General Data Protection Regulation (GDPR), there has been a need to update the E-Privacy Directive. From April to June 2016, the Commission consulted on reform of the E-Privacy Directive and, in August 2016, the Commission published a summary report on the results of that consultation.

The proposed E-Privacy Regulation includes significant changes to the current framework that, if enacted in its current form, would impact a wide range of companies that operate online.  Among other things, the draft introduces new rules in relation to traffic and location data, modifies the controversial “cookie” rule, and aligns fines for breach of the proposed Regulation with the GDPR – meaning a maximum fine of up to 4% of annual worldwide turnover for certain breaches.
Continue Reading European Commission Unveils Data Economy Package: E-Privacy Regulation

On September 16, 2016, Digital Rights Ireland (“DRI”), a digital rights advocacy group, lodged an action with the EU General Court for annulment of the European Commission’s Decision on the EU-U.S. Privacy Shield arrangement.  While the existence of the application has only recently become public knowledge, it was widely-expected that the Privacy Shield would face a legal challenge.  It is also unsurprising that DRI have brought the action (given its objections to the Privacy Shield before it was agreed and its intervention in the Safe Harbor case).

Background

The Privacy Shield was agreed earlier this year, replacing the Safe Harbor framework that was invalidated by the Court of Justice of the EU (“CJEU”) in Schrems.  The Privacy Shield provides a legal basis for transfers of personal data from the European Economic Area to Privacy Shield-certified companies in the U.S.  To date, over 600 companies have certified to the Privacy Shield.  The Privacy Shield contains a much more robust set of commitments than those underpinning the Safe Harbor and will provide stronger protections to data subjects in the EU than its predecessor.
Continue Reading Challenge to EU-U.S. Privacy Shield Lands at EU Court

The EU-U.S. Privacy Shield’s recent introduction has created an efficient mechanism to ensure that trans-Atlantic personal data flows are lawful.  With that in place, attention is now turning back to restrictions within the EU, particularly around hosting data in cloud computing services.

European healthcare is particularly affected by such restrictions.  This has motivated a significant group of organizations and policymakers to come together and launch a collective “call to action” to European policymakers, urging greater support and reforms to enable broader use of cloud computing in healthcare.  The Call to Action was previewed at eHealth Week 2016 in June.
Continue Reading EU Organizations Call for More Support for Cloud Computing in Healthcare

On July 8, 2016, the draft EU-U.S. Privacy Shield adequacy decision was formally approved by the so-called “Article 31 Committee” of EU Member States (see press release, here).

That approval opens the door for the College of EU Commissioners to approve the Privacy Shield on Monday (July 11).  Once translated and published in the Official Journal of the EU, the adequacy decision will then enter into force.

However, there may need to be an implementation period during which the EU and U.S. put in place relevant structures; it is expected that Commissioner Věra Jourová will provide more details to the European Parliament on Monday, and in a joint press conference on Tuesday with U.S. Secretary of Commerce Penny Pritzker.

Once that implementation phase is complete, U.S.-based companies will be able to self-certify under the Privacy Shield.  Doing so provides a legal basis which entities in the European Economic Area can rely on to transfer personal data to those Privacy Shield-certified companies in the US.
Continue Reading Privacy Shield Deal Passes Major EU Hurdle

The EU Network and Information Security (NIS) Directive now looks likely to enter into force in August of this year.  Member States will then have 21 months to implement it into national law before the new security and incident notification obligations will start to apply to the following entities:

  • designated* “operators of essential services” within the energy, transport, banking, financial market infrastructures, health, drinking water supply and distribution, and digital infrastructure sectors; and
  • certain “digital service providers” that offer services within the EU, namely online market places, online search engines and cloud computing services, excluding small/micro enterprises.

* Once implemented in national law, Member States will have a further 6 months to apply criteria laid down in the Directive to identify specific operators of essential services covered by national rules; they do not need to undertake this exercise in relation to digital service providers, which shall be deemed to be under the jurisdiction of the Member State in which it has its “main establishment” (i.e., its head office in the Union).
Continue Reading EU Cyber Security Directive To Enter Into Force In August

By Kristof Van Quathem

Yesterday, the European Commission launched its “Digitising European Industry” package, a series of industry related initiatives aimed at “updating Europe’s digital infrastructure”, see press release here, Q&A here and homepage here.  The package includes reports and proposals addressing cloud computing, ICT standardization, eGovernment, Internet of Things (“IoT”), quantum technologies and high performance computing / big data.

Below we summarize the data protection aspects of the key communications published yesterday.
Continue Reading Digital Single Market – New Initiatives for Cloud Computing and Internet of Things

Today, the Article 29 Data Protection Working Party (“Working Party”), a group consisting of representatives from the European data protection authorities, the European Data Protection Supervisor, and the European Commission, published its opinion on the EU-U.S. Privacy Shield draft adequacy decision (“Opinion”) (see here). The Opinion is accompanied by a second document, Working Document 01/2016 on the justification of interferences with the fundamental rights to privacy and data protection through surveillance measures when transferring personal data (“European Essential Guarantees”) (see here). This document sets out EU standards for surveillance by public authorities in the EU and U.S., as formulated by the Working Party. The Working Party also issued a press release (see here). The chairwoman of the Working Party, CNIL President Falque-Pierrotin, presented the documents today in a press conference, a recording of which is available here.

According to the Working Party, the Privacy Shield contains significant improvements compared to the now-defunct EU-U.S. Safe Harbor framework; however, there remain certain concerns and a need for clarification. 
Continue Reading EU Data Protection Authorities Call For Further Clarifications on the EU-U.S. Privacy Shield and Raise Some Concerns

Following the expected approval of the final text of the General Data Protection Regulation (“GDPR”) in the European Parliament this week, the Commission is now turning its attention towards the ePrivacy Directive.

On Monday (April 11, 2016), the Commission launched a public consultation to review and propose changes to the
Continue Reading European Commission Launches Consultation on Reform of the ePrivacy Directive