Privacy

Europe adopts US data adequacy decision

Comment

EU-US Data Privacy Framework

The European Union has adopted a new transatlantic data adequacy agreement with the U.S.

The much anticipated decision means there’s an immediate resolution to legal uncertainty around exports of EU users’ personal data by U.S. companies — a problem that’s affected thousands of businesses in recent years, big and small, including the likes of Meta and Google to name a couple of the most high-profile examples.

Speaking during a press conference announcing adoption of the U.S. adequacy decision, EU justice commissioner Didier Reynders sounded confident that this time — the third such high-level data transfer arrangement the bloc’s executive has granted the U.S. — will indeed be third time lucky.

“With the adoption of the adequacy decision, personal data can now flow freely and safely from the European Economic Area to the United States without any further conditions or authorizations,” he said. “Therefore, the adequacy decision, ensure that data can be transmitted between the European Union and the U.S. on the basis of a stable and trusted arrangement that protects individuals and provides legal certainty to companies.”

Political agreement on the EU-U.S. Data Privacy Framework (DPF) was announced back in March 2022 but it’s taken over a year to get all the i’s dotted and t’s crossed, while the prior mechanism for simplifying exports of data over the pond was invalidated by EU judges almost three years ago. So the adoption of a new adequacy deal really does pull the shutter down on years of legal uncertainty affecting major U.S. cloud services and scores of other digital players.

That said, the big question for the DPF is how enduring this third EU-U.S. data adequacy agreement will be — and that very much remains to be seen, despite the EU taking more time than it did last time to sweat the detail of the new framework.

At today’s press conference Reynders was sounding a lot more bullish than usual on this topic, arguing the framework is not simply a copy/paste of earlier (failed) transfer mechanisms but “a very different system” — one he suggested is “a very robust solution” to an entrenched legal divide.

He also suggesting the EU has listened closely to feedback as it worked to finalize a framework he claimed ensures “full compliance with the conditions set in the ruling of the EU’s highest court.”

“This was my mandate and my focus in these negotiations, and this is reflected in the solutions we have obtained,” he suggested. “They specifically address the requirements set by the court as regards the need for limitations and safeguards for access to data by U.S. intelligence agencies in line with the principles of necessity and proportionality and the need to ensure effective redress for EU individuals.”

Nonetheless, legal challenges to the DPF are on the way. Both predecessor arrangements (i.e., Safe Harbor and Privacy Shield) were struck down by the bloc’s top court after judges found exported personal data was not protected to the required legal standard given risks posed by sweeping U.S. surveillance powers. And privacy campaigners are warning the new framework could be in front of the CJEU (Court of Justice of the European Union) within months.

One key point for critics is that since Privacy Shield’s demise, we have still not seen reform of U.S. surveillance powers, with no moves by lawmakers to accept the need to reform the controversial FISA 702 provision and pass protections for foreigners’ information.

That means, at root, the DPF is still papering over the same fundamental legal conflict between EU privacy rights and U.S. surveillance powers, and it could inexorably face the same assessment of inadequacy once EU judges get to scrutinize the detail.

In recent months, a number of other EU institutions have raised concerns that the Commission’s planned replacement lacks clarity, also suggesting the tweaks on the prior approach may fall short of delivering the necessary essential equivalence in protection for data when it’s over the pond. Although there has also been a recognition by bodies such as the European Data Protection Board that the DPF goes further than earlier data transfer deals. The question is whether it goes far enough to meet the CJEU’s bar.

The Commission decision itself doesn’t mean much since it’s solely responsible for adopting EU adequacy decisions — and Reynders conceded that today’s green light is essentially a “unilateral” decision by the EU’s executive — so the bloc’s lawmakers are in the luxurious position of getting to mark their own homework once again, despite a history of getting these self-same equations wrong.

Privacy campaign group noyb — whose founder and chairman, Max Schrems, was behind the original complaint against Facebook’s EU-U.S. data transfers — remains critical of the framework.

Responding to the Commission’s adequacy decision announcement today, noyb confirmed it will lodge a legal challenge — saying it has “options for a challenge” ready to be sent to regulators and expects the issue to be back with the CJEU by the beginning of next year.

If noyb’s slated timeline holds, it would still have to be followed by months (or even years) of deliberation by the bloc’s court. So a final verdict on the DPF could be years away. (For some comparative context, legal questions pertaining the DPF’s predecessor, Privacy Shield, were referred to the court in May 2018 — with the CJEU ruling striking down the mechanism landing in July 2020.)

For now, Schrems and noyb argue the new framework is largely the same as the Privacy Shield that failed to pass must with EU judges — dismissing the main changes highlighted by EU and U.S. teams involved in negotiating the replacement deal, such as the U.S. apparently adopting an EU law principle of “proportionate” data use. This amounts to proportionality theater, noyb suggests, arguing the U.S. is not assigning the same definition to the term that EU judges would understand in the Executive Order attached to the DPF where the U.S. now vows its surveillance of foreigners will be “proportionate.”

They are also also unimpressed by an attempt in the DPF to rework another problem that led to the CJEU skewering Privacy Shield — related to redress. So instead of the latter’s ombudsperson, the DPF offers up a civil liberties protection officer and what’s being named as a “court” but that, they point out, is not actually a court of law; rather it’s a “partly independent executive body” — hence summing up the changes as only “minor improvements.”

“They say the definition of insanity is doing the same thing over and over again and expecting a different result. Just like ‘Privacy Shield’ the latest deal is not based on material changes but by political interests,” argued Schrems in a statement. “Once again the current Commission seems to think that the mess will be the next Commission’s problem. FISA 702 needs to be prolonged by the U.S. this year but with the announcement of the new deal the EU has lost any power to get a reform of FISA 702.”

Anticipating the key lines of attack, Reynders took some time to tackle both areas in his remarks today — fleshing out why the Commission thinks this deal is different and will stick. He said:

We have achieved significant changes to the U.S. legal framework to address these two sets of requirements. This new framework is substantially different than the EU-U.S. Privacy Shield as a result of the Executive Order issued by President Biden last year following our negotiations. The necessity and proportionality requirements are now clearly spelled out through binding and enforceable safeguards in the U.S. legal order.

In practice this means that when deciding whether and to what extent U.S. intelligence agencies should access data, they will be required to balance the same factors as those required by the case law of the EU Court of Justice. These factors include the nature of the data, the seriousness of the threat, or the likely impact on the rights of individuals. On that basis, each U.S. intelligence agency has reviewed its internal rules and procedures to implement these new requirements at the operational level.

On the reworked redress mechanism, Reynders described it as “an independent and impartial tribunal that is empowered to investigate complaints lodged by Europeans and to issue binding remedial decisions,” also noting the body has the power to oder the deletion of data collected in violation of the requirements of necessity or proportionality.

He further emphasized that the Commission has paid attention to accessibility of redress — suggesting the mechanism has been designed to be “user friendly” and noting there’s no charge for EU people to lodge a complaint (which he stipulated they can do in their own language via their local data protection authority, which will then channel the complaint to the relevant authorities for them).

He emphasized:

Very low admissibility requirements will apply. In particular, the complainant will not have to demonstrate that their data has been accessed by U.S. intelligence agencies. This is very important and this is crucial to ensure effective access to redress in an area which is by nature secret.

Before the [tribunal] the complainant’s interest will be represented by a special advocate, again, free of charge with the necessary security clearances. These proceedings involve a certain degree of secrecy. With a special advocate, the court will take its decision only after hearing both sides. Finally, the functioning of this redress mechanism, including due process aspects and compliance with the decisions of the new court, will be overseen by an independent body specifically responsible for data protection, the Privacy and Civil Liberties Oversight Board.

“The principles of the Data Privacy Framework are solid and I’m convinced that we have made significant progress which meets the requirements of the Court,” Reynders also said, before offering a word of caution to U.S. authorities vis-à-vis the need to actually deliver on their commitments.

“At the same time the Commission will be paying particularly close attention to implementation of this new legal framework and will not hesitate to react in case of any problems or issues,” he warned.

Cynics might say the whole EU-U.S. adequacy saga is simply a way for lawmakers on either side of an immoveable legal schism to buy another few years’ grace (and keep the wheels of commerce turning) by repeatedly kicking the flash-point down the road — leaving EU regulators and courts saddled with the resulting fallout (and businesses facing yet another expensive legal mess if the deal ends up being unpicked yet again).

It’s a point of view that’s lent credence when you consider how Meta, which has been subject to a complaint over its EU-U.S. data transfers for around a decade — and was finally, earlier this year, ordered to suspend data flows after EU privacy regulators confirmed the breach of the bloc’s data export requirements — has never actually had to stop shipping out Europeans’ data despite the exports being found to be unlawful.

In May the tech giant was given a period of around six months to comply with the data suspension order. Now, a few weeks on from that order, we have a freshly ratified high-level transfer mechanism for the company to latch on to — meaning it can simply ignore the still ink-wet suspension order by switching its claimed legal basis for data exports to the DPF and avoid actually having to suspend any data flows, essentially dodging hard enforcement (albeit, with a bill of around $1.3 billion to pay).

This seemingly never-ending dance — which noyb dubs a frustrating “legal ping pong” — illustrates how challenging it is for EU citizens to exercise the privacy rights the law claims exists to protect their information, even as tech giants with lucrative data-mining business models get to carry on trampling people’s rights as per usual, just so long as they make enough profit to be able to write off any penalty payments as a cost of doing business.

Still, Reynders had a word of caution for U.S. tech giants today: “It will be for the companies to show that they’re in full compliance with the GDPR [General Data Protection Regulation].”

And on that front, Meta, at least, does have a growing headache as EU regulators — and, most recently, the CJEU — have cast doubt upon the legal basis it claims for processing people’s data for ad targeting. So even if the adtech giant won’t now be forced to cut off all its EU-U.S. data flows, some hard reforms to how it operates its behavioral advertising business in the EU do now look unavoidable.

MEPs raise concerns over draft EU-US data transfer deal

EU confirms draft decision on replacement US data transfer pact

More TechCrunch

The Oversight Board has overturned Meta’s decision to take down a documentary revealing the identities of child abuse victims in Pakistan.

Meta’s Oversight Board overturns takedown decision for Pakistan child abuse documentary

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

Adam Selipsky is stepping down from his role as CEO of Amazon Web Services, Amazon has confirmed to TechCrunch.  In a memo shared internally by Amazon CEO Andy Jassy and…

AWS CEO Adam Selipsky steps down

VC and podcaster David Sacks has revealed a new AI chat app called Glue that fixes “Slack channel fatigue,” he says.

David Sacks reveals Glue, the AI company he’s been teasing on his All In podcast

Harness isn’t founder Jyoti Bansal’s first startup. He sold AppDynamics to Cisco for $3.7 billion in 2017, the week it was supposed to go public. His latest venture has raised…

After surpassing $100M in ARR, Harness grabs a $150M line of credit

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

The company’s autonomous vehicles have had a number of misadventures lately, involving driving into construction sites.

Waymo’s robotaxis under investigation after crashes and traffic mishaps

Sona, a workforce management platform for frontline employees, has raised $27.5 million in a Series A round of funding. More than two-thirds of the U.S. workforce are reportedly in frontline…

Sona, a frontline workforce management platform, raises $27.5M with eyes on US expansion

Uber Technologies announced Tuesday that it will buy the Taiwan unit of Delivery Hero’s Foodpanda for $950 million in cash. The deal is part of Uber Eats’ strategy to expand…

Uber to acquire Foodpanda’s Taiwan unit from Delivery Hero for $950M in cash 

Paris-based Blisce has become the latest VC firm to launch a fund dedicated to climate tech. It plans to raise as much as €150M (about $162M).

Paris-based VC firm Blisce launches climate tech fund with a target of $160M

Maad, a B2B e-commerce startup based in Senegal, has secured $3.2 million debt-equity funding to bolster its growth in the western Africa country and to explore fresh opportunities in the…

Maad raises $3.2M seed amid B2B e-commerce sector turbulence in Africa

The fresh funds were raised from two investors who transferred the capital into a special purpose vehicle, a legal entity associated with the OpenAI Startup Fund.

OpenAI Startup Fund raises additional $5M

Accel has invested in more than 200 startups in the region to date, making it one of the more prolific VCs in this market.

Accel has a fresh $650M to back European early-stage startups

Kyle Vogt, the former founder and CEO of self-driving car company Cruise, has a new VC-backed robotics startup focused on household chores. Vogt announced Monday that the new startup, called…

Cruise founder Kyle Vogt is back with a robot startup

When Keith Rabois announced he was leaving Founders Fund to return to Khosla Ventures in January, it came as a shock to many in the venture capital ecosystem — and…

From Miles Grimshaw to Eva Ho, venture capitalists continue to play musical chairs

On the heels of OpenAI announcing the latest iteration of its GPT large language model, its biggest rival in generative AI in the U.S. announced an expansion of its own.…

Anthropic is expanding to Europe and raising more money

If you’re looking for a Starliner mission recap, you’ll have to wait a little longer, because the mission has officially been delayed.

TechCrunch Space: You rock(et) my world, moms

Apple devoted a full event to iPad last Tuesday, roughly a month out from WWDC. From the invite artwork to the polarizing ad spot, Apple was clear — the event…

Apple iPad Pro M4 vs. iPad Air M2: Reviewing which is right for most

Terri Burns, a former partner at GV, is venturing into a new chapter of her career by launching her own venture firm called Type Capital. 

GV’s youngest partner has launched her own firm

The decision to go monochrome was probably a smart one, considering the candy-colored alternatives that seem to want to dazzle and comfort you.

ChatGPT’s new face is a black hole

Apple and Google announced on Monday that iPhone and Android users will start seeing alerts when it’s possible that an unknown Bluetooth device is being used to track them. The…

Apple and Google agree on standard to alert people when unknown Bluetooth devices may be tracking them

The company is describing the event as “a chance to demo some ChatGPT and GPT-4 updates.”

OpenAI’s ChatGPT announcement: Watch here

A human safety operator will be behind the wheel during this phase of testing, according to the company.

GM’s Cruise ramps up robotaxi testing in Phoenix

OpenAI announced a new flagship generative AI model on Monday that they call GPT-4o — the “o” stands for “omni,” referring to the model’s ability to handle text, speech, and…

OpenAI debuts GPT-4o ‘omni’ model now powering ChatGPT

Featured Article

The women in AI making a difference

As a part of a multi-part series, TechCrunch is highlighting women innovators — from academics to policymakers —in the field of AI.

23 hours ago
The women in AI making a difference

The expansion of Polar Semiconductor’s facility would enable the company to double its U.S. production capacity of sensor and power chips within two years.

White House proposes up to $120M to help fund Polar Semiconductor’s chip facility expansion

In 2021, Google kicked off work on Project Starline, a corporate-focused teleconferencing platform that uses 3D imaging, cameras and a custom-designed screen to let people converse with someone as if…

Google’s 3D video conferencing platform, Project Starline, is coming in 2025 with help from HP

Over the weekend, Instagram announced that it is expanding its creator marketplace to 10 new countries — this marketplace connects brands with creators to foster collaboration. The new regions include…

Instagram expands its creator marketplace to 10 new countries

Four-year-old Mexican BNPL startup Aplazo facilitates fractionated payments to offline and online merchants even when the buyer doesn’t have a credit card.

Aplazo is using buy now, pay later as a stepping stone to financial ubiquity in Mexico

We received countless submissions to speak at this year’s Disrupt 2024. After carefully sifting through all the applications, we’ve narrowed it down to 19 session finalists. Now we need your…

Vote for your Disrupt 2024 Audience Choice favs