
News 2: ‘Data Adequacy’ process for the UK
Monday, 15th March 2021
The Trade and Cooperation Agreement (“TCA”) agreed on 24 December 2020 (and still to be ratified by the European Parliament), includes interim provisions for continuing unrestricted transmission of personal data from the European Union (“EU”) to the United Kingdom (“UK”) until 1 May, with a possible extension until 1 July 2021. Now that it has left the EU the UK is a ‘third country’ and must demonstrate an adequate level of personal data protection, in accordance with article 45 of the General Data Protection Regulation (“GDPR”), to allow trouble free cross-border transfers of personal data from the EU to continue. The EU Commission has recently launched the process that may lead to the adoption of an adequacy decision in respect of the UK legal regime for the protection of personal data. For transfers in the opposite direction, the UK government has stated that transfers of data from the UK to the EEA are permitted, although it says it will keep this under review).
The GDPR and the UK – setting the Scene
As it was an operative EU Regulation the GDPR was included as UK domestic law from exit day (31 January 2020) by section 3 of the (UK) Withdrawal Act. Secondary legislation, the prosaically named ‘Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019’ (“DPPExitRegs19”), came into force on exit day. The DPPExitRegs19 amend the main pre-existing national legal instrument, the Data Protection Act 2018 (“DPA18”) to remove all references to EU Institutions and bring a ‘UK GDPR’ into existence.
Schrems I and II
The two Schrems judgments of the Court of Justice of the European Union (“CJEU”) clarify that the basis for granting an Adequacy Decision is ‘essential equivalence’. By reference to last year’s Schrems II judgment, the EU Commission identifies the guiding principles under which Government access to personal data transferred to the UK would fulfil the ‘essential equivalence’ test. These were published in its draft adequacy Decision on 19 February 2021.
The ‘guiding principles’ include that:
- Any limitation to the right to the protection of personal data must be provided for by law and the law permitting such interference must itself define the scope of the limitation of the exercise of the right concerned.
- The legislation must be legally binding under domestic law and the legal requirements must also be enforceable against the authorities of the third country in question.
- In particular, data subjects must have the possibility of bringing legal action before an independent and impartial court in order to have access to their personal data, or to obtain the rectification or erasure of such data.
General Legal Framework
In making its assessment of the UK’s compliance with the guiding principles mentioned above, the EU Commission has referred itself in particular to the general legal framework applicable in the UK and its relationship to international legal standards. Specifically, it takes into account that the UK has ratified the European Convention on Human Rights (“ECHR”) and the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (“Convention 108”). It also recognises that the UK signed the Protocol (known as Convention 108+) amending and updating Convention 108, in 2018.
EU Commission conclusions regarding Government access
The EU Commission concludes that through membership of the Council of Europe, adherence to the ECHR and submission to the jurisdiction of the European Court of Human Rights in Strasbourg (not to be confused with the Court of Justice of the European Union (“CJEU”), in Luxembourg), the UK’s arrangements for Government access are subject to principles, safeguards and individual rights similar to those guaranteed under EU law and applicable in the EU the Member States.
The EU Commission re-emphasises that continued adherence to such international instruments is a particularly important element of the assessment on which its (draft) Decision is based. The CJEU considered the lack of an independent procedure for judicial review under the Ombudsperson mechanism to be a fundamental flaw of the EU Commission’s Privacy Shield adequacy Decision.
Analysis
Any adequacy decision is likely to be adopted on the basis of this static analysis of the UK’s legal framework concerning human rights and independent judicial review, notwithstanding the fact that the framework is likely to change. The UK Government is reviewing the 1998 Human Rights Act, which implements the ECHR in UK Law. The 2019 Conservative Party Manifesto says:
“We will update the Human Rights Act and administrative law to ensure that there is a proper balance between the rights of individuals, our vital national security and effective government. We will ensure that judicial review is available to protect the rights of the individuals against an overbearing state, while ensuring that it is not abused to conduct politics by another means or to create needless delays”.
UK Government Reviews
In fact two Government reviews have been set up. The first, an Independent Review of Administrative Law (“IRAL”) was launched in July 2020 to consider options for reform to the process of Judicial Review. The second, launched by the Government on 7 December 2020 is an Independent Human Rights Act Review (“IHRAR”). The IRAL was due to report at the end of 2020 but its report has been delayed. The IHRAR is due to report in the summer of 2021.
Recent Government statements show the UK’s future intention to diverge from GDPR
In an article for the Financial Times on 27 February, the UK government minister for Digital, Culture, Media and Sport, Oliver Dowden, launched the recruitment process to find the UK’s next Information Commissioner and explained a new approach to sharing data “quickly, efficiently and responsibly for the public good”.
He commented that:
“The EU doesn’t hold the monopoly on data protection”. “So, having come a long way in learning how to manage data risks, the UK is going to start making more of the opportunities”. (…) “Right now, too many businesses and organisations are reluctant to use data — either because they don’t understand the rules, or are afraid of inadvertently breaking them. That has hampered innovation and the improvement of public services, and prevented scientists from making new discoveries”. (…) “The next Information Commissioner will not just be asked to focus on privacy, but also be empowered to ensure people can use data to achieve economic and social goals”.
The current Prospects
The EU Commission has responded to concerns over the future of data adequacy in the UK by pointing out that an adequacy decision would be subject to review after an initial four-year period.
Commissioner Věra Jourová, EU Commission Vice-President for values and transparency, stated when the draft adequacy decision was published, that:
“Ensuring free and safe flow of personal data is crucial for businesses and citizens on both sides of the Channel. The UK has left the EU, but not the European privacy family. At the same time, we should ensure that our decision will stand the test of time. This is why we included clear and strict mechanisms in terms of both monitoring and review, suspension or withdrawal of such decisions, to address any problematic development of the UK system after the adequacy would be granted.” (Emphasis added)
Conclusions
- Unfinished business from the UK-EU Exit negotiations is continuing as regards EU-to-UK personal data transfers.
- Hopefully, for commerce and in the interests of their respective citizens, the wider tensions that also remain (notably in respect of the Ireland Northern Ireland Protocol) will not have a negative impact on the proposed personal data adequacy Decision.
- However, there certainly are signs that both the UK and the EU are using the December 2020 Trade and Cooperation Agreement in a confrontational manner rather treating it as a platform that can be built upon.
- Accordingly, it may well be prudent for businesses to look at other means to ensure continuing EU/UK data flows, including the use of the new EU Standard Contractual Clauses. Following the joint (European Data Protection Board / European Data Protection Supervisor) Opinions of 14 January 2021, they should be available for use shortly.
- For larger companies, putting in place Binding Corporate Rules under Article 47 GDPR remains an important option.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions.
Read More
News: UK-EU Trade and Co-operation Agreement N° 1
05 January 2021
On 24 December 2020, with a certain political theatricality, agreement on a UK-EU Trade and Co-operation (the “TCA”) was announced. In the opening paragraph of his foreword to the Summary Explainer of the TCA (the “Summary Explainer”), issued by the UK government on 27 December 2020, the Prime Minister, Mr Johnson, confirmed:
“This Agreement with the European Union is designed to honour the instruction of the British people – expressed in the referendum of 2016 and the general election last year – to take back control of our laws, borders, money, trade and fisheries. It changes the basis of our relationship with our European neighbours from EU law to free trade and friendly cooperation”.
That summary is intended to clarify, in political terms, that by agreeing the TCA the UK Government carried into effect what it was mandated to do by the British people.
Positive Statements and Normative Statements
The passage quoted above can be viewed simply as a general introductory statement but, given its importance, it may be subject to further analysis. Many readers will recall that a distinction is drawn in economics between positive and normative statements. Positive statements are those that are fact-based and objective, so that they can be proved or disproved against evidence. (‘It’s raining outside’ is a ‘positive’ statement!) Normative statements, on the other hand, are value judgments based on opinion, as such they are inherently subjective and are not capable of proof. (‘It will be better to keep inflation below 3% next year’, is a normative statement.) ‘Positive’ and ‘Normative’ are used with these latter meanings below.
Take back control of:
Laws – general dispute resolution process
The TCA does not mention the Court of Justice of the European Union (“CJEU”). Disputes will initially be subject to a process of consultation between the parties, followed by independent arbitration if there is still disagreement. In those narrow terms therefore a Positive statement. Whether the replacement of a judicial system for dispute resolution, with a consultative system backed by arbitration will prove to be as effective, timely and less costly remains to be seen.
Borders
Free movement of persons from the EU is ending and the UK will implement a points-based system that will treat EU citizens in the same way as those from other parts of the world. Therefore, a Positive statement. The price is that equivalent rights in the EU notably mutual recognition of qualifications and freedom to provide services based on ‘home country’ recognition and passporting have been withdrawn.
Trade
EU Trade will be tariff free and subject to zero quotas. The UK is free to conclude trade deals on its own terms. In those terms therefore, a Positive statement (as defined). By comparison with the previous situation however trade between the EU and the UK will not be frictionless (not less red-tape but an increase in formalities and documents). The UK TCA does contain provisions (in Chapter 4: Technical barriers to trade of Title 1 on Trade in Goods) intended to prevent unnecessary technical barriers to trade.
Chapter 4 applies to the preparation, adoption and application of all standards, technical regulations and conformity assessment procedures, which may affect trade in goods. Even if there is no mutual recognition of conformity assessment (meaning that all products exported from the EU to the UK will have to comply with UK technical regulations and will be subject to any applicable regulatory compliance checks and controls – and vice-versa for UK exports to the EU) the TCA does include provisions permitting continued self-assesment and certification of conformity by the manufacturer where that procedure is currently available.
Fisheries
The UK leaves the Common Fisheries policy and becomes an independent coastal state. The arrangements are subject to a five-and-a-half-year transition regarding quota shares and access to territorial waters and will be subject to annual re-negotiation thereafter. Therefore, a Normative statement.
Conclusions
The Withdrawal Agreement and TCA are concluded and there is a general sense of relief (from both sides) about that. It should enable both the UK and the EU to concentrate on their own priorities – in the UK’s case showing: “what Global Britain can do” (Summary Explainer, final paragraph). In the EU’s case six priorities including the ‘European Green Deal’ and ‘A Europe fit for the digital age’ (Political Guidelines for the European Commission 2019-2024). The two programmes will publicly coincide for the first time at the UN climate change conference COP26, postponed in April 2020 until November 2021, and due to be hosted by the UK in Glasgow.
As a ‘European Agreement’, the TCA does not require ratification by the twenty-seven member states’ national parliaments. However, the European Parliament needs to ratify the proposed TCA and it is scheduled to do so before 28 February. Ironically perhaps, in terms of sovereignty, the European Parliament, often accused by its detractors of not being fully representational, will therefore have a better opportunity to consider and debate the TCA than their colleagues in Westminster did.
With the arrangements below still to be implemented:
- The institutional arrangements to support the TCA (the Partnership Council, Trade Partnership Committee, Trade Specialised Committees (ten), Specialised Committees (eight), Working Groups (four) and the (potential) Parliamentary Partnership Assembly);
- The consent mechanism in the Ireland-Northern Ireland Protocol (“P-INI”) requires the UK to provide Northern Ireland with the opportunity to decide whether or not those provisions shall remain in place after four years but the Withdrawal Agreement does not say how;
- The interim provisions for continuing transmission of personal data to the United Kingdom until 1 May 2021 (which can be extended until 1 July) if there is no decision on the adequacy of the UK’s data-privacy regime by that date (TCA Final Provisions, Article FINPROV.10A);
Brexit is far from ‘Done’.
* * *
In the medium term, and in-line with the Fixed-term Parliaments Act, the next United Kingdom general election is scheduled to be held on Thursday, 2 May 2024, expect some of the Brexit issues, including the P-INI, to re-surface around that time, if not before.
And finally, there is a five-year review mechanism (also in the TCA Final Provisions, Article FINPROV.3) under which the Parties are to jointly review the implementation of the TCA and its supplementing agreements five years after its entry into force.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions.
Read More
Google’s failure to respect the « right to be forgotten » results in €600,000 fine
In its Decision 37/2020 of 14 July 2020 X c/Google (Decision) the Belgian Data Protection Authority (APD/GBA) fined Google Belgium 600,000 euros for failing to respect a citizen’s right to have certain harmful information delisted. (The right is sometimes referred to as the ‘right to be forgotten’). This is the highest fine imposed by the APD/GBA to date. The APD/GBA also ordered delisting of the content in the European Economic Area (EU + Iceland, Liechtenstein and Norway) – but it stopped short of ordering the worldwide ban that the Plaintiff (“X”) had called for.
Facts
X brought a complaint against Google Belgium SA (GB) complaining that GB had refused to deregister certain out of date articles appearing on web-pages available from Google Search (Search) which X alleged were damaging to X’s reputation. X has a prominent position in public life. The case therefore meant that the APD/GBA Litigation Chamber had to assess the correct balance between X’s fundamental rights to protection for personal data (Article 7 and 8 EU Charter of Fundamental Rights {EUCFR}) against the public interest right to freedom of information, (Article 11 EUCFR).
The decision has five operative parts each of which is summarised in the headings below.
- Jurisdiction of the APD/GBA; and
- Is Google Belgium a data controller for the purpose of the complaint?
The Litigation Chamber had asked to be informed about the roles of the different entities in the Google Group (GB, Google Ireland Ltd. and Google LLC, established in California (hereafter together ‘Google’). GB argued that the complaint was unfounded because the data controller was Google LLC in California.
That argument should be viewed in the light of the well-known May 2014 judgment of the CJEU in Costeja (Case C-131/12) which found that Google’s national subsidiaries in the EU are establishments of the company and that processing for Search is carried out in the context of the activities of those establishments – which makes them subject to EU data protection rules.
- Although the APD/GBA accepted that Google LLC was the data controller it held that, because the activities of Google Belgium and Google LLC are inextricably linked, the Belgian subsidiary should be considered to be an establishment of the data controller within the EU, subject to compliance with EU data-protection rules and against whom X’s complaint could properly be brought. The territorial application of a request for delisting
X requested a worldwide delisting. The Litigation Chamber had some doubts that a worldwide delisting might be unenforceable. On the other hand it consulted informally with its counterpart supervisory authorities on an EEA-wide delisting to ensure that they considered such an order would not disproportionately infringe the freedom of information of Internet users in other Member States. With one exception the other authorities supported such a course of action.
- X’s specific requests for delisting
X made two categories of specific de-listing requests, first concerning political affiliation and second regarding an allegation of harassment that had been declared unfounded more than ten years ago. Google decided not to de-list any of the pages in question. The APD/GBA found that maintenance of the pages concerning X’s political affiliation was in the public interest in view of X’s role in public life. However, concerning the harassment allegations, APD/GBA found the request for delisting was well-founded and that Google’s refusal was negligent and constituted a serious breach because it had clear evidence that the facts alleged had been dismissed.
- Infractions of the GDPR and the penalties applied
The €600,000 fine imposed took account of the lack of transparency in the delisting form that Google provided, the lack of information provided to X to justify the refusal to delist as well as the negligent refusal to delist the historical allegations of harassment. Google was also ordered to change its de-listing request forms so as to clarify which entity or entities are the data controller(s) responsible for the data processing.
Conclusions
In the APD/GBA Press Release Hielke Hijmans, Chairman of the APD/GBA Litigation Chamber, is reported to have commented: (our informal translation): ‘This decision is historic for the protection of personal data in Belgium, not only because of the amount of the penalty, but also because it ensures that full and effective protection of the citizen is supported in cases related to large international groups’ (…) whose structure is very complex. The Decision can be appealed within thirty days.
Practical takeaways from the case include that:
- Data controllers should ensure their privacy policies and their answers to data subject requests are precise and transparent.
- Data subjects have an interest in bringing their complaints before the competent data protection authorities (DPA) as the costs are likely to be less, the DPA has its own investigative powers and the procedure is likely to be quicker.
- The range of sanctions available to a DPA is important and they are being used more actively as experience of implementing GDPR builds up.
- The case confirms the Costeja jurisprudence that, as regards GDPR enforcement, where the activities of an EU subsidiary are inextricably linked with those of a data controller outside the EU a GDPR complaint may be legitimately brought against the EU subsidiary and the competent DPA will have jurisdiction to decide the complaint.
Read More

Schrems II Judgment of 16 July 20: Personal Data Transfers to the USA
“The case raises issues of very major, indeed fundamental, concern to millions of people within the European Union and beyond. Firstly, it is relevant to the data protection rights of millions of residents of the [EU]. Secondly, it has implications for billions of euros worth of trade between the EU and the US and, potentially, the EU and other non-EU countries”. Judgment of Ms. Justice Costello, 3 October 2017, Irish High Court.
“At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data protection laws that require privacy”. //noyb.eu/en/project/eu-us-transfers; consulted on 16 July 2020.
“The Court clarified for a second time now that there is a clash between EU privacy law and US surveillance law. As the EU will not change its fundamental rights to please the NSA” [the US National Security Agency], “the only way to overcome this clash is for the US to introduce solid privacy rights for all people – including foreigners. Surveillance reform thereby becomes crucial for the business interests of Silicon Valley.” Max Schrems (Chair of noyb.eu and party in the case) First Statement 16 July 2020.
(…) “we are still studying the decision to fully understand its practical impacts.” “We have been and will remain in close contact with the European Commission and European Data Protection Board on this matter and hope to be able to limit the negative consequences to the $7.1 trillion transatlantic economic relationship that is so vital to our respective citizens, companies, and governments”. U.S. Secretary of Commerce Wilbur Ross 16 July 2020 Statement on the Schrems II case.
“Today’s judgment provides” [a decisive statement of position from the CJEU], “firmly endorsing the substance of the concerns expressed by the DPC (and by the Irish High Court) to the effect that EU citizens do not enjoy the level of protection demanded by EU law when their data is transferred to the United States. In that regard, while the judgment most obviously captures Facebook’s transfers of data relating to Mr Schrems, it is of course the case that its scope extends far beyond that, addressing the position of EU citizens generally”. Data Protection Commission (Ireland) Statement on CJEU decision 16/07/2020.
[At the time of writing no written statements from Facebook Inc. or Facebook Ireland Limited were available : // about.fb.com/news/]Background
Mr Schrems, an Austrian national resident in Austria and a Facebook social network user since 2008, filed a complaint with the Irish Data Protection Commissioner (the DPC) in June 2013 requesting the DPC to prohibit Facebook Ireland, as data controller, from transferring his personal data to the United States. Mr Schrems complaint was that law and practice in the United States did not ensure ‘adequate’ protection of the personal data held in its territory against the surveillance activities of the US public authorities contrary to the requirements of the Data Protection Directive (the DPD). In result of that complaint, and following a reference to the EU Court of Justice {CJEU}, the original EU Commission Decision which had found that the US Safe Harbor arrangements for transfers of personal data to the USA were ‘adequate’ (providing for essentially equivalent protection for such personal data as that required in the EU) was ruled invalid. (‘Schrems I’, Judgment of the CJEU of 6 October 2015).
In practice, thereafter, many companies turned to Standard Contractual Clauses (the SCCs) as a contractual means of ensuring compliant transfers of personal data to the USA. (There are currently three sets of SCCs, adopted by separate Commission Decisions, including the 2010 SCCs).
‘Safe Harbor’ was replaced by the ‘EU-US Privacy Shield’ approved by a Commission Decision of July 2016. An innovation in Privacy Shield was the creation of an Ombudsperson, independent of the intelligence community, to mediate surveillance concerns. In its approval Decision the Commission found that the United States ensured an adequate level of protection for personal data transferred from the EU to organisations in the USA who had self-certified that they comply with the Privacy Shield. The 2010 SCCs were amended in 2016 to take account of Schrems I and Privacy Shield.
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) was adopted in April 2016 and replaced the Data Protection Directive as from 25 May 2018.
The story does not end there. Back in Dublin, the Irish Data Protection Commissioner (DPC) invited Mr Schrems to amend his original 2013 complaint requesting the DPC to prohibit the transfer of his personal data to Facebook in the USA to take account of the Schrems I judgment. Mr Schrems wrote to Facebook and asked them to clarify the lawful grounds they relied on for making such transfers of users’ personal data. Facebook replied that they substantially relied on the 2010 SCCs for their EU data controller to non-EU data processor transfers.
The Reference to the CJEU
In his reformulated complaint, Mr Schrems asserted that the contractual clauses relied on by Facebook do not correspond to the 2010 SCCs and moreover that the SCCs do not themselves offer adequate protection for personal data of Facebook’s users because Facebook is required to make the data available to the US authorities. The DPC investigated to determine: first, whether the USA ensures adequate protection of the personal data of EU Citizens and, second, whether the SCCs offer sufficient safeguards of fundamental rights and freedoms. In a draft Decision of May 2016 the DPC considered, provisionally, that, taking account of EU citizens’ rights to respect for their private life, home and communications; protection of personal data; and to have an effective remedy before a tribunal; as provided respectively by Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union (CFREU): (…) “the SCC Decisions are likely to offend against article 47 of the Charter insofar as they purport to legitimise the transfer of the personal data of EU citizens to the US notwithstanding the absence of a complete framework for any such citizen to pursue effective legal remedies in the US”.
On that basis the DPC brought proceedings before the High Court in Dublin, including Mr Schrems and Facebook as defendants, and requesting the court to determine whether issues regarding validity of the SCCs required a reference to the CJEU, which alone is competent to rule on the validity of EU legislative acts (Schrems I and cf. Achmea, Case C-284/16 [2018] ECLI:EU:C:2018:158). Pursuant to a judgment of Ms. Justice Costello of 3 October 2017, the High Court in Dublin referred eleven detailed questions to the CJEU, under the preliminary ruling procedure, including on the interpretation and validity of the 2010 SCCs.
Case C-311/18 – Advocate General Saugmandsgaard Øe’s Opinion of 19 December 2019
The reference was made on 8 May 2018. In his Opinion the Advocate General stated at the outset that his examination had not disclosed anything to affect the validity of the 2010 SCCs in principle (in abstracto) – but drew a distinction between that determination and whether the transfers in dispute should be suspended in concreto (Opinion at §166). He suggested, however, that the CJEU did not need to respond to the other questions from the referring Court or analyse the validity of the Privacy Shield Decision – because the referring Court had not directly questioned the validity of the finding of adequacy in that Decision. Nevertheless, and in case the CJEU considered that it should respond in detail on the questions asked, he did go on to find that the ‘essential equivalence’ between the judicial protection afforded in the United States legal order to persons whose data are transferred to the United States from the EU was “open to question” (Opinion at §341).
CJEU Judgment in Case C-311/18 of 16 July 2020
The CJEU has been more forthright than the Advocate General felt able to be. Regarding territorial scope, the Court confirmed that Article 2(1) and (2) of the GDPR applied to the transfer of personal data for commercial purposes by an economic operator established in the EU to an economic operator in a third country outside the EU irrespective of whether the data is liable to be processed by authorities in the third country for purposes of public security, defence and State security.
The Court found that the Commission’s Privacy Shield Decision was invalid. On the other hand, it did not invalidate the 2010 SCCs. However, on that subject it clarifiedé that:
- Transfers supported by using SCCs, must provide data subjects with a level of protection equivalent to that guaranteed within the European Union by the GDPR read in the light of the CFREU: [The validity of the Commission’s SCC decisions] “depends, … , on whether, … such a [SCC] decision incorporates effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection required by EU law and that transfers of personal data pursuant to the clauses of such a decision are suspended or prohibited in the event of the breach of such clauses or it being impossible to honour them”. (Judgment at 137.)
- Unless there is a valid European Commission adequacy decision, the National Supervisory Authority which is competent to consider a case, is required to suspend or prohibit the transfer of data to a third country pursuant to SCCs if it takes the view that in practice the contractual clauses cannot be complied with in a third country and cannot be assured by other mechanisms if the controller or processor has not itself suspended or put an end to the transfer. (see Judgment at 113.)
Conclusions
- The judgment makes very clear how important a finding of adequacy is to permit frictionless personal data transfers to third countries.
- It emphasises that SCCs are not ‘sign-and-forget’ documents but need to be reviewed and supported where necessary. “In that regard, recital 109 of the [GDPR] states that ‘the possibility for the controller … to use [SCCs] … should [not] prevent [it] … from adding other clauses or additional safeguards’ and states, in particular, that the controller ‘should be encouraged to provide additional safeguards… that supplement [SCCs]” (Judgment at 132).
- The Irish DPC will now need to assess whether it is required to suspend or prohibit the transfer of personal data from Facebook Ireland to Facebook Inc. in the United States. (A more general prohibition on personal data transfers to the USA, would need to be referred to the European Data Protection Board for a binding opinion: see Judgment at 147.)
- For the United Kingdom (UK), taking account of the fact that it has chosen to exit from the CFREU, the judgment increases the pressure to secure an adequacy decision before 31 December 2020 and the end of the transition period.

Consequences of the United Kingdom’s withdrawal from the European Union n° 5: Implementing the Protocol on Ireland (I) / Northern Ireland (NI)
2 July 2020
“Clarity on the practical measures that will be necessary to implement the Protocol, and the steps that businesses based in or trading with Northern Ireland need to take to prepare, is now required as a matter of acute urgency if damage to the Northern Ireland economy is to be avoided”. (House of Lords European Union Committee: Report on the Protocol on Ireland/Northern Ireland [HL Report on the P-INI] – 1 June 2020, paragraph 329).
Trade in Goods – Some Brief Facts
Most trade in goods through Northern Ireland’s ports (68%) was with Great Britain (England, Scotland and Wales). A total of 863,511 road goods vehicles passed through NI ports in 2018. Source: NISRA Northern Ireland Ports Traffic 2018 Published on June 2020. Source: NISRA Northern Ireland Ports Traffic 2018 Published in June 2020.

NI – Intersection of EU’s Customs Union & Single Market with the UK’s Internal Market
In less than six months’ time, on 1 January 2021, the P-INI to the UK Withdrawal Agreement (WA) becomes operational – whether or not a Free Trade Agreement is concluded. Northern Ireland is where the UK’s Internal Market intersects with the EU’s Customs Union and Single Market. The significance of that intersection lies in the acutely important link between economic prosperity and political stability.
The P-INI expressly recognises the unique circumstances that exist on the island of Ireland. It affirms that the successful culmination of the peace process, the Belfast/Good Friday Agreement of 10 April 1998, should be protected. Its key assumption is that there shall be no return to a hard border for the movement of goods on the island of Ireland. Practically, that objective is achieved by situating a (virtual) border between GB and NI – in the Irish Sea.
Trade in goods the tension between P-INI Articles 4 and 5
The main proposition of P-INI Article 4 is short and straightforward, it states that “Northern Ireland is part of the customs territory of the United Kingdom”. That apparent simplicity has to be read subject to Article 5 which is about customs and the free movement of goods.
P-INI Articles 5(1), 5(3) and 5(4) are more technical, they say respectively:
- P-INI 5(1) No customs duties shall be payable for a good brought into Northern Ireland from another part of the United Kingdom by direct transport, notwithstanding paragraph 3, unless that good is at risk of subsequently being moved into the Union, whether by itself or forming part of another good following processing. (…)
- P-INI 5(3) “Legislation as defined in point (2) of Article 5 of Regulation (EU) No 952/2013 shall apply to and in the United Kingdom in respect of Northern Ireland (not including the territorial waters of the United Kingdom)” (…).
- P-INI 5(4) “The provisions of Union law listed in Annex 2 to this Protocol shall also apply, under the conditions set out in that Annex, to and in the United Kingdom in respect of Northern Ireland”. (…) (All emphases added.)
Interpretation of the combined effect of P-INI Articles 4 and 5
The reference to Regulation 952/2013 makes the entirety of the EU Customs legislation applicable in Northern Ireland. The provisions listed in P-INI Annex 2 are EU single market rules and regulations. The combined effect is to introduce what we can refer to for simplicity’s sake as red and green channels for direct transport of goods from GB to NI. Goods that are ‘at risk’ of being moved subsequently to Ireland (whether by themselves or having been incorporated in other products) will be subject to EU standards, customs treatment and EU tariffs – (red channel). The Joint Committee which is to administer the P-INI is to define what ‘at risk goods’ are. Green channel goods that are not ‘at risk’ will be subject to fewer formalities.
Reducing the complexity of implementing P-INI Article 5
The HL Report referred to at the start of this article identifies a number of potential means to mitigate the potential impact of Article 5 on Northern Ireland (at para. 98) including:
- Agreement of a comprehensive UK-EU free trade agreement;
- Streamlining customs processes;
- Implementing the Joint Committee’s definitions of goods that are ‘at risk’.
- Technological solutions;
However, neither the FTA nor these practical arrangements are yet in place.
Northern Ireland Business – Brexit Working Group (NIB-BWG) working paper
On 29 May the NIB-BWG published a detailed paper on implementing the P-INI subtitled: What Business in Northern Ireland needs and why. It sets out almost sixty practical questions about implementing the arrangements. (The paper is a response to the UK Government’s 20 May Command Paper: The UK’s Approach to the Northern Ireland Protocol. ‘Command Papers’ are official publications that set out details about major government initiatives.)
The delayed ‘Freeports’ consultation – an added complexity?
Up to ten ‘Freeports’ are to be introduced within the UK’s geographical territory but outside its ordinary customs territory including, potentially, in Northern Ireland. Freeports are intended to be innovative hubs and attract inward investment. They will have separate customs rules. The UK Government’s Freeports consultation, due to close in April, will now close on 13 July 2020.
Conclusion: A great deal remains to be done in a short time to help businesses that are either in or trading with NI make practical preparations to implement the P-INI.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions. FLINN stands ready to provide any further information that you may require.
Read More
Making compliant use of CCTV
In line with its 2020 priorities (see the previous article ‘Two years of the GDPR’), the Belgian Data Protection Authority (APD/GBA) recently published Decision 16/2020 (Decision) clarifying the regulatory requirements for use of surveillance cameras (CCTV) and keeping of compliant records.
Facts
Plaintiff (“P”) complained that his image was captured without his consent while walking on the pavement outside the defendant’s shop in violation of the applicable law. P stated that he could see his image displayed on a screen at the rear of the shop. He assumed the images had been recorded. The APD/GBA Litigation Chamber formally reprimanded the defendant (D) for D’s failure to declare the use of CCTV as well as failure to establish a Register of its personal data processing activities. It also required D to establish a record of all processing activities within 3 months.
Rules on the installation and use of CCTV
Article 6 § 2 of the “Camera Law” (Law of 21 March 2007 on the installation and use of surveillance cameras as amended and up-dated), requires a data controller who intends to install surveillance cameras in an “enclosed place accessible to the public”, such as a shop or supermarket, to notify the APD/GBA and police authorities using the mandatory electronic form before the surveillance cameras are put into operation. They must also display signs showing that CCTV is in use.
Register of CCTV image processing
A Royal Decree of 8 May 2018 (Royal Decree) defines the record of the image processing activities that must be kept. In addition to the data controller’s record of personal data processing (required by article 30(1) General Data Protection Regulation (GDPR) – see below) the image processing register must include information such as:
- The legal basis for the processing;
- What type of premises are concerned;
- A technical description of the surveillance cameras and, in the case of fixed cameras, a plan of the premises showing where they are installed;
- Whether or not viewing in real-time is organized and, if so, how it is organized.
The image processing register must be made available to the APD/GBA or to the police on request.
Record of personal data processing under GDPR
According to article 30(1) GDPR, any controller of personal data must keep a record of data processing activities carried out under his/her responsibility including, amongst other things:
- Name and contact details of the controller and the purpose(s) of the processing;
- Description of the categories of data subjects and the categories of personal data processed.
The article 30 GDPR register of processing activities is a living document which needs to evolve as the data controller’s activities change. It must be kept up to date.
Clarifications and confirmations made by the APD/GBA Decision
The APD/GBA Decision clarifies that it is not necessary to maintain two separate registers. A single Register can be kept, provided that it contains all the mandatory entries – including those specifically required by the Royal Decree for surveillance cameras.
The Decision also confirms that keeping of an article 30(1) GDPR register will be mandatory for most small and medium sized businesses. The four exceptions for enterprises with fewer than 250 employees set out in article 30(5) GDPR will be considered separately and interpreted narrowly.
In particular, the exception for ‘occasional’ processing of personal data is unlikely to apply in the majority of cases, because data processing related to customer management, personnel management (human resources) or supplier management is routine (in practice often monthly) and therefore not occasional.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions. FLINN stands ready to provide any further information that you may require.
Read More
Making compliant use of CCTV
In line with its 2020 priorities (see the previous article ‘Two years of the GDPR’), the Belgian Data Protection Authority (APD/GBA) recently published Decision 16/2020 (Decision) clarifying the regulatory requirements for use of surveillance cameras (CCTV) and keeping of compliant records.
Facts
Plaintiff (“P”) complained that his image was captured without his consent while walking on the pavement outside the defendant’s shop in violation of the applicable law. P stated that he could see his image displayed on a screen at the rear of the shop. He assumed the images had been recorded. The APD/GBA Litigation Chamber formally reprimanded the defendant (D) for D’s failure to declare the use of CCTV as well as failure to establish a Register of its personal data processing activities. It also required D to establish a record of all processing activities within 3 months.
Rules on the installation and use of CCTV
Article 6 § 2 of the “Camera Law” (Law of 21 March 2007 on the installation and use of surveillance cameras as amended and up-dated), requires a data controller who intends to install surveillance cameras in an “enclosed place accessible to the public”, such as a shop or supermarket, to notify the APD/GBA and police authorities using the mandatory electronic form before the surveillance cameras are put into operation. They must also display signs showing that CCTV is in use.
Register of CCTV image processing
A Royal Decree of 8 May 2018 (Royal Decree) defines the record of the image processing activities that must be kept. In addition to the data controller’s record of personal data processing (required by article 30(1) General Data Protection Regulation (GDPR) – see below) the image processing register must include information such as:
- The legal basis for the processing;
- What type of premises are concerned;
- A technical description of the surveillance cameras and, in the case of fixed cameras, a plan of the premises showing where they are installed;
- Whether or not viewing in real-time is organized and, if so, how it is organized.
The image processing register must be made available to the APD/GBA or to the police on request.
Record of personal data processing under GDPR
According to article 30(1) GDPR, any controller of personal data must keep a record of data processing activities carried out under his/her responsibility including, amongst other things:
- Name and contact details of the controller and the purpose(s) of the processing;
- Description of the categories of data subjects and the categories of personal data processed.
The article 30 GDPR register of processing activities is a living document which needs to evolve as the data controller’s activities change. It must be kept up to date.
Clarifications and confirmations made by the APD/GBA Decision
The APD/GBA Decision clarifies that it is not necessary to maintain two separate registers. A single Register can be kept, provided that it contains all the mandatory entries – including those specifically required by the Royal Decree for surveillance cameras.
The Decision also confirms that keeping of an article 30(1) GDPR register will be mandatory for most small and medium sized businesses. The four exceptions for enterprises with fewer than 250 employees set out in article 30(5) GDPR will be considered separately and interpreted narrowly.
In particular, the exception for ‘occasional’ processing of personal data is unlikely to apply in the majority of cases, because data processing related to customer management, personnel management (human resources) or supplier management is routine (in practice often monthly) and therefore not occasional.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions. FLINN stands ready to provide any further information that you may require.
Read More
Two years of the « GDPR »
25 May 2020
Today is the second anniversary of the date in 2018 when the General Data Protection Regulation (GDPR) became enforceable. It is also the date on which the first official evaluation of the GDPR should be made. Even if the formal evaluation is delayed – some trends can already be identified.
Requirement for an evaluation
The formal requirement for the EU Commission to submit a review and evaluation to the European Parliament and to the Council is set out in Article 97 GDPR. The first such evaluation was scheduled for today, 25 May 2020. Subsequent reviews are to be made every four years.
European Data Protection Board (EDPB) pre-evaluation
The EDPB issued its contribution to the EU Commission’s formal evaluation in February this year. It made a generally positive assessment of the GDPR but acknowledged that implementation has been especially challenging for small or medium sized enterprises (SMEs). It pointed out that the ability of the member states’ Data Protection Authorities (DPAs) to support the ‘one-stop-shop’ mechanism (intended, together with co-operation, to improve cross-border legal certainty for data controllers and data processors) depends on them being provided with sufficient resources. As regards international transfers, to third countries outside the EU, EDPB called on the EU Commission to update the existing Standard Contract Clauses (SCC’s) in-line with the GDPR and emphasised the need to adopt a set of processor-to-processor SCC’s. (The Court of Justice of the European Union is due to deliver its judgment, regarding legality of the existing SCCs, on 16 July in the Schrems II case, Case C‑311/18.)
What else do we know Europe-wide?
Before the impact of Covid-19 in April/May 2020, the number of fines per month was increasing significantly. An insufficient legal basis for data processing was the reason for the greatest number of fines. The heaviest fines were issued for a lack of technical and organisational measures to ensure data security. (Supporting statistics are available here.)
What else do we know that specifically concerns Belgium?
Although legislation creating the Belgian DPA (APD/GBA) was adopted in December 2017, the transition period towards full GDPR implementation has been relatively long. The new Executive Committee, of five directors, did not take office until 24 April 2019, just over one year ago. Priority areas for the APD/GBA’s Strategic Plan 2020-2025 include: Telecommunications and Media, Direct Marketing, Education, support for SMEs and certain societal issues, notably: use of surveillance cameras and photography, online data protection and protection of sensitive data (see the summary here).
The APD/GBA now has significant inspection and sanctioning powers. Accordingly, it has two new departments: a litigation chamber, which is supported by an inspection service. Complaints to the APD/GBA are the source of the majority of most ongoing case referrals, but current own initiative investigations of the cookies policies of online media websites are likely to be followed by reviews of several of the other ‘most consulted’ websites in Belgium.
Conclusions
The level and intensity of GDPR enforcement in Belgium and across the EU is set to increase.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions.
Read More
How can contact tracing help limit the spread of the Covid-19 coronavirus?
19 May 2020
Belgium has taken the decision that a coronavirus ‘App’ is not necessary for contact tracing. In the UK, NHSX has launched a trial on the Isle of Wight of a proprietary smartphone App. Other European countries, including Germany, have opted to deploy systems facilitated by co-operation between Apple (iOS) and Google (Android) on Blue-tooth technology. Are there clear benefits of using data applications for contact tracing? What are the potential detriments?
Contact tracing – a proven technique
Contact tracing is used to help break chains of transmission and control virus outbreaks. Using interviews and questionnaires to carry out the contact tracing manually is a well-known and proven technique. Nevertheless, it is labour intensive and time consuming. (You can consult the WHO’s report on using manual tracing to help control outbreaks of Ebola here.)
Digital proximity tracing using smartphones
The idea behind digital proximity tracing is to make use of ‘Bluetooth’ Low Energy (LE) signals, from the smartphone in your pocket, to record and estimate the distance between you and other smartphone users with whom you have come into reasonably close contact. Such tracing can establish, from among those who subscribe to and turn on the App, a list of persons to whom you have been physically close. If you test positive, contacts identified through the App can be alerted to take action, by self-isolating or accessing a Covid-19 test for example.
Centralised or decentralised digital proximity tracing?
In digital proximity tracing, users download an App to their smartphone which, when enabled, transmits random ‘identifiers’ (a string of digits) using Bluetooth LE. Other similarly enabled smartphones, that come close enough, detect and record the unique identifiers.
In a centralised system, if a person tests positive for Covid-19, the anonymised identifiers transmitted by their phone can be uploaded to the central server together with the time and duration of near contacts with other smartphones. Third-party contacts calculated to be at risk are centrally contacted and notified that they have been in proximity to an infected person.
In a decentralised system, a person who tests positive for Covid-19 self-reports their identifiers to a database. The database of positive identifiers is available to be consulted daily by all other users of the App, but any matching takes place on the user’s own device – not centrally.
The legal issues?
A balance needs to be struck between a government’s duty to protect public health and restrictions of individual rights to privacy. Even if App usage is voluntary, the health advantages must be weighed against privacy disadvantages (see the open letters here and here). Public confidence that the right balance has been struck will underpin widespread adoption.
Data Protection Authorities and Contact Tracing Apps
The ICO document about how data protection principles should be implemented in such Apps is here. Data protection aspects of the UK’s current NHSX proposal were criticised by politicians here and by an academic here. France’s CNIL emphasised that voluntariness, a correct legal basis, transparency and technical efficiency are all necessary to generate public confidence. Its cautious initial approval for a (centralised) French contact tracing system is here.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions.
Read More
Prolongation of the general moratorium provided for by Royal Decree No. 15
On Wednesday 13th of May, the Belgian Government decided to extend the series of measures contained in Royal Decree No. 15 regarding the temporary suspension of enforcement measures and other measures in favour of companies during the COVID-19 crisis. The initial date of the end of the moratorium scheduled for 17 May 2020 has been postponed until 17 June 2020, which date could itself be subject to further prolongation by further legislative decree.
Further information on Royal Decree No. 15 can be found in our article “Royal Decree No. 15 regarding the temporary suspension of enforcement measures and other measures in favour of companies during the COVID-19 crisis” and its practical implications are discussed in our FAQs:
- What precautions should be taken prior to initiating new business relationships?
- What securities may be effectively taken notwithstanding the limitations imposed by Royal Decree No. 15?
- My debtor is known to be bankrupt, what can I do?

