What the CJEU's New Opinion Means for International Data Transfers
On Thursday, the Advocate General of the Court of Justice of the European Union (CJEU) delivered his opinion on data transfers in the so-called "Schrems II" legal case.
Why are international data transfers important?
Data transfers between the EU and the U.S. are at stake now more than ever. The European General Assembly questions the validity of the Privacy Shield. He proposes—and the EU generally follows these proposals—that the Standard contractual clauses are generally applicable; however, if a data importer is unable to provide the guarantees set forth by signing the model clauses, the importer is contractually obligated to notify the data exporter so that the data transfer can be halted and the data subjects notified. This is particularly the case when national security regulations prevent an adequate level of data protection and make it impossible to provide the guarantees to which the data importer has committed. This applies to importers such as Microsoft, Amazon, Google, Facebook, …, which must comply with the Foreign Intelligence Surveillance Act (FISA).
The General Advocate indicated that the European Court of Justice does not need to rule on the Privacy Shield in the context of this decision, but nevertheless set forth his opinion in the event that the Court were to rule on the Privacy Shield as well. He made it quite clear that the Privacy Shield, as well as the Safe Harbor—Certification, is still more of a marketing label than a means of providing the safeguards required by the EU courts in the Safe Harbor ruling, and that he would propose to Privacy Shield to declare it invalid once again.





