Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Saturday, 25 January 2020

Exporting personal data I: introduction (and a small Brexit niggle)


Well, I'm back.

I hope to carry on blogging about the law from the slightly different perspective that I have adopted in the past. In particular, I want to try talking about some difficult questions that I come across while working with clients and which I can't help thinking about in my spare time. Thank you for helping me scratch that itch.

This post is just an introduction. If you are familiar with how the GDPR works, then you should skip to the bit about Brexit.

The export of personal data

I want to start by talking about the General Data Protection Regulation, or GDPR as it is affectionately known, which will have been in force for two years in May. In particular, I want to talk about the regime create by the GDPR for the international transfer of data. From a technical point of view, transferring data around the world is, thanks to the Internet, not only straightforward but often invisible. However, from a legal perspective it is not so simple.

The reason why the GDPR tries to control international transfers of data is simple to see. The GDPR's aim is to create a region of really strong protection for personal data in the European Union and the European Economic Area. If someone processing personal data could simply transfer it outside that region and do whatever they liked with it, it would be really easy to get around the GDPR. The protection it gives would be much less useful.

How exports are controlled

The GDPR divides the world into two parts: a "safe" part, which at the moment contains the EU and the EEA; and a potentially wild and dangerous part consisting of what are called "third countries". By the way, there is (as far as I have been able to discover) no formal definition of "third country" as you might expect. It seems to be understood to mean anywhere that isn't a member state of the EU or the EEA, but maybe other countries (eg the UK after Brexit) could escape being "third countries" in the same way as the EEA members have done.

By default, moving data from the safe part of the world to a third country is forbidden, unless one of a (long) list of conditions is met. I plan to look through some of these conditions over this blog series, but in a moment, I will give a brief summary of two that are particularly significant.

Adequacy

The European Commission can declare that a country has "adequate" protection. Even though the country is a mere third country, it has done enough to live up to the high standards set by Europeans and data may be exported there.

This is a sort of data imperialism, perhaps with the hope that European data protection law will dominate the world. Given the steadily increasing list of countries declared "adequate", this may be working.

But, a word of caution about adequacy. Adequacy decisions can be made that are limited to certain kinds of transfer. In other words, just because a country is in the list, does not mean that you can just export data there without further thought. A few countries, for example the United States and Japan have adequacy decisions that are limited in various ways.

For example, the United States clearly does not think that it has to play along with the EU's data protection rules but has set up a system known as the "Privacy Shield" which allows companies to opt into a lightweight version of the GDPR. The USA only counts as having "adequate" protection for transfer to companies who are members of the Privacy Shield. I will have quite a bit to say about the Privacy Shield in a later blog.

Standard Contractual Clauses

A very popular option is for the export and importer to sign an agreement which contains a set of standard clauses approved by the European Commission (or in theory by another regulator). These are, in essence, a promise by the importer that they will not take advantage of the fact that the data is now outside the "safe" part of the world to do evil and/or unspeakable things to it and that they will in all ways be good. The standard clauses are meant to be enforceable by individuals whose personal data is being processed and they contain their own rules controlling further export of the data.

At first sight this system seems very flexible. Most transfer of data will either be internal to a company (in which case each part can sign the standard clauses) or be made subject to some terms or conditions, even if they are standard terms on a website. Including some standard material cut and pasted from the European Commission or elsewhere should be easy enough.

In practice there are quite a few difficulties with the standard clauses, which I intend to look at in some detail later in this series.

What about Brexit?

Unless something dramatic happens between now and then (given past history this is not entirely impossible), the effect of the EU-UK withdrawal agreement and the European Union (Withdrawal Agreement) Act 2020 is that the UK will leave the EU next week on the 31 January 2020.

Article 127 of the withdrawal agreement and section 1 of the Act keep EU law going in the UK for the time being during what is known as the "implementation period" until 31 December 2020 at 11.00pm GMT, though of course that data could end up being renegotiated. So at first sight it would appear that nothing will change for a while yet.

But I still have a concern. From the many examples I have seen, many agreements for sharing, selling or otherwise transferring personal data have provisions in them saying something like "... shall not transfer any personal data outside the European Economic Area..." or wording like that. The problem here is that, despite all the magic words about the implementation period, the UK will not as a matter of fact be in the European Economic Area and so any transfer within or to the UK may well end up being in breach of contract.

I have, since Brexit became a clear possibility, tried to press different wording on clients and their contracting partners. Typically I swap in "third country" for "outside the European Economic Area". It seems to me that the effect of the withdrawal agreement will be that the UK is not a "third country" until at least the end of the implementation period. The alternative would be to include a section attempting to explore all the possibilities along the lines of "If the UK is a member of ...." which seems complicated and fragile.

Does any of this matter? English courts are quite good at preventing over-literal readings of a contract. It's quite possible that a court would be generous and decide that the parties didn't intend that transfer to a country subject to EU law would be prohibited. But I can see the counter-argument quite easily. Not least that the UK is now not nearly as "safe" in GDPR terms as the EU was because in less than a year it could leave the whole protection framework behind. 

That is why I have called this a "niggle" and not a problem. Even so, it is much better to avoid having courts sort your contracts out for you. In my experience, ambiguities make it easier for an aggrieved party to get legal proceedings off the ground, even if they ultimately lose, or to refuse to comply with a contract without being taken to court. It is something that is worth correcting if you can.

Thursday, 20 October 2011

Can we force facebook to give us its "like" database?

Jim Killock of the Open Rights Group pointed me at an interesting response made by facebook to an Irish student named Max's subject access request under Irish data protection legislation which forms a part of the Europe versus facebook campaign.

The particular point that interests me is that, concerns facebook's tracking of all pages visited which show a "like" button - a practice that can be really intrusive. Although Max did obtain a considerable quantity of information, facebook did not release to him their list of "like" tracked data.

In their response facebook say:

Section 4(12) of the Acts carves out an exception to subject access requests where the disclosures in response would adversely affect trade secrets or intellectual property. We have not provided any information to you which is a trade secret or intellectual property of Facebook Ireland Limited or its licensors.

Unfortunately for facebook, that isn't quite what the relevant Irish legislation appears to say (health warning: I am not an Irish lawyer). What section 4(12) of the Irish Data Protection Act 1988 says, according to a consolidated version of the statute, is:

(12) Subsection (1)(a)(iv) of this section is not to be regarded as requiring the provision of information as to the logic involved in the taking of a decision if and to the extent only that  such provision would adversely affect trade secrets or intellectual property (in particular any  copyright protecting computer software).

Note the phrase "information as to the logic involved in the taking of a decision". What this is all about is that section 4 gives data subject several different rights. One right (in section 4(1)(iii)(I)) is to be supplied with a copy of "the information constituting any personal data of which that individual is the data subject" - a simple right to information. Another, and different right, can be found in section 4(1)(iv) which applies to automatic decision making by the data controller. Here the data subject has a right to be informed of the "logic involve in the processing". Obviously that's quite a different right since it is essentially a right to know about algorithms rather than data.

Quite clearly section 4(12) is a restriction on the right under 4(1)(iv) to know about the logic of automatic decision making and not a restriction on the right of information simplicter. Nice try facebook, but I can't see that working.

Our own legislation is very slightly different. We also have a right (in section 7(1)(d) of the Data Protection Act 1998 to be informed about the logic involved in automatic decision making, but the restriction on that right is limited to trade secrets. Section 8(5) says:

Section 7(1)(d) is not to be regarded as requiring the provision of information as to the logic involved in any decision-taking if, and to the extent that, the information constitutes a trade secret.
So that any UK national involved in the Europe v facebook campaign has a much stronger argument.

In any case, at best facebook can claim a database right over the contents of the list of pages visited by Max that they have collected using the "like" button. The database right is a creature of European law (directive 96/9/EC). Recital 48 of the directive states that "the provisions of this Directive are without prejudice to data protection legislation", which seems to me to argue that data protection law ought to trump database right. If you think about it, the contrary would be an impossible situation. Personal data will often be protected by database rights. If you could use database rights to avoid subject access requests they would be of far less use.

Tuesday, 7 July 2009

Data protection: new tiered notification fees

For most of my clients I expect this is a non-event, but it is interesting nonetheless. Fees for notifying the information commissioner are now tiered. Tier 2 consists of organisations with a turnover of £25.9 million or more; or 250 or more members of staff. Charities and small occupational pension schemes escape tier 2 and come under tier 1, as do the rest of us.

The practical effect is that, as from 6th July 2009, tier 2 processors pay a notification fee of £500+VAT, while tier 1 processors continue to pay £35+VAT.

The thinking appears to be that bigger organisations require more regulatory supervision and so should pay more. I'm not sure that's right - surely it depends on the organisation? The reverse might well be true in some fields. As always the numbers (35, 250, 500, 25.9 million) presumably do have a rationale but its not clear to me. Maybe some manipulation of them gives the fine structure constant.

Law changed courtesy of the Data Protection (Notification and Notification Fees) (Amendment) Regulations 2009.

Thursday, 25 June 2009

Social Networking Sites and Data Protection

The Article 29 Data Protection Working Group has published its opinion on the relationship between the Data Protection Directive and Social Networking Sites (SNS).

A key point to take away is that operators of SNS are data controllers rather than merely data processors, so that they are more likely to be subject to European data protection law than if they were merely “data processors”.

Who is the working party?

The working party was set up by by the data protection directive as an advisory body. Its opinions are not legally binding, but they are likely to be persuasive and the Commission must respond them.

Key points

The response to the opinion (so far) has concentrated on the view that SNS operators are probably data controllers. I’ll have more to say about that at the end of this post.

For me the most interesting points are:

  • SNS operators are usually data controllers
  • … and so are many third party application providers
  • … as indeed will be many users
  • privacy should be the default setting
  • release of profile information beyond a user’s selected friends should never be implicit
  • third party applications should not by default be given access to all an individual’s profile information, but only what is necessary for that application to work

It seems to me that this signals a tougher line to SNS like facebook which will not be able to get away with, for example, a completely cavalier attitude to third party applications.

There are a couple of specific points of interest.

Users

Almost anything about someone is “personal data” but most individuals using an SNS won’t be subject to the Directive because it excludes processing “by a natural person in the course of a purely personal or household activity”.

The working group notes an increased use of SNS for other purposes such as for businesses or campaigning. Those would fall outside the household exception and such users would need to comply with the Act.

The Working Group makes three recommendations on this point:

- SNS providers provide adequate warnings to users about the privacy risks to themselves and to others when they upload information on the SNS - SNS users should also be reminded that uploading information about other individuals may impinge upon their privacy and data protection rights; - SNS users should be advised by SNS that if they wish to upload pictures or information about other individuals, this should be done with the individual’s consent.

Which seems entirely positive. Strictly speaking you don’t always need an individual’s permission to process their data, so the last point is not quite right, though it is good practice. What the Directive does require is that individual’s are notified of the processing, which could be done by a tagging system.

Having said that, the Directive was not (I think) written with uses of SNS in mind. I suspect that more difficulties will follow.

Controller vs Processor

The Directive makes a distinction between “controllers” on the one hand “processors” on the other. A controller is an entity which “alone or jointly with others determines the purposes and means of the processing of personal data.”

In the context of an SNS you might argue that it is the users of the site who decide the purpose and means of processing the data, the operator of the site provides nothing more than an environment for the users to do what they wish (post pictures, disclose information about themselves and so on). In other words, they are just a processor.

The Working Party thinks not. Amongst other things sites like facebook decide what use is to be made of data contributed to the site for the purposes of advertising and marketing.

This matters for two reasons: first because it is on the controller (not the processor) that most of the obligations of the directive are imposed; but second because the location of the controller affects whether or not the directive applies at all.

How far does the Directive reach?

The answer to that question applies in article 4 of the directive which states:

(a) the processing is carried out in the context of the activities of an establishment of the controller on the territory of the Member State; when the same controller is established on the territory of several Member States, he must take the necessary measures to ensure that each of these establishments complies with the obligations laid down by the national law applicable; (b) the controller is not established on the Member State’s territory, but in a place where its national law applies by virtue of international public law; (c) the controller is not established on Community territory and, for purposes of processing personal data makes use of equipment, automated or otherwise, situated on the territory of the said Member State, unless such equipment is used only for purposes of transit through the territory of the Community.

The first two provisions give little difficult: if your processing is being carried out in/with or by an establishment of yours in a member state (or somewhere else that state’s law applies) then unsurprisingly you have to comply with the Directive.

The odd one is (c). The Working Group have previously in their opinion on search engines said that storing a cookie in a user’s browser amounts to “making use of” equipment (the user’s browser) so that wherever on the plant a data controller might be, if their processing of the data involves cookies they will be subject to the directive.

I am not entirely convinced by that argument. It would require any such site to have a designated representative in every member state from which anyone were to browse them (under article 4(2)). It also seems to me that what the directive means is that if you process the data in question in a member state then the directive applies to the processing of that data in that member state. A cookie will necessarily contain much personal data of itself.

Conclusion

The opinion seems to me to be useful. It is relatively short and an easy read. Let us hope that it contributes to the pressure on sites like facebook to put their house in order.