03/02/2020
CURIA - Documents
involving the large-scale collection and processing of personal data had been revealed. The report contained inter
alia a detailed analysis of United States law as regards, in particular, the legal bases authorising the existence of
surveillance programmes and the collection and processing of personal data by United States authorities.
In point 1 of Communication COM(2013) 846 final, the Commission stated that ‘[c]ommercial exchanges are
addressed by Decision [2000/520]’, adding that ‘[t]his Decision provides a legal basis for transfers of personal data
from the [European Union] to companies established in the [United States] which have adhered to the Safe
Harbour Privacy Principles’. In addition, the Commission underlined in point 1 the increasing relevance of personal
data flows, owing in particular to the development of the digital economy which has indeed ‘led to exponential
growth in the quantity, quality, diversity and nature of data processing activities’.
In point 2 of that communication, the Commission observed that ‘concerns about the level of protection of
personal data of [Union] citizens transferred to the [United States] under the Safe Harbour scheme have grown’
and that ‘[t]he voluntary and declaratory nature of the scheme has sharpened focus on its transparency and
enforcement’.
It further stated in point 2 that ‘[t]he personal data of [Union] citizens sent to the [United States] under the Safe
Harbour may be accessed and further processed by US authorities in a way incompatible with the grounds on which
the data was originally collected in the [European Union] and the purposes for which it was transferred to the
[United States]’ and that ‘[a] majority of the US internet companies that appear to be more directly concerned by
[the surveillance] programmes are certified under the Safe Harbour scheme’.
In point 3.2 of Communication COM(2013) 846 final, the Commission noted a number of weaknesses in the
application of Decision 2000/520. It stated, first, that some certified United States companies did not comply with
the principles referred to in Article 1(1) of Decision 2000/520 (‘the safe harbour principles’) and that improvements
had to be made to that decision regarding ‘structural shortcomings related to transparency and enforcement, the
substantive Safe Harbour principles and the operation of the national security exception’. It observed, secondly,
that ‘Safe Harbour also acts as a conduit for the transfer of the personal data of EU citizens from the [European
Union] to the [United States] by companies required to surrender data to US intelligence agencies under the US
intelligence collection programmes’.
The Commission concluded in point 3.2 that whilst, ‘[g]iven the weaknesses identified, the current implementation
of Safe Harbour cannot be maintained, ... its revocation would[, however,] adversely affect the interests of member
companies in the [European Union] and in the [United States]’. Finally, the Commission added in that point that it
would ‘engage with the US authorities to discuss the shortcomings identified’.
Communication COM(2013) 847 final
On the same date, 27 November 2013, the Commission adopted the communication to the European Parliament
and the Council on the Functioning of the Safe Harbour from the Perspective of EU Citizens and Companies
Established in the [European Union] (COM(2013) 847 final) (‘Communication COM(2013) 847 final’). As is clear
from point 1 thereof, that communication was based inter alia on information received in the ad hoc EU-US Working
Group and followed two Commission assessment reports published in 2002 and 2004 respectively.
Point 1 of Communication COM(2013) 847 final explains that the functioning of Decision 2000/520 ‘relies on
commitments and self-certification of adhering companies’, adding that ‘[s]igning up to these arrangements is
voluntary, but the rules are binding for those who sign up’.
In addition, it is apparent from point 2.2 of Communication COM(2013) 847 final that, as at 26 September 2013,
3 246 companies, falling within many industry and services sectors, were certified. Those companies mainly
provided services in the EU internal market, in particular in the internet sector, and some of them were EU
companies which had subsidiaries in the United States. Some of those companies processed the data of their
employees in Europe which was transferred to the United States for human resource purposes.
The Commission stated in point 2.2 that ‘[a]ny gap in transparency or in enforcement on the US side results in
responsibility being shifted to European data protection authorities and to the companies which use the scheme’.
It is apparent, in particular, from points 3 to 5 and 8 of Communication COM(2013) 847 final that, in practice, a
significant number of certified companies did not comply, or did not comply fully, with the safe harbour principles.
In addition, the Commission stated in point 7 of Communication COM(2013) 847 final that ‘all companies involved
in the PRISM programme [a large-scale intelligence collection programme], and which grant access to US
authorities to data stored and processed in the [United States], appear to be Safe Harbour certified’ and that ‘[t]his
has made the Safe Harbour scheme one of the conduits through which access is given to US intelligence authorities
to collecting personal data initially processed in the [European Union]’. In that regard, the Commission noted in
point 7.1 of that communication that ‘a number of legal bases under US law allow large-scale collection and
processing of personal data that is stored or otherwise processed [by] companies based in the [United States]’ and
that ‘[t]he large-scale nature of these programmes may result in data transferred under Safe Harbour being
accessed and further processed by US authorities beyond what is strictly necessary and proportionate to the
protection of national security as foreseen under the exception provided in [Decision 2000/520]’.
In point 7.2 of Communication COM(2013) 847 final, headed ‘Limitations and redress possibilities’, the Commission
noted that ‘safeguards that are provided under US law are mostly available to US citizens or legal residents’ and
that, ‘[m]oreover, there are no opportunities for either EU or US data subjects to obtain access, rectification or
erasure of data, or administrative or judicial redress with regard to collection and further processing of their
personal data taking place under the US surveillance programmes’.
According to point 8 of Communication COM(2013) 847 final, the certified companies included ‘[w]eb companies
such as Google, Facebook, Microsoft, Apple, Yahoo’, which had ‘hundreds of millions of clients in Europe’ and
transferred personal data to the United States for processing.
The Commission concluded in point 8 that ‘the large-scale access by intelligence agencies to data transferred to
the [United States] by Safe Harbour certified companies raises additional serious questions regarding the continuity
of data protection rights of Europeans when their data is transferred to the [United States]’.
curia.europa.eu/juris/document/document.jsf;jsessionid=9ea7d2dc30dd5b610279af57461688cfc1d680446584.e34KaxiLc3qMb40Rch0SaxuRbN90?text=&doc…
7/14
اختر الفقرة المستهدفة3
الاتصال بفقرة
Connect to an entity
Disable highlights
أضف إلى جدول المحتويات