03/02/2020
CURIA - Documents
...
FAQ 11 — Dispute Resolution and Enforcement
How should the dispute resolution requirements of the Enforcement Principle be implemented, and how will an
organisation’s persistent failure to comply with the Principles be handled?
The Enforcement Principle sets out the requirements for safe harbour enforcement. How to meet the requirements
of point (b) of the Principle is set out in the FAQ on verification (FAQ 7). This FAQ 11 addresses points (a) and (c),
both of which require independent recourse mechanisms. These mechanisms may take different forms, but they
must meet the Enforcement Principle’s requirements. Organisations may satisfy the requirements through the
following: (1) compliance with private sector developed privacy programmes that incorporate the Safe Harbour
Principles into their rules and that include effective enforcement mechanisms of the type described in the
Enforcement Principle; (2) compliance with legal or regulatory supervisory authorities that provide for handling of
individual complaints and dispute resolution; or (3) commitment to cooperate with data protection authorities
located in the European Union or their authorised representatives. This list is intended to be illustrative and not
limiting. The private sector may design other mechanisms to provide enforcement, so long as they meet the
requirements of the Enforcement Principle and the FAQs. Please note that the Enforcement Principle’s requirements
are additional to the requirements set forth in paragraph 3 of the introduction to the Principles that self-regulatory
efforts must be enforceable under Article 5 of the Federal Trade Commission Act or similar statute.
Recourse Mechanisms
Consumers should be encouraged to raise any complaints they may have with the relevant organisation before
proceeding to independent recourse mechanisms. ...
...
FTC Action
The FTC has committed to reviewing on a priority basis referrals received from privacy self-regulatory
organisations, such as BBBOnline and TRUSTe, and EU Member States alleging non-compliance with the Safe
Harbour Principles to determine whether Section 5 of the FTC Act prohibiting unfair or deceptive acts or practices in
commerce has been violated. ...
…’
Annex IV to Decision 2000/520 states:
‘Damages for Breaches of Privacy, Legal Authorisations and Mergers and Takeovers in US Law
This responds to the request by the European Commission for clarification of US law with respect to (a) claims for
damages for breaches of privacy, (b) “explicit authorisations” in US law for the use of personal information in a
manner inconsistent with the safe harbour principles, and (c) the effect of mergers and takeovers on obligations
undertaken pursuant to the safe harbour principles.
...
B.
Explicit Legal Authorisations
The safe harbour principles contain an exception where statute, regulation or case-law create “conflicting
obligations or explicit authorisations, provided that, in exercising any such authorisation, an organisation can
demonstrate that its non-compliance with the principles is limited to the extent necessary to meet the overriding
legitimate interests further[ed] by such authorisation”. Clearly, where US law imposes a conflicting obligation, US
organisations whether in the safe harbour or not must comply with the law. As for explicit authorisations, while the
safe harbour principles are intended to bridge the differences between the US and European regimes for privacy
protection, we owe deference to the legislative prerogatives of our elected lawmakers. The limited exception from
strict adherence to the safe harbour principles seeks to strike a balance to accommodate the legitimate interests on
each side.
The exception is limited to cases where there is an explicit authorisation. Therefore, as a threshold matter, the
relevant statute, regulation or court decision must affirmatively authorise the particular conduct by safe harbour
organisations ... In other words, the exception would not apply where the law is silent. In addition, the exception
would apply only if the explicit authorisation conflicts with adherence to the safe harbour principles. Even then, the
exception “is limited to the extent necessary to meet the overriding legitimate interests furthered by such
authorisation”. By way of illustration, where the law simply authorises a company to provide personal information
to government authorities, the exception would not apply. Conversely, where the law specifically authorises the
company to provide personal information to government agencies without the individual’s consent, this would
constitute an “explicit authorisation” to act in a manner that conflicts with the safe harbour principles. Alternatively,
specific exceptions from affirmative requirements to provide notice and consent would fall within the exception
(since it would be the equivalent of a specific authorisation to disclose the information without notice and consent).
For example, a statute which authorises doctors to provide their patients’ medical records to health officials without
the patients’ prior consent might permit an exception from the notice and choice principles. This authorisation
would not permit a doctor to provide the same medical records to health maintenance organisations or commercial
pharmaceutical research laboratories, which would be beyond the scope of the purposes authorised by the law and
therefore beyond the scope of the exception ... The legal authority in question can be a “stand alone” authorisation
to do specific things with personal information, but, as the examples below illustrate, it is likely to be an exception
to a broader law which proscribes the collection, use, or disclosure of personal information.
...’
Communication COM(2013) 846 final
On 27 November 2013 the Commission adopted the communication to the European Parliament and the Council
entitled ‘Rebuilding Trust in EU-US Data Flows’ (COM(2013) 846 final) (‘Communication COM(2013) 846 final’). The
communication was accompanied by the ‘Report on the Findings by the EU Co-chairs of the ad hoc EU-US Working
Group on Data Protection’, also dated 27 November 2013. That report was drawn up, as stated in point 1 thereof,
in cooperation with the United States after the existence in that country of a number of surveillance programmes
curia.europa.eu/juris/document/document.jsf;jsessionid=9ea7d2dc30dd5b610279af57461688cfc1d680446584.e34KaxiLc3qMb40Rch0SaxuRbN90?text=&doc…
6/14