03/02/2020
CURIA - Documents
...’
Decision 2000/520
Decision 2000/520 was adopted by the Commission on the basis of Article 25(6) of Directive 95/46.
Recitals 2, 5 and 8 in the preamble to that decision are worded as follows:
The Commission may find that a third country ensures an adequate level of protection. In that case personal data
may be transferred from the Member States without additional guarantees being necessary.
The adequate level of protection for the transfer of data from the Community to the United States recognised by
this Decision, should be attained if organisations comply with the safe harbour privacy principles for the protection
of personal data transferred from a Member State to the United States (hereinafter “the Principles”) and the
frequently asked questions (hereinafter “the FAQs”) providing guidance for the implementation of the Principles
issued by the Government of the United States on 21 July 2000. Furthermore the organisations should publicly
disclose their privacy policies and be subject to the jurisdiction of the Federal Trade Commission (FTC) under
Section 5 of the Federal Trade Commission Act which prohibits unfair or deceptive acts or practices in or affecting
commerce, or that of another statutory body that will effectively ensure compliance with the Principles implemented
in accordance with the FAQs.
In the interests of transparency and in order to safeguard the ability of the competent authorities in the Member
States to ensure the protection of individuals as regards the processing of their personal data, it is necessary to
specify in this Decision the exceptional circumstances in which the suspension of specific data flows should be
justified, notwithstanding the finding of adequate protection.’
Articles 1 to 4 of Decision 2000/520 provide:
‘Article 1
1.
For the purposes of Article 25(2) of Directive 95/46/EC, for all the activities falling within the scope of that
Directive, the “Safe Harbour Privacy Principles” (hereinafter “the Principles”), as set out in Annex I to this Decision,
implemented in accordance with the guidance provided by the frequently asked questions (hereinafter “the FAQs”)
issued by the US Department of Commerce on 21 July 2000 as set out in Annex II to this Decision are considered
to ensure an adequate level of protection for personal data transferred from the Community to organisations
established in the United States, having regard to the following documents issued by the US Department of
Commerce:
the safe harbour enforcement overview set out in Annex III;
a memorandum on damages for breaches of privacy and explicit authorisations in US law set out in Annex IV;
a letter from the Federal Trade Commission set out in Annex V;
a letter from the US Department of Transportation set out in Annex VI.
2.
In relation to each transfer of data the following conditions shall be met:
the organisation receiving the data has unambiguously and publicly disclosed its commitment to comply with the
Principles implemented in accordance with the FAQs; and
the organisation is subject to the statutory powers of a government body in the United States listed in Annex VII
to this Decision which is empowered to investigate complaints and to obtain relief against unfair or deceptive
practices as well as redress for individuals, irrespective of their country of residence or nationality, in case of noncompliance with the Principles implemented in accordance with the FAQs.
3.
The conditions set out in paragraph 2 are considered to be met for each organisation that self-certifies its
adherence to the Principles implemented in accordance with the FAQs from the date on which the organisation
notifies to the US Department of Commerce (or its designee) the public disclosure of the commitment referred to in
paragraph 2(a) and the identity of the government body referred to in paragraph 2(b).
Article 2
This Decision concerns only the adequacy of protection provided in the United States under the Principles
implemented in accordance with the FAQs with a view to meeting the requirements of Article 25(1) of Directive
95/46/EC and does not affect the application of other provisions of that Directive that pertain to the processing of
personal data within the Member States, in particular Article 4 thereof.
Article 3
1.
Without prejudice to their powers to take action to ensure compliance with national provisions adopted
pursuant to provisions other than Article 25 of Directive 95/46/EC, the competent authorities in Member States
may exercise their existing powers to suspend data flows to an organisation that has self-certified its adherence to
the Principles implemented in accordance with the FAQs in order to protect individuals with regard to the processing
of their personal data in cases where:
the government body in the United States referred to in Annex VII to this Decision or an independent recourse
mechanism within the meaning of letter (a) of the Enforcement Principle set out in Annex I to this Decision has
determined that the organisation is violating the Principles implemented in accordance with the FAQs; or
there is a substantial likelihood that the Principles are being violated; there is a reasonable basis for believing that
the enforcement mechanism concerned is not taking or will not take adequate and timely steps to settle the case at
issue; the continuing transfer would create an imminent risk of grave harm to data subjects; and the competent
authorities in the Member State have made reasonable efforts under the circumstances to provide the organisation
with notice and an opportunity to respond.
The suspension shall cease as soon as compliance with the Principles implemented in accordance with the FAQs is
assured and the competent authorities concerned in the Community are notified thereof.
2.
Member States shall inform the Commission without delay when measures are adopted on the basis of
paragraph 1.
curia.europa.eu/juris/document/document.jsf;jsessionid=9ea7d2dc30dd5b610279af57461688cfc1d680446584.e34KaxiLc3qMb40Rch0SaxuRbN90?text=&doc…
4/14