03/02/2020 CURIA - Documents involving the large-scale collection and processing of personal data had been revealed. The report contained inter alia a detailed analysis of United States law as regards, in particular, the legal bases authorising the existence of surveillance programmes and the collection and processing of personal data by United States authorities. In point 1 of Communication COM(2013) 846 final, the Commission stated that ‘[c]ommercial exchanges are addressed by Decision [2000/520]’, adding that ‘[t]his Decision provides a legal basis for transfers of personal data from the [European Union] to companies established in the [United States] which have adhered to the Safe Harbour Privacy Principles’. In addition, the Commission underlined in point 1 the increasing relevance of personal data flows, owing in particular to the development of the digital economy which has indeed ‘led to exponential growth in the quantity, quality, diversity and nature of data processing activities’. In point 2 of that communication, the Commission observed that ‘concerns about the level of protection of personal data of [Union] citizens transferred to the [United States] under the Safe Harbour scheme have grown’ and that ‘[t]he voluntary and declaratory nature of the scheme has sharpened focus on its transparency and enforcement’. It further stated in point 2 that ‘[t]he personal data of [Union] citizens sent to the [United States] under the Safe Harbour may be accessed and further processed by US authorities in a way incompatible with the grounds on which the data was originally collected in the [European Union] and the purposes for which it was transferred to the [United States]’ and that ‘[a] majority of the US internet companies that appear to be more directly concerned by [the surveillance] programmes are certified under the Safe Harbour scheme’. In point 3.2 of Communication COM(2013) 846 final, the Commission noted a number of weaknesses in the application of Decision 2000/520. It stated, first, that some certified United States companies did not comply with the principles referred to in Article 1(1) of Decision 2000/520 (‘the safe harbour principles’) and that improvements had to be made to that decision regarding ‘structural shortcomings related to transparency and enforcement, the substantive Safe Harbour principles and the operation of the national security exception’. It observed, secondly, that ‘Safe Harbour also acts as a conduit for the transfer of the personal data of EU citizens from the [European Union] to the [United States] by companies required to surrender data to US intelligence agencies under the US intelligence collection programmes’. The Commission concluded in point 3.2 that whilst, ‘[g]iven the weaknesses identified, the current implementation of Safe Harbour cannot be maintained, ... its revocation would[, however,] adversely affect the interests of member companies in the [European Union] and in the [United States]’. Finally, the Commission added in that point that it would ‘engage with the US authorities to discuss the shortcomings identified’. Communication COM(2013) 847 final On the same date, 27 November 2013, the Commission adopted the communication to the European Parliament and the Council on the Functioning of the Safe Harbour from the Perspective of EU Citizens and Companies Established in the [European Union] (COM(2013) 847 final) (‘Communication COM(2013) 847 final’). As is clear from point 1 thereof, that communication was based inter alia on information received in the ad hoc EU-US Working Group and followed two Commission assessment reports published in 2002 and 2004 respectively. Point 1 of Communication COM(2013) 847 final explains that the functioning of Decision 2000/520 ‘relies on commitments and self-certification of adhering companies’, adding that ‘[s]igning up to these arrangements is voluntary, but the rules are binding for those who sign up’. In addition, it is apparent from point 2.2 of Communication COM(2013) 847 final that, as at 26 September 2013, 3 246 companies, falling within many industry and services sectors, were certified. Those companies mainly provided services in the EU internal market, in particular in the internet sector, and some of them were EU companies which had subsidiaries in the United States. Some of those companies processed the data of their employees in Europe which was transferred to the United States for human resource purposes. The Commission stated in point 2.2 that ‘[a]ny gap in transparency or in enforcement on the US side results in responsibility being shifted to European data protection authorities and to the companies which use the scheme’. It is apparent, in particular, from points 3 to 5 and 8 of Communication COM(2013) 847 final that, in practice, a significant number of certified companies did not comply, or did not comply fully, with the safe harbour principles. In addition, the Commission stated in point 7 of Communication COM(2013) 847 final that ‘all companies involved in the PRISM programme [a large-scale intelligence collection programme], and which grant access to US authorities to data stored and processed in the [United States], appear to be Safe Harbour certified’ and that ‘[t]his has made the Safe Harbour scheme one of the conduits through which access is given to US intelligence authorities to collecting personal data initially processed in the [European Union]’. In that regard, the Commission noted in point 7.1 of that communication that ‘a number of legal bases under US law allow large-scale collection and processing of personal data that is stored or otherwise processed [by] companies based in the [United States]’ and that ‘[t]he large-scale nature of these programmes may result in data transferred under Safe Harbour being accessed and further processed by US authorities beyond what is strictly necessary and proportionate to the protection of national security as foreseen under the exception provided in [Decision 2000/520]’. In point 7.2 of Communication COM(2013) 847 final, headed ‘Limitations and redress possibilities’, the Commission noted that ‘safeguards that are provided under US law are mostly available to US citizens or legal residents’ and that, ‘[m]oreover, there are no opportunities for either EU or US data subjects to obtain access, rectification or erasure of data, or administrative or judicial redress with regard to collection and further processing of their personal data taking place under the US surveillance programmes’. According to point 8 of Communication COM(2013) 847 final, the certified companies included ‘[w]eb companies such as Google, Facebook, Microsoft, Apple, Yahoo’, which had ‘hundreds of millions of clients in Europe’ and transferred personal data to the United States for processing. The Commission concluded in point 8 that ‘the large-scale access by intelligence agencies to data transferred to the [United States] by Safe Harbour certified companies raises additional serious questions regarding the continuity of data protection rights of Europeans when their data is transferred to the [United States]’. curia.europa.eu/juris/document/document.jsf;jsessionid=9ea7d2dc30dd5b610279af57461688cfc1d680446584.e34KaxiLc3qMb40Rch0SaxuRbN90?text=&doc… 7/14

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents