Page 77 - CBM23
P. 77
~ Spotlight On ~
The main issue with data protection in America, at least in implementation of data encryption by Google has proven to be
the European authorities’ eyes, is that U.S. domestic laws do an insufficient technical measure as Google LLC itself encrypts
not provide adequate safeguards against the risk of unlawful the data and is obliged to grant access to or provide imported
access by governmental authorities to personal data, at least not data in its possession, including the encryption keys necessary to
sufficient in comparison with the strict European standards (U.S. make the data intelligible. As Google LLC retains the possibility
intelligence can implement surveillance programmes without to access the data of individuals in the clear, such technical
many limitations). This happens with Google Analytics, yes, but measures cannot be considered effective in this case.”
also with most U.S.-based digital businesses, we should believe.
Shortly after the Austrian ruling, the French data protection Yet, if the encryption keys are kept under the exclusive control
authority, the Commission Nationale de l’Informatique et des of the data exporter or by other entities established in a country
Libertés – CNIL, followed the path by issuing multiple decisions offering an adequate level of data protection, then encryption can
against local businesses using Google Analytics on similar be a sufficient safeguard.
grounds.
Moreover, continues the CNIL, a solution involving a proxy
The CNIL then published detailed guidelines on Analytics server to avoid any direct contact between the user’s terminal
in July. They state that all the data controllers using Google and the servers of Google Analytics could be a suitable way out,
Analytics in a similar way to the organisations concerned by the provided that various strict security measures are met.
previous decision should now consider this use as unlawful under The CNIL has recommended other audience measurement
the GDPR. tools as an alternative to Google’s, a good share of which is,
patriotically enough, from France.
More broadly, the “transfers [of personal data to the U.S.]
may now only take place if additional technical, legal and Not less active is the Italian Garante della Privacy, who ruled
organisational safeguards are put in place by organisations to in June on the case of a website using Google Analytics 3. The
prevent these accesses [by the U.S. authorities].” Italian data protection authority reiterated that an I.P. address
constitutes personal data, and its truncation doesn’t represent
Given the growing number of cases and controversies concerning a form of anonymisation but of simple pseudo-anonymisation,
Analytics (plus other providers) in all the E.U., the European considering that Google has the means to enrich the data
Data Protection Board, a body composed of representatives of and make them identifiable again. The Garante ordered the
the national data protection authorities, has recently established a concerned website to take initiatives leading to full compliance
working group to jointly examine the legal issues and coordinate with data protection law to avoid the application of hefty GDPR
the member states’ positions. The risk is otherwise that of seeing penalties. In an interview with Netcomm, the main Italian
privacy laws applied in a conflicting manner all around Europe e-commerce association, a member of the Italian data protection
(exactly the risk against which the GDPR was introduced four authority, stated that the decision concerns Google Analytics
years ago). 3 and not the latest version. However, this is far from implying
that GA4 is GDRP-proof.
The standard contractual clauses in place by default between
Google and its partners have not been deemed sufficient to We should soon expect initiatives by the data protection
provide a sufficient level of protection in case of a request authorities of other countries, for instance, Denmark and the
for access from foreign authorities, especially if such access Netherlands, where cases are pending. In March, the European
is provided for by local laws, which are likely to overrule the Commission and the U.S. Government issued a joint statement
contractual clauses. So, the GDPR provision whereby personal on the possibility of a future decision to adequately regulate
data may be transferred to extra-EU countries in the presence personal data flows to the U.S.
of suitable contractual arrangements with the recipient of the
personal data (for example, the standard contractual clauses Perhaps the light at the end of the tunnel? ••
approved by the European Commission) doesn’t apply here.
Likewise, user consent to the data transfer to the U.S. does not
solve the issue. Consent can only be used for occasional transfers,
in fact, and does not represent a long-term solution, as already
highlighted by the European Data Protection Board.
Data encryption may be a solution, but only under
specific conditions. The French CNIL has stated that “the
Alan Rhode is a co-founder at Taxmen, the one-stop-shop for legal and tax services to the e-commerce industry.
77

