Page 77 - CBM27
P. 77

~ Spotlight On ~





            European Commission President Ursula von der Leyen and U.S.   Clearly the most controversial EU GDPR decision taken since
            President Joe Biden and their respective industry and justice   it was approved five years ago took place in May when the EU
            ministers.                                        Data Protection Agency imposed a 1.3 billion euro fine on
                                                              META (otherwise known as Facebook) for alleged violations
            The dispute traces back to 1995 when the EU first approved a   of EU data law when transferring data to the U.S. The fine
            Data Privacy Directive, which gave the European Commission   came despite META relying on Standard Contractual Clauses
            the power to block international data transfers to any country   previously approved by the EU as a legal shield while the
            without data protection standards on par with the EU.  The   wrangling over U.S. data protection adequacy status is pending.
            law was significantly upgraded in 2018 in the form of the EU
            GDPR, including new enforcement powers and hefty fines for    The massive META fine, which the Silicon Valley company is
            violators. For nearly three decades data transfers from the EU to   appealing at the ECJ, was levied even though it was opposed by
            the U.S. have been in legal limbo primarily due to a fundamental   Irish Data Protection Authority, which, according to EU law,
            legal and culture divide when it comes to data privacy.  Through   is supposed to have the final say since META’s EU corporate
            the era of Web 1.0 and 2.0 the U.S. Government approach has   headquarters are in Ireland. “The general concern is that the EU
            can be summed up simply as laissez-faire. As a result, there has   data privacy order is flexible and malleable, and it can be used in
            never been political consensus in the U.S. Congress for a federal   different and arbitrary ways,” said Fredrik Erixon, the director
            data protection law.                              of the Europe Centre for International Political Economy, a
                                                              Brussels- based think tank. He added that those arbitrary ways
            In Europe, where the ghosts of 20th century autocrats   are “a factor of political considerations” made obvious by the size
            haunt and the fury over continuous U.S. National Security   of the META fine.
            Agency snooping scandals linger, data privacy is considered a
            fundamental right – and was codified as such in the EU Charter   The criticism of the EU GPDR notwithstanding, thanks to the
            for Fundamental Rights.                           heft of the 27-country, 450 - million EU single market, the bloc
                                                              has become the world’s global data protection standard bearer –
            Besides the overall legal and cultural data privacy differences two   an impact often referred to as the “Brussels Effect.”   But there
            key pivotal factors make the dispute a constant legal burden for   is now an ongoing effort to challenge the EU by the United
            many large and small American and European businesses and   States, Japan, South Korea, the United Kingdom and others via
            a rallying cry for many privacy advocates, lawmakers and   the Global Cross-Border Privacy Rules Forum (GCBPRF).  It is
            bureaucrats – even if it is remote issue to the average European   based on a voluntary data transfer protection approach.
            citizen.  One of those factors traces back to 2013 when Edward
            Snowden decided to sacrifice his U.S. citizenship and Hawaii-  “The Forum allows the United States to offer an alternative
            based National Security Agency job by exposing the U.S.   to the EU GDPR and therefore prevent the EU from setting
            government’s bulk data surveillance of U.S. Telecom and Internet   future personal data protection standards for the world,” data
            service providers.                                privacy expert Patrick Lebland stated in article published
                                                              earlier this year for the Washington, D.C.-based International
            The most important December concession offered by the Biden   Centre for Governance Innovation. “While the Forum calls
            Administration to meet the EU and ECJ demands include a   for interoperability with other systems it is not clear if this is
            new multi-layered redress mechanism called the Data Protection   possible.”
            Review Court where EU citizens can pursue legal claims. Also,
            the White House insisted “intelligence agencies will adopt   Lebland added this important caveat: “without a federal [U.S.]
            procedures ensuring effective oversight of new privacy and civil   privacy or data-protection framework in place Washington
            liberty standards.” However bulk data collection will continue.   has little to offer in terms of rules to promote.” Despite the
                                                              GCBPRF’s budding efforts to offset the “Brussels Effect” it is
            As a result of these changes the European Commission officials   little help to companies large and small currently transferring
            said in July, they are confident they “can credibly defend the   data across the Atlantic Ocean. According to Brian McGinnis,
            framework” in the ECJ.  Throughout the long running EU-  a data privacy lawyer with the U.S.-based law firm Barns &
            U.S. dispute there have been critics, especially in the U.S. but   Thornburg LLP, “businesses are currently spending money,
            also in the EU business community, that insist the EU data   time and other resources attempting to comply with the
            protection demands are extraterritorial, protectionist and are   ever-changing [EU] legal landscape of data transfers and even
            often conveniently finessed to accommodate mandatory EU   compliance with the alternative safeguards listed with the
            data transfers involving taxation, money laundering and others   GDPR may not be enough to avoid fines.”  ••
            sensitive company data.

               Alan Rhode is a co-founder at Taxmen, the one-stop-shop for legal and tax services to the e-commerce industry.
               Joe Kirwin is a US-born journalist based in Brussels.









                                                            77
   72   73   74   75   76   77   78   79   80