Page 77 - CBM27
P. 77
~ Spotlight On ~
European Commission President Ursula von der Leyen and U.S. Clearly the most controversial EU GDPR decision taken since
President Joe Biden and their respective industry and justice it was approved five years ago took place in May when the EU
ministers. Data Protection Agency imposed a 1.3 billion euro fine on
META (otherwise known as Facebook) for alleged violations
The dispute traces back to 1995 when the EU first approved a of EU data law when transferring data to the U.S. The fine
Data Privacy Directive, which gave the European Commission came despite META relying on Standard Contractual Clauses
the power to block international data transfers to any country previously approved by the EU as a legal shield while the
without data protection standards on par with the EU. The wrangling over U.S. data protection adequacy status is pending.
law was significantly upgraded in 2018 in the form of the EU
GDPR, including new enforcement powers and hefty fines for The massive META fine, which the Silicon Valley company is
violators. For nearly three decades data transfers from the EU to appealing at the ECJ, was levied even though it was opposed by
the U.S. have been in legal limbo primarily due to a fundamental Irish Data Protection Authority, which, according to EU law,
legal and culture divide when it comes to data privacy. Through is supposed to have the final say since META’s EU corporate
the era of Web 1.0 and 2.0 the U.S. Government approach has headquarters are in Ireland. “The general concern is that the EU
can be summed up simply as laissez-faire. As a result, there has data privacy order is flexible and malleable, and it can be used in
never been political consensus in the U.S. Congress for a federal different and arbitrary ways,” said Fredrik Erixon, the director
data protection law. of the Europe Centre for International Political Economy, a
Brussels- based think tank. He added that those arbitrary ways
In Europe, where the ghosts of 20th century autocrats are “a factor of political considerations” made obvious by the size
haunt and the fury over continuous U.S. National Security of the META fine.
Agency snooping scandals linger, data privacy is considered a
fundamental right – and was codified as such in the EU Charter The criticism of the EU GPDR notwithstanding, thanks to the
for Fundamental Rights. heft of the 27-country, 450 - million EU single market, the bloc
has become the world’s global data protection standard bearer –
Besides the overall legal and cultural data privacy differences two an impact often referred to as the “Brussels Effect.” But there
key pivotal factors make the dispute a constant legal burden for is now an ongoing effort to challenge the EU by the United
many large and small American and European businesses and States, Japan, South Korea, the United Kingdom and others via
a rallying cry for many privacy advocates, lawmakers and the Global Cross-Border Privacy Rules Forum (GCBPRF). It is
bureaucrats – even if it is remote issue to the average European based on a voluntary data transfer protection approach.
citizen. One of those factors traces back to 2013 when Edward
Snowden decided to sacrifice his U.S. citizenship and Hawaii- “The Forum allows the United States to offer an alternative
based National Security Agency job by exposing the U.S. to the EU GDPR and therefore prevent the EU from setting
government’s bulk data surveillance of U.S. Telecom and Internet future personal data protection standards for the world,” data
service providers. privacy expert Patrick Lebland stated in article published
earlier this year for the Washington, D.C.-based International
The most important December concession offered by the Biden Centre for Governance Innovation. “While the Forum calls
Administration to meet the EU and ECJ demands include a for interoperability with other systems it is not clear if this is
new multi-layered redress mechanism called the Data Protection possible.”
Review Court where EU citizens can pursue legal claims. Also,
the White House insisted “intelligence agencies will adopt Lebland added this important caveat: “without a federal [U.S.]
procedures ensuring effective oversight of new privacy and civil privacy or data-protection framework in place Washington
liberty standards.” However bulk data collection will continue. has little to offer in terms of rules to promote.” Despite the
GCBPRF’s budding efforts to offset the “Brussels Effect” it is
As a result of these changes the European Commission officials little help to companies large and small currently transferring
said in July, they are confident they “can credibly defend the data across the Atlantic Ocean. According to Brian McGinnis,
framework” in the ECJ. Throughout the long running EU- a data privacy lawyer with the U.S.-based law firm Barns &
U.S. dispute there have been critics, especially in the U.S. but Thornburg LLP, “businesses are currently spending money,
also in the EU business community, that insist the EU data time and other resources attempting to comply with the
protection demands are extraterritorial, protectionist and are ever-changing [EU] legal landscape of data transfers and even
often conveniently finessed to accommodate mandatory EU compliance with the alternative safeguards listed with the
data transfers involving taxation, money laundering and others GDPR may not be enough to avoid fines.” ••
sensitive company data.
Alan Rhode is a co-founder at Taxmen, the one-stop-shop for legal and tax services to the e-commerce industry.
Joe Kirwin is a US-born journalist based in Brussels.
77

