In 2013, Edward Snowden publicly disclosed that US Intelligence Agencies have access to the personal data of European users via surveillance programs such as PRISM or Upstream. These disclosed documents also listed a number of companies that are providing data to the US government for surveillance programs, including Apple, Microsoft, Facebook, Google and Yahoo. Following the Snowden disclosures, Max Schrems filed a complaint against Facebook Ireland Ltd before the Irish Data Protection Commissioner (DPC), arguing that Facebook may not transfer his personal data to the US anymore, given that Facebook USA has to provide that data to the US secret services without adequate protection.
After lengthy back and forth between the DPC, Facebook and Max Schrems, the case was referenced to the Court of Justice of the European Union (CJEU). In a groundbreaking judgment in 2015 the CJEU declared the first legal instrument (“Safe Harbor”) invalid. In 2019, the CJEU also declared “Privacy Shield” (the successor of Safe Harbor) invalid and highlighted that Facebook may also not use “Standard Contractual Clauses”, which was another type of transfer mechanism.
At its core, there is a fundamental conflict between US surveillance laws (which demand surveillance of non-US persons) and European data protection laws (which requires privacy protections), that can only be overcome by a common standard for privacy protections, no matter the citizenship. Until such time, it is unlikely that the matter will be resolved.
More information on EU-US Data Transfers
More information on EU-US Data Transfers
In this project, noyb
- filed 101 model complaints against companies that are still transferring data to the US after invalidation of Privacy Shield in July 2020,
- is providing information for EU companies on how to comply with the ruling and informing users about their options to stop data transfers to the US,
- is prompting the Irish Data Protection Commissioner, the responsible authority for Facebook, to enforce the judgment and stop Facebook’s data transfers to the US,
- is actively preparing to challenge any upcoming new EU-US data transfer deal that is not based on any substantial change of US laws and practices and
- advocates for a long-term solution, based on an agreement among democratic countries, which limits surveillance of private individuals (no matter the citizenship), unless common thresholds (such as probable cause and a judicial approval) are met.
Case | Controller | DPA | Status | Duration |
---|---|---|---|---|
C029-44 | netdoktor.at GmbH | DSB (Austria) | Pending (4 years and more) | Filed:
Closed: (2 years 7 months) |
C029-45 | CZECH NEWS CENTER a.s. | DSB (Austria), UOOU (Czech Republic) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-46 | oe24 GmbH | DSB (Austria) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-47 | POMO Media Group sro | DSB (Austria), UOOU (Czech Republic) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-48 | Politis | DSB (Austria), Commissioner (Cyprus) | Partly Won | Filed:
(4 years 4 months ago) |
C029-49 | Cyprus Football Association | DSB (Austria), Commissioner (Cyprus) | Partly Won | Filed:
(4 years 4 months ago) |
C029-5 | Syn | DSB (Austria), Persónuvernd (Island) | Other Outcome | Filed:
(4 years 4 months ago) |
C029-50 | CYPRUS NEWS AGENCY | DSB (Austria), Commissioner (Cyprus) | Partly Won | Filed:
(4 years 4 months ago) |
C029-51 | DYO DEKA EDITORIAL SA (lifo) | DSB (Austria), HDPA (Greece) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-52 | FIRST ISSUE SA | DSB (Austria), HDPA (Greece) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-53 | iefimerida | DSB (Austria), HDPA (Greece) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-54 | Scrooge SA | DSB (Austria), HDPA (Greece) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-55 | Liechtenstein Marketing | Datenschutzstelle (Liechtenstein) | Withdrawn (Complied) | Filed:
(4 years 4 months ago) |
C029-56 | Incrementum AG | Datenschutzstelle (Liechtenstein) | Withdrawn (Complied) | Filed:
Closed: (2 weeks) |
C029-57 | Universität Liechtenstein | Datenschutzstelle (Liechtenstein) | Withdrawn (Complied) | Filed:
Closed: (4 weeks) |
C029-58 | RTÉ Head Office | DPC (Ireland) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-59 | Allied Irish Banks | DPC (Ireland) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-6 | DV | DSB (Austria), Persónuvernd (Island) | Other Outcome | Filed:
(4 years 4 months ago) |
C029-60 | UCD | DPC (Ireland) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |
C029-61 | Vacaciones eDreams S.L. | AEPD (Spain) | Pending (4 years and more) | Filed:
(4 years 4 months ago) |