Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
C-311/18 (Schrems II)
Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.
How it connects
References
- Art. 2(2)
- Art. 3(2)
- Art. 28(3)
- Art. 4(2)
- Art. 26(2)
- Art. 25(2)
- Art. 2(1)
- Art. 93(2)
- Art. 45(3)
- Art. 51(1)
- Art. 55(1)
- Art. 57(1)
- Art. 58(2)
- Art. 64(2)
- Art. 65(1)
- Art. 64(1)
- Art. 25(1)
- Art. 45
- Art. 46
- Art. 58
- Art. 3
- Art. 25
- Art. 31
- Art. 20
- Art. 47
- Art. 4
- Art. 23
- Art. 34
- Art. 5
- Art. 44
- Art. 40
- Art. 42
- Art. 49
- Art. 30
- Art. 61
- Art. 62
- Art. 64
- Art. 77
- Art. 78
- Art. 94
- Art. 29
- Art. 99
- Art. 1
- Art. 2
- HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)
- HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)
- HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)
- Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C
- Judgment of the Court (Grand Chamber) of 6 October 2020.#État luxembourgeois v B and Others.#Requests for a preliminary ruling from the Cour administrative (Luxembourg).#References for a preliminary ruling – Directive 2011/16/EU – Administrative cooperation in the field of taxation – Articles 1 and 5 – Decision ordering that information be provided to the competent authority of a Member State, acting in response to a request for exchange of information from the competent authority of another Mem
Related across sources
Full text 9 paragraphs
In that case, any supervisory authority concerned or the Commission may communicate the matter to the Board.’
Article 78 of the GDPR, under the heading ‘Right to an effective judicial remedy against a supervisory authority’, provides, in paragraphs 1 and 2: ‘1. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.
Article 94 of the GDPR provides: ‘1. Directive [95/46] is repealed with effect from
May 2018.’ The SCC Decision
Recital 11 of the SCC Decision reads as follows: ‘Supervisory authorities of the Member States play a key role in this contractual mechanism in ensuring that personal data are adequately protected after the transfer. In exceptional cases where data exporters refuse or are unable to instruct the data importer properly, with an imminent risk of grave harm to the data subjects, the standard contractual clauses should allow the supervisory authorities to audit data importers and sub-processors and, where appropriate, take decisions which are binding on data importers and sub-processors. The supervisory authorities should have the power to prohibit or suspend a data transfer or a set of transfers based on the standard contractual clauses in those exceptional cases where it is established that a transfer on contractual basis is likely to have a substantial adverse effect on the warranties and obligations providing adequate protection for the data subject.’
Article 1 of the SCC Decision states: ‘The standard contractual clauses set out in the Annex are considered as offering adequate safeguards with respect to the protection of the privacy and fundamental rights and freedoms of individuals and as regards the exercise of the corresponding rights as required by Article 26(2) of Directive [95/46].’
In accordance with the second paragraph of Article 2 of the SCC Decision, that decision ‘shall apply to the transfer of personal data by controllers established in the European Union to recipients established outside the territory of the European Union who act only as data processors’.
Article 3 of the SCC Decision provides: ‘For the purposes of this Decision, the following definitions shall apply: … (c) “data exporter” means the controller who transfers the personal data; (d) “data importer” means the processor established in a third country who agrees to receive from the data exporter personal data intended for processing on the data exporter’s behalf after the transfer in accordance with his instructions and the terms of this Decision and who is not subject to a third country’s system ensuring adequate protection within the meaning of Article 25(1) of Directive [95/46]; … (f) “applicable data protection law” means the legislation protecting the fundamental rights and freedoms of individuals and, in particular, their right to privacy with respect to the processing of personal data applicable to a data controller in the Member State in which the data exporter is established; …’
According to its original wording, prior to the entry into force of Implementing Decision 2016/2297, Article 4 of Decision 2010/8