Skip to content
Link

Start a project

Send us an email with a short description of your project, and we will get back to you within 24 hours.

Send an email to
mail@linkutvikling.no
Subject
New project

What should you include?

Tell us briefly what you want to build, who it is for, and when you would like to get started. The more we know, the better the estimate we can give you.

We will then invite you to a no-obligation meeting, so we can find out together whether we are a good match.

All articles

Business

GDPR and American companies

Can personal data be transferred to American companies under GDPR?

Cover image for the article “GDPR og Amerikanske selskap”

- Introduction

Through our work as legal advisers for Link Utvikling AS we have worked on a range of new legal questions. We have found it exciting and challenging to explore new areas of law. Some questions have been more difficult than others. The one that was perhaps hardest was whether the company could use Google Firebase as server and database for an app they were building. Google Firebase is software made by Google for developing mobile and web applications. Since Google is an American company, this raised the question of transferring personal data to a third country. We learned that the answer to that question is far from clear. In what follows I will explain how we went about resolving it, and which challenges exist in current law.

- The GDPR requires a legal basis for transfer

The question of whether personal data can be transferred to a third country has to be resolved under the provisions of the General Data Protection Regulation (Regulation 2016/679), known as the GDPR. The GDPR is implemented in Norwegian law through the Personal Data Act of 15 June 2018. The purpose of the GDPR is to create a consistent, high level of protection for natural persons and to remove obstacles to the free flow of personal data within the EU, see recital 10.

If personal data is to be transferred to countries outside the EEA, the GDPR requires a specific legal basis for the transfer to be lawful. The reason is that countries outside the EEA may have different rules for how personal data is processed. The transfer basis is meant to ensure that the personal data still enjoys protection equivalent to that within the EEA.

The GDPR sets out three options for transferring personal data to third countries. First, the data can be transferred if the European Commission has decided that the area has rules protecting privacy in a way equivalent to the EEA, see article 45. This is known as an adequacy decision. If there is no adequacy decision for the country, the natural next option is article 46. That provision states that a transfer can take place if the controller or processor has provided appropriate safeguards, and on the condition that data subjects have enforceable and effective remedies, see article 46(2). If that option cannot be used either, the last resort is the derogations in article 49. That provision will not be discussed further here.

- Transfer to the USA: the legal development with the Schrems II ruling

Until recently, Privacy Shield was the adequacy decision for transferring personal data to the USA under article 45. Privacy Shield was an agreement between the USA and the EU that allowed American companies to self-certify. The companies had to demonstrate that the personal data transferred to them enjoyed a level of protection equivalent to that under the GDPR. That changed on 16 July 2020 with the Schrems II ruling.

In Schrems II (C-311/18) the Court of Justice of the European Union decided that the Privacy Shield agreement was invalid as a basis for transfer. The court held that the agreement did not provide an adequate level of protection under the GDPR, read in light of the human rights in the Charter. Central to that assessment were the far-reaching powers of American intelligence services and the lack of opportunity for European citizens to challenge surveillance decisions.

At the same time the court expressed that standard contractual clauses remain a valid basis for transfer. The standard clauses are developed by the European Commission. When a data importer signs standard contractual clauses, they commit to processing personal data in line with the requirements applying within the EEA.

The court also stated, however, that standard contractual clauses are not always sufficient as a transfer basis. Sometimes they have to be supplemented with additional measures to achieve an adequate level of protection. This has to be seen in light of the fact that the standard clauses are not binding on the authorities of the third country, and the country may have laws that override them. The problem arises when those laws interfere with the protection European citizens have under the GDPR. For example, the third country may have laws that let the authorities access personal data to a greater extent than the GDPR considers proportionate and necessary. If additional measures are needed and they either do not exist or the company is not able to implement them, the transfer is unlawful and must stop.

In what follows I will describe how to assess whether a transfer is lawful. This description will be at an overall, general level.

- So how should you assess whether the transfer is lawful?

After Schrems II it is now up to each individual organisation to assess whether transferring personal data is lawful. We found that to be far from simple. One particular challenge is that

you have to work out which laws and practices apply in the third country in order to determine whether the level of protection is adequate under the GDPR. That is no easy task. Which laws or practices apply can depend on a range of factors, such as the purpose of the processing and the transfer, the kinds of actors involved, the sector in question, the type of personal data concerned, whether the data is stored in a third country or whether there will be remote access to data stored within the EEA, the data format and the possibility of onward transfer to other third countries. See (footnote 1) https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/overforing-av-personopplysninger-ut-av-eos/tilleggskrav-til-overforingsgrunnlag-schrems-ii/

Once the relevant legislation and practice has been identified, a new challenge appears: you then have to assess whether the level of protection is adequate under the GDPR. Here the organisation has to consider whether the rules amount to a violation of privacy. This is a proportionality assessment. According to the guidance from the Norwegian Data Protection Authority, this assessment can draw on factors such as the case law of the European Court of Human Rights on mass surveillance under article 8 of the ECHR, the factors the Court of Justice highlights in Schrems II, the factors in article 45(2), and the recommendations of the European Data Protection Board on European essential guarantees for surveillance measures (footnote 2). That is a fairly extensive body of legal sources. The result is that the line for what constitutes an adequate level of protection becomes unclear.

If you conclude that the regulation in question in the third country amounts to a violation of privacy, the organisation has to assess whether additional measures can compensate for it so that the level of protection becomes equivalent to the GDPR. The EDPB has produced a recommendation on which measures can be put in place (footnote 3).

The central question in that assessment is whether the additional measures counteract the violation of privacy. That too has to be described as a fairly complex legal assessment.

- Conclusion

Taken together, the Schrems II decision appears to create a range of challenges for organisations wanting to transfer personal data to American companies. They are required to make complex legal assessments in light of American legislation and EU/EEA law, and it is unclear what is lawful. Given how many companies transfer personal data to American companies, it seems concerning that assessing lawfulness is so difficult. This problem will be examined more closely in the second blog post.

Written by:

Håvard Sveier Ottemo and Marthe Hella