BLOG

The Data Privacy Framework: the new mechanism for transferring personal data

On July 10, 2023, the European Commission adopted its adequacy decision on the EU-US data protection framework. The decision concludes that the US ensures an adequate level of protection—comparable to that of the European Union—for personal data transferred from the EU to US companies under the new framework. Based on the new adequacy decision, personal data can flow safely from the EU to U.S. companies participating in the framework without the need for additional data protection safeguards.

In this blog post, a summary of the Olfeo podcast on the Data Privacy Framework, in collaboration with Richard Montbeyre, a lawyer specializing in Internet law and DPO, we look back at the origins and history of this agreement and its previous versions, while discussing the legal and business impact on the use of American SaaS applications.

The Data Privacy Framework is the third attempt to establish a legal agreement on the transfer of personal data between the United States and Europe. How did we get here?

Since 2000, when the first iteration of this agreement, known as Safe Harbor, was established, the history of data transfers between the European Union and the United States has been somewhat of a troubled partnership, dating back to Edward Snowden's revelations in 2013. In June 2013, the European Union and the rest of the world realized that the United States had developed massive electronic surveillance practices by accessing European data, particularly through well-known American service providers.
Since these revelations shook the world, there has been a pendulum swing between the desire to maintain an economic, strategic, and commercial partnership between the United States and Europe, and rules that remain incompatible between Europe and the United States on national security, fundamental freedoms, and very different ways of proceeding.
We have swung back and forth five times between authorizing the transfer of data from Europe to the United States and a virtual ban. If we want to quickly retrace the timeline, in 2000, the US Department of Commerce and the European Commission signed an agreement called Safe Harbor, which authorized transfers as long as US organizations registered on an online list and thus certified that they would comply with European law, including in the United States.
In 2013, there was the Snowden affair and the Prism scandal. And so, two years later, the Court of Justice of the European Union, at the instigation of a figure who has since become very well known, Maximilian Schrems, at the time an Austrian law student, launched an action against Facebook on the grounds that Facebook was transferring data to the United States illegally. And Safe Harbor was canceled the following year in 2016. Given this desire to maintain a strategic partnership, the European Commission and the Department of Commerce adopted the Privacy Shield in 2016, which is very similar to Safe Harbor. Four years passed. The same Maximilian Schrems returned to the Court of Justice in July 2020. The Privacy Shield was canceled, and so we find ourselves once again in a situation where transfers to the United States are much more difficult to implement.
And in 2023, the same players are still involved. The European Commission and the US Department of Commerce set up a third partnership, which is very similar to the previous two, called the DPF, or Data Privacy Framework, which allows companies that register on a website, as was the case with the Privacy Shield symbol, to legitimize their transfers to the United States.

So, indeed, there is considerable instability and legal uncertainty for companies that use American SaaS software. How does this relate to the application of the GDPR in Europe?

The GDPR has changed virtually nothing in terms of the rules applicable to transfers. It has simply taken over the pre-existing rules, and transfers to the United States were possible before the GDPR, then prohibited, then possible again. In fact, what happened after the GDPR with regard to transfers was that, once again, attempts were made to reconcile European law and US law on issues that go beyond the scope of the GDPR. In fact, we are talking about the balance between the protection of freedoms, the protection of privacy, and state surveillance practices and access to data for national security purposes. And so what the GDPR did was dramatize the situation because it increased the penalties.
This is the game being played between players who are now well known and therefore in a context that is easy to relate to the geopolitical context. What facilitated the conclusion of the Data Privacy Framework and this renewed partnership between Europe and the United States was clearly the geopolitical context and what happened in Ukraine. The decisions are also political, not just legal.

Which tools are actually affected by this agreement? Are they products hosted in the United States? Products hosted in Europe? Tools based on American technologies but hosted in Europe?

This is not solely a question of server location. Nor is it a question of the obligation to locate this data on a European server. Ultimately, it is not a question of the nationality of the provider.
Once a company or individual is subject to US law, either because they are a US resident, because they have a subsidiary in the United States, or because they have operations in the United States, they become subject to US law in the same way that someone who is in Europe, has a subsidiary in Europe, or has operations in Europe would be subject to European law. The question to ask is not only where the servers are located, nor is it only whether the provider with whom I am signing the contract is a US company. In fact, it could also be a French subsidiary of a US company.
The real question is whether the data of European citizens and residents will be accessible remotely or on site by people who are subject to US law. Because if that is the case, there is what is known as the Cloud Act, which makes US law applicable beyond US territory. All products and services covered by this scenario are affected.

For the cloud, for example, as soon as there is a need for maintenance, an update, incident resolution, or support, it quickly becomes clear that it is complicated to maintain cloud hosting while completely depriving the main service provider or the partner who will handle support of access to data.
So when choosing a service, it is important to consider all aspects of the service, not just the server on which the environment will be hosted, because otherwise your risk analysis will not be complete.

If today a company wanted to use a solution that was 100% sovereign or at least not subject to the Cloud Act, what boxes would need to be checked for such a solution?

It's quite simple, really: any company subject to US law must be completely excluded from the provision of services. This means that we are entering into scenarios where we are using solutions, whether cloud-based or not, that are containerized in a purely European environment where no function, accessory, or service is provided by an entity subject to US law.

This is complicated in practice because Americans have developed services and offerings that are relatively indispensable, at least for certain activities.

On July 10, the situation reversed, as it is once again "authorized" to use American SaaS solutions.

It is indeed a reversal, since we are returning somewhat to the previous legal situation, back to the Privacy Shield in a way. This does not mean that we can use solutions, whether American or from another source, without any conditions or precautions. We are in a situation where we are no longer faced with a ban, but with conditional authorization.
We must ensure that the way in which the service is provided does not give access to data without reason to people who should not be authorized. We must ensure general compliance with the GDPR, i.e., user information, respect for their rights, and limited data retention periods. All of this, of course, is unrelated to transfers; it must be provided and respected in the context of the use of services. Without going into too much detail, what happened on July 10 was that we reinstated the possibility of registering on a Privacy Shield-type list.

The GDPR must apply regardless of whether there is a transfer or not. So it's true that this puts companies in a somewhat complicated situation. Two examples come to mind. There's Meta, which was fined €1.2 billion a few months ago, the largest fine ever imposed by European data protection authorities. This fine would probably not have been imposed today since July 10.
Another somewhat troubling example concerns the use of Google Analytics for analyzing user navigation on a website and displaying targeted advertising based on the use of cookie trackers. Many European companies have stopped using Google Analytics because the conditions for using it had become too complex and have therefore switched to other tools that are supposedly more compliant. Today, since July 10, I don't see what's stopping companies from using Google Analytics again in its standard version. So we can clearly see that companies are in a situation where they are forced to take on a degree of risk, which they must assess, understand, and control because their business did not suddenly stop when the Privacy Shield was canceled, and it will not suddenly start again from scratch on the day the Data Privacy Framework is adopted.

So we have to navigate this regulatory storm, stay on course, and assess the risk for each supplier we use, saying to ourselves: here is this new supplier, here is the level of trust I place in them, here is the level of compliance I recognize in them. To what extent does this change my exposure to risk vis-à-vis my own customers, vis-à-vis a supervisory authority, vis-à-vis my decision-making and internal control bodies? And it's a real balancing act. In fact, it's not an exercise where you're either 100% or 0%. You're always in a bit of a gray area.

What is the probability that this new start will also be invalidated by Schrems or someone else?

It must be acknowledged that this new scheme is very similar in its main functioning to the two previous ones. So it is difficult to imagine that it will be completely immune to the same criticisms as its predecessors and that it will not end up in the same way, even if improvements have been made.
What is certain is that it shows one thing: that Europe and the United States want to maintain a partnership on many levels. And so these repeated cancellations are causing real concern and real turmoil among organizations and businesses.

Furthermore, it cannot be ruled out that we will find ourselves back in the same situation as before. And so, at some point, we may well ask ourselves whether there is not a touch of madness in repeating the same measures. If Europe and the United States have a desire, recognized by the organizations in charge, i.e., by the executives and parliaments on both sides, to move forward together, what is preventing Europe and the United States from signing an international treaty and recognizing, once and for all, that transfers can take place?
In which case it would escape the jurisdiction of the Court of Justice of the European Union. I'm not saying that this is what data protection organizations want. I don't know if it's what everyone wants, but there's something a little ridiculous about working hard, canceling, and then starting over. These measures waste a lot of everyone's time, rather than working on real compliance and looking at how we can truly protect people's privacy. So I think an international treaty would be a legal way out of this madness surrounding transfers.

You work for a company and are expected to purchase various software programs to keep your business running smoothly. The question is, should you make your choices based on the current legal framework between the United States and the European Commission? Or should you try to remain independent and instead use common sense and consider the constraints and trade-offs necessary for the company to run smoothly?

It's a bit of all of the above. Obviously, I think the most important thing for a company is to have the tools, instruments, means, and resources that enable it to fulfill its function, carry out its activities, and therefore comply with applicable law. It is unavoidable, essential, and a source of risk if not done, so it must be part of the decision-making process. But legal compliance is a condition. It is not the reason why we would use a supplier. Some people make decisions based on one, two, or three criteria and say so clearly. It is clear that in this area, there are many criteria. There is one that we have not mentioned, even though we have talked a lot about politics, geopolitics, and international relations. It is the fact that the Data Privacy Framework, the mechanism that has just been adopted, is legally based on the European Commission's assessment that the executive order limiting US surveillance practices, which was signed by President Biden last October, is in place and effective.

The US elections will take place in just over a year. We are talking about what could be called a presidential decree, an Executive Order. It is therefore not difficult to imagine, without resorting to political fiction, that if the presidential majority changes in the United States in a year's time, this type of decision, the purpose of which is to reduce the powers of the US national security authorities in favor of the Europeans, could be modified, or even canceled or withdrawn.
And in such cases, once again, it is not completely unimaginable that the European Commission, when it reassesses the effectiveness of the DPF, will realize that ultimately the deal is not being respected. I therefore believe that this should encourage both caution and a refusal to imagine that things have been settled once and for all, because we have clearly seen that this is not the case, as well as a certain degree of serenity in the sense that we know that the partnership between Europe and the United States will continue. We know that measures will be taken on both sides to enable us to continue working together while respecting certain conditions.