• Nenhum resultado encontrado

UIA - The New EU General Data Protection Regulation. Use of Cloud Computing after the Digital Rights Ireland judgment

N/A
N/A
Protected

Academic year: 2021

Share "UIA - The New EU General Data Protection Regulation. Use of Cloud Computing after the Digital Rights Ireland judgment"

Copied!
13
0
0

Texto

(1)
(2)

Judgment of the CJEU (Grand Chamber) of 8 April 2014 (joined cases C-293/12 and C-594/12): the Court declared the invalidity of the Data Retention Directive The Directive

• Historic context of Approval • Scope – Types of Data Retained

• Findings: the EU legislator exceeded the limits imposed by compliance with the principle of proportionality in the light of Articles 7, 8 and 52(1) of the Charter of Fundamental Rights of the European Union

(3)

Digital Rights Ireland Landmark Judgment

• Directive allows acquiring very precise information on the private lives of the persons whose data are retained, such as the habits of everyday life,

permanent or temporary places of residence, daily or other movements, activities carried out, social relationships and the social environments frequented.

• By requiring the retention of those data and by allowing the competent national authorities to access those data, the directive interferes in a particularly

serious manner with the fundamental rights to respect for private life and to the protection of personal data.

(4)

• However, the retention does not adversely affect the essence of the

fundamental rights to respect for private life and to the protection of personal data:

i. the directive does not allow the retention of content

ii. the service or network providers must respect certain principles of data protection and data security.

• It satisfies an objective of general interest, namely the fight against serious crime and, ultimately, public security.

(5)

Digital Rights Ireland Landmark Judgment

• By adopting the Data Retention Directive, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality.

• The interference of the directive with the fundamental rights was not limited to what is strictly necessary.

• The type of retained data provides a lot of information on the people in question, including:

 the identity of the person with whom the communication took place and by what means, and

 the time of the communication as well as the place from which that communication took place and

• The frequency of the communications with certain persons during a given period.

(6)

Main problems with the directive:

• Covers, all individuals, all means of electronic communication and all traffic data without any differentiation, limitation or exception being made in the light of the objective of fighting against serious crime.

• Fails to lay down any objective criterion which would ensure that the

competent national authorities have access to the data and can use them

only for the purposes of prevention, detection or criminal prosecutions concerning offences that may be considered to be sufficiently serious to justify such an interference.

• Refers in a general manner to ‘serious crime’ as defined by each Member State in its national law.

(7)

Digital Rights Ireland Landmark Judgment

• Does not lay down substantive and procedural conditions for access to and

subsequent use of the data: access to is not made dependent on prior review

by a court or by an independent administrative body.

• The minimum retention period of six months does not make any distinction between the categories of data on the basis of the persons concerned or the usefulness of the data in relation to the objective pursued and no criteria are provided for justifying maximum retention period of up to two years.

• No sufficient safeguards provided to ensure effective protection of the data against the risk of abuse and against unlawful access and use of the data (e.g. service providers can have regard to economic considerations when determining the level of security) and it does not ensure the irreversible

(8)

• Last (unexpected) concern of the Court:

The Directive does not require that the data be retained within the EU: in doing

so, it does not fully ensure the control of compliance with the requirements of protection and security by an independent authority, as is, however, explicitly required by the Charter.

Control of a DPA, carried out on the basis of EU law, is an essential

component of the protection of individuals with regard to the processing of

personal data.

Important decision for cloud computing: the Court seems to imply that retained data (or any sensitive data) must be stored and processed exclusively within the European Union

(9)

International transfer issues for cloud computing

• Introduction to cloud computing: models, cloud providers (controllers and/or processors), main contractual issues, concerns

• International transfers under Directive 95/46/EC (BCRs, Model Clauses Controller-Processor (2010), ad hoc Contracts, Safe Harbor)

• Article 29 WP Working Document of a Co-operation Procedure For Issuing Common Opinions on “Contractual Clauses”

considered compatible with the EC Model Clauses

• Approval of model clauses of Microsoft and Amazon Web Services

(10)

• Safe Harbor Regime under scrutiny/transatlantic discussions for an umbrella agreement

• Data Nationalism and its impact in cloud computing (Brazil, Europe, Australia, Russia, France, Portugal) • Microsoft Case (US), Schrems v. Data Protection

(11)

International transfer issues for cloud computing

• Transfers of data by EEA based cloud providers to sub processors outside the EEA – how to solve the problem?

• WP29, Working document 01/2014 on Draft Ad hoc contractual clauses “EU data processor to non-EU sub-processor”;

• How can we improve model clauses and make them more effective?

• Impact of the draft EC Data Protection Regulation on data transfers Company Supplier of Cloud Service Subcontractor Sub-subcontractor in a third country

UE + EEA

(12)

Obrigado | Thank you.

Luis Neto Galvão

Sócio/Partner

T +351 21 313 20 00 | F +351 21 313 20 01

(13)

Av. Zarco, nº2, 2º, 9000-069 T. +351 291 20 2260 | F. +351 291 20 2261 PORTO (*) R. Tenente Valadim, nº215, 4100-479 T. +351 22 543 2610 | F. +351 22 543 2611 _MOÇAMBIQUE

Referências

Documentos relacionados

didático e resolva as ​listas de exercícios (disponíveis no ​Classroom​) referentes às obras de Carlos Drummond de Andrade, João Guimarães Rosa, Machado de Assis,

No campo, os efeitos da seca e da privatiza- ção dos recursos recaíram principalmente sobre agricultores familiares, que mobilizaram as comunidades rurais organizadas e as agências

H„ autores que preferem excluir dos estudos de prevalˆncia lesŽes associadas a dentes restaurados para evitar confus‚o de diagn€stico com lesŽes de

Ao Dr Oliver Duenisch pelos contatos feitos e orientação de língua estrangeira Ao Dr Agenor Maccari pela ajuda na viabilização da área do experimento de campo Ao Dr Rudi Arno

Ousasse apontar algumas hipóteses para a solução desse problema público a partir do exposto dos autores usados como base para fundamentação teórica, da análise dos dados

Nos dados obtidos, os professores apontaram a relevância da experiência profissional no seu desenvolvimento e de suas ações e relataram ter aprendido sobre si, sobre seus

não existe emissão esp Dntânea. De acordo com essa teoria, átomos excita- dos no vácuo não irradiam. Isso nos leva à idéia de que emissão espontânea está ligada à