Privacy

Facebook told it may have to suspend EU data transfers after Schrems II ruling

Comment

Image Credits: Tom Williams/CQ Roll Call / Getty Images

Ireland’s data protection watchdog, the DPC, has sent Facebook a preliminary order to suspend data transfers from the EU to the US, the Wall Street Journal reports, citing people familiar with the matter and including a confirmation from Facebook’s VP of global affairs, Nick Clegg.

The preliminary suspension order follows a landmark ruling by Europe’s top court this summer which both struck down a flagship data transfer arrangement between the EU and the US and cast doubt on the legality of an alternative transfer mechanism (aka SCCs) — certainly in cases where data is flowing to a non-EU entity that falls under US surveillance law. 

Facebook’s use of Standard Contractual Clauses to claim a legal basis for EU data transfers therefore looks to be fast running out of borrowed time.

European privacy campaigner Max Schrems, whose surname is colloquially attached to the CJEU ruling (aka Schrems II) — and to an earlier ruling which invalidated the prior EU-US data transfer deal, Safe Harbor, on the same grounds of US surveillance overreach — filed his original complaint about Facebook’s use of SCCs all the way back in 2013. So the tech giant has had more than half a decade to get its European data ducks in order.

Reached for comment on the WSJ report, Facebook pointed us to a freshly published blog post, also penned by Clegg — who acknowledges “significant uncertainty” for businesses operating online services that rely on transatlantic data flows in the wake of the Schrems II ruling.

In the blog post the former deputy prime minister of the United Kingdom goes on to advocate for “global rules that can ensure consistent treatment of data around the world”.

“The Irish Data Protection Commission has commenced an inquiry into Facebook controlled EU-US data transfers, and has suggested that SCCs cannot in practice be used for EU-US data transfers,” Cleggs writes. “While this approach is subject to further process, if followed, it could have a far reaching effect on businesses that rely on SCCs and on the online services many people and businesses rely on.”

Facebook’s blog post lobbying for global rules to ensure “stability” for cross-border data transfers paints a picture of how the Schrems II ruling might negatively affect European startups — claiming it could result in local businesses being unable to use US-based cloud providers or run operations across multiple time zones.

The blog post doesn’t have anything much to say on how Facebook itself having to stop using SCCs might affect Facebook’s own business — but we’ve discussed that before here. (The short version is Facebook may need to split its infrastructure in two, and offer a federated version of its service to EU users — which would clearly be expensive and time consuming for Facebook.)

“Businesses need clear, global rules, underpinned by the strong rule of law, to protect transatlantic data flows over the long term,” Clegg goes on, before lobbying for regulatory leniency in the meanwhile, as Facebook continues to transfer EU data to the US in what he claims is “good faith” — despite the acknowledged legal uncertainty and the complaint in question dating back well over half a decade at this point.

Here he is pleading for data transfer mercy on behalf of other businesses who are not involved in this specific complaint: “While policymakers are working towards a sustainable, long-term solution, we urge regulators to adopt a proportionate and pragmatic approach to minimise disruption to the many thousands of businesses who, like Facebook, have been relying on these mechanisms in good faith to transfer data in a safe and secure way.”

EU lawmakers warned recently that there would be no quick fix for US data transfers, despite some parallel Commission noises about working with the US on an enhanced replacement mechanism for the now defunct ‘Privacy Shield’. (Although for businesses that aren’t, as Facebook is, subject to FISA 702 there may be ways to use SCCs for US transfers that are legal, or at least law firms willing to suggest measures you could take… )

Speaking to the EU Parliament last week, justice commissioner Didier Reynders suggested changes to US surveillance law will be needed to bridge the legal schism between US surveillance law and EU privacy rights.

And of course legislative changes require both time and political will. Although it’s interesting to see Facebook’s global VP feeling moved to wade in and call for global solutions for cross-border data transfers. Perhaps the tech giant will funnel some of its multi-million dollar domestic lobbying budget on making the case for reforming US surveillance law in future.

Ireland’s data protection regulator declined to comment on the WSJ report when we got in touch.

Schrems, meanwhile, is not sitting on his hands. In a statement following the newspaper’s report he said his digital rights not-for-profit, noyb, was not informed about the preliminary order by the DPC — speculating the information was leaked to the newspaper by Facebook to draw political attention to its cause.

He also reveals an intent by noyb to start a legal procedure against the DPC, saying it informed Ireland’s regulator this week that it plans to file an interlocutory injunction over the opening a ‘second’ procedure into the matter — arguing this move is in breach of a 2015 court order and is essentially the equivalent of letting Facebook carry on a multi-year game of legal whack-a-mole where it never actually faces enforcement for breaking each specific law.

“Facebook is knowingly in violation of the law since 2013. So far the DPC has covered them and for seven years refused to enforce the law. It seems after the second judgement by the Court of Justice not even the DPC can deny that Facebook’s international data transfers are built on sand,” Schrems told TechCrunch.

“At the same time, Facebook has in internal communication indicated that it has again shifted its legal basis from the SCCs to [the GDPR] Article 49 and the contract they allegedly sign with users. We are therefore very concerned that the DPC is again only investigating one of two legal basis that Facebook uses. This approach could lead to another frustrated case, like the ‘Safe Harbor’ case in 2015.”

What’s new since 2015 is Europe’s General Data Protection Regulation (GDPR) — which came into application in May 2018 and has led EU lawmakers to claim standard-setting geopolitical glory, as the issue of data privacy has risen up the agenda around the world, propelled by the deforming effects of platform power on societies and democracies.

However the two-year-old framework has so far failed to deliver anything much at all on major cross-border complaints which pertain to platform giants like Facebook (or indeed to the adtech industry). This summer a Commission review of the regulation highlighted what it described as a lack of uniformly vigorous enforcement.

Ireland’s DPC is fully in the spotlight on this front too, as the lead regulator for a large number of US tech firms.

It finally submitted the first draft decision on a cross border complaint earlier this summer — but a final decision on that case (relating to a Twitter security breach) has been delayed as the draft failed to gain the backing of all the region’s data supervisors, triggering further procedures related to joint working under the GDPR’s one-stop-shop mechanism.

Any order from the DPC to Facebook to suspend SCCs would similarly need to gain the backing of the bloc’s other regulators (or at least a majority of them). Per the WSJ’s report, Ireland’s regulator has given Facebook until mid-September to respond to the order — after which a new draft would be sent to the other supervisors for joint approval.

So there’s further delay built into the GDPR process before any final suspension order could be issued against Facebook in this seven year+ case. Move fast and break things this most certainly is not.

The WSJ also speculates that Facebook could try to challenge such an order in court. “Internally, Facebook considers the preliminary order and its future implications a big deal,” it adds, citing one of its unnamed sources.

Max Schrems on the EU court ruling that could cut Facebook in two

More TechCrunch

To give AI-focused women academics and others their well-deserved — and overdue — time in the spotlight, TechCrunch has been publishing a series of interviews focused on remarkable women who’ve contributed to…

Women in AI: Rep. Dar’shun Kendrick wants to pass more AI legislation

We took the pulse of emerging fund managers about what it’s been like for them during these post-ZERP, venture-capital-winter years.

A reckoning is coming for emerging venture funds, and that, VCs say, is a good thing

It’s been a busy weekend for union organizing efforts at U.S. Apple stores, with the union at one store voting to authorize a strike, while workers at another store voted…

Workers at a Maryland Apple store authorize strike

Alora Baby is not just aiming to manufacture baby cribs in an environmentally friendly way but is attempting to overhaul the whole lifecycle of a product

Alora Baby aims to push baby gear away from the ‘landfill economy’

Bumble founder and executive chair Whitney Wolfe Herd raised eyebrows this week with her comments about how AI might change the dating experience. During an onstage interview, Bloomberg’s Emily Chang…

Go on, let bots date other bots

Welcome to Week in Review: TechCrunch’s newsletter recapping the week’s biggest news. This week Apple unveiled new iPad models at its Let Loose event, including a new 13-inch display for…

Why Apple’s ‘Crush’ ad is so misguided

The U.K. Safety Institute, the U.K.’s recently established AI safety body, has released a toolset designed to “strengthen AI safety” by making it easier for industry, research organizations and academia…

U.K. agency releases tools to test AI model safety

AI startup Runway’s second annual AI Film Festival showcased movies that incorporated AI tech in some fashion, from backgrounds to animations.

At the AI Film Festival, humanity triumphed over tech

Rachel Coldicutt is the founder of Careful Industries, which researches the social impact technology has on society.

Women in AI: Rachel Coldicutt researches how technology impacts society

SAP Chief Sustainability Officer Sophia Mendelsohn wants to incentivize companies to be green because it’s profitable, not just because it’s right.

SAP’s chief sustainability officer isn’t interested in getting your company to do the right thing

Here’s what one insider said happened in the days leading up to the layoffs.

Tesla’s profitable Supercharger network is in limbo after Musk axed the entire team

StrictlyVC events deliver exclusive insider content from the Silicon Valley & Global VC scene while creating meaningful connections over cocktails and canapés with leading investors, entrepreneurs and executives. And TechCrunch…

Meesho, a leading e-commerce startup in India, has secured $275 million in a new funding round.

Meesho, an Indian social commerce platform with 150M transacting users, raises $275M

Some Indian government websites have allowed scammers to plant advertisements capable of redirecting visitors to online betting platforms. TechCrunch discovered around four dozen “gov.in” website links associated with Indian states,…

Scammers found planting online betting ads on Indian government websites

Around 550 employees across autonomous vehicle company Motional have been laid off, according to information taken from WARN notice filings and sources at the company.  Earlier this week, TechCrunch reported…

Motional cut about 550 employees, around 40%, in recent restructuring, sources say

The company is describing the event as “a chance to demo some ChatGPT and GPT-4 updates.”

OpenAI’s ChatGPT announcement: What we know so far

The deck included some redacted numbers, but there was still enough data to get a good picture.

Pitch Deck Teardown: Cloudsmith’s $15M Series A deck

Unlike ChatGPT, Claude did not become a new App Store hit.

Anthropic’s Claude sees tepid reception on iOS compared with ChatGPT’s debut

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Look,…

Startups Weekly: Trouble in EV land and Peloton is circling the drain

Scarcely five months after its founding, hard tech startup Layup Parts has landed a $9 million round of financing led by Founders Fund to transform composites manufacturing. Lux Capital and Haystack…

Founders Fund leads financing of composites startup Layup Parts

AI startup Anthropic is changing its policies to allow minors to use its generative AI systems — in certain circumstances, at least.  Announced in a post on the company’s official…

Anthropic now lets kids use its AI tech — within limits

Zeekr’s market hype is noteworthy and may indicate that investors see value in the high-quality, low-price offerings of Chinese automakers.

The buzziest EV IPO of the year is a Chinese automaker

Venture capital has been hit hard by souring macroeconomic conditions over the past few years and it’s not yet clear how the market downturn affected VC fund performance. But recent…

VC fund performance is down sharply — but it may have already hit its lowest point

The person who claims to have 49 million Dell customer records told TechCrunch that he brute-forced an online company portal and scraped customer data, including physical addresses, directly from Dell’s…

Threat actor says he scraped 49M Dell customer addresses before the company found out

The social network has announced an updated version of its app that lets you offer feedback about its algorithmic feed so you can better customize it.

Bluesky now lets you personalize main Discover feed using new controls

Microsoft will launch its own mobile game store in July, the company announced at the Bloomberg Technology Summit on Thursday. Xbox president Sarah Bond shared that the company plans to…

Microsoft is launching its mobile game store in July

Smart ring maker Oura is launching two new features focused on heart health, the company announced on Friday. The first claims to help users get an idea of their cardiovascular…

Oura launches two new heart health features

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI considers allowing AI porn

Garena is quietly developing new India-themed games even though Free Fire, its biggest title, has still not made a comeback to the country.

Garena is quietly making India-themed games even as Free Fire’s relaunch remains doubtful

The U.S.’ NHTSA has opened a fourth investigation into the Fisker Ocean SUV, spurred by multiple claims of “inadvertent Automatic Emergency Braking.”

Fisker Ocean faces fourth federal safety probe