Posts Tagged Data protection

Eva Glawischnig-Piesczek v Facebook. Hate speech at the CJEU.

In Case C-18/18, Eva Glawischnig-Piesczek v Facebook, the Austrian Supreme Court has referred a ‘hate speech’ case to Luxembourg – hearing will be tomorrow, 12 February. The Case revolves around Article 15 of the E-Commerce Directive: one sentence Twitter summary comes courtesy of Tito Rendas: does Article 15 prohibit the imposition on a hosting provider (Facebook, in this case) of an obligation to remove not only notified illegal content, but also identical and similar content, at a national or worldwide level?

Mirko Brüß has more extensive analysis here. I used the case in my class with American University (my students will be at the hearing tomorrow), to illustrate the relationship between secondary and primary law, but also the art in reading EU secondary law (here: A15 which limits what can be imposed upon a provider; and the recitals of the Directive which seem to leave more leeway to the Member States; particularly in the light of the scant harmonisation of tort law in the EU). To readers of the blog the case is probably more relevant in light of the questions on territorial scope: if a duty to remove may be imposed, how wide may the order reach? It is in this respect that the case is reminiscent of the Google etc. cases.

Yet another one to look out for.

Geert.

(Handbook of) EU Private International Law, 2nd ed. 2016, Chapter 2, Heading 2.2.8.2, Heading 2.2.8.2.5.

, , , , , , , , , , , , , , , , , , , , , , , , , ,

Leave a comment

Forget what you have read. Szpunar AG does not restrict EU ‘Right to be forgotten’ /data protection laws to European territory.

I have previously reported extensively on various national and European developments re the right to have search results delisted, more popularly referred to as the ‘right to be forgotten’ (‘RTBF’ – a product of the CJEU in Google Spain) and its territorial limits. (Search string ‘Google’ or ‘rtbf’ ought to assist the reader). Szpunar AG opined mercifully  succinctly last Thursday in C-505/17.

Possibly because of the English-language press release (‘Advocate General Szpunar proposes that the Court should limit the scope of the de-referencing that search engine operators are required to carry out to the EU‘) and because of the actual text of the Opinion hitherto being available in French only, general reporting has been almost unequivocally (note Michèle Finck’s 10th Tweet in an early thread on the Opinion as a cautious exception), that the AG suggests that the RTBF is limited to EU soil only.

Except, he does not.

The Conseil d’Etat has referred one or two specific Qs but also, just to be sure, has also asked the Court of Justice for general insight into how data protection laws apply to the internet.

The AG of course departs from the core objective of the data protection Directive and now the GDPR, and Google Spain, and points out that the CJEU has put the protection of the fundamental rights of the data subject at the centre. At 46 he summarises his view before justifying it:

‘in my opinion one should distinguish according to the place in which the search is carried out. Searches carried out outside the EU ought not to be made subject to delisting’. (My translation from the French).

Geo-blocking can be ordered and ensures that within the EU territory, no Google extension may be used to access the information at issue (at 64 ff) after duly having balanced the right of freedom of information against the right to be forgotten.

Turning to his arguments, the AG points out at 47 ff first of all – briefly: see e.g. Belgian case-law on Facebook for more extensive discussion –  that public international law defines the borders of the EU and its Member States. The AG sees no reason (48-49) exceptionally to extend the scope of application beyond that border in the case of the Directive or the GDPR.

(51-52) Other examples of ‘extraterritoriality’ do not sway him, such as the Trademark Directive or EU competition law. He argues that in these cases the Internal Market is impacted and EU law applies to these situations ex-EU only because the Internal Market is a finite, territorial unit. The internet is not (at 53: Le marché intérieur est un territoire clairement délimité par les traités. En revanche, l’internet est, par nature, mondial et, d’une certaine manière, est présent partout. Il est donc difficile de faire des analogies et des comparaisons).

Note that references to other instances of ‘extraterritoriality’ (or not) could have been made: such as the cases surrounding animal welfare (Zuchtvieh), cosmetics, or the EU’s emissions trading scheme.

The AG also briefly discusses ‘extraterritorial’ protection of rights under the ECHR, but distinguishes the EU Charter from same. (On the topic of the ‘extraterritorial’ impact of the EU’s human rights obligations, see excellently Lorand Bartels here).

At 60-61 the AG argues (paras which have been more or less literally translated in the Press release) that if worldwide de-referencing were permitted, the EU authorities would not be able to define and determine a right to receive information, let alone balance it against the other fundamental rights to data protection and to privacy. This, the AG argues, is all the more so since ‘the right of the public to access such information’ (un tel intérêt du public à accéder à une information; this word string bizarrely translated in the press release as ‘such a publication’) will necessarily vary from one third State to another depending on its geographic location. There would be a risk, the AG suggests, that if worldwide de-referencing were possible, persons in third States would be prevented from accessing information and, in turn, that third States would prevent persons in the EU Member States from accessing information. This might in turn lead to a race to the bottom in the right to access of information.

This is an important point, because it essentially encapsulates a core argument made by Google: that particularly in the US, the constitutional right to free speech and the corollary of the freedom to receive information, gazumps a right to be forgotten – putting Google in the event of worldwide delisting orders between SCOTUS’ rock and CJEU’s hard place.

Crucially however at 62 the AG then in my view perhaps not quite torpedoes but certainly seriously softens his overall general analysis by suggesting that his views on territoriality are the default position only, which may be varied should specific instances of the balancing act of fundamental rights, so require: it’s just that the specific circumstances of the case do not.

Les enjeux en cause n’exigent donc pas que les dispositions de la directive 95/46 soient d’application au-delà du territoire de l’Union. Cela ne signifie pas pour autant que le droit de l’Union ne saurait jamais imposer à un exploitant de moteur de recherche tel que Google qu’il entreprenne des actions au niveau mondial. Je n’exclus pas qu’il puisse y avoir des situations dans lesquelles l’intérêt de l’Union exige une application des dispositions de la directive 95/46 au-delà du territoire de l’Union. Mais dans une situation telle que celle de la présente affaire, il n’y a pas de raison d’appliquer les dispositions de la directive 95/46 d’une telle manière.

The circumstances of the case do not justify worldwide blocking. Yet other circumstances might. This is a crucial section for the French data protection authority’s (CNIL) decision at issue, 2016/054 [thank you again to the Dutch Ministry of Foreign Affairs for providing the factual background to the case; also note that in the French decision Google’s name, amusingly, is anonymised] is a general CNIL instruction to Google to carry out global delisting in instances where natural persons request removal; not a case-specific one. In other words the ‘circumstances of the case’ concern a generic, not a factual balancing.

In yet other words: there could be many instances where national data protection authorities might find worldwide delisting to be the only proper means to balance the various fundamental rights at stake. The AG Opinion offers little to no support that such worldwide delisting in concrete cases were to infringe the Directive /the GDPR. Such balancing act would be akin to X v Google LLC at the Tribunal de grande instance de Paris on which I reported last week.

Note that in his Opinion of the same day in C-136/17, the AG Opines that the default response of search engine providers must be to honour requests for delisting, and to only exceptionally not do so.

Some issues for the Grand Chamber to chew on. And then some more.

Geert.

(Handbook of) EU Private International Law, 2nd ed. 2016, Chapter 2, Heading 2.2.8.2, Heading 2.2.8.2.5.

, , , , , , , , , , , , , , , , , , , , , ,

Leave a comment

Territoriality and delisting. Google score (cautious) French points ahead of Thursday’s AG Opinion in CJEU case.

On Thursday the Advocate-General will opine in C-136/17 G.C. e.a. and  C-507/17 Google (FR) – on which I reported ia here. The issue is, in the main, the territorial scope of EU data protection laws.

X v Google LLC at the Tribunal de grande instance de Paris on 14 November 2018 is a good warm-up, forwarded to me (for which many thanks) by Jef Ausloos (I have copy for those interested). The case concerns an article in Le Monde linking a French resident, active in international hotel management, to a Moroccan enquiry into pedophilia. The court’s review of the facts suggests an unsubstantiated link between X and the case – yet the damage to claimant’s reputation evidently is done nevertheless. Claimant requests delinking not just for searches performed in France on all Google extensions, but rather for all searches performed globally.

The court first of all observes that for searches performed in France, delisting of many of the identified urls has already happened – and orders on the basis of French law (which it applies, it suggests, per the GDPR) Google LLC to carry out delisting for the others in as far as searches are carried out from French territory. X’s privacy is given priority over freedom of expression and Google LLC’s US domicile is not mentioned as being relevant (no verbatim discussion of same is recorded in the judgment. X’s French nationality and domicile however, are, hence presumably it is the infamous Article 14  Code Civil which is at play here). Google’s argument that the as listed urls link to articles in languages other than French and relating to facts taking place outside of France is dismissed as irrelevant.

Claimant however had requested global delisting, regardless of the user’s geographical location. That, the court holds, is a request it cannot grant. Its refusal is justified in one sentence only: a global delisting order would be disproportionate in the case of a French national and resident, simply because his employment record is international:

‘une telle mesure apparaît ici disproportionnée, s’agissant d’un résident français, le seul caractère international de ces démarches d’emploi ne pouvant justifier d’une telle restriction, qui conduirait in fine à soumettre le réseau internet à une injonction de portée globale.’ 

The judgment therefore does not tackle the conceptual issues surrounding jurisdiction (which the Belgian courts, for instance, have been tempted into in the Facebook case), neither does it rule out global injunctions in cases which have more than just a fleeting international element.

Happy 2019.

Geert.

 

 

, , , , , , , , , , , , , , , , , , , , , ,

Leave a comment

Protection of privacy and private international law. Interim ILA report.

A short post effectively to deposit relevant documentation on the issue of privacy and private international law – which I frequently report on on the blog (e.g. use tag ‘rtbf’, or ‘internet’, or ‘privacy’, ‘Facebook’, or ‘Google’; see i.a. my recent posts re Facebook, Google , Schrems, etc.

Max Planck Luxembourg have the interim report on the International Law Association’s draft guidelines on jurisdiction and applicable law re privacy on their website, featuring many of the cases I have reported on over the years.

Happy reading.

Geert.

 

, , , , , , , , , , , ,

Leave a comment

EDPB guidelines on the territorial reach of the GDPR: Some clear conflicts overlap.

GDPR (General Data Protection Regulation) aficionados will have already seen the draft guidelines published by the EDPB – the European data protection board – on the territorial scope of the Regulation.

Of particular interest to conflicts lawyers is the Heading on the application of the ‘targeting’ criterion of GDPR’s Article 3(2). There are clear overlaps here between Brussels I, Rome I, and the GDPR and indeed the EDPB refers to relevant case-law in the ‘directed at’ criterion in Brussels and Rome.

Geert.

(Handbook of) EU Private International Law, 2nd ed. 2016, Chapter 2, Heading 2.2.8.2.3, Heading 2.2.8.2.5.

 

, , , , , , , , , , , , , , , , , , , , , , , ,

Leave a comment

Facebook appeal against UK fine puts territoriality of data protection in the spotlight.

I have an ever-updated post on Google’s efforts to pinpoint the exact territorial dimension of the EU’s data protection regime, GDPR etc. Now, Facebook are reportedly (see also here) appealing a fine imposed by the UK’s data protection authority in the wake of the Cambridge Analytica scandal. Facebook’s point at least as reported is that the breach did not impact UK users.

The issue I am sure exposes Facebook in the immediate term to PR challenges. However in the longer term it highlights the need to clarify the proper territorial reach of both data protection laws and their enforcement.

One to look out for.

Geert.

 

, , , , , , , , , , , , , , , , , , , , , ,

Leave a comment

Lloyd v Google. High Court rejects jurisdiction viz US defendant, interprets ‘damage’ in the context of data protection narrowly.

Update 11 December 2018 leave to appeal applied for.

Warby J in  [2018] EWHC 2599 (QB) Lloyd v Google (a class action suit with third party financing) considers, and rejects, jurisdiction against Google Inc (domiciled in the US) following careful consideration (and distinction) of the Vidal Hall (‘Safari users) precedent.

Of note is that the jurisdictional gateway used is the one in tort, which requires among others an indication of damage. In Vidal Hall, Warby J emphasises, that damage consisted of specific material loss or emotional harm which claimants had detailed in confidential court findings (all related to Google’s former Safari turnaround, which enabled Google to set the DoubleClick Ad cookie on a device, without the user’s knowledge or consent, immediately, whenever the user visited a website that contained DoubleClick Ad content.

In essence, Warby J suggests that both EU law (reference is made to CJEU precedent under Directive 90/314) and national law tends to suggest that “damage” has been extended in various contexts to cover “non-material damage” but only on the proviso that “genuine quantifiable damage has occurred”.

Wrapping up, at 74: “Not everything that happens to a person without their prior consent causes significant or any distress. Not all such events are even objectionable, or unwelcome. Some people enjoy a surprise party. Not everybody objects to every non-consensual disclosure or use of private information about them. Lasting relationships can be formed on the basis of contact first made via a phone number disclosed by a mutual friend, without asking first. Some are quite happy to have their personal information collected online, and to receive advertising or marketing or other information as a result. Others are indifferent. Neither category suffers from “loss of control” in the same way as someone who objects to such use of their information, and neither in my judgment suffers any, or any material, diminution in the value of their right to control the use of their information. Both classes would have consented if asked. In short, the question of whether or not damage has been sustained by an individual as a result of the non-consensual use of personal data about them must depend on the facts of the case. The bare facts pleaded in this case, which are in no way individualised, do not in my judgment assert any case of harm to the value of any claimant’s right of autonomy that amounts to “damage”…”

The judgment does not mean that misuse of personal data cannot be disciplined under data protection laws (typically: by the data protection authorities) or other relevant national courses of action. But where it entails a non-EU domiciled party, and the jurisdictional gateway of ‘tort’ is to be followed, ‘damage’ has to be shown.

Geert.

 

, , , , , , , , , , , , , , , , , , , , , , , , ,

Leave a comment

%d bloggers like this: