CCIA Welcomes Advocate General Opinion on Validity of EU Data Flow Instrument

BY Heather Greenfield
December 19, 2019

Brussels, BELGIUM — Advocate General Saugmandsgaard Øe has issued a non-binding opinion in response to a case involving data transfers that are used to process information like credit card transactions or insurance claims. The case examined whether so-called Standard Contractual Clauses provide sufficient protection to EU citizens’ data when transferred outside the European Union. Standard Contractual Clauses (“SCCs”) are an EU instrument used by thousands of European and international companies to transfer data outside Europe, including over 150 countries which are not deemed “adequate” by the European Commission. 

Although this opinion is non-binding, the EU Court of Justice tends to follow the conclusions of the Advocate General. 

In today’s opinion, the AG said that SCCs provide sufficient protection to citizens’ data as long as they are duly enforced by national data protection authorities. Companies which choose to implement SCCs must implement organisational and technical measures and divide up their respective data protection obligations. The laws of the country of destination may also offer additional safeguards, including limitations and judicial redress mechanisms when data is accessed by non-EU authorities for reasons of national security. Finally, European data protection authorities can enforce SCCs, including the prohibition or temporary suspension of data flows if they have serious concerns that SCC cannot be complied with because of foreign legislation.

The Computer & Communications Industry Association has been a longtime advocate for stronger privacy safeguards and the need for data transfers between the E.U. and the rest of the world. 

The following can be attributed to CCIA Senior Policy Manager Alexandre Roure: 

“AG Saugmandsgaard Øe has found that Standard Contractual Clauses provide strong protection when data is transferred outside the EU and it is the responsibility of national authorities to enforce them. This is good news for European internet users and businesses as Standard Contractual Clauses are the only viable and affordable instrument for European companies to transfer data beyond the dozen countries the EU deems adequate.”

 

For media inquiries, please contact Heather Greenfield [email protected]

 

Related Articles

Senate Commerce Hearing On Privacy; CCIA Welcomes Push To Fund FTC, Pass Privacy Legislation

Sep 29, 2021

Washington — The Senate Commerce Committee held a hearing today on consumer privacy with Chairwoman Maria Cantwell focusing on the need to pass baseline federal privacy and to ensure the FTC has adequate resources to address privacy. Ahead of the hearing, the Computer & Communications Industry Association sent a letter to committee leaders expressing appreciation…

Transatlantic industry groups urge swift agreement on EU-US commercial data flows

Jul 14, 2021

Brussels, BELGIUM — Ahead of the first anniversary of the invalidation of the Privacy Shield on Friday, more than 20 EU and U.S. associations today sent a letter urging EU Commissioner Reynders and U.S. Secretary Raimondo to swiftly ensure an agreement for secure transatlantic data flows. Thousands of EU and U.S. companies continue to be…

Industry Groups Urge Protection of Fundamental Principles and Rights in the Digital Services Act

Jul 9, 2021

Brussels, BELGIUM — The Computer & Communications Industry Association (CCIA) today joined other industry organizations in a joint statement asking EU Member States to respect the fundamental principles of the e-Commerce Directive during the negotiations of the Digital Services Act (DSA)  The signatories support an ambitious DSA and its objectives to protect consumers and their…