Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Thursday, December 4, 2025

Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

“If EU citizens’ data goes to the United States, will it still receive GDPR-level protection?” Schrems II rewrote the balance between global data flows and fundamental rights.


Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

Hello! Today we look at Schrems II (2020). Brought by Austrian privacy activist Max Schrems, the case centered on concerns that personal data transferred from the EU to the U.S. could be exposed to large-scale surveillance by U.S. intelligence agencies. In particular, the constitutionality—better, the validity—of the Privacy Shield framework (adopted after Safe Harbor was invalidated) was back under scrutiny. Studying this judgment made me realize that the idea of “data borders” is anything but abstract.

Background and Facts

The case began with Austrian privacy advocate Max Schrems suing Facebook Ireland. Schrems argued that when EU citizens’ data is transferred to the United States, it may be subject to extensive surveillance by U.S. intelligence agencies (notably the NSA). In his view, this fails to meet the GDPR’s requirement of an “essentially equivalent” level of protection. After the 2015 Schrems I ruling had already invalidated Safe Harbor, this case targeted its successor, the EU-U.S. Privacy Shield.

The question was whether the Privacy Shield framework meets the level of protection required by the GDPR. The breadth of U.S. surveillance programs and the lack of adequate judicial redress for EU citizens were central concerns.

Issue Problems with Privacy Shield GDPR Requirements
Scope of surveillance Allows large-scale collection by U.S. government Only necessary and proportionate surveillance allowed
Judicial redress EU citizens lack effective remedies in U.S. courts Remedies must be effective and accessible
Level of protection Not equivalent to the EU level Protection essentially equivalent to (or exceeding) GDPR

The Judgment and Reasoning

The CJEU held that Privacy Shield is invalid. However, it deemed Standard Contractual Clauses (SCCs) valid in principle, while emphasizing that national supervisory authorities must assess the level of protection in each particular case. The reasoning:

  • U.S. surveillance programs do not satisfy necessity and proportionality.
  • EU citizens lack effective judicial redress in the United States.
  • SCCs remain valid, but controllers/processors and supervisory authorities must verify case-by-case whether equivalent protection is ensured.

Impact on the EU Legal System

Schrems II brought sweeping changes to EU-U.S. data transfers. Privacy Shield was invalidated immediately, confronting thousands of companies with legal uncertainty. In response, the EU and the U.S. negotiated a new framework—the EU-U.S. Data Privacy Framework—and supervisory authorities took on stricter oversight of SCCs. The ruling strengthened the global effect of the GDPR and amplified worldwide debates on data sovereignty.

Criticism and Academic Debate

While hailed for strengthening privacy, Schrems II has also been criticized for imposing heavy practical burdens on companies and regulators.

Perspective Main Argument
Critical Greater uncertainty for data transfers; potential chill on global business
Supportive Firmly protects EU citizens’ fundamental data rights and elevates the GDPR’s global standing

Contemporary Significance and Takeaways

Schrems II remains a reference point for governing international data flows—not only for the EU-U.S. relationship but also for legislation in India, Brazil, Korea, and beyond. Key takeaways:

  • Exposes the fragility of transfer frameworks (e.g., Privacy Shield) and calls for new models of international cooperation
  • Reinforces the GDPR’s global standard-setting effect, influencing foreign legislation
  • Emphasizes the shared responsibility of companies and regulators to verify “concrete protective measures”

Frequently Asked Questions (FAQ)

Q What is the core of Schrems II?

The validity of the EU-U.S. Privacy Shield, the applicability of SCCs, and the role of supervisory authorities (DPAs) in overseeing transfers.

Q How did the CJEU rule on Privacy Shield?

It invalidated Privacy Shield due to the breadth of U.S. surveillance and insufficient redress mechanisms.

Q What happened to SCCs?

They remain valid in principle, but DPAs must verify in each transfer whether an equivalent level of protection is ensured.

Q What should companies do after the ruling?

Use SCCs together with a Transfer Impact Assessment (TIA), implement supplementary measures (encryption, pseudonymization), and review local surveillance laws.

Q What is its significance today?

Schrems II strengthened the GDPR’s international influence and spurred debates on data sovereignty and surveillance reform.

In Closing

Schrems II (2020) makes clear that data flows are not merely technical—they are tied directly to fundamental rights. For exams and practice, structure your analysis around ① Privacy Shield invalid, ② SCCs valid with conditional verification, and ③ surveillance programs and redress gaps. Emphasizing the Transfer Impact Assessment (TIA) and supplementary measures will align you with current GDPR enforcement trends. This case convinced me that “data is the new border.” The topic will only heat up—so keep a close eye on cases and controversies. 🙂

Wednesday, December 3, 2025

Google v. CNIL (2019): The Geographic Limits of the Right to Be Forgotten

Google v. CNIL (2019): The Geographic Limits of the Right to Be Forgotten

“Does the EU’s right to be forgotten apply to Google Search worldwide?” Google v. CNIL shows how data protection and freedom of expression can clash across borders.

Google v. CNIL (2019): The Geographic Limits of the Right to Be Forgotten

Hello! Today we summarize the Google v. CNIL (2019) judgment. The dispute concerned how the EU’s Right to be Forgotten applies to Google’s global search engine. The French regulator CNIL argued that Google must apply delisting (de-referencing) not only to EU domains but to search results worldwide, while Google pushed back, citing freedom of expression and the risk of international conflicts. Studying this case made me rethink how digital rights collide with the very concept of borders.

Background and Facts

Following the Google Spain (2014) ruling, the EU recognized the right of data subjects to request search-result removal—i.e., the right to be forgotten. France’s data protection authority, CNIL, ordered Google to apply delisting not only on EU domains (.fr, .de, etc.) but also on all global search results (such as google.com). Google argued this demand was excessive and could conflict with freedom of expression and other jurisdictions’ laws. The case reached the CJEU, raising a new question about the right to be forgotten’s geographic scope.

At stake was whether EU delisting requests can bind Google’s search results worldwide. A global effect would extend EU regulation into other countries’ free-expression domains, while an EU-only effect could weaken the practical effectiveness of the right to be forgotten in the digital space.

Issue Global Application Application within the EU
Data protection Ensures the highest level of protection Protection confined to the EU; access from outside may remain
Freedom of expression Risk of infringing other countries’ free-speech regimes Minimizes international conflicts
International-law legitimacy Concern over encroaching on other States’ sovereignty Rationalizable as a regional measure

The Judgment and Reasoning

The CJEU held that Google is not required to ensure delisting on search results worldwide. However, it must ensure delisting within the EU. The reasoning:

  • EU law has direct effect only within the EU’s territory.
  • Worldwide application could clash with other countries’ free-speech protections and regulatory frameworks.
  • Nevertheless, effective delisting measures must operate within the EU.

Impact on the EU Legal System

Google v. CNIL clarified the geographic limits of the right to be forgotten in the EU. It shows how data protection and freedom of expression may conflict in an international setting. After the ruling, the EU maintained strong delisting obligations within its territory while refraining from asserting universal extraterritorial reach—an approach seen as measured restraint regarding the external scope of EU law.

Criticism and Academic Debate

The ruling drew mixed reactions: some argued it was not strong enough to protect EU citizens’ data, while others praised it as a sensible way to avoid overextending EU regulation globally.

Perspective Main Argument
Critical Limiting the effect to the EU weakens real protection; personal data may still be reachable via non-EU searches
Supportive Balances strong protection within the EU with restraint to avoid conflicts with other countries’ free-speech regimes

Contemporary Significance and Takeaways

Today, Google v. CNIL is a leading case on how internet regulation meets borders. Key takeaways:

  • A precedent illustrating the international balancing of data protection and freedom of expression
  • Strong EU-only delisting obligations paired with international-law restraint
  • Underscores the importance of the “inside–outside the EU” distinction in global internet regulation debates

Frequently Asked Questions (FAQ)

Q What is Google v. CNIL?

A case about whether the EU’s right to be forgotten requires Google to delist search results worldwide.

Q Who brought the case?

France’s data protection authority, CNIL, demanded that Google delist results across all global domains, triggering the dispute.

Q What was the legal issue?

Whether the EU right to be forgotten has worldwide effect or is confined to the EU.

Q How did the CJEU decide?

Google is not required to delist results worldwide, but it must delist within the EU.

Q What does the ruling mean?

EU law applies robustly within the EU but shows restraint to avoid conflicts with other legal orders abroad.

Q Is it still important today?

Yes. It is a staple precedent when discussing the scope of the EU’s right to be forgotten in global internet regulation.

In Closing

Google v. CNIL (2019) reminds us that even on a “borderless internet,” legal boundaries still matter. For application tips, frame proportionality around ① the data subject’s rights, ② freedom of expression and the right to know, and ③ inside–outside EU effects. On exams, the geographic scope is a common pitfall—state clearly the “mandatory in-EU + restraint outside the EU” conclusion. In practice, the implementation details—geoblocking, EU IP–based delisting, and management of public-interest exceptions—are key. If you have a scenario in mind, let’s build a checklist together. 🙂

Saturday, November 29, 2025

Digital Rights Ireland (2014): Balancing Data Protection and Security

Digital Rights Ireland (2014): Balancing Data Protection and Security

“Can we retain everyone’s communications data—or does that violate fundamental rights?” The Digital Rights Ireland ruling is a symbolic case showing how security and privacy collide within the EU legal order.


Digital Rights Ireland (2014): Balancing Data Protection and Security

Hello! Today we’re looking at Digital Rights Ireland (2014). This landmark judgment annulled the EU’s Data Retention Directive and made me ask, “Security or privacy?” The Court emphasised the right to private life and the confidentiality of communications under the EU Charter and subjected mass data retention to strict review. It became a key moment for re-articulating constitutional principles in the digital age.

Background and Facts

In 2006, the EU adopted the Data Retention Directive to combat terrorism and serious crime. It required all electronic communications providers to store users’ traffic data (call logs, email metadata, location information, etc.) for between six months and two years. The Irish NGO Digital Rights Ireland challenged the regime, arguing it treated the entire population as potential suspects and violated Articles 7 (respect for private life) and 8 (protection of personal data) of the Charter of Fundamental Rights. The case ultimately reached the CJEU.

At the heart of the case was the clash between the public interest in security and public safety and the fundamental rights to private life and data protection.

Issue Security and Public Safety Data Protection
Legal basis Treaty provisions on security and crime prevention EU Charter of Fundamental Rights, Arts. 7 & 8
Argument Prevent terrorism and enhance investigative effectiveness Generalised, indiscriminate data collection violates fundamental rights
Concern Security could become a pretext for pervasive surveillance People without any suspicion are swept into tracking regimes

The Court’s Judgment and Reasoning

The CJEU annulled the Data Retention Directive for disproportionately interfering with fundamental rights. While accepting the legitimacy of security objectives, the Court found that general and indiscriminate retention breached the principle of proportionality. Key points:

  • Security aims are legitimate, but blanket retention exceeds what is strictly necessary.
  • Retention periods, scope, and access procedures were set too broadly without concrete limits.
  • Any restriction on fundamental rights must satisfy necessity and proportionality—this directive did not.

Impact on the EU Legal Order

This was the first time in EU history that legislation aimed at security was struck down in its entirety. Digital Rights Ireland is seen as proof of the Charter’s real force. After the ruling, Member States had to revisit their retention laws, and EU data protection rules were further strengthened, feeding directly into the 2018 GDPR and consolidating a “privacy-first EU legal order.”

Criticism and Academic Debate

Reactions were mixed. Some argued the Court applied unduly strict scrutiny despite growing security threats. Others hailed the decision as a “constitutional victory” sounding the alarm against mass surveillance in the digital age.

Perspective Main Argument
Critical Overly constrains crime-fighting and security measures, reducing effectiveness
Supportive Affirms privacy as a top value and protects citizens from mass surveillance

Contemporary Significance and Takeaways

Today, Digital Rights Ireland remains a core reference in EU debates on digital governance. It is frequently cited in discussions on big data, AI, and national-security surveillance systems. Key takeaways include:

Frequently Asked Questions (FAQ)

Q What is Digital Rights Ireland?

An Irish NGO challenged the EU’s Data Retention Directive, which required the collection and storage of communications metadata for the entire population, alleging violations of fundamental rights.

Q What was the legal issue?

Whether security-driven data collection infringed Articles 7 and 8 of the Charter—respect for private life and protection of personal data.

Q How did the Court rule?

The CJEU annulled the directive for violating proportionality by mandating general and indiscriminate retention that intruded excessively on personal data.

Q Why is the case significant?

It demonstrated the real bite of the Charter, prioritised privacy in the security-freedom balance, and influenced subsequent regulation, including the GDPR.

Q What criticisms were made?

Some said the ruling hampered responses to threats; others praised it for checking mass surveillance.

Q Does it still have impact today?

Yes. It directly shaped stronger EU data-protection rules like the GDPR and remains central to debates on surveillance in the digital era.

In Closing

Digital Rights Ireland (2014) moves beyond the false binary of “security versus freedom” and reaffirms the constitutional principle that both must be protected. For application: check (1) whether the measure is generalised/indiscriminate, (2) whether the scope and duration are clearly delimited, (3) whether there is independent judicial control and oversight, and (4) whether there are minimisation and security safeguards such as encryption/anonimisation. Fit these into a proportionality frame and the contours of judgment in similar cases become clearer. If you have real-world scenarios or research projects, share them. We can map out the follow-up case law (e.g., Tele2 Sverige, La Quadrature du Net) together. 🙂

Sunday, May 4, 2025

British Royal Family vs. Paparazzi – The Frontline of Privacy Lawsuits

British Royal Family vs. Paparazzi – The Frontline of Privacy Lawsuits

A single photo enraged the royal family. Can public figures truly expect privacy?


British Royal Family vs. Paparazzi – The Frontline of Privacy Lawsuits


Hello. Today, let's explore one of the most symbolic cases where law, media, and privacy collide — the British royal family's lawsuit against the paparazzi. Since high-end cameras and long-zoom lenses became widespread, royal family members have become prey through the lens, especially Prince Harry and Meghan Markle, who had to face legal battles over their child's photos. More than just a celebrity privacy issue, this case questions how we balance data privacy and freedom of expression in modern times.

1. Case Background: When and What Happened?

In 2021, Prince Harry and Meghan Markle filed a lawsuit against paparazzi who used drones and long lenses to illegally photograph their infant son Archie near their Los Angeles residence. This marked the most significant privacy violation since their move to the U.S., igniting a legal battle over personal privacy.

Additionally, in 2020, the British tabloid The Mail on Sunday published a private letter Meghan had sent to her father, sparking another lawsuit that escalated to the High Court. The core question was to what extent a public figure like a royal could be protected as a private individual.

At the heart of the lawsuit lies a clash between two values: the right to privacy and freedom of the press. Tabloid media and paparazzi photographers argued that "reporting on public figures aligns with the public’s right to know," while the royal family maintained that "unauthorized photography within private spaces is clearly illegal."

Royal Family's Arguments Media's Counterclaims
Drone photography over private property is clearly illegal Public figures are legitimate subjects of public interest
Children's rights require heightened protection They have actively sought public attention themselves
Selling unauthorized photos constitutes commercial exploitation Photography is part of reporting and artistic freedom

3. Court's Judgment and Its Implications

In December 2021, the California Superior Court ruled in favor of Prince Harry and Meghan, declaring that “unauthorized photography of a minor seriously violates their privacy.” The photographer was ordered to pay monetary damages, destroy all photos, and the media outlet had to issue a formal apology.

  • The fact that the photography took place on private property was a key factor
  • The involvement of a minor increased the level of legal protection
  • The photographer's commercial intent was deemed an aggravating factor

4. European Human Rights and Privacy Standards

The European Union enforces one of the world's strictest data protection frameworks through the GDPR (General Data Protection Regulation). According to GDPR, individuals have the legal right to respond when their private lives are photographed or published without consent. When such incidents conflict with press freedom, the EU applies the principle of proportionality to determine which side holds greater public interest.

The European Court of Human Rights (ECHR) maintains that even public figures must have their private domains protected, reinforcing that the royal family’s lawsuits are consistent with European legal standards.

5. Public and Media Reactions

The case stirred intense debate among the media and the public. Some argued, “The royal family has actively engaged with the media, so claims of privacy invasion are questionable,” while others insisted, “Children and private family life must be protected at all costs.”

Position Main Argument
Support for Press Freedom Public figures' privacy is limited; they are subjects of public scrutiny
Support for Privacy Minor children and violations of private property go too far
Neutral or Critical Perspective The royal family wants both media attention and privacy

6. Future Boundaries Between Privacy and the Press

This case has sparked global discussion on how to draw the line between the public’s right to know and an individual’s right to privacy. New elements like minor children, drone photography, and AI-powered facial tracking are emerging, prompting ongoing legal reinterpretations.

  • Need for updated standards on press ethics and tech regulations
  • Social consensus required on how much privacy public figures deserve
  • Stronger protection expected for portrait rights and personal image data

Frequently Asked Questions (FAQ)

Q Can public figures receive privacy protection?

Yes. Even public figures are legally protected when in private spaces, especially their homes or with their families. The privacy of minors receives even stronger protection.

Q Is drone photography illegal?

Using drones to film without permission over private property or to invade someone’s privacy can be considered illegal and subject to penalties or lawsuits.

Q Can the press photograph public figures anytime?

Photography in public spaces is generally allowed, but there are legal limits when it comes to private homes, hospitals, or private events. Press freedom is not absolute.

Q Do lawsuits by the royal family influence the legal system?

Yes, they do. High-profile rulings often set precedents that influence future cases and can lead to changes in how media outlets and paparazzi operate.

Q What are the differences between U.S. and EU privacy standards?

The EU enforces strong privacy protections through GDPR and emphasizes privacy rights. The U.S., in contrast, tends to prioritize freedom of speech under the First Amendment, which creates differences in how privacy is handled between the two regions.

Q When is media reporting in the public interest allowed?

Media coverage is permitted when it clearly relates to public safety, accountability of public officials, or significant social issues. Pure curiosity or commercial motives are not protected.

Where Should We Draw the Line Between Privacy and Reporting?

Though members of the royal family may live in the spotlight, they are still human, parents, and part of a family. This lawsuit is more than a celebrity dispute or media overreach—it poses a fundamental question about how privacy should be respected in the digital era. As we navigate curiosity, the public interest, freedom of the press, and respect for private life, we must continuously reevaluate where to draw the line. I hope this article encourages you to reflect on the standards you hold when reading the news or sharing a photo.

Puttaswamy (Privacy) (India, 2017): Privacy Is a Fundamental Right

Puttaswamy (Privacy) (India, 2017): Privacy Is a Fundamental Right “How far can the state look into your body, your data, and your choi...