Consent and Contract under EU Data Protection Law

Slides:



Advertisements
Similar presentations
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Advertisements

Rule-Making Book II EU Administrative Procedures – The ReNEUAL Draft Model Rules 2014 Brussels, May th Herwig C.H. Hofmann University of Luxembourg.
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Ide kerülhet az előadás címe CCTV operation at work Belgrade, 11 th April 2013.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Access to Commercial Information A Comparative Overview Darian Pavli Open Society Justice Initiative.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
Vienna 14 March 2006 Andrew J. Popham Vice-President of FEE Partner, PricewaterhouseCoopers LLP The New Directive on Statutory Audit in the EU.
Privacy, data protection and connected cars Lilian Edwards, Professor of Internet Law University of Strathclyde Researcher in Residence, Digital Catapult.
Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
General Data Protection Regulation (EU 2016/679)
Surveillance around the world
Brussels Privacy Symposium on Identifiability
Student Privacy in an Ever-Changing Digital World
GDPR (General Data Protection Regulation)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
A trust-based framework for the data-driven economy
▸ Agustín Reyna Conference dedicated to European Consumer Day Vilnius
THE 6TH ANNUAL BCLT PRIVACY LAW FORUM: Silicon Valley
General Data Protection Regulation (GDPR)
Data Protection: EU & International
Presentation to GTMC on GDPR
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
Data protection issues in regulatory investigations
International Regulatory Trends
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
Information Governance and Data Privacy: A World of Risk
GDPR Overview Gydeline – October 2017
Nina Barakzai November 2017
Data protection reform:
Data Protection & Human Rights
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
Bob Siegel President Privacy Ref, Inc.
DP BILL: GROUNDS FOR PROCESSING
State of the privacy union
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
ESF Monitoring & Evaluation and Data Protection in Spain
Ethical questions on the use of big data in official statistics
General Data Protection Regulation
Relocation CARNIVAL come one…come all
Guide to overview of changes under GDPR ww.ZAKSIT.com
How is the GDPR enforced ?
GDPR (Patrix interpretation)
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
Welcome!.
Data transfers to non-EU countries under the new GDPR
Chapter 3: American Free Enterprise Section 1
Presentation privacy law
Avv. Roberto Panetta LL.M. Ph.D. ISCL Secretary General
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Chapter 3: American Free Enterprise Section 1
Chapter 3: American Free Enterprise Section 1
The principle of proportionality and the contents of a contract
Personal data protection in public institutions – effective approach
Chapter 3: American Free Enterprise Section 1
Why are we processing data
Global Data Privacy: The EU Way
General Data Protection Regulation (GDPR)
Data protection & FOIA considerations
Unit 8 European Aministrative Law Principles
EU Data Protection Legislation
General Data Protection Regulation
DEMOCRATIC PRINCIPLES
The EU General Data Protection Regulation
Presentation transcript:

Consent and Contract under EU Data Protection Law Paul M. Schwartz BCLT Privacy Law Forum: Silicon Valley March 24, 2017 Twitter: @paulmschwartz

My Co-Author Professor Peifer Prof. Dr. Karl-Nikolaus Peifer Director, Institute for Media Law And Communications Law And Director, Institute for Broadcasting Law University of Cologne

Katherine Tassi, Snap

Lindsey L. Tonsager, Covington & Burling

Dr. Kai Westerwelle, Taylor Wessing

Different visions of Data Privacy Overview Different visions of Data Privacy Shared Doctrine: Contract and Consent EU: Rights Talk in Action US: Protecting the Privacy Consumer Data Privacy’s International Future

Different Visions of Data Privacy: the EU “Rights talk”: strong constitutionalization of privacy and data protection Statutory laws anchored in constitution rights Proportionality test to protect privacy European Court of Justice, Luxembourg

Different Visions of Data Privacy: the US Weak constitutional protections for information privacy Strong constitutional protections for free flow of information “Marketplace discourse”: protection of privacy consumer in marketplace

EU: Rights Talk in Action Strong limits on contract and consent in EU “EU data protection puts a core of important data privacy rights beyond the ability of a person to trade because such individual behavior would both erode a capacity of self-determination and have a negative collective impact.” Contract and consent cannot trump the GDPR’s fundamental rules, including legal basis for processing, data minimization, and purpose specification.

GDPR on Consent, Article 7 If consent presented as part of written declaration concerning other matters, “the request for consent must be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language” Right to withdraw consent at any time. “It shall be as easy to withdraw consent as to give it”

GDPR on Consent, Article 7 “When assessing whether consent is freely given, utmost account shall be taken of the fact whether, among others, the performance of a contract, including the provision of a service, is made conditional on the consent to the processing of data that is not necessary for the performance of this contract.”

US: Protecting the Privacy Consumer Main privacy inalienability is that of mandated disclosure requirements Contract largely irrelevant– for data processors, a realm of “heads, I win; tails, you lose.” Consent plays a limited role in U.S. law. Minor role for “warning function” -- opt-in.

Data Privacy’s International Future (1) “Rights talk” is a key part of the EU project “Privacy consumers” ties into deep-rooted US concepts A shift to institutions: e.g., Privacy Shield: Data Integrity, Choice, Enforcement and Oversight

Privacy Shield (2016)

Privacy Shield (2016)

A Way Forward? Law is “agreement about the things that are fundamental.” Cardozo, 1924

Data Privacy’s International Future (2) New Institutions and New Structures New understandings of data privacy to be created in international institutions and new processes European Data Protection Board Privacy Shield – deputizes U.S. institutions, officials and private parties to enforce the interests of EU citizens

Katherine Tassi, Snap

GDPR, Article 6, “legitimate interests” Article 6: Processing is lawful when it “is necessary for the purposes of the legitimate interests pursued by the controller or by a third party except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data…”

GDPR, Article 47, “legitimate interests Recital 47: “The legitimate interests of a controller … or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of the data subjects based on their relationship with the controller.”

Katherine Tassi, Snap Will the “legitimacy” basis in GDPR turn into important grounds for processing for US companies? Is the future one of segregation of EU personal data from the rest of the world’s?

Lindsey L. Tonsager, Covington & Burling

Lindsey L. Tonsager, Covington & Burling Are US and EU privacy laws really different? Can the GDPR actually be value-added for your business?

Dr. Kai Westerwelle, Taylor Wessing

Dr. Kai Westerwelle, Taylor Wessing Threats to the Privacy Shield and Model Clauses: the State of Play Privacy Shield under scrutiny Schrems II: Model Contractual Clauses Opinions of EU Regulators

Question and Answer Period