Few recent decisions of the Court of Justice have attracted as much comment -- or controversy -- as the Schrems decision on the data protection "safe harbor." As part of our ongoing series of posts regarding the case, we are delighted to publish here an analysis and comment by network member Herwig Hofmann (Luxembourg). Herwig's perspective is of particular interest, as he represented Max Schrems before the Court of Justice in the case. In the post below, he explores some of the broader implications of the decision.
* * *
The Essence of EU Fundamental Rights and their Global Reach
Herwig C.H. Hofmann[1]
The background to Schrems v DPC is as follows: Supervision of compliance with EU data protection rules takes place by national authorities vested with “complete independence”[3] within the territory of each Member State. Transfer of data from the EU to a third country is possible only if that country has an “adequate level” of data protection, a fact the European Commission may certify by means of a decision.[4] In 2000, the Commission had taken an adequacy decision with respect to the United States of America, a decision became known as the “Safe Harbour Decision”.[5] The Court of Justice of the European Union (CJEU) had the opportunity to review the compliance of the various elements of the data protection regime, especially the conditions of the Commission decisions declaring a third country to maintain an adequate level of protection, upon request for preliminary reference by the High Court of Ireland in a judicial review procedure of a decision of the Irish Data Protection Commissioner (DPC) not to accept a complaint about Facebook Ireland transferring personal data to Facebook servers in the US.