成人小说亚洲一区二区三区,亚洲国产精品一区二区三区,国产精品成人精品久久久,久久综合一区二区三区,精品无码av一区二区,国产一级a毛一级a看免费视频,欧洲uv免费在线区一二区,亚洲国产欧美中日韩成人综合视频,国产熟女一区二区三区五月婷小说,亚洲一区波多野结衣在线

首頁 500強(qiáng) 活動 榜單 商業(yè) 科技 領(lǐng)導(dǎo)力 專題 品牌中心
雜志訂閱

用戶數(shù)據(jù)不許被傳送到美國?歐盟法庭裁定“隱私盾”無效

David Meyer
2020-07-22

歐洲法院近期做出一項(xiàng)重要裁決,可能使美國企業(yè)無法再為歐盟的用戶提供服務(wù)。

文本設(shè)置
小號
默認(rèn)
大號
Plus(0條)

如果一家美國企業(yè)有歐洲用戶或客戶,而且會將個(gè)人數(shù)據(jù)傳到美國供企業(yè)使用,那么它就應(yīng)該了解歐盟最高法院的動向。

因?yàn)闅W洲法院(CJEU)近期做出了一項(xiàng)重要裁決。最后結(jié)果可能是企業(yè)無法再為歐盟的用戶提供服務(wù),即便不是現(xiàn)在,不遠(yuǎn)的將來也會發(fā)生。

隱私保護(hù)

如果美國企業(yè)利用歐洲用戶的個(gè)人數(shù)據(jù),那么就要提出合法理由。因?yàn)槊绹]有歐盟級別強(qiáng)大的聯(lián)邦隱私法(或者說根本沒有全面的聯(lián)邦隱私法)。

到目前為止,保持合法性最簡單的方法就是加入所謂的“隱私之盾”成員,只要能自證遵守歐盟的規(guī)定即可。而“隱私之盾”是根據(jù)美國和歐盟2016年達(dá)成的同名跨大西洋協(xié)議制定。

如今當(dāng)初的協(xié)議宣告結(jié)束。7月16日,歐盟委員會宣布取消協(xié)議并立即生效,主要有兩個(gè)原因:一是即便相關(guān)企業(yè)已經(jīng)是成員,協(xié)議并未阻止美國情報(bào)部門調(diào)用企業(yè)數(shù)據(jù);二是歐盟公民在美國沒有有效的申訴手段。

美國商務(wù)部的反應(yīng)是,在某種意義上這仍然是商業(yè)問題。商務(wù)部對裁決發(fā)布了一份表示失望的聲明,稱將“繼續(xù)管理‘隱私之盾’項(xiàng)目,包括處理提交給‘隱私之盾框架’的自證和重新證明,以及維護(hù)‘隱私之盾’成員名單?!?

美國商務(wù)部還補(bǔ)充稱,“當(dāng)前的決定并不能免除企業(yè)參與‘隱私之盾’承諾的義務(wù)?!?

而歐洲人卻不敢茍同。套用巨蟒劇場《死鸚鵡》短劇的臺詞就是:“隱私之盾”已經(jīng)死了;完了;離開了人世,謝幕了,給上帝唱詩去了。這是一份死協(xié)議。

因此,你可以繼續(xù)遵守成員義務(wù),盡可能尊重歐盟隱私法。但在歐洲人看來,從歐盟往美國傳輸數(shù)據(jù)傳輸不再合法。而之前加入“隱私之盾”就是為了讓數(shù)據(jù)傳輸合法。

(不過,在美國遵守承諾可能仍然有法律上的原因?!叭绻麉⑴c隱私之盾的企業(yè)做出隱私承諾,那么不履行承諾就可能因?yàn)槠墼p而受到處理。”Alston & Bird律師事務(wù)所的高級律師彼得?斯維爾說。)

7月16日,數(shù)據(jù)創(chuàng)新中心(Center for Data Innovation)的高級政策分析師艾琳?奇沃特在一份聲明中詳細(xì)介紹了影響:“這一決定對歐洲和美國5000多家將歐美隱私之盾作為跨大西洋數(shù)據(jù)傳輸法律依據(jù)的企業(yè)造成了嚴(yán)重沖擊。如今數(shù)據(jù)傳輸?shù)囊罁?jù)會立刻推翻,很多情況下歐美之間的數(shù)據(jù)傳輸將中止,而且多家企業(yè)并沒有合適的替代方案?!?

標(biāo)準(zhǔn)合同條款

但如果隱私之盾并不是數(shù)據(jù)傳輸唯一的法律依據(jù)呢?

Facebook(涉及此案)和微軟之類的美國公司多年來一直依賴“標(biāo)準(zhǔn)合同條款”的機(jī)制。顧名思義,都是由歐盟委員會撰寫已就緒的條款,概述了一系列符合歐盟嚴(yán)格的《通用數(shù)據(jù)保護(hù)條例》的權(quán)利和責(zé)任。

盡管法院可以撤銷“標(biāo)準(zhǔn)合同條款”,但其并未這么做。

法院稱,“標(biāo)準(zhǔn)合同條款”總體上沒有什么問題,如果有企業(yè)違反相關(guān)條款或無法遵守相關(guān)規(guī)定,比如說因?yàn)槠髽I(yè)無法阻止本國情報(bào)部門對數(shù)據(jù)進(jìn)行大規(guī)模監(jiān)視,法院則可以根據(jù)具體情況宣布條款無效。

這也是為何對Facebook以及其他依賴標(biāo)準(zhǔn)合同條款將歐洲數(shù)據(jù)傳輸?shù)矫绹拿绹笮涂萍脊緛碚f,推翻隱私之盾體系是個(gè)問題。

2013年斯諾登事件曝光導(dǎo)致美國監(jiān)控法做出了有限改革,但《外國情報(bào)監(jiān)視法》(FISA)第702條仍然允許從大型科技公司大量收集非美國人的私人數(shù)據(jù)。

美國一些人認(rèn)為,只有當(dāng)相關(guān)機(jī)構(gòu)真正查看數(shù)據(jù)時(shí),監(jiān)控才真正開始,而查看數(shù)據(jù)是更受限制的活動。但歐洲人認(rèn)為,監(jiān)控從收集就已經(jīng)開始。所以在歐洲人看來,美國經(jīng)常對歐洲人的數(shù)據(jù)進(jìn)行大規(guī)模監(jiān)控,而處理數(shù)據(jù)的美國公司對此無能為力。

這種現(xiàn)象已經(jīng)非常嚴(yán)重,會破壞隱私之盾(及其前身安全港)。因此,如果Facebook等企業(yè)使用的標(biāo)準(zhǔn)合同條款受到歐盟隱私監(jiān)管機(jī)構(gòu)的挑戰(zhàn),很難想象將如何繼續(xù)。

“盡管原則上標(biāo)準(zhǔn)合同條款體系將保留,剛開始已經(jīng)簽訂的標(biāo)準(zhǔn)合同將保持有效,但必須由數(shù)據(jù)保護(hù)當(dāng)局根據(jù)(歐盟法院)的裁決進(jìn)行審查,如有必要予以暫停。”德國前數(shù)據(jù)保護(hù)主管彼得?沙爾在博客中寫道。

現(xiàn)在怎么辦?

當(dāng)然,為歐洲人提供服務(wù)的美國企業(yè)并非每家都是Facebook或谷歌。如果并沒有出現(xiàn)美國專門機(jī)構(gòu)根據(jù)FISA第702條審查收集的數(shù)據(jù),比如航空公司或零售商,那么仍然可以援引標(biāo)準(zhǔn)合同條款。

而現(xiàn)在最大的不同在于,必須首先說服歐盟隱私監(jiān)管機(jī)構(gòu),歐洲客戶的數(shù)據(jù)在美國并未受到監(jiān)控。

“援引標(biāo)準(zhǔn)合同條款的數(shù)據(jù)出口商和進(jìn)口商首先必須核實(shí)(數(shù)據(jù)流向國家)的保護(hù)水平。進(jìn)口商還有義務(wù)向出口商報(bào)告出現(xiàn)的問題?!盝MW律師事務(wù)所的合伙人托尼?維塔萊在一份聲明中表示。

如果企業(yè)的業(yè)務(wù)中處理歐洲人的個(gè)人數(shù)據(jù)對履行用戶合同屬于“必要”,比如電子郵件提供商處理郵件數(shù)據(jù),那么根據(jù)歐盟法律也沒有問題。

“法庭明確強(qiáng)調(diào),隱私之盾無效不會造成‘法律真空’,因?yàn)橹陵P(guān)重要的數(shù)據(jù)流仍然可以繼續(xù)?!痹诓脹Q通過后,提起訴訟的訴訟當(dāng)事人馬克斯?施雷姆斯發(fā)表聲明稱。

但無論規(guī)模大小,現(xiàn)在很多美國企業(yè)可能仍然在四處奔忙尋找法律解決方案,解決7月16日上午突然降臨的問題。

目前唯一可靠且一勞永逸的解決方案就是修改美國隱私和監(jiān)視法。估計(jì)硅谷很快就會加強(qiáng)相關(guān)方面的游說。(財(cái)富中文網(wǎng))

譯者:Feb

如果一家美國企業(yè)有歐洲用戶或客戶,而且會將個(gè)人數(shù)據(jù)傳到美國供企業(yè)使用,那么它就應(yīng)該了解歐盟最高法院的動向。

因?yàn)闅W洲法院(CJEU)近期做出了一項(xiàng)重要裁決。最后結(jié)果可能是企業(yè)無法再為歐盟的用戶提供服務(wù),即便不是現(xiàn)在,不遠(yuǎn)的將來也會發(fā)生。

隱私保護(hù)

如果美國企業(yè)利用歐洲用戶的個(gè)人數(shù)據(jù),那么就要提出合法理由。因?yàn)槊绹]有歐盟級別強(qiáng)大的聯(lián)邦隱私法(或者說根本沒有全面的聯(lián)邦隱私法)。

到目前為止,保持合法性最簡單的方法就是加入所謂的“隱私之盾”成員,只要能自證遵守歐盟的規(guī)定即可。而“隱私之盾”是根據(jù)美國和歐盟2016年達(dá)成的同名跨大西洋協(xié)議制定。

如今當(dāng)初的協(xié)議宣告結(jié)束。7月16日,歐盟委員會宣布取消協(xié)議并立即生效,主要有兩個(gè)原因:一是即便相關(guān)企業(yè)已經(jīng)是成員,協(xié)議并未阻止美國情報(bào)部門調(diào)用企業(yè)數(shù)據(jù);二是歐盟公民在美國沒有有效的申訴手段。

美國商務(wù)部的反應(yīng)是,在某種意義上這仍然是商業(yè)問題。商務(wù)部對裁決發(fā)布了一份表示失望的聲明,稱將“繼續(xù)管理‘隱私之盾’項(xiàng)目,包括處理提交給‘隱私之盾框架’的自證和重新證明,以及維護(hù)‘隱私之盾’成員名單?!?

美國商務(wù)部還補(bǔ)充稱,“當(dāng)前的決定并不能免除企業(yè)參與‘隱私之盾’承諾的義務(wù)?!?

而歐洲人卻不敢茍同。套用巨蟒劇場《死鸚鵡》短劇的臺詞就是:“隱私之盾”已經(jīng)死了;完了;離開了人世,謝幕了,給上帝唱詩去了。這是一份死協(xié)議。

因此,你可以繼續(xù)遵守成員義務(wù),盡可能尊重歐盟隱私法。但在歐洲人看來,從歐盟往美國傳輸數(shù)據(jù)傳輸不再合法。而之前加入“隱私之盾”就是為了讓數(shù)據(jù)傳輸合法。

(不過,在美國遵守承諾可能仍然有法律上的原因?!叭绻麉⑴c隱私之盾的企業(yè)做出隱私承諾,那么不履行承諾就可能因?yàn)槠墼p而受到處理。”Alston & Bird律師事務(wù)所的高級律師彼得?斯維爾說。)

7月16日,數(shù)據(jù)創(chuàng)新中心(Center for Data Innovation)的高級政策分析師艾琳?奇沃特在一份聲明中詳細(xì)介紹了影響:“這一決定對歐洲和美國5000多家將歐美隱私之盾作為跨大西洋數(shù)據(jù)傳輸法律依據(jù)的企業(yè)造成了嚴(yán)重沖擊。如今數(shù)據(jù)傳輸?shù)囊罁?jù)會立刻推翻,很多情況下歐美之間的數(shù)據(jù)傳輸將中止,而且多家企業(yè)并沒有合適的替代方案?!?

標(biāo)準(zhǔn)合同條款

但如果隱私之盾并不是數(shù)據(jù)傳輸唯一的法律依據(jù)呢?

Facebook(涉及此案)和微軟之類的美國公司多年來一直依賴“標(biāo)準(zhǔn)合同條款”的機(jī)制。顧名思義,都是由歐盟委員會撰寫已就緒的條款,概述了一系列符合歐盟嚴(yán)格的《通用數(shù)據(jù)保護(hù)條例》的權(quán)利和責(zé)任。

盡管法院可以撤銷“標(biāo)準(zhǔn)合同條款”,但其并未這么做。

法院稱,“標(biāo)準(zhǔn)合同條款”總體上沒有什么問題,如果有企業(yè)違反相關(guān)條款或無法遵守相關(guān)規(guī)定,比如說因?yàn)槠髽I(yè)無法阻止本國情報(bào)部門對數(shù)據(jù)進(jìn)行大規(guī)模監(jiān)視,法院則可以根據(jù)具體情況宣布條款無效。

這也是為何對Facebook以及其他依賴標(biāo)準(zhǔn)合同條款將歐洲數(shù)據(jù)傳輸?shù)矫绹拿绹笮涂萍脊緛碚f,推翻隱私之盾體系是個(gè)問題。

2013年斯諾登事件曝光導(dǎo)致美國監(jiān)控法做出了有限改革,但《外國情報(bào)監(jiān)視法》(FISA)第702條仍然允許從大型科技公司大量收集非美國人的私人數(shù)據(jù)。

美國一些人認(rèn)為,只有當(dāng)相關(guān)機(jī)構(gòu)真正查看數(shù)據(jù)時(shí),監(jiān)控才真正開始,而查看數(shù)據(jù)是更受限制的活動。但歐洲人認(rèn)為,監(jiān)控從收集就已經(jīng)開始。所以在歐洲人看來,美國經(jīng)常對歐洲人的數(shù)據(jù)進(jìn)行大規(guī)模監(jiān)控,而處理數(shù)據(jù)的美國公司對此無能為力。

這種現(xiàn)象已經(jīng)非常嚴(yán)重,會破壞隱私之盾(及其前身安全港)。因此,如果Facebook等企業(yè)使用的標(biāo)準(zhǔn)合同條款受到歐盟隱私監(jiān)管機(jī)構(gòu)的挑戰(zhàn),很難想象將如何繼續(xù)。

“盡管原則上標(biāo)準(zhǔn)合同條款體系將保留,剛開始已經(jīng)簽訂的標(biāo)準(zhǔn)合同將保持有效,但必須由數(shù)據(jù)保護(hù)當(dāng)局根據(jù)(歐盟法院)的裁決進(jìn)行審查,如有必要予以暫停。”德國前數(shù)據(jù)保護(hù)主管彼得?沙爾在博客中寫道。

現(xiàn)在怎么辦?

當(dāng)然,為歐洲人提供服務(wù)的美國企業(yè)并非每家都是Facebook或谷歌。如果并沒有出現(xiàn)美國專門機(jī)構(gòu)根據(jù)FISA第702條審查收集的數(shù)據(jù),比如航空公司或零售商,那么仍然可以援引標(biāo)準(zhǔn)合同條款。

而現(xiàn)在最大的不同在于,必須首先說服歐盟隱私監(jiān)管機(jī)構(gòu),歐洲客戶的數(shù)據(jù)在美國并未受到監(jiān)控。

“援引標(biāo)準(zhǔn)合同條款的數(shù)據(jù)出口商和進(jìn)口商首先必須核實(shí)(數(shù)據(jù)流向國家)的保護(hù)水平。進(jìn)口商還有義務(wù)向出口商報(bào)告出現(xiàn)的問題?!盝MW律師事務(wù)所的合伙人托尼?維塔萊在一份聲明中表示。

如果企業(yè)的業(yè)務(wù)中處理歐洲人的個(gè)人數(shù)據(jù)對履行用戶合同屬于“必要”,比如電子郵件提供商處理郵件數(shù)據(jù),那么根據(jù)歐盟法律也沒有問題。

“法庭明確強(qiáng)調(diào),隱私之盾無效不會造成‘法律真空’,因?yàn)橹陵P(guān)重要的數(shù)據(jù)流仍然可以繼續(xù)?!痹诓脹Q通過后,提起訴訟的訴訟當(dāng)事人馬克斯?施雷姆斯發(fā)表聲明稱。

但無論規(guī)模大小,現(xiàn)在很多美國企業(yè)可能仍然在四處奔忙尋找法律解決方案,解決7月16日上午突然降臨的問題。

目前唯一可靠且一勞永逸的解決方案就是修改美國隱私和監(jiān)視法。估計(jì)硅谷很快就會加強(qiáng)相關(guān)方面的游說。(財(cái)富中文網(wǎng))

譯者:Feb

If you're an American company with European users or customers, and you transfer their personal data to the U.S. for company use, you need to be aware of what just went down at the EU's top court today.

That's because the Court of Justice (CJEU) just made a huge ruling. The upshot: It's possible you will no longer be able to serve people in the EU—if not now, then in the not-too-distant future.

Privacy Shield

U. S. companies using Europeans' personal data need some sort of legal justification for doing so. That's because the U.S. lacks an EU-strength federal privacy law (or indeed any comprehensive federal privacy law at all).

By far the easiest way to keep things legal was to sign up to the so-called Privacy Shield register—essentially, self-certifying that the company will stick to EU rules. This register was created under a transatlantic deal of the same name, struck between the U.S. and EU in 2016.

That deal is now dead. The CJEU on July 16 canceled it with immediate effect, basically for two reasons: It didn't stop U.S. intelligence from poking around companies' data even if they were on the list, and there was no effective way for EU citizens to file a complaint about this in the U.S.

The U.S. Department of Commerce reacted by indicating it would be, in a sense, business as usual. In a statement expressing disappointment with the ruling, the department said it would "continue to administer the Privacy Shield program, including processing submissions for self-certification and recertification to the Privacy Shield Frameworks and maintaining the Privacy Shield List."

It added, "Today’s decision does not relieve participating organizations of their Privacy Shield obligations."

The Europeans beg to differ. To paraphrase Monty Python's Dead Parrot sketch, Privacy Shield has passed on; it has kicked the bucket; it has shuffled off its mortal coil, run down the curtain, and joined the bleeding choir invisible. It is an ex-agreement.

So you can continue to abide by the register's obligations—essentially, respecting EU privacy law as best you can—but that no longer means your EU-U.S. data transfers are legal in European eyes. Which was the whole point of the register to start with.

(There may still be a legal reason to keep those promises over in the U.S., though. "Companies that have made privacy promises under Privacy Shield could be subject to enforcement for deceptive practices if they do not live up to those privacy promises," said Peter Swire, a senior counsel at law firm Alston & Bird.)

Eline Chivot, senior policy analyst at the Center for Data Innovation, described the impact well in a statement July 16: "The decision delivers a severe blow to the operations of over 5,000 European and American companies who use the EU-U.S. Privacy Shield as the legal basis for transatlantic data transfers. It will immediately upend, and in many cases even halt, data transfers between the EU and the United States, leaving many businesses with no suitable alternative."

Standard contractual clauses

But what if Privacy Shield isn't your only legal basis for those transfers?

Some U.S. companies such as Facebook (the firm involved in this particular case) and Microsoft have for years also been relying on a mechanism called "standard contractual clauses," or SCCs. These are, as the name suggests, oven-ready clauses that the European Commission wrote, again outlining a range of rights and responsibilities in line with the EU's strict GDPR privacy law.

The court did not strike down SCCs, though it had the option to do so.

It said SCCs were fine in general because an EU privacy regulator can still invalidate them on a case-by-case basis if a company is breaking the clauses' terms or is unable to stick to them—because, say, it can't stop the intelligence services back home from conducting mass surveillance on the data.

This is where the striking-down of the Privacy Shield becomes a problem for Facebook and any other big American tech company relying on SCCs to send Europeans' data over to the U.S.

Although the Snowden revelations of 2013 led to some limited reforms in U.S. surveillance law, Section 702 of the Foreign Intelligence Surveillance Act (FISA) still allows for the mass collection of non-Americans' personal data from Big Tech firms.

Some in the U.S. argue that surveillance starts only when the agencies actually look at the data—which is a more restricted activity. But the Europeans see surveillance as starting at the point of collection. So in European eyes, the U.S. regularly conducts mass surveillance on Europeans' data—and there's nothing the U.S. companies handling that data can do about it.

That's serious enough to have scuppered Privacy Shield (and its predecessor, Safe Harbor), so it is difficult to see how the SCCs used by a company like Facebook can survive if challenged before an EU privacy authority.

"Although the system of standard contractual clauses will remain in principle and the standard contracts concluded will initially remain in force, they will have to be reviewed and, if necessary, suspended by the data protection authorities in the light of the [CJEU] ruling," wrote former German data protection chief Peter Schaar in a blog post.

So what now?

Of course, not every American company serving Europeans is a Facebook or Google. If you don't have U.S. agencies scrutinizing your data under Section 702 of FISA—if, for example, you're an airline or a retailer—then SCCs could still work for you.

The big difference now is that you'll first have to convince EU privacy regulators that European customers' data isn't subject to surveillance in the U.S.

"Data exporters and importers using the standard contract clauses must verify the level of protection in the [country where the data is going] first. The importer also has a duty to report any issues to the exporter," said Toni Vitale, a partner at JMW Solicitors, in a statement.

And if your processing of Europeans' personal data is "necessary" for the fulfillment of your user contracts—if you're an email provider handling emails, for example—then that's also automatically kosher under EU law.

"The court explicitly highlighted that the invalidation of the Privacy Shield will not create a 'legal vacuum' as crucially necessary data flows can be still undertaken," Max Schrems, the litigant who brought the case, said in a statement after the ruling came through.

But an awful lot of U.S. companies, big and small, are still likely to be flailing around now, looking for a legal solution to a problem that abruptly landed in their laps on July 16 morning.

The only reliable, long-term solution would be changes in U.S. privacy and surveillance law. Expect to see Silicon Valley's lobbying efforts step up on that front very soon.

財(cái)富中文網(wǎng)所刊載內(nèi)容之知識產(chǎn)權(quán)為財(cái)富媒體知識產(chǎn)權(quán)有限公司及/或相關(guān)權(quán)利人專屬所有或持有。未經(jīng)許可,禁止進(jìn)行轉(zhuǎn)載、摘編、復(fù)制及建立鏡像等任何使用。
0條Plus
精彩評論
評論

撰寫或查看更多評論

請打開財(cái)富Plus APP

前往打開
熱讀文章
国产乱婬AV片免费| 伊人久久大香线焦AV综合影院| 久久久久久黃色網站免費 | 中文字幕久久综合久久88| 激情内射亚洲一区二区三区爱妻| 美女被男人桶到爽免费网站国产| 国产99视频精品免费观看6| 日日噜噜夜夜狠狠久久丁香五月| 亚洲综合无码精品一区二区三区| 全部免费的毛片在线看| 人人人澡人人肉人人精品| 综合色区亚洲熟女妇p | 在线a级毛片无码免费真人版| 亚洲AV中文无码乱人伦在线播放| 在线免费播放一级毛片| 荡公乱妇HD在线播放BD| 人人添人人妻人人爽夜欢视AV| 特级做A爰片毛片A片免费| 国产在线精品观看免费观看| 亚洲欧美国产五月天综合| 久久精品国产免费观看三人同眠| 国产91流白浆喷水免费观看| 国产一区二区波多野结衣| 乱人伦中文视频在线| 亚洲国产精品一区二区第四页| 一区二区三区免费av| 九九99久久精品国产| 夜添久久精品亚洲精品第一国产综合高清| 18岁未禁亚洲男人的天堂| 人人妻人人澡人人爽欧美一区九九| 久久中文精品无码中文字幕| 与亲女洗澡时伦了毛片| 欧美交A欧美精品喷水| 亚洲欧美v国产一区二区| 久久久久亚洲精品中文| 毛片黄色人人艹电影在线观看| 熟妇女人妻丰满少妇中文字幕| 91午夜精品亚洲一区二区三区| 亚洲AV综合性爱网亚| 国产AV无码专区亚洲AWWW| 亚洲AⅤ日韩AV电影在线观看|