UIA - The New EU General Data Protection Regulation. Use of Cloud Computing after the Digital Rights Ireland judgment

Documentos relacionados
Governação Novo Código e Exigências da Função Auditoria

75, 8.º DTO LISBOA

Comércio Eletrônico e a proteção de dados pessoais do consumidor E-commerce and the protection of consumer's personal data

Erasmus Student Work Placement

Interface between IP limitations and contracts

Lloyd s no brasil. 2 anos após a abertura do mercado de resseguros MARCO ANTONIO DE SIMAS CASTRO


NORMAS PARA AUTORES. As normas a seguir descritas não dispensam a leitura do Regulamento da Revista Portuguesa de Marketing, disponível em

Normalização e interoperabilidade da informação geográfica

Technical Information

Trabalho de Compensação de Ausência - 1º Bimestre

INTERNATIONAL CRIMINAL COURT. Article 98 TREATIES AND OTHER INTERNATIONAL ACTS SERIES

What is Bullying? Bullying is the intimidation or mistreating of weaker people. This definition includes three important components:1.

ANATEL AGÊNCIA NACIONAL DE TELECOMUNICAÇÕES

Planejamento de comunicação integrada (Portuguese Edition)

Para Aplicação do Artigo 9º do Acordo / For the purposes of Article 9 of the Agreement

75, 8.º DTO LISBOA

Erasmus Student Work Placement

COMITÊ DO ESPECTRO PARA RADIODIFUSÃO - CER SPECTRUM DAY A REVISÃO DA REGULAMENTAÇÃO DO USO DA FAIXA DE 3,5 GHZ UMA NECESSIDADE COMPROVADA.

IN RE: GUARDIAN ADVOCATE OF/ REF: CURATELA ESPECIAL DE

WP8 Quality and Management/Governance National study Portuguese version 2012

Visitor, is this is very important contact with you. WATH DO WE HERE?

GUIÃO Domínio de Referência: CIDADANIA E MULTICULTURALISMO

Serviços: API REST. URL - Recurso


ANÚNCIO DE LANÇAMENTO DE OFERTA PÚBLICA DE TROCA DE OBRIGAÇÕES PELO BANIF BANCO INTERNACIONAL DO FUNCHAL, S.A. ( BANIF )

CAPLE EXAMS 2018 WHAT ARE CAPLE EXAMS?

Célia Antunes Barroca. Subsídios do Governo no âmbito do SNC NCRF 22. Universidade de Aveiro Ano 2011

A Protecção de Dados na Cloud Luís Neto Galvão, Advogado, Sócio da SRS Advogados

COMO ESCREVER PARA O ENEM: ROTEIRO PARA UMA REDAçãO NOTA (PORTUGUESE EDITION) BY ARLETE SALVADOR

NOVAS VANTAGENS NEW BENEFITS

Projeto VISIT Victim Support for Identity Theft. Lisboa, 30 Outubro 2015

Peering Fórum - April 30, 2018 in Panamá - IX.br - 1

GERENCIAMENTO DA ROTINA DO TRABALHO DO DIA A DIA (PORTUGUESE EDITION) BY VICENTE FALCONI

REPÚBLICA DE ANGOLA VISA APPLICATION FORM PEDIDO DE VISTO DE ENTRADA

Normas de correta fabricação de APIs e Produtos Manufaturados. Experiência da Industria Farmacêutica Europeia.

Conversação Para Viagem - Inglês (Michaelis Tour) (Portuguese Edition)

01-A GRAMMAR / VERB CLASSIFICATION / VERB FORMS

Project Management Activities

MICROINSURANCE IN BRAZIL

Colaborar: Missão impossível? Lições da área da saúde mental. José Miguel Caldas de Almeida 17 de Janeiro de 2017

Guia de Preenchimento da Proposta de Adesão ao Plano de Saúde Claro Dental

Objetivo da Consulta: Amparo Legal para adoção de Cláusula Restritiva de Utilização para aeronaves BRADESCO SEGUROS A MULTI-CHANNEL APPROACH

MASTER S DEGREE IN INTELLECTUAL PROPERTY ADMISSION EXAM

Versão: 1.0. Segue abaixo, os passos para o processo de publicação de artigos que envolvem as etapas de Usuário/Autor. Figura 1 Creating new user.

Retsudvalget REU Alm.del Bilag 408 Offentligt. National Unit for Drugs Trafficking Fighting

Direito da Comunicação. A criação e difusão de informação na Internet

How UMA Contributes to Solving the IDESG Healthcare Relationship Location Service Use tinyurl.com/umawg 19 Jan 2014

ATLAS COLORIDO DE ANATOMIA VETERINáRIA DE EQUINOS (EM PORTUGUESE DO BRASIL) BY STANLEY H. ASHDOWN RAYMOND R. DONE

Um olhar que cura: Terapia das doenças espirituais (Portuguese Edition)

// gaiato private label

Doing Business in Brazil : Pathways to success, Innovation and Access under the Legal Framework

Welcome to Lesson A of Story Time for Portuguese

INFORMATION SECURITY IN ORGANIZATIONS

Consultoria em Direito do Trabalho

HANCOCK ASSET MANAGEMENT BRASIL LTDA. POLÍTICA DE RATEIO E DIVISÃO DE ORDENS POLICY ON ASSESSMENT AND DISTRIBUTION OF INVESTMENT ORDERS

Futebol em Transmissão. Football is on the Air.

NORMAS DE FUNCIONAMENTO DOS CURSOS DE LÍNGUAS (TURMAS REGULARES E INTENSIVAS) 2015/2016

National workshop on malaria control at Community level. Room of the National Institute of Public Health

GUIÃO A. Ano: 9º Domínio de Referência: O Mundo do Trabalho. 1º Momento. Intervenientes e Tempos. Descrição das actividades

NÚCLEO DE TECNOLOGIA EDUCACIONAL PARA A SAÚDE UNIVERSIDADE FEDERAL DO RIO DE JANEIRO

Calendarização da Componente Letiva Ano Letivo 2015/16. Área Disciplinar de Inglês. Períodos 1º Período

Teoria Económica Clássica e Neoclássica

Efficient Locally Trackable Deduplication in Replicated Systems. technology from seed

Terms and Conditions

A Avaliação dos Projetos

DevOps. Carlos Eduardo Buzeto IT Specialist IBM Software, Rational Agosto Accelerating Product and Service Innovation

Planning for and Managing Devices in the Enterprise: Enterprise Management Suite (EMS) & On-Premises Tools (20398)

DG(SANCO)/ MR

Criando diferenciais competitivos e minimizando riscos com uma boa. Claudio Yamashita Country Manager Intralinks Brasil

PROGRAM FOR 3 DAYS in Faial and S. Jorge Islands, Azores

INSTRUÇÕES INSTRUCTIONS

Legislar melhor : os Estados -membros devem empenhar-se em aplicar efectivamente o direito comunitário

Schmidt, Valois, Miranda, Ferreira & Agel - Advogados

Labrador: Guia prático ilustrado (Coleção Pet Criador) (Portuguese Edition)

Receitas na Pressão - Vol. 01: 50 Receitas para Panela de Pressão Elétrica (Portuguese Edition)

Guião A. Descrição das actividades

NOTA INFORMATIVA. 1. Enquadramento

Interactive Internet TV Architecture Based on Scalable Video Coding

VIA VAREJO S.A. Companhia Aberta de Capital Autorizado CNPF/MF nº / NIRE: FATO RELEVANTE

MySQL: Comece com o principal banco de dados open source do mercado (Portuguese Edition)

Como testar componentes eletrônicos - volume 1 (Portuguese Edition)

AMENDMENTS XM United in diversity XM 2012/2191(DEC) Draft report Gerben-Jan Gerbrandy. PE v01-00

GERENCIAMENTO PELAS DIRETRIZES (PORTUGUESE EDITION) BY VICENTE FALCONI

Adoção: guia prático doutrinário e processual com as alterações da Lei n , de 3/8/2009 (Portuguese Edition)

Vendors Enquiries for RFP 003/2015

Política de. Gestão de Serviços. Service Management Policy. A direcção pretendida The desired direction

Estereoscopia Digital no Ensino da Química AGRADECIMENTOS

IMMIGRATION Canada. Study Permit. São Paulo Visa Office Instructions. Table of Contents. For the following country: Brazil IMM 5849 E ( )

eposters evita impressões avoid printing reduz a pegada ecológica reduce the ecological footprint

CMDB no ITIL v3. Miguel Mira da Silva

As 100 melhores piadas de todos os tempos (Portuguese Edition)

O IMPACTO DA REGULAÇÃO GERAL DE PROTEÇÃO DE DADOS DA UE EM EMPRESAS BRASILEIRAS

PURCHASE-TO-PAY SOLUTIONS

Business Ecosystem Transformation: Tax & Finance

Introdução A Delphi Com Banco De Dados Firebird (Portuguese Edition)

Perguntas & Respostas

Vaporpunk - A fazenda-relógio (Portuguese Edition)

Transcrição:

UIA - The New EU General Data Protection Regulation Use of Cloud Computing after the Digital Rights Ireland judgment Luís Neto Galvão, Partner, SRS Legal

Judgment of the CJEU (Grand Chamber) of 8 April 2014 (joined cases C-293/12 and C-594/12): the Court declared the invalidity of the Data Retention Directive The Directive Historic context of Approval Scope Types of Data Retained Findings: the EU legislator exceeded the limits imposed by compliance with the principle of proportionality in the light of Articles 7, 8 and 52(1) of the Charter of Fundamental Rights of the European Union Transatlantic impact? 2

Directive allows acquiring very precise information on the private lives of the persons whose data are retained, such as the habits of everyday life, permanent or temporary places of residence, daily or other movements, activities carried out, social relationships and the social environments frequented. By requiring the retention of those data and by allowing the competent national authorities to access those data, the directive interferes in a particularly serious manner with the fundamental rights to respect for private life and to the protection of personal data. 3

However, the retention does not adversely affect the essence of the fundamental rights to respect for private life and to the protection of personal data: i. the directive does not allow the retention of content ii. the service or network providers must respect certain principles of data protection and data security. It satisfies an objective of general interest, namely the fight against serious crime and, ultimately, public security. 4

By adopting the Data Retention Directive, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality. The interference of the directive with the fundamental rights was not limited to what is strictly necessary. The type of retained data provides a lot of information on the people in question, including: the identity of the person with whom the communication took place and by what means, and the time of the communication as well as the place from which that communication took place and The frequency of the communications with certain persons during a given period. 5

Main problems with the directive: Covers, all individuals, all means of electronic communication and all traffic data without any differentiation, limitation or exception being made in the light of the objective of fighting against serious crime. Fails to lay down any objective criterion which would ensure that the competent national authorities have access to the data and can use them only for the purposes of prevention, detection or criminal prosecutions concerning offences that may be considered to be sufficiently serious to justify such an interference. Refers in a general manner to serious crime as defined by each Member State in its national law. 6

Does not lay down substantive and procedural conditions for access to and subsequent use of the data: access to is not made dependent on prior review by a court or by an independent administrative body. The minimum retention period of six months does not make any distinction between the categories of data on the basis of the persons concerned or the usefulness of the data in relation to the objective pursued and no criteria are provided for justifying maximum retention period of up to two years. No sufficient safeguards provided to ensure effective protection of the data against the risk of abuse and against unlawful access and use of the data (e.g. service providers can have regard to economic considerations when determining the level of security) and it does not ensure the irreversible destruction of the data at the end of the retention period. 7

Last (unexpected) concern of the Court: The Directive does not require that the data be retained within the EU: in doing so, it does not fully ensure the control of compliance with the requirements of protection and security by an independent authority, as is, however, explicitly required by the Charter. Control of a DPA, carried out on the basis of EU law, is an essential component of the protection of individuals with regard to the processing of personal data. Important decision for cloud computing: the Court seems to imply that retained data (or any sensitive data) must be stored and processed exclusively within the European Union What message did the Court intend to transmit? 8

International transfer issues for cloud computing Introduction to cloud computing: models, cloud providers (controllers and/or processors), main contractual issues, concerns International transfers under Directive 95/46/EC (BCRs, Model Clauses Controller-Processor (2010), ad hoc Contracts, Safe Harbor) Article 29 WP Working Document of a Co-operation Procedure For Issuing Common Opinions on Contractual Clauses considered compatible with the EC Model Clauses Approval of model clauses of Microsoft and Amazon Web Services 9

International transfer issues for cloud computing Safe Harbor Regime under scrutiny/transatlantic discussions for an umbrella agreement Data Nationalism and its impact in cloud computing (Brazil, Europe, Australia, Russia, France, Portugal) Microsoft Case (US), Schrems v. Data Protection Commissioner (CJEU) 10

International transfer issues for cloud computing Transfers of data by EEA based cloud providers to sub processors outside the EEA how to solve the problem? UE + EEA Company WP29, Working document 01/2014 on Draft Ad hoc contractual clauses EU data processor to non-eu subprocessor ; Supplier of Cloud Service Subcontractor How can we improve model clauses and make them more effective? Impact of the draft EC Data Protection Regulation on data transfers Sub-subcontractor in a third country 11

Obrigado Thank you. Luis Neto Galvão Sócio/Partner T +351 21 313 20 00 F +351 21 313 20 01 luis.galvao@srslegal.pt www.srslegal.pt 12

LISBOA R. Dom Francisco Manuel de Melo, nº21, 1070-085 T. +351 21 313 2000 F. +351 21 313 2001 FUNCHAL Av. Zarco, nº2, 2º, 9000-069 T. +351 291 20 2260 F. +351 291 20 2261 Em parceria com_ Simmons & Simmons (*) Andreia Lima Carneiro & Associados _ANGOLA _BRASIL _MACAU _MOÇAMBIQUE PORTO (*) R. Tenente Valadim, nº215, 4100-479 T. +351 22 543 2610 F. +351 22 543 2611