Showing posts with label CJEU. Show all posts
Showing posts with label CJEU. Show all posts

Wednesday, January 16, 2019

EU member states attempt to circumvent CJEU rulings on data retention

One of the things the UK government is going to miss desperately, once Brexit deal is done, is the monumental amount of policy washing they have been able to drive though the EU in the past four plus decades. Not that this will prevent future UK governments from blaming the EU for whatever their prevailing set of woes happens to be.

Case in point.

The Court of  Justice of the EU has repeatedly ruled that blanket data retention is a breach of the  Charter of Fundamental rights of the EU, most notably in the Digital Rights Ireland case in April 2014 and the Tele2 case in December 2016.

Ever since, EU member state governments and various branches of EU institutions have been furiously trying to find ways to circumvent the Court's judgments and continue and expand data retention practices. They are very happy, thank you very much, with their current illegal data retention regimes.

The contortionist wordplay at large in some of the forums considering the issue is bordering on awe inspiring.

The current great hope of those working to maintain, enhance and expand data retention practices is that the planned new e-Privacy directive can be constructed in such a way as to pretend that data retention is not really data retention. In diplomatese they are working towards a more “favourable” environment for data retention than the current ePrivacy Directive of 2002. Article 15(1) of that directive when read in conjunction with the EU Charter of Fundamental Rights, rather irritatingly, for its supporters and according to the CJEU, prohibits blanket data retention. It requires data retention to be
"a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system"
Thank you to the excellent crew at EDRi for the update on the ongoing shenanigans on this today.

Monday, February 26, 2018

Proposed immigration exemption in UK Data Protection Bill

Having co-signed an Open Rights Group coordinated letter to EU Commissioners Frans Timmermans, Věra Jourová, and Tiina Astola about the proposed immigration exemption in UK Data Protection Bill, I have now written to my local MP, Layla Moran, on the matter. Copies of both communications below.

Dear Layla,

The UK government are proposing to incorporate an unconscionable clause in the Data Protection Bill, currently going through parliament, relating to immigrants. The immigration exemption provision removes individuals’ right to data protection if it is likely to prejudice “effective immigration control”. This will remove the right of individuals to receive information from a subject access request: a core mechanism in any immigration dispute.

According to the Chief Inspector of Borders and Immigration 10% of immigration dispute cases involved administrative errors, errors that can throw people’s lives into disarray. The Guardian is one of the few mainstream media outlets making any effort to report on the devastating impact of the government’s destructive approach to immigration and has covered stories of numerous people who have been in the UK for, in some cases, decades being deported or threatened with deportation. Some of these have been able to challenge the bureaucratic brutality of Home Office mistakes affecting them. If the proposed immigration exemption clause passes into law in the new data protection legislation it will callously derail the capacity of future victims of Home Office errors to defend themselves.

Along with a number of other concerned academics I have co-signed a letter, co-ordinated by the Open Rights Group, to EU commissioners, Frans Timmermans, Věra Jourová, and Tiina Astola asking that they intercede with the UK government on this matter. Copies have also been sent to Guy Verhofstadt, chief Brexit representative of the European Parliament, and the European Data Protection Supervisor,  Giovanni Buttarelli. I include a full copy of the letter below. It is also available at https://www.openrightsgroup.org/ourwork/correspondence/letter-to-eu-commissioners.

The immigration exemption does not belong in the Data Protection Bill. Please use your voice in Parliament to encourage your fellow MPs to ensure it is removed from the Bill.

Regards,

Ray Corrigan


Concern over United Kingdom’s proposed ‘immigration exemptions’ from Data Protection Bill
Dear Frans Timmermans, Věra Jourová, and Tiina Astola
We, the undersigned, write to express our concern regarding the UK Government’s incorporation of the General Data Protection Regulation into domestic law. Setting aside other areas of concern, the UK’s Data Protection Bill proposes an exemption that would remove individuals’ fundamental right to data protection if it is likely to prejudice “effective immigration control”.
This proposed exemption (‘the immigration exemptions’) will remove the right of individuals to receive information from a subject access request: a core mechanism in any immigration dispute. Further restrictions would remove the government’s responsibility to process an individual’s data in accordance with the principles of data protection including lawful, fair and transparent processing. The exemption would allow data to be shared across UK government institutions without accountability or opportunity for recourse.
The immigration exemptions would potentially leave EU citizens applying for residency post- Brexit without access to their personal data at the most crucial time. As a result, decisions taken about a person’s right to remain which may be based on incorrect information would not be rectified, because individuals would be unable to see that the personal data held is incorrect.
EU citizens could be mistakenly forced to leave the United Kingdom as a result of the immigration exemptions.
Further, the proposed immigration exemptions would appear to violate both the General Data Protection Regulation and the Charter of Fundamental Rights:
- The General Data Protection Regulation Article 23(1) stipulates that any restrictions underthe clause must “respect the essence of the fundamental rights and freedoms and [must be] a necessary and proportionate measure in a democratic society...”.
- Under Article 8 of the Charter of Fundamental Rights every individual in the European Union is entitled to the protection of personal data concerning him or her. This includes the right of access to data which has been collected concerning him or her, and the right to have it rectified.
The blanket immigration exemptions go beyond the necessity and proportionality of restrictions under Article 23 of the GDPR and directly interfere with an individual’s right of access to data, and for their data to be processed fairly under Article 8 of the Charter of Fundamental Rights.
We are concerned about the potential impact the immigration exemptions will have on the United Kingdom’s adequacy when it leaves the European Union. The judgment by the Court of Justice of the European Union in Maximillian Schrems v. Data Protection Commissioner C- 362/14, lays out at para 74 in no uncertain terms, that the practical requirement for adequacy requires:
“...protection essentially equivalent to that guaranteed within the European Union.”
And at para. 95:
“Legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter.”
Each of you represent an institution which holds a mandate to protect the interests of EU citizens and uphold the Charter of Fundamental Rights. That mandate includes the respect of these rights by member states.
We believe these proposed exemptions are particularly significant to all EU citizens currently resident in the United Kingdom in maintaining the protection of rights guaranteed to them in the Charter of Fundamental Rights.
We call on you:
- to communicate to the United Kingdom that the immigration exemptions must be removed to secure the compatibility with the essence of the fundamental right to data protection, and the Charter of Fundamental Rights; and
- to examine the exemptions impact on EU citizens’ ability to enforce their residency rights after Brexit under the agreements currently being brokered.
Yours sincerely,
Douwe Korff, Emeritus Professor of International Law, London Metropolitan University and Associate, Oxford Martin School of the University of Oxford
Judith Rauhofer, Lecturer in IT Law, University of Edinburgh
Dr Andrew A. Adams, Deputy Director, Centre for Business Information Ethics, Meiji University, Tokyo, Japan
Anna Fielder, Trustee and Chair Emeritus, Privacy International
Mike O’Neill, Director, Baycloud Systems, The Oxford Centre for Innovation
Marie Georges, Independent expert and member of the FREE Group
Prof Andy Phippen, University of Plymouth
Dr Reuben Binns, Department of Computer Science, University of Oxford
Dr Robin Callender Smith, Professor of Media Law, QMUL Information Rights Judge and former Immigration Judge
Dr Paul Bernal, Senior Lecturer in IT, IP and Media Law, University of East Anglia Law School Milena Popova, Digital Cultures Research Centre, UWE Bristol
Dr. Maureen O. Mapp, Lecturer and Module leader for Cyberlaw, University of Birmingham Law School
Dr Duncan Campbell, Visiting Senior Fellow (Law and Sociology), University of Sussex
Dr. Nicholas J. Gervassis, Lecturer in Law, University of Plymouth
Damian Tambini, Associate Professor, London School of Economics
Dr Sally Broughton Micova, Lecturer in Communications Policy and Politics, University of East Anglia
Vian Bakir, Professor in Political Community and Journalism, Bangor University
Ray Corrigan, Senior Lecturer, Science Technology Engineering & Mathematics Faculty, The Open University
Lilian Edwards, Professor of E-Governance, Law School, Strathclyde University Marian Petre, Professor of Computing, The Open University
Blaine Price, Professor of Computing, The Open University
Andrew McStay, Professor of Digital Life, Bangor University
Marian Petre, Professor of Computing, The Open University
Milena Popova, Digital Cultures Research Centre, UWE Bristol
Note: This letter was sent in copy to Guy Verhofstadt, chief Brexit representative of the European Parliament, and the European Data Protection Supervisor 

Update: In the quickest response I have ever had from an MP, Layla Moran says:

Dear Ray Corrigan,

Thank you for taking the time to email me. In short, I absolutely share your concerns and I am planning on speaking out against them when the Data Protection Bill comes before MPs in a fortnight’s time. I know my Lib Dem colleagues are also in favour of removing this clause.

With best wishes, Layla

Layla Moran MP
Liberal Democrat Member of Parliament for Oxford West and Abingdon

Thursday, July 20, 2017

CJEU AG opinion in Peter Nowak v Data Protection Commissioner

Students are going to like this one. Lily livered, liberal, commie, Brexit hating, elitist, expert, EU & CJEU & human rights loving, ivory towered, [insult of choice] academics, a constituency the scars of which yours truly can display two decades plus residency of, possibly not quite so much. Educational bureaucrats may well spurt their morning tea into their cornflakes on noticing tomorrow morning's headlines relating the news.

The Advocate General of the European Court of Justice has decided, in Case C‑434/16, Novak v Irish Data Protection Commissioner, that exam scripts are classifiable as personal data under the data protection directive 95/46/EC.

Mr Novak failed the Strategic Finance and Management Accounting examination of the Chartered Accountants of Ireland (CAI) on four occasions. In the end he decided to submit a subject access request for all personal data held by the CAI, with the intention of getting hold of his exam scripts. CAI refused to hand over the scripts, so he complained to the data protection commissioner. The commissioner declared the scripts to be outside the scope of what constituted personal data.

And so it was onward to the courts and eventually the Irish Supreme Court referred the matter to the Court of Justice, requesting a response to the following questions:
‘(1)      Is information recorded in/as answers given by a candidate during a professional examination capable of being personal data within the meaning of Data Protection Directive?
(2)      If the answer to Question 1 is that all or some of such information may be personal data within the meaning of the Directive, what factors are relevant in determining whether in any given case such script is personal data, and what weight should be given to such factors?’
In accordance with Article 2(a) of the data protection directive, ‘personal data’ means any information relating to an identified or identifiable individual. So it has a very wide scope.

In paragraphs 19 to 28 of her opinion, AG Kokott today clearly disagrees with the decision of the Irish Data Protection Commissioner not to support Mr Novak's perspective. The logic underpinning that opinion is clear from paragraph 24:
"24.      However, in every case, the aim of an examination — as opposed, for example, to a representative survey — is not to obtain information that is independent of an individual. Rather, it is intended to identify and record the performance of a particular individual, i.e. the examination candidate. Every examination aims to determine the strictly personal and individual performance of an examination candidate[emphasis added] There is a good reason why the unjustified use in examinations of work that is not one’s own is severely punished as attempted deception. 
25.      Consequently, an examination script incorporates information about the examination candidate and is in that sense a collection of personal data. [emphasis added]
26.      That this is the correct conclusion is also shown, moreover, in the fact that an examination candidate has a legitimate interest, based on the protection of his private life, in being able to object to the processing outside the examination procedure of the examination script ascribed to him. An examination candidate does not have to accept that his script can be disclosed to third parties or published without his permission.
27.      Contrary to the argument of the Irish Data Protection Commissioner, the personal data incorporated in an examination script is not confined to the examination result, the mark achieved or even points scored for certain parts of an examination. That marking merely summarises the examination performance, which is recorded in detail in the examination script itself.

28.      The classification of an examination script as incorporating personal data is not affected if, instead of bearing the examination candidate’s name, the script has an identification number or bar code. Under Article 2(a) of the Data Protection Directive, it is sufficient for the existence of personal information that the data subject may at least be indirectly identified. (6) Thus, at least where the examination candidate asks for the script from the organisation that held the examination, that organisation can identify him by means of the identification number."
AG Kokott is very clear that exam scripts are personal data. She also notes the importance of handwriting:
"29.      Mr Nowak, Poland and the Czech Republic also rightly argue that answers that are handwritten contain additional information about the examination candidate, namely about his handwriting. A script that is handwritten is thus, in practice, a handwriting sample that could at least potentially be used at a later date as evidence to determine whether another text was also written in the examination candidate’s writing. It may thus provide indications of the identity of the author of the script.
30.      The question whether such a handwriting sample is a suitable means of identifying the writer beyond doubt is of no importance for its classification as personal data. Many other items of personal data are equally incapable, in isolation, of allowing the identification of individuals beyond doubt. For that reason, neither is it necessary to determine whether the handwriting should be regarded as biometrical information."  
I'm a skeptic on handwriting analysis, so interested to see she refers to the potential practice of the use of handwriting analysis being the determinative factor here, rather than whether it has any legitimacy as a forensic tool.

Next up she tackles Ireland's concern that section 12(b), relating to the right to rectification of inaccurate data, will be used by unscrupulous students to demand incorrect answers to exams be declared correct. She beings by pointing out in paragraphs 32 to 34 that:
"32.      First, it must be remembered that the issue of right of access is only secondary in this case, where the main issue is in fact the interpretation of the concept of ‘personal data’... 
34.      Therefore, the classification of information as personal data cannot be dependent on whether there are specific provisions about access to this information which might apply in addition to the right of access or instead of it[emphasis added] Further, neither can problems connected with the right of rectification be decisive in determining whether there exists personal data. If those factors were regarded as determinative, certain personal data could be excluded from the entire protective system of the Data Protection Directive,[emphasis added] even though the rules applicable in their place do not ensure equivalent protection but fragmentary protection at best."
So, even if there were to be hypothetical problems with what someone might do with the personal data once they gain access to it, that cannot be used as an excuse to exclude access.

On the right to rectification of inaccurate data in this context again she is clear:
"35.      However, if one concentrates on the right of access and the issue of rectification, it must be recognised that in relation to an examination script this right clearly cannot be claimed in order, subsequent to obtaining that access, to demand rectification, pursuant to Article 12(b) of the Data Protection Directive, of the contents of the script, i.e. the solution written down by the examination candidate. [emphasis added] (9) As Poland has rightly emphasised, the accuracy and completeness of personal data pursuant to Article 6(1)(d) must be judged by reference to the purpose for which the data was collected and processed. The purpose of an examination script is to determine the knowledge and skills of the examination candidate at the time of the examination, which is revealed precisely by his examination performance and particularly by the errors in the examination. The existence of errors in the solution does not therefore mean that the personal data incorporated in the script is inaccurate.
36.      However, rectification would be conceivable if it were the case that the script inaccurately or incompletely recorded the examination performance of the data subject. For example, such a situation would arise if — as observed by Greece — the script of another examination candidate had been ascribed to the data subject, [emphasis added] which could be shown by means of, inter alia, the handwriting, or if parts of the script had been lost."
Next up comes the section of the decision - paragraphs 42 to 50 - that exams administrators, especially, are going gnash multitudes of molars on. The Irish Data Protection Commissioner, with the support of the Czech Republic, attempted to have Mr Novak's claim classed as abusive because he didn't follow the requisite procedures laid down for checking exam results. Instead he tried to bypass those procedures and get the information he wanted via data protection legislation.

Now anyone who has spent even a short time working in the education sector will tell you that it is a mortal sin, in the land of educational administrators, to attempt to circumvent their inviolable procedures. Forms must be filled in, boxes must be ticked and procedures must be followed. Even when those procedures are mutually exclusive and diametrically opposed. Exams procedures, in particular, are absolutely sacrosanct. In fairness to the exams zombies, this is often for good reasons - to protect the integrity of the institution, the exams and the interests of the students. But they are, nevertheless, sacrosanct, even if, over the generations, they evolve primarily to serve the interests of the examination bureaucracy.

AG Kokott does not see that Mr Novak was attempting, improperly or fraudulently, to take advantage of provisions of EU law, to gain access to scripts. After all, if he could otherwise have obtained access through exams procedures, why should he be considered to be engaged in abusive exploitation of data protection regulations, just to get access to the same information?
"45.      If examination scripts incorporate personal data, according to the pleadings of the Data Protection Commissioner and Ireland, a misuse of the aim of the Data Protection Directive would arise in so far as a right of access under data protection legislation would allow circumvention of the rules governing the examination procedure and objections to examination decisions.
46.      However, any alleged circumvention of the procedure for the examination and objections to the examination results via the right of access laid down by data protection legislation would have to be dealt with using the provisions of the Data Protection Directive. In that regard, Article 13 in particular comes to mind, which allows for exceptions to the right of access to be established to protect certain interests specified therein.
47.      To the extent that these grounds do not justify exceptions in certain situations, as may be the case in connection with examinations, it must be recognised that the legislature has given precedence to the data protection requirements which are anchored in fundamental rights over any other interests affected in a specific instance.
48.      However, it should be pointed out that the General Data Protection Regulation, which will apply in the future, resolves this tension. First, under Article 15(4) of the regulation, the right to obtain a copy of personal data is not to adversely affect the rights and freedoms of others. Second, Article 23 of the regulation sets out the grounds for a restriction of data protection guarantees in slightly broader terms than Article 13 of the Directive, since, in particular, protection of other important objectives of general public interest of the Union or of a Member State pursuant to Article 23(1)(e) of the regulation may justify restrictions.
49.      On the other hand, the mere existence of other national legislation that also deals with access to examination scripts is not sufficient to allow the assumption that the purpose of the Directive is being misused.
50.      However, even if one wished to assume misuse of purpose, it is still not apparent where the undue advantage lies if an examination candidate were to obtain access to his script via his right of access. In particular, no abuse can be identified in the fact that someone obtains information via the right of access which he could not otherwise have obtained. If there were already access to personal information, the introduction of a right of access under data protection law would not have been required. It is instead the task of the right to access under data protection legislation to make available to the person concerned — subject to the exceptions provided for in Article 13 of the Data Protection Directive — access to his own data, where otherwise no right of access exists."
The unuttered assumption, of course, is that Mr Novak would have had access to the information he was requesting under the requisite exams procedures or other national legislation. Even if there was a clash in relation to degree of access then, as paragraph 47 insists "data protection requirements which are anchored in fundamental rights over any other interests affected in a specific instance" take precedence. The AG is optimistic (para 48) that the GDPR will resolve any such tension in the future. I can't share that optimism until the scope and boundaries of articles 15(4) and 23 become more clearly defined in practice when such clashes do arise, in the wake of the GDPR implementation in May 2018.

That part of the analysis complete the AG declares in paragraph 51 that
"51.      In brief, it can be concluded that a handwritten examination script capable of being ascribed to an examination candidate constitutes personal data within the meaning of Article 2(a) of the Data Protection Directive."
She next tackles the question of examiner's corrections on an exam script in paragraphs 52 to 65. In particular she notes that it is a question for the Irish data protection commissioner whether the examiner's comments corrections are information about Mr Novak:
"53.      However, an answer to this question is not necessary for a decision in the main proceedings since it is not at issue whether any such corrections constitute information about Mr Nowak. Rather, the subject matter of the proceedings is whether the then Irish Data Protection Commissioner was entitled to dismiss the complaint submitted by Mr Nowak on the ground that his examination script was a priori not personal data. The extent to which corrections should also be regarded as data relating to the examination candidate would have to be ruled upon not by the Supreme Court but rather, should the action be successful, at first instance by the present Irish Data Protection Commissioner."
Having said it is a question for the DPC she, nevertheless, goes on to opine that examiner's corrections are information about an examination candidate, as well as the examiner's own personal data.
"61.      Nonetheless, the purpose of comments is the evaluation of the examination performance and thus they relate indirectly to the examination candidate. The organisation holding the examination is also able to identify the candidate without difficulty and link him with the corrections once it receives the marked script back from the examiner.
62.      ...in general, comments on an examination script are typically inseparable from the script itself ... because they would not have any informative value without it. However, the script itself incorporates, as previously stated, personal data of the examination candidate. The purpose of collecting and processing this data is precisely to permit the evaluation of the examination candidate’s performance as incorporated in the examiner’s corrections.
63.      Precisely because of that close link between the examination script and any corrections made on it, the latter also are personal data of the examination candidate pursuant to Article 2(a) of the Data Protection Directive.
[...]
65.      It should be mentioned for the sake of completeness that corrections made by the examiner are, at the same time, his personal data. His rights are an appropriate basis in principle for justifying restrictions to the right of access pursuant to Article 13(1)(g) of the Data Protection Directive if they outweigh the legitimate interests of the examination candidate. However, the definitive resolution to this potential conflict of interests is likely to be the destruction of the corrected script once it is no longer possible to carry out a subsequent check of the examination procedure because of the lapse of time."
AG Kokott then briefly addresses additional requirements on the application of the data protection directive and its facilitation of restrictions on the right to information.
"67.      However, no questions have been raised about these additional requirements and restriction options and therefore the Court need not address them. It would also appear that their consideration is not necessary in order for the Supreme Court to be able to rule on whether the then Irish Data Protection Commissioner was right to refuse further examination of the complaint made by Mr Nowak.
She finally concludes:
"70.      I therefore propose that the Court should rule as follows:
A handwritten examination script capable of being ascribed to an examination candidate, including any corrections made by examiners that it may contain, constitutes personal data within the meaning of Article 2(a) of Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data."
So it would appear that the Irish Supreme Court will be obliged to rule that the then Irish Data Protection Commissioner was not entitled to dismiss the complaint submitted by Mr Nowak, on the ground that his examination script was a priori not personal data.

As it is the Advocate General's opinion only, it remains advisory and it will be interesting to see if the the Court of Justice comes to the same conclusions. The Court often takes a strong lead from the AG Educational institutions, exams administrators in particular, would do well to take note.

Tuesday, October 06, 2015

CJEU Schrems, The Irish Data Protection Commissioner and Facebook

The Court of Justice of the European Union has today declared the EU-US Safe Harbour agreement, which  facilitates the transfer of personal data from the EU to the US, invalid.

The Court opens by highlighting the provisions of the 1995 Data Protection Directive
Object of the Directive
1. In accordance with this directive, Member States shall protect the fundamental rights and freedoms of natural persons, and in particular their right to privacy with respect to the processing of personal data.
Article 25 of the directive lays down the principles under which it may be permitted to transfer personal data to countries outside the EU, "a third country" (or countries), primarily that the 3rd country offer "an adequate level" of data protection. The European Commission has the power to declare 3rd countries compliant with EU standards but are obliged to engage in due diligence in accordance with procedures outlined in article 31 of the directive, to ensure the requisite checks and balances are in place.

Under article 26, EU member states can sanction personal data transfers to third countries not yet in possession of the Commission's seal of approval under a specific set of circumstances e.g. if the person whose data is to be transferred agrees to it.

From an initial scan of the decision, it seems that the Safe Harbour agreement of 2000, declaring the US a safe 3rd country for EU personal data transfers, has been declared invalid by the Court because the EU were not careful enough in checking out the US; and because untrammeled US mass surveillance practices would appear to make it an unsafe third country.

From paragraph 5, the Court outlines the Commission's Safe Harbour Decision 2000/520 (including principles and US organisations' self certification and dispute resolution processes) declaring the US a safe third country for personal data transfers. The agreement allowed for US law to override Safe Harbour obligations. So if US law explicitly imposes an obligation on US organisations to process or transfer data in ways that would breach the Safe Harbour principles it is ok for them to do so. The idea being to give US companies an exit when caught between complying with conflicting legal obligations.

At the time, privacy advocates were unhappy with the Safe Harbour decision, accusing EU negotiators of folding in the face of US demands. Several reviews of the agreement, including this one by a group of internationally renowned scholars, in the summer of 2007, have noted that the Safe Harbour scheme does not meet the requirements of the 1995 data protection directive or EU privacy standards. Documentary evidence, released to journalists by NSA whistleblower Edward Snowden in 2013, on the mass surveillance practices of the US and UK governments, have given weight to those conclusions.

The CJEU get to the Snowden revelations and the EU's response to these in paragraph 11 to 25 of the Schrems decision. In a kind of an 'ooops, oh dear, those nice US Safe Harbour compliant companies are doing things they shouldn't be with EU data; but let's not upset them because it's the government's fault' realisation, the Commission issued Communication COM(2013) 846 final and Communication COM(2013) 847 final; noting US mass surveillance (though they didn't call it that) "raises serious questions".

As our US cousins might say, you're darn tootin' it raises serious questions.

Paragraph's 26 to 36 deal with the Schems complaint about Facebook to the Irish Data Protection Commissioner and the Irish High Court.

Schrems asserted that Facebook's data transfers to the US undermined his fundamental rights to privacy and the protection of his personal data, guaranteed by articles 7 and 8 the Charter of Fundamental Rights of the European Union.

The Irish Data Protection Commissioner said not my job guv, get lost but even if it was, there was no specific evidence that the NSA had been playing with Mr Schrems's data.

Judge Hogan in the Irish High Court took a different view. Whilst accepting that electronic surveillance and interception "serve necessary and indispensable objectives in the public interest... the revelations made by Edward Snowden had demonstrated a ‘significant over-reach’ on the part of the NSA and other federal agencies." [para 30 Schrems] Judge Hogan also noted that EU citizens have no effective right to be heard in relation to the "indiscriminate surveillance and interception" carried out on them on a large scale by US federal agencies like the FBI and NSA. Protections for privacy, fundamental rights and freedoms guaranteed by the Irish Constitution were essentially being undermined by indiscriminate and disproportionate mass surveillance by US authorities. On the basis of Irish law alone, the Irish Data Protection Commissioner was wrong to reject Mr Schrems complaint.

Judge Hogan's view, that then brings the Commission's Safe Harbour decision of 2000 into play. Does that decision, certifying the US as a safe place for EU personal data, bind member states, obliging them to accept that certification; or can a data protection authority of a Member State, independently examine the claim of a person concerning a breach of their rights by a third country, when the law and practices in the third country do not ensure an adequate level of protection? Additionally, given what we know from Snowden, Judge Hogan believes the Safe Harbour decision itself to be invalid - as the fundamental right to privacy would be rendered meaningless if "State authorities were authorised to access electronic communications on a casual and generalised basis without any objective justification based on considerations of national security or the prevention of crime that are specific to the individual concerned and without those practices being accompanied by appropriate and verifiable safeguards."

The Court's deliberations play out in paragraphs 37 to 107.

The fundamental rights to privacy and data protection have been affirmed and re-affirmed in the Court time and again (Österreichischer Rundfunk and Others, Google Spain and Google, Ryneš, Rijkeboer, Digital Rights Ireland and Others). The independence of national supervisory authorities is an important element in protecting those rights in practice. They are obliged, however, to balance those rights with the interests of those requiring free movement of data and have no power relating to the processing of data, once it is transferred to another country. They do have an obligation, under articles 25, 26 and 28 of the 1995 directive, to monitor the transfer of data to a third country and ensure it complies with EU standards. Transfers may only be effected where the country the data is being sent to offers an "adequate level of protection".

Member states or the Commission may assess and determine whether protections offered by a third country are adequate. When the Commission makes a decision that a third country provides adequate protections it is binding on member states, until it is declared invalid by the CJEU. But that Commission decision cannot prevent EU citizens from pursuing a claim through the national supervisory authorities and, if necessary, national courts, if they have reason to be concerned that their fundamental rights are being undermined by the transfer to and processing of their personal data in a third country. If the national courts consider the complaint well founded, as did Judge Hogan in the Schrems case, they must refer it to the CJEU.

Bottom line - even if the Commission white-lists a country like the US, it does not prevent national data protection authorities investigating and national courts hearing an individual's complaint. And if an individual, like Mr Schrems, has a legitimate complaint, then it may be referred to the CJEU and the Commission's decision approving the US as a privacy respecting jurisdiction, may itself be reviewed [exclusively] by the Court of Justice.
"66 Having regard to the foregoing considerations, the answer to the questions referred is that Article 25(6) of Directive 95/46, read in the light of Articles 7, 8 and 47 of the Charter, must be interpreted as meaning that a decision adopted pursuant to that provision, such as Decision 2000/520, by which the Commission finds that a third country ensures an adequate level of protection, does not prevent a supervisory authority of a Member State, within the meaning of Article 28 of that directive, from examining the claim of a person concerning the protection of his rights and freedoms in regard to the processing of personal data relating to him which has been transferred from a Member State to that third country when that person contends that the law and practices in force in the third country do not ensure an adequate level of protection."
Paragraphs 67 to 106 review the validity of the Commission's Safe Harbour decision and constitute another CJEU warning over US and UK mass surveillance practices and the tepid European Commission response to these, following in the tradition of the Google Spain and Digital Rights Ireland cases from 2014.

Short version: the Commission failed totally, in its obligation to ensure that the laws and international obligations of the US actively respected the privacy rights of EU citizens, when approving the US as a trusted data protection nation, in their Safe Harbour decision of 2000. US organisations were permitted approval under a Safe Harbour self certification scheme which had no effective US public authority or legislative oversight (the US Federal Trade Commission's oversight being restricted to commercial disputes relating to unfair or deceptive practices in or affecting commerce and not the legality of interference with fundamental rights) and no remedies for individuals concerned about the potential abuse or misuse of their personal data. Not only did it fail, the Commission didn't even bother to check but eventually did get round to admitting, once the Snowden revelations emerged, that there might be "serious questions" over the Safe Harbour agreement.

Additionally the Commission, in the Safe Harbour decision, exceeded its authority in attempting to nullify national data protection authorities' powers to enable individuals to raise concerns about the processing of data in Commission approved third countries like the US.
86 ... Decision 2000/520 lays down that ‘national security, public interest, or law enforcement requirements’ have primacy over the safe harbour principles, primacy pursuant to which self-certified United States organisations receiving personal data from the European Union are bound to disregard those principles without limitation where they conflict with those requirements and therefore prove incompatible with them. ...
88 In addition, Decision 2000/520 does not contain any finding regarding the existence, in the United States, of rules adopted by the State intended to limit any interference with the fundamental rights of the persons whose data is transferred from the European Union to the United States, interference which the State entities of that country would be authorised to engage in when they pursue legitimate objectives, such as national security.
89 Nor does Decision 2000/520 refer to the existence of effective legal protection against interference of that kind...
92 Furthermore and above all, protection of the fundamental right to respect for private life at EU level requires derogations and limitations in relation to the protection of personal data to apply only in so far as is strictly necessary (judgment in Digital Rights Ireland and Others, C‑293/12 and C‑594/12, EU:C:2014:238, paragraph 52 and the case-law cited).
93 Legislation is not limited to what is strictly necessary where it authorises, on a generalised basis, storage of all the personal data of all the persons whose data has been transferred from the European Union to the United States without any differentiation, limitation or exception being made in the light of the objective pursued and without an objective criterion being laid down by which to determine the limits of the access of the public authorities to the data, and of its subsequent use, for purposes which are specific, strictly restricted and capable of justifying the interference which both access to that data and its use entail ...
94 In particular, legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life, as guaranteed by Article 7 of the Charter (see, to this effect, judgment in Digital Rights Ireland and Others, C‑293/12 and C‑594/12, EU:C:2014:238, paragraph 39).
95 Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter...
96 As has been found in particular in paragraphs 71, 73 and 74 of the present judgment, in order for the Commission to adopt a decision pursuant to Article 25(6) of Directive 95/46, it must find, duly stating reasons, that the third country concerned in fact ensures, by reason of its domestic law or its international commitments, a level of protection of fundamental rights essentially equivalent to that guaranteed in the EU legal order, a level that is apparent in particular from the preceding paragraphs of the present judgment.
97 However, the Commission did not state, in Decision 2000/520, that the United States in fact ‘ensures’ an adequate level of protection by reason of its domestic law or its international commitments. 98 Consequently, without there being any need to examine the content of the safe harbour principles, it is to be concluded that Article 1 of Decision 2000/520 fails to comply with the requirements laid down in Article 25(6) of Directive 95/46, read in the light of the Charter, and that it is accordingly invalid... 
99      ... national supervisory authorities must be able to examine, with complete independence, any claim concerning the protection of a person’s rights and freedoms in regard to the processing of personal data relating to him. That is in particular the case where, in bringing such a claim, that person raises questions regarding the compatibility of a Commission decision adopted pursuant to Article 25(6) of that directive with the protection of the privacy and of the fundamental rights and freedoms of individuals...  
102 The first subparagraph of Article 3(1) of Decision 2000/520 must ... be understood as denying the national supervisory authorities the powers which they derive from Article 28 of Directive 95/46, where a person, in bringing a claim under that provision, puts forward matters that may call into question whether a Commission decision that has found, on the basis of Article 25(6) of the directive, that a third country ensures an adequate level of protection is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals.
103 The implementing power granted by the EU legislature to the Commission in Article 25(6) of Directive 95/46 does not confer upon it competence to restrict the national supervisory authorities’ powers referred to in the previous paragraph of the present judgment.
104 That being so, it must be held that, in adopting Article 3 of Decision 2000/520, the Commission exceeded the power which is conferred upon it in Article 25(6) of Directive 95/46, read in the light of the Charter, and that Article 3 of the decision is therefore invalid.
105 As Articles 1 and 3 of Decision 2000/520 are inseparable from Articles 2 and 4 of that decision and the annexes thereto, their invalidity affects the validity of the decision in its entirety. 106 Having regard to all the foregoing considerations, it is to be concluded that Decision 2000/520 is invalid."
The Court concludes that the Safe Harbour Decision 2000/520 is invalid.

I would just repeat paragraph 93 for emphasis: "Legislation is not limited to what is strictly necessary where it authorises, on a generalised basis, storage of all the personal data of all the persons whose data has been transferred from the European Union to the United States without any differentiation, limitation or exception being made in the light of the objective pursued and without an objective criterion being laid down by which to determine the limits of the access of the public authorities to the data, and of its subsequent use, for purposes which are specific, strictly restricted and capable of justifying the interference which both access to that data and its use entail"

So, in summary, national data protection authorities and national courts can review claims of abuse of personal data by third countries and the Safe Harbour EU-US agreement, Decision 2000/520 is invalid.
"On those grounds, the Court (Grand Chamber) hereby rules: 1. Article 25(6) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data as amended by Regulation (EC) No 1882/2003 of the European Parliament and of the Council of 29 September 2003, read in the light of Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that a decision adopted pursuant to that provision, such as Commission Decision 2000/520/EC of 26 July 2000 pursuant to Directive 95/46 on the adequacy of the protection provided by the safe harbour privacy principles and related frequently asked questions issued by the US Department of Commerce, by which the European Commission finds that a third country ensures an adequate level of protection, does not prevent a supervisory authority of a Member State, within the meaning of Article 28 of that directive as amended, from examining the claim of a person concerning the protection of his rights and freedoms in regard to the processing of personal data relating to him which has been transferred from a Member State to that third country when that person contends that the law and practices in force in the third country do not ensure an adequate level of protection.
2. Decision 2000/520 is invalid."

Update: Peter Swire who was one of the US expert negotiators when the Safe Harbour provisions were agreed, yesterday criticised CJEU AG's opinion in the case, as suffering from particular inaccuracies concerning the law and practice of U.S. foreign intelligence law, notably the PRISM program. He particularly emphasises changes to US law since the original Snowden revelations notes with approval the PRISM program is governed by Section 702 of the law enacted in 2008 to amend the Foreign Intelligence Surveillance Act. I suspect, given s702's 'guilty of being a foreigner' provisions Caspar Bowden would have had a few words to say on the subject.

The full court don't get into the intricacies of PRISM but it does hint strongly that Kafkaesque mass surveillance, without remedy available to those affected, undermines the rule of law.

Update 2: Daniel Solove does a really accessible analysis of the Court's decision and its possible implications. I suspect he over-estimates the likely impact of the coming revisions to EU data protection laws, given the giant privacy avoidance loopholes built into the draft general data protection regulations. But it is still essential reading.

Update 3: I also highly recommend Andres Guadamuz's analysis of the case.

Update 4: Some typos plus one error relating to FTC corrected. There follow links to EU Commission/Parliament reviews of Safe Harbour in 2002, 2004 and the post Snowden reviews of 2013 COM(2013) 846 final Rebuilding Trust in EU-US Data Flows and COM(2013) 847 final on the Functioning of the Safe Harbour from the Perspective of EU Citizens and Companies Established in the EU