Regulation—it would be difficult in many cases to establish the quality of a rule
being crucial to safeguard the public interest of the forum.
The scope of application of the particular regime established by Art. 3 GDPR in
private law cases, i.e. with a private person as controller, is determined by the
Regulation, which determines the content of the lex protectionis datorum. In particular, it covers the general ban on data processing and its exceptions, and the
particular subjective rights under the Regulation. In particular, Art. 3 GDPR determines the law applicable to the consent of the data subject. The parties may not
deviate from the lex protectionis datorum by a choice of law under article 3 Rome I
Regulation. On the other hand, the relationship to the contract in which such consent
is integrated is determined by the lex contractus. This includes the rules on unfair
contract terms. Therefore, consent of the data subject declared in standard terms
must comply with both sets of rules, the lex contractus (and Art. 6 Rome I
Regulation in particular) and the lex protectionis datorum under Art. 3 GDPR.
2.7.2 Application to Entities Seated Outside the European Union
The electronic data processing by entities seated outside the Union is comprised in
the scope of application of local rules. This exactly is the very purpose of Art. 3 para.
2 GDPR and Art. 3 para. 1 ePR.
91
2.7.3 Transfer of Personal Data to a Foreign Jurisdiction
The transfer of personal data to a foreign jurisdiction is subject to specific conditions.
Under the GDPR, any transfer to a third country or international organization may
only take place where the Commission has decided that the third country or the
organization in question ensures an adequate level of protection, Art. 44, 45 GDPR.
When assessing the adequacy of the level of protection, the Commission shall take
account of elements like the respect for human rights and fundamental freedoms,
data protection rules and security measures, effective and enforceable data subject
rights and effective administrative and judicial redress. The effective functioning of
independent supervisory authorities is also essential.
92
Formerly, the Safe Harbor Framework, negotiated in 2009, concerned data transfers from Europe to the United States and provided the basis for the aforementioned
decision by the European Commission under the Directive 95/46. However, the Safe
Harbor Framework has been declared invalid by the ECJ in 2015.
93 It has been
replaced by the EU-U.S. Privacy Shield, which will certainly be under review by the
ECJ sooner or later.
91 See Sect. 2.7.1.
92 See for a full listing of elements: Art. 45 para. 2 GDPR.
93 ECJ, judgment of 6 October 2015, C-362/14 ¼ ZD 2015, 549.
208
C. Breunig and M. Schmidt-Kessel
being crucial to safeguard the public interest of the forum.
The scope of application of the particular regime established by Art. 3 GDPR in
private law cases, i.e. with a private person as controller, is determined by the
Regulation, which determines the content of the lex protectionis datorum. In particular, it covers the general ban on data processing and its exceptions, and the
particular subjective rights under the Regulation. In particular, Art. 3 GDPR determines the law applicable to the consent of the data subject. The parties may not
deviate from the lex protectionis datorum by a choice of law under article 3 Rome I
Regulation. On the other hand, the relationship to the contract in which such consent
is integrated is determined by the lex contractus. This includes the rules on unfair
contract terms. Therefore, consent of the data subject declared in standard terms
must comply with both sets of rules, the lex contractus (and Art. 6 Rome I
Regulation in particular) and the lex protectionis datorum under Art. 3 GDPR.
2.7.2 Application to Entities Seated Outside the European Union
The electronic data processing by entities seated outside the Union is comprised in
the scope of application of local rules. This exactly is the very purpose of Art. 3 para.
2 GDPR and Art. 3 para. 1 ePR.
91
2.7.3 Transfer of Personal Data to a Foreign Jurisdiction
The transfer of personal data to a foreign jurisdiction is subject to specific conditions.
Under the GDPR, any transfer to a third country or international organization may
only take place where the Commission has decided that the third country or the
organization in question ensures an adequate level of protection, Art. 44, 45 GDPR.
When assessing the adequacy of the level of protection, the Commission shall take
account of elements like the respect for human rights and fundamental freedoms,
data protection rules and security measures, effective and enforceable data subject
rights and effective administrative and judicial redress. The effective functioning of
independent supervisory authorities is also essential.
92
Formerly, the Safe Harbor Framework, negotiated in 2009, concerned data transfers from Europe to the United States and provided the basis for the aforementioned
decision by the European Commission under the Directive 95/46. However, the Safe
Harbor Framework has been declared invalid by the ECJ in 2015.
93 It has been
replaced by the EU-U.S. Privacy Shield, which will certainly be under review by the
ECJ sooner or later.
91 See Sect. 2.7.1.
92 See for a full listing of elements: Art. 45 para. 2 GDPR.
93 ECJ, judgment of 6 October 2015, C-362/14 ¼ ZD 2015, 549.
208
C. Breunig and M. Schmidt-Kessel
