objective is met, have chosen to confer a scope on the rights enshrined in those
provisions which would go beyond the territory of the Member States (para. 62).
From this it follows, according to the Court, that there is no obligation under EU
law, for a search engine operator who grants a request for de-referencing made by a
data subject to carry out such a de-referencing on all the versions of its search engine
(para. 64).
Nevertheless, the Court added, it is for the search engine operator to take, if
necessary, “sufficiently effective measures” to ensure the effective protection of the
data subject’s fundamental rights (para. 70). Such measures should have the effect of
“preventing or seriously discouraging” Internet users in the Member States from
accessing the links in question using a search based on that data subject’s name
(ibidem).
4.3 The Specific Conditions Applicable to the Transfer
of Personal Data to a Foreign Jurisdiction
Thirdly, one may ask whether the transfer of personal data to a foreign authority is
freely allowed or subject to specific conditions and, in the latter case, what they are.
The free flow of data across national borders is, of course, a major concern in a
global information society; but the different levels of protection of personal data that
still prevail in national legal systems inevitably entail restrictions to their transfer
abroad.
The GDPR addresses this issue in chapter V. According to article 45(1), transfer
of personal data to a third country or an international organization may, in principle,
only take place when the Commission has decided that:
the third country, a territory or one or more specified sectors within that third country, or the
international organization in question ensures an adequate level of protection.
When assessing the adequacy of the level of protection in the third country or
international organization, the Commission shall, pursuant to article 45(2) of the
GDPR, take account in particular of: (1) the rule of law and respect for human rights
and fundamental freedoms; (2) the existence and effective functioning of one or
more independent supervisory authorities; and (3) the international commitments
that the country or organization has entered into in relation to the protection of
personal data.
This rule reflects the CJEU’s 2015 judgment in the Schrems case,
161 in which it
held that the notion of an “adequate level of protection” cannot be understood as
requiring a level of protection identical to that guaranteed in EU law, but rather as
demanding the third country in fact to ensure, by reason of its domestic law or its
161 On which see CJEU of 6 October 2015, C-362/14, Schrems v. Data Protection Commissioner,
ECLI:EU:C:2015:650.
Data Protection in the Internet: General Report
35
provisions which would go beyond the territory of the Member States (para. 62).
From this it follows, according to the Court, that there is no obligation under EU
law, for a search engine operator who grants a request for de-referencing made by a
data subject to carry out such a de-referencing on all the versions of its search engine
(para. 64).
Nevertheless, the Court added, it is for the search engine operator to take, if
necessary, “sufficiently effective measures” to ensure the effective protection of the
data subject’s fundamental rights (para. 70). Such measures should have the effect of
“preventing or seriously discouraging” Internet users in the Member States from
accessing the links in question using a search based on that data subject’s name
(ibidem).
4.3 The Specific Conditions Applicable to the Transfer
of Personal Data to a Foreign Jurisdiction
Thirdly, one may ask whether the transfer of personal data to a foreign authority is
freely allowed or subject to specific conditions and, in the latter case, what they are.
The free flow of data across national borders is, of course, a major concern in a
global information society; but the different levels of protection of personal data that
still prevail in national legal systems inevitably entail restrictions to their transfer
abroad.
The GDPR addresses this issue in chapter V. According to article 45(1), transfer
of personal data to a third country or an international organization may, in principle,
only take place when the Commission has decided that:
the third country, a territory or one or more specified sectors within that third country, or the
international organization in question ensures an adequate level of protection.
When assessing the adequacy of the level of protection in the third country or
international organization, the Commission shall, pursuant to article 45(2) of the
GDPR, take account in particular of: (1) the rule of law and respect for human rights
and fundamental freedoms; (2) the existence and effective functioning of one or
more independent supervisory authorities; and (3) the international commitments
that the country or organization has entered into in relation to the protection of
personal data.
This rule reflects the CJEU’s 2015 judgment in the Schrems case,
161 in which it
held that the notion of an “adequate level of protection” cannot be understood as
requiring a level of protection identical to that guaranteed in EU law, but rather as
demanding the third country in fact to ensure, by reason of its domestic law or its
161 On which see CJEU of 6 October 2015, C-362/14, Schrems v. Data Protection Commissioner,
ECLI:EU:C:2015:650.
Data Protection in the Internet: General Report
35
