In the Schrems case, Decision 2000/520, adopted by the Commission on the basis
of Article 25(6) of Directive 95/46/EC, whereby the “Safe Harbor Privacy Principles” issued by the U.S. Department of Commerce in 2000 were considered to
ensure an adequate level of protection for personal data transferred from the EU to
organizations established in the U.S., was held invalid by the CJUE.
Thereafter, a new “Privacy Shield Framework”,
164 which imposes stronger, selfcertified, obligations on American companies, was designed for the transfer of
personal data from the EU to the U.S. On July 12, 2016, the European Commission
considered that the Framework is adequate to enable such data transfers under EU
law, which allowed it to enter into force as of 1 August 2016.
165
Rules similar to those adopted in the EU in respect of the transfer of personal data
to third countries have been enacted in Cape-Verde,
166 Japan,
167 Singapore,
168 and
South Africa.
169
4.4 The Law Applicable to Liability for Damages Caused by
the Unlawful Processing of Personal Data
Finally, the question should be addressed of what law applies to liability for damages
caused by the unlawful processing of personal data in the jurisdictions under analysis
in this report.
As the EU Special Report emphasizes, there are no common European conflict of
laws rules on this topic, since non-contractual obligations arising out of violations of
privacy and rights relating to personality, including defamation, are excluded from
the scope of application of Regulation (EC) No. 864/2007 of the European Parliament and of the Council of 11 July 2007 on the law applicable to non-contractual
obligations (the “Rome II Regulation”) by its article 1(2)(g).
170
Although the GDPR proclaims in article 82(1) that “[a]ny person who has
suffered material or non-material damage as a result of an infringement of this
Regulation shall have the right to receive compensation from the controller or
164 Available at https://www.privacyshield.gov.
165 However, on 3 October 2017 the High Court of Ireland has ruled, in The Data Protection
Commissioner v. Facebook Ireland Limited and Maximillian Schrems (available at https://www.
dataprotection.ie/docimages/documents/Judgement3Oct17.pdf), to make a reference for a preliminary ruling to the CJEU in order to determine, inter alia, whether certain features of the Privacy
Shield constitute an adequate remedy for the protection of the rights to privacy and personal data
enshrined in the EU Charter of Fundamental Rights.
166 See the Cape-Verdean National Report, Sect. 4.3.
167 See the Japanese National Report, Sect. 4.3.
168 See the Singaporean National Report, Sect. 4.2.
169 See the South-African National Report, Sect. 5.2.
170 See the European Union Special Report, Sect. 4.4.
Data Protection in the Internet: General Report
37
Précédent

- 46/540

Suivant