51
phenomenon, which has thrived after the Snowden revelations about the
US mass surveillance programmes, also suggests that data localisation is
emerging as a response to the risk of data access from foreign intelligence
agencies (Hon et al. 2016).
In Europe too, a series of data localisation initiatives has recently
emerged. Since 2011, ideas of a Europe-only cloud, if not even a “virtual
Schengen area”, have been circulating (Kuner et al. 2015; Hon et al.
2016). In 2013, the German telecommunications operator, Deutsche
Telekom announced a plan to create a German “Internetz”, by ensuring
that traffic data are only routed nationally (Hon et al. 2016). Similarly,
after Russia’s annexation of Crimea in 2014, Estonia explored the possibility of creating a “data embassy” via a combination of a physical diplomatic seat in a friend country to locate data centres, and a “virtual embassy”
in a private cloud to store critical data (Millard 2015).
More recently, the European Commission has launched a European
Cloud Initiative in the context of its Digital Single Market Strategy
(European Commission 2016). This policy includes the creation of a
European Open Science Cloud, which aims to offer European researchers
a safe environment to store and share data, and a European Data
Infrastructure, which would provide the necessary super-computing solutions. Moreover, in 2019, the German Ministry for Economic Affairs and
Energy has officially presented ‘Gaia-X’, the project for a European federated cloud-based data infrastructure (Federal Ministry for Economic
Affairs and Energy (BMWi) 2019).
These initiatives show that the concept of “digital sovereignty” has
recently emerged as a common thread in the European debate on data
localisation. Originally, proposals such as the virtual Schengen area were
politically justified by the need to ensure a sufficient level of security in the
digital environment (Hon et al. 2016). The protection of human rights,
and in particular the rights to privacy and data protection, has been the
second main driver of discussions about data localisation in Europe. In the
Digital Rights Ireland case, for example, the ECJ invalidated Directive
2006/24/EC, compelling telecommunications operators to retain all
users’ metadata for a fixed period of time, on the basis, inter alia, that it
failed to require the storage of personal data in Europe (Digital Rights
Ireland 2014, para. 68; Celeste 2019). According to the ECJ, the Data
Retention Directive, by allowing telecommunications operators to store
retained meta-data outside Europe, undermined the power of member
states’ national data protection authorities to control data processing, as
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
phenomenon, which has thrived after the Snowden revelations about the
US mass surveillance programmes, also suggests that data localisation is
emerging as a response to the risk of data access from foreign intelligence
agencies (Hon et al. 2016).
In Europe too, a series of data localisation initiatives has recently
emerged. Since 2011, ideas of a Europe-only cloud, if not even a “virtual
Schengen area”, have been circulating (Kuner et al. 2015; Hon et al.
2016). In 2013, the German telecommunications operator, Deutsche
Telekom announced a plan to create a German “Internetz”, by ensuring
that traffic data are only routed nationally (Hon et al. 2016). Similarly,
after Russia’s annexation of Crimea in 2014, Estonia explored the possibility of creating a “data embassy” via a combination of a physical diplomatic seat in a friend country to locate data centres, and a “virtual embassy”
in a private cloud to store critical data (Millard 2015).
More recently, the European Commission has launched a European
Cloud Initiative in the context of its Digital Single Market Strategy
(European Commission 2016). This policy includes the creation of a
European Open Science Cloud, which aims to offer European researchers
a safe environment to store and share data, and a European Data
Infrastructure, which would provide the necessary super-computing solutions. Moreover, in 2019, the German Ministry for Economic Affairs and
Energy has officially presented ‘Gaia-X’, the project for a European federated cloud-based data infrastructure (Federal Ministry for Economic
Affairs and Energy (BMWi) 2019).
These initiatives show that the concept of “digital sovereignty” has
recently emerged as a common thread in the European debate on data
localisation. Originally, proposals such as the virtual Schengen area were
politically justified by the need to ensure a sufficient level of security in the
digital environment (Hon et al. 2016). The protection of human rights,
and in particular the rights to privacy and data protection, has been the
second main driver of discussions about data localisation in Europe. In the
Digital Rights Ireland case, for example, the ECJ invalidated Directive
2006/24/EC, compelling telecommunications operators to retain all
users’ metadata for a fixed period of time, on the basis, inter alia, that it
failed to require the storage of personal data in Europe (Digital Rights
Ireland 2014, para. 68; Celeste 2019). According to the ECJ, the Data
Retention Directive, by allowing telecommunications operators to store
retained meta-data outside Europe, undermined the power of member
states’ national data protection authorities to control data processing, as
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
