EU-US Data Privacy Framework (DPF) Declared Valid by General Court of European Union

The General Court of the European Union has upheld the validity of the EU-US Data Privacy Framework (DPF), a mechanism allowing for the transfer of personal data from the EU to the US, resolving a direct annulment action brought by French MP and CNIL Commissioner Philippe Latombe. The case centered on concerns over US surveillance practices, the independence of oversight bodies, and the applicability of Article 45 GDPR. In a comprehensive judgment, the Court rejected Latombe's pleas on several key issues, including the lack of independence of the Data Protection Review Court (DPRC), the illegality of bulk collection of personal data by US intelligence agencies, and the failure to include a provision establishing rights against automated decision-making under Article 22 GDPR.

Key Takeaways:

  • The General Court has upheld the validity of the EU-US Data Privacy Framework (DPF) as a lawful transfer mechanism under Article 45 GDPR.
  • The DPF was challenged by French MP and CNIL Commissioner Philippe Latombe, who argued that it violated both the EU Charter of Fundamental Rights and the GDPR.
  • The Court rejected Latombe's pleas on several key issues, including:

* The lack of independence of the Data Protection Review Court (DPRC): The Court held that Executive Order 14086 and the Attorney General Regulation provide sufficient guarantees to ensure the independence and impartiality of the DPRC.

* The illegality of bulk collection of personal data by US intelligence agencies: The Court stated that while targeted collection is not defined in US law, it is generally used to describe the collection of intelligence directed at a specific individual, communications account, or other identified target by intelligence agencies under the Foreign Intelligence Surveillance Act ("FISA") and E.O. 14086.

* The failure to include a provision establishing rights against automated decision-making under Article 22 GDPR: The sectoral protections provided by US laws, e.g. in the recruitment, employment, housing, insurance, home loans and credit sectors, were found to meet the test of an essentially equivalent level of protection to that guaranteed in the EU.

  • The decision underscores the continuing validity of the DPF as a lawful transfer mechanism, but many organizations have already provided an alternative "fallback" transfer mechanism, such as SCCs, in contracts to ensure compliance in case the DPF would be invalidated in the future.

Statistics:

  • 2 months + 10 days: The time frame for lodging an appeal in the General Court's judgment.
  • 54 days: The time frame for which the General Court reviewed the Data Privacy Framework's (DPF) validity.
  • 14086: The Executive Order that guarantees the independence and impartiality of the Data Protection Review Court (DPRC).

Sources:

  • European Union General Court
  • Latombe v Commission (T553/23)
  • Article 45 GDPR
  • Executive Order 14086
  • Attorney General Regulation
  • FISA (Foreign Intelligence Surveillance Act)
  • E.O. 14086 (Executive Order 14086)