Skip to main content

Cross-border data exchange

Page 1

POSITION I EXTERNAL ECONOMIC POLICY | DATA EXCHANGE

Cross-border data exchange Regulatory options in international collaboration

November 2020 BDI’s core demands: 1.

Oktober 2017 Cross-border data exchange is often hampered by protectionist laws. As a23. result, in important third markets European companies are discriminated against in an unjustified way in relation to their competitors. It is therefore important to counter these protectionist tendencies comprehensively through trade agreements and other international arrangements and to strengthen free trade.

2.

Global solutions must be found for the regulation of cross-border flow of goods. National unilateral efforts must be avoided. The World Trade Organisation WTO must, by the latest at its 12th Ministerial Conference, extend the decision to not require customs clearance of electronic transmissions, if possible, without a time limit.

3.

The EU's proposed arrangements in FTAs for cross-border data exchange and against localisation constraints are too inflexible compared to those in existing North American and AsiaPacific Free Trade Agreements (USMCA, CPTPP) and allow for disproportionate state intervention. The EU needs to strengthen safeguards against digital protectionism in trade agreements.

4.

The mechanisms under the EU, North America and Asia-Pacific Free Trade Agreements (CPTPP) should be made interoperable to promote data exchange. The G20 representatives identified this issue in the Osaka Declaration of June 2019. The agreements reached there must now be implemented quickly. It is important to set strong global standards for international data exchange.

5.

Before revoking an adequacy decision, EU institutions need to check thoroughly that the conditions for revocation are met. If revocation is required, the companies involved must be informed of the case at an early stage, in order to be able to adapt to the changes that the revocation will bring.

6.

The BDI prefers legislation in the area of data exchange through binding, practicable rules compared to soft law, as these create legal certainty. However, soft law is still important. It can be helpful, for example, in cooperation in global forums with important partners. Moreover, soft law often results in binding law. In this respect, it also has the function to inspire.


Cross-border data exchange

Table of Contents Cross-border data exchange.............................................................................................................. 3 International regulatory frameworks ................................................................................................. 3 Trade policy ......................................................................................................................................... 3 Free Trade Agreements ...................................................................................................................... 4 EU-MERCOSUR-FTA ........................................................................................................................... 4 Horizontal chapter on data exchange of the European Commission .................................................... 4 Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) ......................... 5 USMCA – The FTA in North America between the U.S., Mexico and Canada (NAFTA 2.0) ............... 5 The multilateral level of trade policy – the WTO ................................................................................... 7 Regulations on cross-border data exchange outside of trade policy ........................................... 8 EU-Japan-Adequacy Decision ........................................................................................................... 8 EU-US Privacy Shield .......................................................................................................................... 9 Council of Europe ............................................................................ Fehler! Textmarke nicht definiert. OECD – The Organisation for Economic Cooperation and Development ................................... 11 BDI’s recommendations ................................................................................................................... 12 Imprint ............................................................................................... Fehler! Textmarke nicht definiert.

2


Cross-border data exchange

Cross-border data exchange The digital transformation has led to an increase in global data flow. The global data sphere will grow from 33 zettabytes in 2018 to 175 zettabytes (the number 175 with 21 zeros) in 2025. 1 Not only consumers, but also companies are producing data ("Internet of Things"). Data is increasingly becoming the raw material for new services and business models. The size of the Internet economy is expected to more than double for the G20 economies, with an even higher growth rate for developing countries. This data production has a significant impact on companies and their production processes. In the age of digitalisation, production and trade are highly dependent on the increasing ability to transport, store and use digital information (data) across borders. The use of data facilitates, for example, the coordination of international production processes along global value chains. Small and medium-sized enterprises (SMEs) will have easier access to global markets, and larger firms will also benefit from increasingly digitalised operations. The transfer of personnel data to and from headquarters, for example, the sending of data to research and development (R&D) institutions abroad and after-sales services will be simplified. In view of the growth in data, questions arise about the legal framework. In the following, some of the already common international cooperation models regarding cross-border data transfer or data exchange are presented and critically explained, and the German industry's demands on policies are derived from them. It is not the aim of the paper to deal with the individual unilateral measures and laws of a single state. The following presentation makes no claim to be complete.

International regulatory frameworks German industrial companies are at home in markets around the world. They produce along global supply chains and sell their products and services through global distribution networks. For reasons of legal and operational efficiency, the BDI advocates globally uniform regulatory approaches ("one set of rules") and opposes acting unilaterally on a national scope. It is important to avoid an unnecessary patchwork of regulations, to which export-oriented SMEs find it difficult to adapt. This is important in order to benefit from the necessary economies of scale in the field of digital technology and to promote innovation. Where global solutions are difficult to find, well-designed bilateral, regional or plurilateral regulatory approaches should help to support companies in their operational business. Finally, protectionism must also be avoided. International regulation should create political and legal levers to counteract unjustified or disproportionate discrimination against European companies in world markets.

Trade policy Cross-border data exchange is increasingly regulated in trade agreements. This applies to bilateral and plurilateral initiatives and to the multilateral level of the World Trade Organisation (WTO). One reason for this is the direct or indirect connection between data flow and cross-border business processes and trade and investment decisions. On the other hand, data transfers are closely related to central political considerations such as the protection of personal rights and security (e.g. cyber-security). Regulations on data transfers are thus always a balancing act between partly competing political objectives. In terms of trade policy, they are linked to questions of market access and possible digital protectionism.

1

Seagate, Data Age 2025, The Digitization of the World From Edge to Core, Page 3, URL: https://www.seagate.com/files/www-content/our-story/trends/files/idc-seagate-dataage-whitepaper.pdf.

3


Cross-border data exchange

For example, state restrictions, such as mandatory data localisation, can be considered a non-tariff barrier to trade (NTB) in the digital economy. Regulations on cross-border data exchange in trade agreements can reduce such barriers to a necessary minimum. Similarly, international rules on data protection can help to create a reliable, open and trustworthy environment for cross-border economic exchange. In its Communication 374 (2019), the European Commission correctly stated that negotiations on data protection and trade are separate, but can be complementary.2

Free trade agreements EU-MERCOSUR-FTA After long negotiations (the negotiating mandate dates back to 1999), the parties agreed in principle on the text of a trade agreement between the EU and the MERCOSUR in July 2019. However, it is not yet clear when the agreement can be signed by the negotiating parties, given the current resistance in some EU Member States. It will regulate market access for certain services sectors. The rules on electronic commerce and telecommunications services can be found in the services chapter of the agreement. They aim to remove unjustified barriers to e-commerce, provide legal certainty for businesses, and ensure a safer online environment for consumers. The chapter contains binding rules prohibiting customs duties on electronic transmissions. The Parties agreed on provisions aimed at preventing excessive authorisation procedures, ensuring the legal validity and effectiveness of electronic contracts, and preventing the spread of data waste ("spam"). A separate chapter on cross-border data transfer, processing and localisation is not included. The article on general exceptions allows all parties to introduce and enforce measures to protect private data, provided that such measures do not result in arbitrary and unjustified discrimination. Horizontal chapter on data exchange for the European Commission Since summer 2018, the EU Commission has been negotiating chapters on digital trade in free trade agreements with third countries such as Australia, New Zealand, Chile and Indonesia. Part of such a chapter are provisions on data exchange.3 This represents an important development in terms of trade law. With regard to a definition of the term "personal data", the EU Commission is guided in this context by the existing definitions of the OECD and the Council of Europe (see below). This can be seen by looking at Article 6 IV of the EU negotiating text on a free trade agreement with Australia within the digital chapter. Content of the chapter: 4 The principle of the EU's approach is that data should circulate freely between the partners in the EU trade agreement. The circulation of data must not be restricted by four listed groups of cases (see also Article 5(1)). These are:

COM (2019) 374: “Whereas dialogues on data protection and trade negotiations must follow different tracks, they can complement each other. “ 3 http://trade.ec.europa.eu/doclib/docs/2018/july/tradoc_157130.pdf 4 https://trade.ec.europa.eu/doclib/docs/2018/december/tradoc_157570.pdf; Text of the EU Commission's proposal for a free trade agreement with Australia. The texts proposed for the negotiations with New Zealand, Indonesia and Chile are similar. 2

4


Cross-border data exchange

- The obligation to use computer equipment or network elements within the territory of the trading partner; - provisions that would require the localisation of data in the other party's territory for storage or processing; - prohibition of the storage or processing of data in the territory of the other party; - prohibition from making the cross-border transfer of data dependent on the use of data processing facilities or network elements located in the territory of the party, or on the localisation requirements in the territory of the party. Should similar trade-restrictive measures be added at a later stage, for example because they were developed or introduced at a later stage, they would not be covered by the ban, as they are not included in the exhaustive list. The EU and its trading partners would then have to meet again and agree accordingly on the inclusion of the trade defence measure (Article 5(2)). In addition, the EU's model chapter contains an exception for the protection of personal data and privacy. Each Party may therefore adopt "safe harbours" to protect personal data and privacy, even if these may be contrary to the above categories of cases. Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP) This agreement5 was signed by Canada, Australia, Brunei, Chile, Japan, Malaysia, Mexico, New Zealand, Peru, Singapore and Vietnam. The agreement between Canada, Australia, Japan, Japan, Mexico, New Zealand and Singapore entered into force on 30 December 2018. On 14 January 2019, Vietnam joined. The United States also initially joined the negotiating parties, but withdrew from the negotiations after Donald Trump's presidential election. The United States is therefore not part of this agreement. In its chapter on electronic commerce, the agreement protects the cross-border flow of personal data and prohibits, in principle, government coercion to locate data (Article 14.13). With regard to the prohibition of data localisation and the freedom of data circulation, exceptions remain possible, in particular if the measure is necessary to achieve a legitimate public interest. In this context, a prohibition of discrimination and the principle of proportionality of the state measure apply. USMCA – The FTA in North America between the U.S., Mexico and Canada (NAFTA 2.0) The USMCA trade agreement6 between the US, Canada and Mexico, which entered into force on 1 July 2020, replaces NAFTA ("North American Free Trade Area"). The chapter on "digital trade" prevents restrictions on cross-border information transfer - with exceptions that are necessary for legitimate policy objectives (Article 19.11). As in the CPTPP area, the principle of non-discrimination and the principle of proportionality of the state measure apply. The data localisation rules prohibit making the use of local computer facilities, or the establishment of such facilities, a condition of doing business in the country (Article 19.12). The Agreement does not provide for an exception to this rule. Therefore, the USMCA restricts national measures and laws more than the CPTPP.

5

https://www.mfat.govt.nz/assets/CPTPP/Comprehensive-and-Progressive-Agreement-for-Trans-Pacific-Partnership-CPTPPEnglish.pdf 6 https://ustr.gov/trade-agreements/free-trade-agreements/united-states-mexico-canada-agreement/agreement-between

5


Cross-border data exchange

BDI’s position on the approach of the EU, CPTPP und USMCA EU FTAs must include comprehensive and ambitious chapters on digital commerce, including rules on data flows. The BDI therefore welcomes in principle the fact that such chapters are being negotiated. It is important that the EU maintains this course and that the rules are developed in a modern way. The EU must create a regulatory framework that enables cross-border data flow and, at the same time, ensures that cross-border data flow is subject to the highest security standards. The EU should advocate strong standards for digital commerce worldwide, which go hand in hand with trade liberalisation. These chapters should remove the barriers to digital commerce, ensure cross-border data flow and minimise government-imposed data localisation. In principle, the approach proposed by the EU seems somewhat rigid and inflexible. The list approach drawn up by the EU Commission does create a certain degree of legal certainty for the four groups of cases mentioned. However, technology is evolving rapidly, and the regulatory framework should be able to follow these rapid developments. The EU’s proposal only partially succeeds in doing this, as the legal adaptation provided for in Article 5 II may be slow, or even impossible. The review and renegotiation of the groups of cases provided for in Article 5 II depends on the goodwill and willingness to compromise of the contracting parties and may take a long time. It would make more sense if the EU's list of banned measures were not exhaustive (marked in the text, i.a., with "in particular") in order to cover similar trade disruptive measures which are comparable in their effect to the four groups of cases already mentioned. In order to provide the necessary legal certainty, it is important that the conditions for comparability are high, to avoid an unnecessary extension of the scope. There is also a risk that the full regulatory freedom to protect personal data and privacy will mean that the agreements cannot be used effectively to prevent restrictions on cross-border data traffic and localisation constraints in the partner countries. Practically any restrictions could be justified on the pretext of these protective interests. Against this background, the BDI proposes this alternative wording for the exception for the protection of personal data and privacy in the EU model chapter: - "State measures restricting the cross-border transfer of personal data, - must not be arbitrary, - must be proportionate - and may not be used for purposes other than data protection". Moreover, the texts from the USMCA and the CPTPP are older than the EU proposal. It would have been perfectly possible for the EU to use the Pacific texts as a basis for setting strong common standards in global fora. The BDI regrets that this did not happen. If the regulations of these important economic areas cannot be clearly harmonised, the mechanisms underlying the texts should be interoperable, at least regarding minimum standards. In this respect, the BDI welcomes the fact that the G20 representatives have recognised this problem and in their "Osaka Declaration" of June 2019, expressly declare themselves in favour of these interoperable mechanisms in order to make cross-border data exchange as fluid as possible worldwide. The G20 countries should draw up a concrete work plan for this purpose and work hard to reach agreements to this effect. However, the fact that the EU uses existing OECD and Council of Europe definitions for the definition of personal data is to be welcomed. Such an approach provides important clarity and avoids unnecessary complexity.

6


Cross-border data exchange

The data exchange rules in the USMCA and CPTPP are more flexible than the EU proposal. General principles of law (including the principles of arbitrariness and proportionality) are largely respected, which is positive. The two agreements are very similar, and in some cases identical, in terms of cross-border data transfer and data localisation issues. The agreements are finely balanced and clearly set out the principle and exception. Since German industrial companies are based in both North America and the Asia-Pacific Economic Area, and conduct business in the region, this is very important, particularly for reasons of legal certainty. The multilateral level of trade policy – the WTO At WTO level, there are numerous legal instruments dealing with trade policy issues related to the data economy. These include in particular the WTO Agreement on Trade Facilitation (WTO TFA), the WTO Agreement on Trade in Services (GATS), the customs moratorium on electronic transmissions and the WTO Agreement on Information Technology (ITA). Apart from the WTO TFA, which was agreed by WTO members in 2013, all WTO agreements falling into the category described above were negotiated in the early 1990s. Given the mass of data that circulates worldwide today, and its economic importance , the question therefore arises whether these WTO agreements are sufficient. WTO members have recognised the problem and launched a working programme on e-commerce in 1998.7 Even though the WTO puts e-commerce on the agenda of every ministerial conference, unfortunately little progress has been made so far. Consequently, many WTO members have focused on the bilateral and plurilateral or regional initiatives described above in order to develop, in a small circle, trade policy instruments which can provide viable solutions for the data economy, particularly in the field of e-commerce. In addition, since the second WTO Ministerial Conference in 1998, there has been a WTO moratorium on the non-customs clearance of data transfers (electronic transmissions) across national borders. This moratorium has so far been extended in good time every two years and will now apply until the next (twelfth) Ministerial Conference.8 The conference was supposed to have taken place in June 2020, but has now been postponed for an indefinite period (probably until summer 2021) due to the COVID-19 pandemic. If the agreement is not renewed by the WTO General Council, new burdens and conflicts in world trade could arise. Customs clearance would be complex, costly for business and consumers and politically controversial. In addition, the European Centre for International Political Economy (ECIPE) concludes in a study 9 from 2019 that the benefits of a state through customs revenues on data flow would be turned into a financial disadvantage through a decline in economic performance. For these reasons, the BDI and international business associations such as the International Chamber of Commerce (ICC) are in favour of agreeing a permanent exemption from customs duties on electronic data transfers. This would create confidence and planning security for business and consumers and put a stop to protectionism. After a ban on customs clearance of data transfers was already included in 59 bilateral and regional free trade agreements according to an ICC investigation, plurilateral progress on e-commerce was made at WTO level in January 2019. The EU and 48 other members, including China and the United States, have set themselves the objective of deepening cooperation on e-commerce and achieving

7 8 9

https://www.wto.org/english/tratop_e/ecom_e/ecom_e.htm https://www.wto.org/english/news_e/news19_e/gc_10dec19_e.htm https://ecipe.org/publications/moratorium/

7


Cross-border data exchange

regulatory progress at plurilateral level. 10 Other WTO members that are not yet part of the initiative may join at any time. The EU has already been actively involved in this process and in April 2019, presented a proposal11 on cross-border e-commerce data exchange. This proposal establishes the principle of the freedom of movement of data and prohibits inter alia data localisation requirements (Article 2.7). Furthermore, cross-border data exchange may not be made dependent on a company using, for example, computer networks within the jurisdiction of a WTO member. In addition, the plurilateral e-commerce initiative can be used to permanently exclude customs duties on data transfers. BDI’s position The BDI views the work in the WTO area on e-commerce and the open character of the corresponding plurilateral initiative as positive. The wording of the EU proposal for the plurilateral initiative is similar to the wording of the USMCA and CPTPP agreements in the field of e-commerce. The BDI expressly welcomes this, as it increases the overview and congruence regarding the regulatory framework in important target markets. It is important that the WTO initiative provides binding rules for free, secure and reliable cross-border data transmission. Legal rights of intervention for localisation should be minimised. The freedom of companies to decide whether, and which data should be transferred, should not be restricted. Transfer or access to source codes and algorithms should not be a market access requirement for software. It would be desirable to have a comprehensive progress report and agreement on a concrete work plan, substantive issues and priorities at the next WTO Ministerial Conference (probably in Kazakhstan in summer 2021). Customs duties on electronic transmissions should be permanently banned.

Regulations on cross-border data exchange outside of trade policy EU-Japan-Adequacy Decision The transfer of personal data between the EU and Japan is not covered by the Free Trade Agreement between the two countries, but a renegotiation clause is included. The transfer of data is based on the EU adequacy decision, which complements the EU-Japan trade agreement accordingly. The Adequacy Decision is based on the EU's Basic Data Protection Regulation (DSGVO) and applies to data transferred from the EU to Japan. As the level of data protection in the EU and Japan is considered to be similar, a free exchange of data between the EU and Japan is allowed. The adequacy of the level of data protection will be established by the EU Commission in an implementing act. The implementing act provides for a regular review mechanism at least every four years, taking into account all relevant developments in Japan (Article 45(3) of the DPA). Article 45(5) of the DSGVO provides that the Commission may revoke its decision if the conditions for adequacy are no longer met. Also, in this case, personal data may be transferred further to the third country, in this case Japan. Such a transfer can then only take place subject to

10 11

http://trade.ec.europa.eu/doclib/docs/2019/january/tradoc_157643.pdf http://trade.ec.europa.eu/doclib/docs/2019/may/tradoc_157880.pdf

8


Cross-border data exchange

certain conditions (Articles 44 to 50 DSGVO). In particular, appropriate guarantees under Article 46 DSGVO, such as EU standard contractual clauses, the consent of the data subject (Article 49(1) a DSGVO), Binding Corporate Rules (Article 46(2) b, Article 47 DSGVO), Code of Conducts (Article 40 DSGVO), recognised certification mechanisms (Article 42 DSGVO) or the existence of a public interest (Article 49 DSGVO) should be mentioned. As Japan is now not subject to additional restrictions on data flow, other third countries have an incentive to improve their data protection standards in order to benefit from the advantages of an EU adequacy decision in the future. Canada, Israel, Japan, New Zealand, Switzerland and Uruguay are some of the twelve countries that have been certified by the European Commission to have a comparable level of data protection. The EU's basic data protection regulation has already inspired some countries in key third markets to adopt comparable laws. Argentina already has a similar approach to international data transfers, and the new Data Protection Act that the government presented to Congress in October 2018 would bring the country even closer to the EU's basic data protection regulation in Europe. 12 This is also the case in Brazil, where the new General Data Protection Law was adopted in August 2018 and came into force in February 2020. International data transfers are only allowed in certain situations, such as when an adequate level of data protection is ensured in the recipient countries, when approved legal mechanisms (e.g. model contract clauses) are used, or when the data subjects have given their consent. BDI’s position

BDI expressly welcomes the EU adequacy decision on Japan. The EU data protection basic regulation thus sets international standards. In dialogue with other key markets, the EU should also work towards harmonising data protection standards there. Ideally, this could lead to an extension of the EU's Adequacy Decisions. This could de facto transfer the high EU standards to key markets ("protection travels with the data").

EU-US Privacy Shield The EU-US Privacy Shield Agreement had been in force since 2016 and was overturned by the European Court of Justice (ECJ) in its judgment of 16 July 2020 (C-3111/18 - "Schrems II"). The ruling was triggered by a complaint lodged by a citizen with the Irish data protection authority, in which he repeatedly objected to the transfer of his data by Facebook to the US. This is the second time that the ECJ has overturned the essential legal basis for the transfer of personal data of European citizens to the US after the decision on the Safe Harbour Agreement in 2015 (C 362/14 - "Schrems I"). Until the ruling, the Privacy Shield Agreement negotiated on 12 July 2016 was, in addition to the standard data protection clauses, the essential basis for the transfer of personal data from the EU to the USA on the possibilities of transfer to third countries under Art. 44 et seq. DSGVO. The agreement facilitated the EU-US data flow for companies. At the same time, the Privacy Shield required stricter obligations on US companies to protect personal data when they receive data from the EU, compared to US data protection. In order to fall within the scope of the agreement and the facilitated data flow, US companies had to self-certify against certain data protection standards. By means of annual

12

https://iapp.org/news/a/argentinas-new-bill-on-personal-data-protection/

9


Cross-border data exchange

registration, they were then included by the US authorities in the Privacy Shield List of the US Department of Commerce. When personal data was transferred to a certified US company on the basis of the Privacy Shield, the EU citizens concerned had the right to be informed by the US company, to object to data processing, to obtain information and to determine the purpose of data storage. An annual review mechanism was also agreed between the US administration, the EU Commission and representatives of the European Data Protection Authorities. The ECJ ruling deprived European companies of the possibility of legally secure data transfers without a transitional period. Following the ECJ ruling, the transatlantic data flow can no longer be based on the so-called standard data protection clauses. In principle, these are still applicable to data transfers to third countries. However, it must be examined on a case-by-case basis whether the contractual agreements from the standard data protection clauses can also be complied within the third country in order to safeguard the level of protection required under Union law. If necessary, further data protection measures would also have to be taken by those responsible. If an adequate level of data protection could not be ensured, even by additional measures, the transfer of data to the country concerned would have to be suspended. If the transfer had already begun, it would have to be stopped immediately. Data already transferred must be returned, the ECJ said. However, since the ECJ negates the adequacy of the level of data protection in the U.S., due to the extensive powers of intervention of the intelligence services there and the lack of legal remedies, and since it requires an extensive case-bycase assessment from the data exporter based in the EU, the transfer of data to the US, even on the basis of the EU standard data protection clauses, is made considerably more difficult in practice, leading to great legal uncertainty overall. In this respect, it should be noted in particular that the standard data protection clauses are - as the Court of Justice states - only applicable between the contracting parties and are not binding on third country authorities. BDI’s position Transatlantic data traffic is of enormous importance to German industry. Especially against the background of the importance of the USA as an investment location and export market, and as a provider of innovative and efficient global IT services, simple and secure transatlantic data transfer is essential. What form and content additional agreements or measures would have to take, in order to overcome the deficits in the level of data protection in the USA, as pointed out by the ECJ, remains unclear. In view of these risks, it is now the urgent task of the EU Commission to negotiate with the US authorities as quickly as possible, an effective and sustainable successor regulation and to improve the EU standard data protection clauses. At the same time, the European Data Protection Board is invited to publish practical, uniform and binding guidelines for complementary safeguards to the standard privacy clauses throughout Europe. European companies need legal certainty in the global data and business environment. The confidence of EU citizens, and not least businesses, in transatlantic data traffic must be restored. This is a task for politicians on both sides of the Atlantic. In the meantime, the supervisory authorities in the EU and Germany should grant an appropriate moratorium to companies that have organised their data processes in confidence that the Privacy Shield and the standard data protection clauses are valid.

10


Cross-border data exchange

Council of Europe The Council of Europe has launched Convention 108 for the protection of individuals with regard to the automatic processing of personal data. This Convention dates from 1981 and protects the right to privacy with respect to the automatic processing of personal data. So far, 53 States have undertaken to impose sanctions and remedies under their own domestic law, for violations of the provisions of the Convention. Some basic principles of the Convention are 1. the prohibition of unlawful processing of data (Art. 5 lit. a); 2. the processing of data must be purpose-related and proportionate (Art. 5 lit. b and c); 3. personal data must be made anonymous as soon as possible (Art. 5 lit. e); 4. Article 10 provides for sanction mechanisms in the event of violation of the provisions of the Convention. Accordingly, the ratifying state regulates corresponding sanction mechanisms itself. One of the interesting features of the Convention is Article 23, which allows countries which are not members of the Council of Europe to accede to the Convention. BDI’s position This set of rules was originally the first binding intergovernmental agreement to deal with data protection. It was reformed in 2018. The Protocol of Amendment is fully consistent with EU data protection law. This is an important development, as it represents another example of the successful export of binding EU data protection legislation. This is positive for business, as it also creates legal certainty.

OECD - The organisation for economic cooperation and development The OECD data protection guidelines date from 1980 and are non-binding and technologically neutral. They were drafted by a commission of experts and are intended to inspire government representatives to ensure comprehensive data protection in their respective jurisdictions. The guidelines also aim to encourage states to cooperate on data protection issues and to support the development of international agreements. This should also promote interoperability between data protection frameworks. The OECD Privacy Guidelines are particularly interesting because they provide a definition of personal data. They define personal data as "information relating to an identified or identifiable individual". In addition, the Guidelines contain provisions on the purposes for which data may be used (Part 2, point 9) and the corresponding safeguards (Part 2, point 11).

11


Cross-border data exchange

BDI’s position

Even though the OECD guidelines are not legally enforceable, due to their lack of legally binding character, the OECD initiative can be considered beneficial in principle. This is particularly true against the background of the fact that many relevant non-European core markets of German industry, such as the USA, South Korea, Japan and Australia, are members of the OECD and participate in these discussions. Against this background, work on cross-border data transfer should be continued in the relevant forums at OECD level. In doing so, the members of the OECD should be guided by the European level of data protection, as is to be found in particular in the DSGVO.

BDI’s recommendations Data flow is global, and global is also the business of German industry. The BDI advocates the creation of an international legal framework to regulate the cross-border exchange of data. National unilateral efforts should be avoided. Where global regulations are not set quickly and ambitiously enough, such as in the area of e-commerce at WTO level, regional and plurilateral initiatives must be taken. The results should be compatible with multilateral rules and gradually transferred to the global level. The same applies to bilateral initiatives with strategically important partners, such as the MERCO-SUR Association of States or Japan. The European Commission has embarked on a new path with the preparation of a horizontal chapter on data flow in the field of trade policy in summer 2018. The BDI welcomes this. However, the EU text appears too rigid, the comparable texts from the USMCA and CPTPP are more flexible and thus also facilitate law enforcement. Instead of working with an exhaustive list approach, it would be better if the EU's banned list were not exhaustive, in order to cover similar trade disruptive measures that are comparable in their effect to the four groups of cases already mentioned. The EU's full regulatory freedom to protect personal data prevents the agreements from being used effectively against restrictions on cross-border data traffic and localisation constraints in the partner countries. In practice, any restrictions could be justified on the pretext of these protective interests. It is important that the measures adopted to protect personal data are proportionate and not arbitrary. Moreover, the purpose of the state measure must be to pursue the protection of personal data. It is now important that the mechanisms underlying the texts are interoperable. The G20 countries recognised this in Osaka in June 2019 and called for interoperable systems to be created. The BDI welcomes this. The German industry needs legal certainty. This becomes clear again against the background of the EU adequacy decision. Should the EU Commission decide to revoke an Adequacy Decision, German industry calls on the decision-makers to thoroughly examine the conditions for revocation. Should the revocation actually be carried out, companies must be informed of the decision in a timely manner. In addition, the EU Commission must ensure that data continues to circulate across borders in a regulated manner and in accordance with the European DSGVO, for example through guarantees or general contractual clauses. In the area of data exchange legislation, binding law is more advantageous for companies because it creates legal certainty, which is important for electronic data exchange. However, soft law solutions are also important as they can be helpful for cooperation in global forums with key partners. In addition,

12


Cross-border data exchange

soft law often gives rise to binding law and can thus also serve as a stimulus and inspiration to the legislator for well-functioning mechanisms. Licensing requirements and restrictions on exports also apply to intangible goods and therefore concern technology and data processing programmes. Notwithstanding the demands set out in the position paper, restrictions on data relevant to export control should therefore be considered.

13


Cross-border data exchange

Imprint Bundesverband der Deutschen Industrie e.V. (BDI) Breite StraĂ&#x;e 29, 10178 Berlin www.bdi.eu T: +49 30 2028-0 Editors Dr. Stormy-Annika Mildner T: +493020281562 s.mildner@bdi.eu Eckart von Unger T: +3227921020 e.vonunger@bdi.eu Stefanie Ellen StĂźndel T: +327921015 s.stuendel@bdi.eu

BDI document number: D 1120

14


Turn static files into dynamic content formats.

Create a flipbook
Cross-border data exchange by Bundesverband der Deutschen Industrie e.V. - Issuu