惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Forbes - Security
Forbes - Security
Cisco Talos Blog
Cisco Talos Blog
Latest news
Latest news
P
Proofpoint News Feed
T
The Exploit Database - CXSecurity.com
Know Your Adversary
Know Your Adversary
S
Securelist
T
Tor Project blog
P
Palo Alto Networks Blog
G
GRAHAM CLULEY
NISL@THU
NISL@THU
C
CERT Recently Published Vulnerability Notes
L
LINUX DO - 热门话题
V
Vulnerabilities – Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
AWS News Blog
AWS News Blog
T
The Blog of Author Tim Ferriss
Security Latest
Security Latest
P
Proofpoint News Feed
C
CXSECURITY Database RSS Feed - CXSecurity.com
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Tenable Blog
博客园_首页
TaoSecurity Blog
TaoSecurity Blog
Attack and Defense Labs
Attack and Defense Labs
Project Zero
Project Zero
The Hacker News
The Hacker News
M
MIT News - Artificial intelligence
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Application and Cybersecurity Blog
Application and Cybersecurity Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
K
Kaspersky official blog
F
Full Disclosure
WordPress大学
WordPress大学
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
N
Netflix TechBlog - Medium
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
MongoDB | Blog
MongoDB | Blog
宝玉的分享
宝玉的分享
GbyAI
GbyAI
J
Java Code Geeks
云风的 BLOG
云风的 BLOG
Recent Announcements
Recent Announcements
博客园 - 叶小钗
Webroot Blog
Webroot Blog
Hacker News: Ask HN
Hacker News: Ask HN

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess Privacy Monthly: August 2023 What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
First challenge to the EU-US data transfer framework
Iron Brands · 2023-09-26 · via Blog of Simple Analytics

On September 6 French MP and CNIL member Philippe Latombe lodged a request to suspend the EU-US Data Privacy Framework before the EU Court of Justice, as first reported by Politico.

Legal action against the Data Privacy Framework was largely expected. However, Mr. Latombe’s action might be short lived, as there are procedural hurdles to bringing the case to the Court.

This blog will explain what is going on with the Data Transfer Framework, and why procedural requirements may spell an early doom for Latombe’s legal battle.

Update: on October 12 the Court denied Mr. Latombe's request on prodedural grounds.

  1. What is the Data Privacy Framework?
  2. What is the story behind the Data Privacy Framework?
  3. Will Mr. Latombe succeed in suspending the framework?
  4. How will things play out in the long term?
  5. Conclusions

The UK Government chose Simple AnalyticsJoin them

What is the Data Privacy Framework?

The Trans-Atlantic Data Privacy Framework (DPF) is a data transfer framework between the EU and the US. The DPF has been in place since July and allows for simple, GDPR-compliant transfers of personal data between the EU and the US.

In other words, the GDPR provides specific rules and standards for transferring data outside the EU, and the DPF helps organizations meet them. Without the framework, some EU-US data transfers would be impossible or trickier.

The Framework is not an agreement under international law, but rather a combination of internal legal acts in the European and US law frameworks. Last year US President Joe Biden published an Executive Order (EO 14068) to limit the powers of surveillance agencies to spy on European data. And in July, the European Commission adopted an adequacy decision- an act that essentially “greenlights” a country as a safe destination for data transfers under the GPDR.

For more information about the DPF and data transfer mechanisms under the GDPR, feel free to visit our blog on the topic.

What is the story behind the Data Privacy Framework?

We already wrote about this topic extensively, so here is the short version.

The DPF is not the first framework of its kind between the EU and the US. Two other frameworks- the Safe Harbor agreement and the Privacy Shield- served the same function in the past. However, both frameworks were invalidated by the EU Court of Justice in the Schrems I and II decisions. The rulings revolved around US surveillance over foreign data and highlighted that the older frameworks were not sufficient to safeguard European data against intelligence agencies.

After Schrems II, privacy NGO noyb pushed for a stricter application of Schrems II through strategic litigation aimed at Google Analytics- a web analytics tool that processes visitor data in the US. Noyb’s litigation led to the de facto ban of Google Analytics from several Member States, and sparked a heated debate about the lawfulness of EU-US data transfers under the GDPR.

The DPF aims to end this situation of chronic uncertainty by striking a balance between individual privacy, and the need to conduct electronic surveillance for national defense.

The US government and the European Commission worked closely to ensure that the new framework would withstand the scrutiny of the EU Court of Justice (CJEU). The Executive Order published by US President somewhat limits surveillance agencies in how far they can snoop on European data, and introduces a new system for oversight and redress against abuses. The US and the European Commission are hoping that these new rules will allow the DPF to survive a “Schrems III” ruling.

Will Mr. Latombe succeed in suspending the framework?

We doubt it, because procedural hurdles might prevent merit from being discussed in the first place.

Most cases end up in the CJEU via a preliminary ruling. In other words, the case is first brought before the court of a Member State, and then referred to the CJEU by the competent judge in order to clarify the interpretation of European law. This is how the Schrems I and II cases made their way to the CJEU as well.

Mr. Latombe’s case is different because he lodged his request as a direct action: he went straight to the Court and asked for the DPF to be annulled.

This strategy has its pros and cons. On the one hand, direct action bypasses domestic courts entirely, drastically shortening the time required to get a decision from the CJEU. On the other hand, EU law prescribes fairly strict requirements for direct actions: the applicant must successfully argue that the DPF concerns them directly and individually. This could be a problem for Mr. Latombe because he is no more concerned by the DPF than any other EU citizen.

Traditionally, the requirement for direct and individual concern has been taken very seriously by the CJEU. This is why the Court will likely dismiss the action without discussing its merit.

We hope to be proven wrong because the fate of the DPF is the source of much legal uncertainty, and many organizations would greatly benefit from the clarity that a CJEU decision would bring.

How will things play out in the long term?

Even if Latombe’s action is declared inadmissible, someone else will step up. Noyb already announced its intention to challenge the framework, and other advocacy organizations may also take action.

So, sooner or later the CJEU will decide the fate of the DPF. And probably shoot it down

Opinions on the new framework are quite polarized in the privacy community. Some believe the DPF to be the solution everyone has been longing for. Others- including noyb- consider it a Privacy Shield paint job and expect the CJEU to invalidate it as soon as the ball lands in its court (pun not intended).

European institutions themselves are divided on the merits of the framework. The Commission is, of course, an enthusiastic proponent of the DPF. On the other hand, the EU Parliament rejected the DPF by a large majority. The vote of the Parliament is not binding but might influence the tone of the debate and put some pressure on the CJEU.

We don't think the new framework stands too many chances. In some ways it is a better framework than the Privacy Shield, but that is not saying much. There are yet too many problematics aspects in the DPF for the CJEU to overlook, and the overwhelmingly negative response of the Parliament will likely pressure the Court to put the framework under very close scrutiny.

Conclusions

We believe that privacy concerns everyone and that companies should be responsible in how they collect data. This is why we created Simple Analytics: the web analytics tool that provides businesses with all the insights they need- without touching personal data. If this sounds good to you, feel free to give us a try!