34
Contract and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz Berkeley Law School Presentation: Annual BCLT Privacy Forum March 11, 2016 Twitter: @paulmschwartz

Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Embed Size (px)

Citation preview

Page 1: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Contract and Consent;General Data Protection Regulation

BCLT Privacy ForumPalo Alto, CA

March 11, 2016Moderated by:Paul M. SchwartzBerkeley Law SchoolPresentation: Annual BCLT Privacy ForumMarch 11, 2016Twitter: @paulmschwartz

Page 2: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Overview

• Comparative Approaches to Contract: US and EU

• Four Assessment Factors• US Approach to Contractual Privacy• EU Approach to Contractual Privacy• The Future

Page 3: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The Future

Page 4: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Two Working Theories

• EU: strenuous efforts to protect consumers

• US: a reign of boilerplate

Page 5: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Four Assessment Factors

• Relevant harms• Legal institutions for policing

contractual privacy• Kinds of enforcement

mechanisms in place• Impact of technology

Page 6: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

U.S. Approach to Contractual Privacy

• Binding statements of practice

•Privacy federalism• Enforcement of privacy

and security statements, development of substantive requirements

• Not equivalent to EU data protection

Page 7: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Assessing the U.S. Approach to Contractual Privacy

• Institutions: Congress, state legislatures, FTC and state AG’s. More limited role for judges developing contract law

• Harm: US law still in search of theory of privacy harms

• Enforcement: high FTC fines • Technology: embedded

“surveillance capitalism”

Page 8: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

EU Approach to Contractual Privacy

• Data Protection Directive (1995) and Draft General Data Protection Regulation (2012 to Present)

• Continuity: skepticism of consensual approaches• Consent carefully embedded in legal and social

structures and limited in reach • Unwaivable data privacy interests: not alienable

through contracts

Page 9: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

GDPR on Consent, Article 7

• If consent is presented as part of written declaration that concerns other matters, “the request for consent must be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language”

• Right to withdraw consent at any time. “It shall be as easy to withdraw consent as to give it”

• “When assessing whether consent is freely given, utmost account shall be taken of the fact whether, among others, the performance of a contract, including the provision of a service, is made conditional on the consent to the processing of data that is not necessary for the performance of this contract.”

Page 10: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Assessing the EU Approach to Contractual Privacy

• Institutions: wide range of institutions involved– from Brussels to Member States

• Harm: well-developed law of privacy harms

• Enforcement: low fines, weak enforcement but changes under GDPR

• Technology: same “surveillance capitalism” as in US

Page 11: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The Future

Page 12: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Contracting and Privacy: Today and Tomorrow

• EU and U.S.: Future of convergence or divergence for contractual privacy?

Page 13: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Assessing the Future for EU and US Approaches to Contractual Privacy

• Institutions: US- greater role for state AG’s? EU- shift to Brussels? Privacy federalism?

• Harm: future divergence likely. Testing FTC enforcement of contract-lite?

• Enforcement: coming will be tough EU enforcement based on antitrust model

• Technology: Snowden marking a turning point? Technological momentum?

Page 14: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley
Page 15: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The General Data Protection Regulation

Page 16: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Dr. Anna Zeiter, L.L.MHead of Data ProtectionEMEA RegioneBay, Inc.

Page 17: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The “One-stop-shop” Rule: Article 51

Page 18: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

And the award for Most Misleading Title goes to…

One-stop-shop!

Page 19: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The “One-stop-shop” Rule

Page 20: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The “One-stop-shop” Rule: Article 51

Page 21: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

James Koenig, Paul HastingsOf Counsel, LitigationPrivacy and CybersecurityPractice Group

Page 22: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Article 17 of the GDPR: The RTBF

Page 23: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The Company That Knew Too Much

Page 24: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The RTBF: Article 17 of the GDPR

Page 25: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Prof. Dr. Karl-Nikolaus PeiferDirector,Institute for Media LawAnd Communications LawAnd Director,Institute for Broadcasting LawUniversity of Cologne

Page 26: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Jurisdiction under the GDPR: Article 3

Page 27: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Article III of the GDPR: Forbidden Planet

Page 28: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The “data processor”: GDPR, Article 5, defined in Article 4(6)

Page 29: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Jurisdiction under the GDPR: Article III

Page 30: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Kurt Wimmer, CovingtonPartner, Chair of theData Privacy and Cybersecurity Practice Group

Page 31: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The GDPR Provides for Fines of Up to 4% of Annual Worldwide Turnover

Page 32: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The Terminator

Page 33: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

The GDPR Provides for Fines of Up to 4% of Annual Worldwide Turnover

Page 34: Contract and Consent; General Data Protection … and Consent; General Data Protection Regulation BCLT Privacy Forum Palo Alto, CA March 11, 2016 Moderated by: Paul M. Schwartz. Berkeley

Question and Answer Period