Tag: Swiss attorney

Covid-19

Covid-19 mini-series | Legal advice for Switzerland Privacy, Health & Technologies

With Covid-19, the world is facing a huge crisis and the economy will be massively impacted.

New coronavirus, known as “Covid-19“, spreads itself from China (Wuhan province) to Europe, and then to the world leading to unprecedented measures from authorities in various countries, including Switzerland. Public health issues combine health law, protection of personal data & Privacy and the use of new technologies to fight and help during this tough historical time. Remote work and the use of online conferencing tools has flourished and turned from B2B to B2C with down sides of using online tools in an urgency mode without proper diligence.

To support as much as we can on providing useful information, we have started a legal mini-series, including tips and downloadable documents for business and organizations. This series of guidance and materials aim at providing simple and practical information to better understand and tackle legal issues and economic repercussions due to the coronavirus.

Both public and private organisations are suffering. We intend to publish regular posts on our LinkedIn page and our dedicated Covid-19 website on datalex, our new digital legal platform for organizations seeking legal advice and services.

_______________________________

ABOUT OUR MINI LEGAL SERIES 

We are committed to providing legal advice and guidance to individuals and companies in connection with Covid-19.  As usual, this series is bilingual (FR/EN) with some episodes in Italian!  The first episode provides information on the application of the law on epidemics and its federal ordinance. For the other ones, here is the list of our episodes:

Episode 1Federal Act on Epidemics

Episode 2: Telemedicine & Law

Episode 3: Criminal sanctions: what are the risks?

Episode 4: Ethics guidelines: rules for triage of patients in intensive care units

_______________________________

DATA PRIVACY PERSPECTIVE FOR SWITZERLAND / GERMANY / BELGIUM

To provide further legal guidance on technology and data protection to businesses, we regularly participate webinars with law firms around the world that are part of the PrivacyRules network on data privacy matters. We have started with the following webinar in 4 parts, in collaboration with German and Belgian experts for comparative data protection considerations between these three countries.

Part 1What Data Protection Authorities are saying

Part 2Challenges and possible solutions

Part 3Top tips and advice for organizations

Part 4 What may happen post-Covid-19

Note that the episodes of this webinar are in English only.

_______________________________

IMPACT ON THE ECONOMY

While Switzerland’s historic decision to limit events to a maximum of 1,000 people intends to reduce the risk of the virus spreading, it has a major impact on event organisers and other sectors of industry. Employers have to deal with teleworking solutions and implement health and remote work policies and deal with travel and distance restrictions. Employers also need to ensure that they do not interrupt the supply of goods, and have to potentially deal with contract termination or damages for non-performance. This includes, where necessary, to invoke force majeure or reject force majeure arguments from suppliers who are under the impossibility to deliver their services.

The economic repercussions in Switzerland and around the world are enormous. The Watches and Wonders exhibition decied to cancel the event on 27 February 2020. After this, the lucrative Geneva International Motor Show (GIMS), took the same path on 28 February 2020. After this, the famous Cully Jazz Festival had to accounce cancellation of its 2020 Edition on March 10, 2020. The organisers of this festival declared that, except with donation and external financial support and given the considerable losses, this cancellation may jeopardise future editions.

When it came to Italy deciding on 9 March 2020 to quarantine the country, the EU population was in shock, realizing the seriousness of the facts. France decided to limit the events to a maximum of 1000 people. In Spain, the World Mobile Exhibition in Barcelona cancelled the event, which was expecting more than 110k visitors. Such event would generate around 492 million euros in local economic spin-offs, as well as more than 14,000 jobs. The same happened to the Formula 1 Chinese Grand Prix. Originally scheduled for April 19 2020 in Shanghai, they decided to postpone it.

A list of all the episodes in this series can be found on the publications page of this blog or on the dedicated page on datalex.ch.

_______________________________

FEDERAL vs CANTONAL COMPETENCES

On 28 February 2020, the Federal Council decided by means of a federal ordinance to ban large scale events involving more than 1,000 people. This decision resulted from the outbreak of the “Covid-19”. This is a measure that is normally under the responsibility of the cantons. However, in special emergency situations, the government must protect the population against communicable diseases.  In those case, the Swiss Confederation may enact measures by means of a federal ordinance. It has used such power to limit the gathering of people. Furthermore, the Federal Office of Public Health (‘FOPH’) explained, in a press release dated 28 February 2020, the different situations that can arise when dealing with a contagious disease that endangers public health.

(1) In normal situations

The cantons are competent to put in place the necessary measures to protect the population. These consist of quarantine and isolation measures.

(2) In special situations

The Federal Council may encroach on the autonomy of the cantons. This may be the case where: (a) the cantons can no longer exercise their prerogatives or take appropriate measures, should there be a (i) high risk of infection and spread to the population, a (ii) risk to public health or (iii) to the economy. This may also be the case if (b) the World Health Organization (WHO) declares an international health emergency threatening Switzerland.

(3) Extraordinary situations

They arise in the event of an “extraordinary threat to public health“. In such circumstances, the Federal Council may issue federal ordinances without the need for a legal basis in order to take rapid and targeted actions applicable to all Switzerland. The cantons may still have some room to implement them or to issue stricter rules. Pandemic situations may be considered as extraordinary situations, which the Federal Council may invoke to use its overriding powers.

By Gabriel Avigdor | NTIC.ch

Google fined €50M by the CNIL under the GDPR

This 21 January 2019, the French data protection supervisory authority (Commission Nationale de l’Informatique et des Libertés – the “CNIL“) fined Google LLC 50 million Euros for breach of the General Data Protection Regulation (the “GDPR“).

In today’s communication (in French), the French authority issued the highest fine against Google LLC since 25 May 2018 considering severe infringements of the GDPR by Google for failing to inform properly the users and collecting valid consent for targeted advertising services.

SCOPE OF THIS DECISION. It is worth noting that this decision is solely based on investigations of the CNIL related to configuration of new Android device for the first time by a user. This particular infringement of the GDPR only relates to the privacy notice displayed to users when they create an account and when logging into their new Android phone. However, the full complaint has not yet been examined by the CNIL and goes far beyond that. The complete case is much broader and related to targeted advertising on Youtube, Gmail and Google Search platforms. The CNIL will have to examine how Google may have or not “forced” users to consent to sharing their personal data via Google targeted ads services. So we can expect to hear more from the CNIL in the upcoming months in this case. This is probably only the beginning of a long series for 2019. The two organizations also filed (as explained below) similar complaints against other GAFAM in several jurisdictions.

________________________________

FINDINGS OF THE CNIL

The CNIL considered that Google did not comply with the GDPR for three main reasons: (1) lack of transparency (art. 5 GDPR); (2) insufficient information (art. 12 and 13 GDPR); and (3) invalid consent collection (art. 7 GDPR).  The two complaints were brought by Max Schrems’ non-profit organization called “None Of Your Business” (NOYB) and the association La Quadrature du Net, a French association that regrouped complaints from 9’974 individuals. Those two organizations claimed that Google’ services, including the targeted advertising services on Android OS, did not comply with its obligation to process personal data with the proper legal basis (art. 6 GDPR), forcing users to share massive amount of personal data and therefore compromising their privacy without their consent.

Those complaints have just been confirmed by the CNIL in today’s findings. After that, it is interesting to read on the blog of NOYB, that Google will move its EU headquarters to Ireland with effect to 22 January 2019, with the Irish DPA (Data Protection Authority) as the lead authority.

The French authority adds some interesting considerations to its findings. The CNIL explains that with Google current services, due to the way the data are collected, the volume that can be processed and the type of data collected through those services, it can result in revealing entire parts of someone’s life, which becomes very intrusive. The CNIL also considered the fact that Google’s business model is partially based on those intrusive services.

Finally, the CNIL explains that, essentially, despite Google’s efforts to change its processes, Google is still not compliant. This also means that as long as Google remains non compliant, it may face other complaints and, potentially other fines unless the way Google processes data about individuals changes drastically.

________________________________

HISTORY OF THE CASE

Two massive complaints on 25 and 28 May 2018 for € 7,6 bn

25 May 2018. Max Schrems – the Austrian privacy advocate who provoked the cancellation of the Safe Harbor framework by the European Court of Justice (see judgement here) – founded a not profit organization called “None Of Your Business” (NOYB) to support consumers and data subjects in filing complaints against companies and to authorities to enforce and protect their privacy. Just the day the GDPR became enforceable on 25 May 2018,  Max Schrems sued Instagram (Belgium), WhatsApp (Hamburg, Facebook (Austria) and Android (France) with a massive complaint amounting to € 7,6 bn via its NGO for infringement of the GDPR. Find more details on NOYB’s website here.

28 May 2018. The French Digital Rights Group “La Quadrature du Net” lodged a complaint on 28 May 2018 against Google, Apple, Facebook, Amazon and LinkedIn in front of the CNIL on the behalf of 12,000 individuals for illegal processing of personal data.

The CNIL’s sanction of € 50 millions issued today is only one sanction against one company – Google LLC – and in one juridiction. There is most likely other sanctions to come if other authorities follow the CNIL’s argumentations and considerations.

In terms of procedure, Google can appeal to this sanction and contest the fine (edit 24-janv-2019), which the company announced publicly. Even if the fine remains low compared to the €4bn it can incur in the event of a maximum fine, the amount is high for this case. In its public statement, Google said:

We´ve worked hard to create a GDPR consent process for personalised ads that is as transparent and straightforward as possible, based on regulatory guidance and user experience testing

By appealing against this decision, Google wants initiates the process of a precedent in interpreting the GDPR’s requirements on information, transparency and how to validly obtain consent, particularly in the area of targeted advertising.

Google’s appeal is therefore highly strategic. Not contesting this fine would create room for potential more severe sanctions, especially as the scope of the case is limited. In addition, it could be seen as an indirect acknowledgment of responsibility for using non-compliant practices.

Finally, Google defends itself by arguing that it has worked hard to set up data collection in order to respect transparency, but also said:

We´re also concerned about the impact of this ruling on publishers, original content creators and tech companies in Europe and beyond

We will see if his work has been sufficient or not and how strong this EU Regulation can effectively be in practice.

________________________________

THE CASE IN MORE DETAILS

To get into more details, the CNIL provides the following explanations to justify the sanction against Google:

  • Breach of transparency: the transparency principle refers to how you inform individuals about the processing activities. This usually takes the form of privacy notices. This information is supposed to remain concise, clear, accessible, unambiguous and intelligible by any person.

This was not really the case. Google spread all that information in many separate places through links and buttons which made it very difficult to access, understand and takes ages. At the end, all that information was only accessible after 5 or 6 actions, in any case after several steps to know what data are collected about the individual. The information was not clear enough, vague and described in a too generic way. That means that if nobody takes the time to read that information (why would Google collect your data for what purpose, for how long, what categories of data are used for the targeted advertising, etc.), the obligation of having a clear and easily accessible notice is not achieved. Also, Google failed to inform about the retention period of certain personal data (for how long will Google keep that data).

  • Invalid consent: Google requested the consent of the users to collect the personal data. However, the CNIL considered that this legal basis was not valid for the options of customized advertising for the two following main reasons:

The consent was not informed. This means that users do not understand the scope of use of the data. For example, in the “customized publicity” section, it is not possible to see how many services, sites and applications are related to the processing and there is no information about the volume of personal data that those services will process and combine.

The consent was not specific, nor unambiguous despite the fact that users may have the ability to select several parameters. According to article 7 of the GDPR:

request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

With Google targeted advertising services and options, the users could only access those parameters by clicking “more options”. Also, the option to use “targeted advertising” was already pre-ticked, which forces the user to turn it off. So the option will remain active, if the user does nothing, unless there is an active action from the user to disable the option. Therefore, using pre-ticked boxes is contrary to the principle of privacy by default (art. 25 GDPR), which requires to turn off any settings or parameters by default to apply a maximum protection of privacy to the user. It is only up to the user to decide whether he or she wishes to increase the level of intrusiveness to his or her privacy and agree to share any personal data. Finally, Google only provided one box for the users to click which appeared like this:

“I accept Google’s terms and conditions” and “I accept that my data are used as described above and as detailed in the privacy policy”

Such bundled consent, which is not specific and do not provide any details for each purpose is not compliant with the requirements as set out in the GDPR.  Where several purposes for processing personal data exist, users must have the ability to only consent to those purposes that they wish. Having all the purposes all-in-one, does not work under the GDPR.

________________________________

ARE THOSE REQUIREMENTS NEW UNDER THE GDPR?

Yes and no.

Yes, the requirements to collect a valid consent has been extensively strengthened. It not as easy as before to collect a valid consent and as this case demonstrates, there are individuals and authorities out there that can have a word and ultimately impose fines to your organization.

No,  the principles of consent, collecting personal data with a valid legal basis and informing the individuals via privacy notice, are not new from an EU data protection legislation. The obligation to process personal data with a lawful ground already existed under Directive 95/46/EC and also applies under the Swiss Federal Data Protection Act (DPA), as probably in most of the jurisdiction that have adopted comprehensive data protection framework. A company responsible for collecting and processing personal data has to justify a valid legal reason. As a reminder, the GDPR offers 6 different legal bases to justify the processing of personal data (article 6 GDPR), which are:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protect the vital interests of natural persons;
  • performance of a task carried out in the public interest or in the exercise of official authority; and
  • legitimate interest.

Each of those legal bases have their pros and cons, but where you use the consent, you should remain careful to collect it lawfully, unless the processing becomes illegal. With the GDPR, the consent has become much more difficult to obtain. In particular, you need to inform and explain who shall consent, what you will do with that data, for what reasons and based on what legal basis you process the data, with whom you will share them. And this shall apply for each purpose. If those conditions are not, the consent is not valid illicit and you cannot process the personal data.

And this is what happened to Google LLC in the case of targeted advertising, for this first part of the story.

________________________________

By Gabriel Avigdor | ICT.ch 

Digital Lawyer