https://iapp.org/news/a/new-eu-data-blockage-as-german-court-would-ban-many-cookie-management-providers/ * language English (EN) * Francais * Espanol * Deutsch * Portugues (Brasil) * About the IAPP * Enterprise Services * Contact * Calendar * MyIAPP * search [iapp_logo] * News * Connect * Train * Certify * Resources * Conferences * Join * Store Store * shopping_cart {[ getCartTotalItems() ]} * Main Menuclose [ ] search close * Back to the News Menutouch_app * Shopping Cart shopping_cart {[ getCartTotalItems() ]} * + English (EN)language o radio_button_checkedEnglish o radio_button_uncheckedFrancais o radio_button_uncheckedEspanol o radio_button_uncheckedDeutsch o radio_button_uncheckedPortugues (Brasil) * Homehome * News * Connectgroup * Trainschool * Certify * Resourcesassessment * Conferencesevent * Joinperson_add * Storestore * MyIAPPperson_outline * About the IAPPinfo_outline * Enterprise Servicesdomain * Contactsend * Calendarcalendar_today * News Menuclose [ ] search close * Open the Main Menutouch_app * Shopping Cart shopping_cart {[ getCartTotalItems() ]} * radio_button_unchecked News Feed * radio_button_unchecked Daily Dashboard * radio_button_unchecked Videos * radio_button_unchecked Privacy Perspectives * radio_button_unchecked The Privacy Advisor * radio_button_unchecked The Privacy Advisor Podcast * radio_button_unchecked Privacy Tracker * radio_button_unchecked Privacy Tech * radio_button_unchecked DPO Confessional * radio_button_unchecked Canada Dashboard Digest * radio_button_unchecked Asia-Pacific Dashboard Digest * radio_button_unchecked Latin America Dashboard Digest * radio_button_unchecked Europe Data Protection Digest * radio_button_unchecked U.S. Privacy Digest * radio_button_unchecked IAPP Westin Research Center * radio_button_unchecked Books * radio_button_unchecked Web Conferences * radio_button_unchecked Advertise * radio_button_unchecked About IAPP Publications menu shopping_cart {[ getCartTotalItems() ]} person_outline Login close News Stream Books Videos Web Conferences Subscriptions Advertise About IAPP Publications Daily Dashboard Daily Dashboard The day's top stories from around the world Privacy Perspectives Privacy Perspectives Where the real conversations in privacy happen The Privacy Advisor The Privacy Advisor Original reporting and feature articles on the latest privacy developments Privacy Tracker Privacy Tracker Alerts and legal analysis of legislative trends Privacy Tech Privacy Tech Exploring the technology of privacy Canada Dashboard Digest Canada Dashboard Digest A roundup of the top Canadian privacy news Europe Data Protection Digest Europe Data Protection Digest A roundup of the top European data protection news Asia-Pacific Dashboard Digest Asia-Pacific Dashboard Digest A roundup of the top privacy news from the Asia-Pacific region Latin America Dashboard Digest Latin America Dashboard Digest A roundup of the top privacy news from Latin America U.S. Privacy Digest U.S. Privacy Digest A roundup of US privacy news Overview KnowledgeNet Chapters Sections Affinity Groups Volunteer Annual Awards Member Directory Privacy List Career Central Celebrate Data Privacy Day See how the IAPP and privacy pros worldwide are celebrating throughout January and find an event near you! Find a KnowledgeNet Chapter Near You Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide. Virtual Networking Connect with IAPP members around the globe without ever leaving your home. Find a Virtual Networking event today. Join the Privacy List Have ideas? Need advice? Subscribe to the Privacy List. It's crowdsourcing, with an exceptional crowd. IAPP Job Board Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer. Member Directory Locate and network with fellow privacy professionals using this peer-to-peer directory. IAPP Calendar Review a filterable list of conferences, KnowledgeNets, LinkedIn Live broadcasts, networking events, web conferences and more. Overview Online Training Live Online Training In-Person Training Books Sample Questions Train Your Staff Official Training Partners Web Conferences European Data Protection (CIPP/E) Understand Europe's framework of laws, regulations and policies, most significantly the GDPR. U.S. Private-Sector Privacy (CIPP/US) Steer a course through the interconnected web of federal and state laws governing U.S. data privacy. Canadian Privacy (CIPP/C) Learn the intricacies of Canada's distinctive federal/provincial/ territorial data privacy governance systems. Privacy Program Management (CIPM) Develop the skills to design, build and operate a comprehensive data protection program. Privacy in Technology (CIPT) Add to your tech knowledge with deep training in privacy-enhancing technologies and how to deploy them. CCPA Training Gain the knowledge needed to address the widest-reaching consumer information privacy law in the U.S. GDPR Training Learn the legal, operational and compliance requirements of the EU regulation and its global influence. Privacy Law Specialist Training (PLS) Meet the stringent requirements to earn this American Bar Association-certified designation. Overview Certification Programs Get Certified How to Prepare Continuing Privacy Education (CPE) Fees Certify Your Staff Verify a Certification CIPP Certification CIPP Certification The global standard for the go-to person for privacy laws, regulations and frameworks CIPM Certification CIPM Certification The first and only privacy certification for professionals who manage day-to-day operations CIPT Certification CIPT Certification As technology professionals take on greater privacy responsibilities, our updated certification is keeping pace with 50% new content covering the latest developments. FIP Designation FIP Designation Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today's complex world of data privacy. Privacy Law Specialist Privacy Law Specialist The first title to verify you meet stringent requirements for knowledge, skill, proficiency and ethics in privacy law, and one of the ABA's newest accredited specialties. CIPP/E + CIPM = GDPR Ready CIPP/E + CIPM = GDPR Ready The IAPP'S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for GDPR readiness. Learn more today. Certificacao CDPO/BR Certificacao CDPO/BR Mostre seus conhecimentos na gestao do programa de privacidade e na legislacao brasileira sobre privacidade. Certification CDPO/FR Certification CDPO/FR Certification des competences du DPO fondee sur la legislation et reglementation francaise et europeenne, agreee par la CNIL. Tools and Trackers Research Glossary DPAs Enforcement Database Westin Research Center Web Conferences Jobs Privacy Vendor Marketplace Privacy Vendor Marketplace Privacy Vendor Marketplace Use the Vendor Demo Center, Privacy Vendor List and Privacy Tech Vendor Report to easily identify privacy products and services to support your work. International Data Transfers On this topic page, you can find the IAPP's collection of coverage, analysis and resources related to international data transfers. US State Privacy Legislation Tracker The IAPP's US State Privacy Legislation Tracker consists of proposed and enacted comprehensive state privacy bills from across the U.S. US Federal Privacy Legislation Tracker The IAPP's US Federal Privacy Legislation Tracker compiles a list of privacy-related bills proposed in Congress to keep our members informed about developments within the fe Reports and Surveys Access all reports and surveys published by the IAPP. White Papers Access all white papers published by the IAPP. CCPA and CPRA IAPP members can get up-to-date information here on the California Consumer Privacy Act and the California Privacy Rights Act. EU General Data Protection Regulation The IAPP's EU General Data Protection Regulation page collects the guidance, analysis, tools and resources you need to make sure you're meeting your obligations. CCPA and CPRA Genius This tool helps IAPP members navigate the CCPA and CPRA by mapping legal requirements, while providing access to critical resources, analysis, compliance guidance and more. GDPR Genius This interactive tool provides IAPP members access to critical GDPR resources -- all in one location. Data Protection Intensive: France Data Protection Intensive: France Concentrated learning, sharing, and networking with all sessions delivered in parallel tracks--one in French, the other in English. Data Protection Intensive: UK Data Protection Intensive: UK DPI: UK returns in-person in March 2022. Register today to network, explore U.K.-oriented issues, and more. Global Privacy Summit Global Privacy Summit The world's top privacy conference. Whether you work in the public or private sector, anywhere in the world, the Summit is your can't-miss event. Canada Privacy Symposium Canada Privacy Symposium Find answers to your privacy questions from keynote speakers and panellists who are experts in Canadian data protection. Asia Privacy Forum Asia Privacy Forum Join top experts discussing the critical data protection issues impacting Asia-Pacific businesses today. Privacy. Security. Risk. (P.S.R.) Privacy. Security. Risk. (P.S.R.) P.S.R. offers the best of the best in privacy and security, with innovative cross-education and stellar networking. ANZ Summit Online ANZ Summit Online Delivering world-class discussion and education on the top privacy issues in Australia, New Zealand and around the globe. Europe Data Protection Congress Europe Data Protection Congress The hub of European privacy policy debate, thought leadership and strategic thinking with data protection professionals. Speak at an IAPP Event View our open calls and submission instructions. Sponsor an Event Increase visibility for your organization--check out sponsorship opportunities today. Individual Membership Corporate Membership Group Membership Student Membership Become a Member Start taking advantage of the many IAPP member benefits today Corporate Members See our list of high-profile corporate members--and find out why you should become one, too Renew Your Membership Don't miss out for a minute--continue accessing your benefits ANZ Members Review current member benefits available to Australia and New Zealand members {[ product.name ]} clear mode_editEdit remove_circle_outline {[ getCartItemQuantity(product.id) ]} add_circle_outline {[ product.price | currencyFilter ]} TOTAL: {[ getCartTotalCost() | currencyFilter ]} Update cart for total shopping_basket Checkout autorenew UPDATE CART Privacy Perspectives | New EU data blockage as German court would ban many cookie management providers Related reading: Hard data localization may be coming to the EU -- Here are 5 concerns rss_feed New EU data blockage as German court would ban many cookie management providers schedule Dec 15, 2021 queue Save This * * * * print GDPR-Ready_300x250-Ad [cybersecurity-tile-ebook] "" [Transcend_Apple-In-App-IAPP-Ad_121521] Headshot Daniel Felz, CIPP/E IAPP Member Contributor Headshot Peter Swire, CIPP/US IAPP Member Contributor * * * * print On Dec. 1, the Wiesbaden Administrative Court issued a first-of-its-kind decision holding that companies cannot use a cookie management provider that relies on a U.S.-based service to collect data, irrespective of whether the data actually ever leaves the EU. Because cookie management requirements apply for EU websites generally, EU-wide adoption of this case's theories would affect a broad range of companies that do business both within and outside the EU. Although the decision was made at the interim injunction stage and could thus be modified if the case proceeds to trial, its implications are significant and warrant attention now. The plaintiff's attorney in the case has described to media his view that "website plugins that are hosted and loaded by a cloud service with any U.S. connection" now create "impermissible data transfers." Although the "any connection" statement is overbroad as a matter of U.S. law, that quotation suggests the range of cross-border transfers prohibited under the court's approach. The Wiesbaden decision The Rhine-Main University of Applied Sciences integrated the cookie management tool "Cookiebot," from the Danish company Cybot, on its website. Cookiebot displays a banner that lets the user set her cookie preferences. When the user does so, Cookiebot collects, inter alia, the user's IP address, the URL governed by the user's preferences (i.e., RMU's website), and a unique random "user key" assigned to the user. The user key and preferences are stored locally so RMU's site continues to honor user preferences. Cookiebot also stores all the above data in its own environment. Per Cookiebot, this is done so -- as required by the EU General Data Protection Regulation -- the company has demonstrable proof users consented to cookie storage. The alleged problem was Cookiebot used a U.S.-based content delivery network (Akamai Technologies) to collect this data. Importantly, the Wiesbaden court appeared to accept that Akamai may have stored Cookiebot data on EU servers, and not in the U.S., which suggests Cookiebot's agreement is with Akamai's German affiliate. But the court, in part supported by testimony it requested from the Hessian Data Protection Commission, ruled this was irrelevant. It held that the mere use of a U.S.-based provider to collect IP addresses and user key data was an unlawful "transfer" because: * Per the Court of Justice of the European Union, IP addresses are personal data (the court also considered Cookiebot's "user key" to be personal data). * Under the Clarifying Lawful Overseas Use of Data Act, a U.S. cloud provider can be obligated to produce all data in its possession, custody, or control to U.S. agencies, irrespective of whether the data is stored in or outside the U.S. This decision has a number of noteworthy implications. Among the more salient are: 1. The court never evaluated whether a "transfer" actually occurred. The decision assumes a "transfer" occurs even if data never leaves the EU, so long as the recipient of data may formally be subject to requests by non-EU authorities. This approach seems different from the European Data Protection Board's recent definition of a "transfer" -- i.e., a disclosure of data to an "importer" who is "in a third country." None of the EDPB examples apply to data that physically stays in the EU. Here, however, the court reasoned that since data "are processed on Akamai servers, a data transfer to a third country is occurring," simply because "Akamai Technologies Inc., as an American company, is subject to the CLOUD Act." 2. The court acknowledged Cookiebot claimed to have executed standard contractual clauses with Akamai (although it is unclear whether these were the "old" or the "new" SCCs). The court also heard allegations from the plaintiff that Cookiebot and Akamai had not implemented any "supplemental safeguards" beyond the SCCs. But the SCCs did not appear to play a role in the court's decision. Instead, the court took the approach that data could only be lawfully transferred to the U.S. via a mutual legal assistance treaty (Article 48 GDPR), or under Article 49 GDPR's derogations, such as consent. It confined its lawfulness analysis to those grounds alone. 3. As a result, the court never evaluated whether there was any significant risk U.S. law would undermine the SCC safeguards. In its final guidance on safeguards needed for transfers, the EDPB allows organizations to consider "the practices in force in the third country" that bear on whether "in practice, the effective protection of the personal data" will be maintained. Nonetheless, the court did not assess the practices in the third country, and how that would impact effective protection. 1. The court failed to consider the lack of any real CLOUD Act risk. IP addresses are one of the most abundant pieces of data created by the internet, broadcast by users hundreds of times daily with every website and app click. It is noteworthy the court never asked whether U.S. agencies would ever, in practice, ask for Cookiebot's specific version of a user's IP address. The CLOUD Act has narrower effect and narrower change to previous U.S. law than many in Europe have stated. In practice, it is difficult to imagine when the U.S. prosecutors would go to court to connect an IP address with a user's cookie preferences for one website -- the information about cookie preferences is of little use to law enforcement, and reveals little about a user's private life or activities. It may be relevant for companies to determine whether they have ever received such a request, much as some companies (like Akamai) have determined that they are not subject to Section 702 of the Foreign Intelligence Surveillance Act. The risk of a criminal investigatory request for this data would appear negligible. 2. The court never assessed whether -- even if IP address data were transferred to the U.S. -- this created any significant risk to users. It is unclear what additional risk users would face if IP addresses were stored on servers in the U.S., versus being stored in the EU. Even the plaintiff seems to have had difficulty identifying any concrete risk; the court notes it argued only that Cookiebot's tool created "a risk" of "unauthorized access." Implications of the decision The new Wiesbaden decision continues a trend toward broader EU definitions of when data may not be processed by entities connected with third countries, including but not limited to the United States. In previous writing for the IAPP, Swire discussed the broad effects of guidance from the EDPB limiting data transfers, which was softened somewhat in final guidance, as well as the April 2021 decision to prohibit cybersecurity provider Cloudflare from providing services to Portugal's census agency. One significant aspect of the new decision is it seems to prohibit data processing even when the personal data is stored in the EU and never leaves the EU. The French cloud regulatory agency, ANSSI, has taken a similar position in its proposed certification program for "trusted" cloud providers, supporting the position that cloud providers be immune from foreign laws. Nigel Cory recently critiqued the breadth of the French proposal, which would set strict limits on non-EU control of providers who would serve French government agencies or other "vital" or "essential" services. As mentioned in the introduction, the plaintiff's attorney in the Wiesbaden case claimed that all "website plugins that are hosted and loaded by a cloud service with any U.S. connection" now create "impermissible data transfers." (Because the Wiesbaden court cited the CLOUD Act as a reason to limit U.S.-based services, we note that the claim for "any US connection" is incorrect, because the CLOUD Act only applies under U.S. law where there is possession, custody, or control in the U.S.) Second, since the crux of the court's decision was that the ability of non-EU governments to request data from an IT provider creates an illicit "transfer," the headquarters of the provider should not be relevant. In other words, this decision would prohibit processing of data by any provider that is subject to both EU and non-EU law -- even if the provider is headquartered in the EU -- as long as a request by a foreign government could require production of data irrespective of storage location. Companies like SAP and Capgemini are just as internationally present as large U.S. organizations, and thus just as subject to receive requests from non-EU governments. Third, another measure of the breadth of the decision concerns the routine nature of the personal data at issue -- IP addresses linked only to a user's cookie preferences on a university website. This breadth contrasts, for instance, with the Cloudflare case, which concerned census data historically treated as more sensitive. To the extent risk of improper access is considered, the Wiesbaden case appears to set a low threshold for permitting any such risk. Fourth, the new case can be seen in context of other pending enforcement actions. NOYB has filed over 100 complaints alleging improper transfers to the U.S., for a range of data analytics and cookie plug-ins that are pervasive in the current online ecosystem. This first, interim Wiesbaden decision may thus be a harbinger of additional enforcement decisions affecting the operations of websites across the EU. Photo from Unsplash.com [IAPP_CPE-F] Approved CDPO, CDPO/BR, CDPO/FR, CIPM, CIPP/A, CIPP/C, CIPP/E, CIPP/G, CIPP/ US, CIPT, LGPD Credits: 1 Submit for CPEs Authors Headshot Daniel Felz, CIPP/E IAPP Member Contributor Headshot Peter Swire, CIPP/US IAPP Member Contributor shareShare This * * * * print Tags Europe U.S. Location Privacy Privacy Law Privacy Opinion Transborder Data Flow 2 Comments If you want to comment on this post, you need to login. * comment Stefan Schindler * Dec 15, 2021 It is truly a pity that neither the statement of the facts that have been published, nor the court's reasoning do provide for sufficient clarity as to what role the SCCs played in this case. At one point the decision mentions that the SCCs lacked "additional safeguards", indicating that these could have been necessary. Later on the court states that the SCCs that have been produced by the defendant were "blank", i.e. they were apparently not filled in / completed. If so, the SCCs could certainly not serve as a valid transfer tool. One may speculate that because of these flaws the court abandoned the SCC-subject and turned to derogations under Art. 49 GDPR to assess whether these could legitimize the (assumed) data transfers. Hopefully the main proceedings will bring more clarity. * comment Michal Jedrzejczak * Dec 20, 2021 Please consider in your comments that: Comment no.1: https://edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-012020-measures-supplement-transfer_en Page 10, note 13 - "Please note that remote access by an entity from a third country to data located in the EEA is also considered a transfer." Comment no.2: Page 34: https://edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-012020-measures-supplement-transfer_en "Use Case 6: Transfer to cloud services providers or other processors which require access to data in the clear"... "...then the EDPB is, considering the current state of the art, incapable of envisioning an effective technical measure to prevent that access from infringing on the data subject's fundamental rights." Comment no.3: Risk evaluation is data controller responsibility (not the court). Related Stories Hard data localization may be coming to the EU -- Here are 5 concerns 1 In November, the European Data Protection Board released two important documents with guidance on when personal data will be allowed to flow to the United States, India, China and many other non-EU countries. Expert European commentators have concluded the draft documents from the EDPB would apparen... Read More queue Save This EDPB's data transfer recommendations adopt a risk-based approach with teeth On June 21, the European Data Protection Board issued its highly anticipated final recommendations on supplementary measures for data transfers. The recommendations outline a process organizations can follow to transfer personal data outside the European Economic Area to ensure compliance with the "... Read More queue Save This New urgency about data localization with Portuguese decision On April 27, 2021, Portugal's data protection authority, the National Data Protection Commission, ordered Statistics Portugal, in carrying out the national census, to suspend processing of personal data in any third country that lacks adequate privacy protections, including the United States. Accord... Read More queue Save This Announcing the new Cross-Border Data Forum With cloud computing, law enforcement investigations increasingly seek evidence that is held across borders, in a different country. As we describe in a separate IAPP post, this globalization of criminal evidence is prompting major legislative change and proposals. In 2018 alone, the United States p... Read More queue Save This Global News Roundup: Dec. 14-20, 2021 The president of the Administrative Court of Luxembourg partially granted Amazon's request to suspend execution of a record 746 million euro EU General Data Protection Regulation fine proposed by Luxembourg's National Commission for Data Protection. The U.S. Federal Trade Commission is considering d... Read More queue Save This [Transcend_Apple-In-App-IAPP-Ad_121521] Related Stories * library_books Hard data localization may be coming to the EU -- Here are 5 concerns * library_books EDPB's data transfer recommendations adopt a risk-based approach with teeth * library_books New urgency about data localization with Portuguese decision * library_books Announcing the new Cross-Border Data Forum * library_books Global News Roundup: Dec. 14-20, 2021 Tags Europe U.S. Location Privacy Privacy Law Privacy Opinion Transborder Data Flow Recent Comments * comment Tips for breaking into privacy from other roles 3 * comment New EDPB guidelines define international transfers: Dancing in place 2 * comment New EU data blockage as German court would ban many cookie management providers 2 * comment The way the third-party cookie crumbles: Part 1 - EU and UK developments 2 [0 ] [iapp_logo_] * * * * * About The IAPP is the largest and most comprehensive global information privacy community and resource. Founded in 2000, the IAPP is a not-for-profit organization that helps define, promote and improve the privacy profession globally. * What is Privacy * Corporate Members * Board of Directors * Advisory Boards * IAPP Staff * Locations Become a member The IAPP is the only place you'll find a comprehensive body of resources, knowledge and experts to help you navigate the complex landscape of today's data-driven world. We offer individual, corporate and group memberships, and all members have access to an extensive array of benefits. Sign Up Today (c) 2021 International Association of Privacy Professionals. All rights reserved. Pease International Tradeport, 75 Rochester Ave. Portsmouth, NH 03801 USA * +1 603.427.9200 * Contact Us * Press * Advertise * Privacy Notice * Cookie Notice * Conditions of Use * Refund Policy * Cookie Settings * language English (EN) * Francais * Espanol * Deutsch * Portugues (Brasil)