Article 45
Transfers on the basis of an adequacy decision
(56) Whereas cross-border flows of personal data are necessary to the expansion of international trade; whereas the protection of individuals guaranteed in the Community by this Directive does not stand in the way of transfers of personal data to third countries which ensure an adequate level of protection; whereas the adequacy of the level of protection afforded by a third country must be assessed in the light of all the circumstances surrounding the transfer operation or set of transfer operations;
(57) Whereas, on the other hand, the transfer of personal data to a third country which does not ensure an adequate level of protection must be prohibited;
(58) Whereas provisions should be made for exemptions from this prohibition in certain circumstances where the data subject has given his consent, where the transfer is necessary in relation to a contract or a legal claim, where protection of an important public interest so requires, for example in cases of international transfers of data between tax or customs administrations or between services competent for social security matters, or where the transfer is made from a register established by law and intended for consultation by the public or persons having a legitimate interest; whereas in this case such a transfer should not involve the entirety of the data or entire categories of the data contained in the register and, when the register is intended for consultation by persons having a legitimate interest, the transfer should be made only at the request of those persons or if they are to be the recipients;
(60) Whereas, in any event, transfers to third countries may be effected only in full compliance with the provisions adopted by the Member States pursuant to this Directive, and in particular Article 8 thereof;
(66) Whereas, with regard to the transfer of data to third countries, the application of this Directive calls for the conferment of powers of implementation on the Commission and the establishment of a procedure as laid down in Council Decision 87/373/EEC (1);
|
Regulation
Art. 45 1. A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation. 2. When assessing the adequacy of the level of protection, the Commission shall, in particular, take account of the following elements: a) the rule of law, respect for human rights and fundamental freedoms, relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, as well as the implementation of such legislation, data protection rules, professional rules and security measures, including rules for the onward transfer of personal data to another third country or international organisation which are complied with in that country or international organisation, case-law, as well as effective and enforceable data subject rights and effective administrative and judicial redress for the data subjects whose personal data are being transferred; b) the existence and effective functioning of one or more independent supervisory authorities in the third country or to which an international organisation is subject, with responsibility for ensuring and enforcing compliance with the data protection rules, including adequate enforcement powers, for assisting and advising the data subjects in exercising their rights and for cooperation with the supervisory authorities of the Member States; and c) the international commitments the third country or international organisation concerned has entered into, or other obligations arising from legally binding conventions or instruments as well as from its participation in multilateral or regional systems, in particular in relation to the protection of personal data. 3. The Commission, after assessing the adequacy of the level of protection, may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article. The implementing act shall provide for a mechanism for a periodic review, at least every four years, which shall take into account all relevant developments in the third country or international organisation. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the supervisory authority or authorities referred to in point (b) of paragraph 2 of this Article. The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93(2). 4. The Commission shall, on an ongoing basis, monitor developments in third countries and international organisations that could affect the functioning of decisions adopted pursuant to paragraph 3 of this Article and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC. 5. The Commission shall, where available information reveals, in particular following the review referred to in paragraph 3 of this Article, that a third country, a territory or one or more specified sectors within a third country, or an international organisation no longer ensures an adequate level of protection within the meaning of paragraph 2 of this Article, to the extent necessary, repeal, amend or suspend the decision referred to in paragraph 3 of this Article by means of implementing acts without retro-active effect. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2). On duly justified imperative grounds of urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93(3). 6. The Commission shall enter into consultations with the third country or international organisation with a view to remedying the situation giving rise to the decision made pursuant to paragraph 5. 7. A decision pursuant to paragraph 5 of this Article is without prejudice to transfers of personal data to the third country, a territory or one or more specified sectors within that third country, or the international organisation in question pursuant to Articles 46 to 49. 8. The Commission shall publish in the Official Journal of the European Union and on its website a list of the third countries, territories and specified sectors within a third country and international organisations for which it has decided that an adequate level of protection is or is no longer ensured. 9. Decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this Article. |
Directive
Art. 25 1. The Member States shall provide that the transfer to a third country of personal data which are undergoing processing or are intended for processing after transfer may take place only if, without prejudice to compliance with the national provisions adopted pursuant to the other provisions of this Directive, the third country in question ensures an adequate level of protection. 2. The adequacy of the level of protection afforded by a third country shall be assessed in the light of all the circumstances surrounding a data transfer operation or set of data transfer operations; particular consideration shall be given to the nature of the data, the purpose and duration of the proposed processing operation or operations, the country of origin and country of final destination, the rules of law, both general and sectoral, in force in the third country in question and the professional rules and security measures which are complied with in that country. 3. The Member States and the Commission shall inform each other of cases where they consider that a third country does not ensure an adequate level of protection within the meaning of paragraph 2. 4. Where the Commission finds, under the procedure provided for in Article 31 (2), that a third country does not ensure an adequate level of protection within the meaning of paragraph 2 of this Article, Member States shall take the measures necessary to prevent any transfer of data of the same type to the third country in question. 5. At the appropriate time, the Commission shall enter into negotiations with a view to remedying the situation resulting from the finding made pursuant to paragraph 4. 6. The Commission may find, in accordance with the procedure referred to in Article 31 (2), that a third country ensures an adequate level of protection within the meaning of paragraph 2 of this Article, by reason of its domestic law or of the international commitments it has entered into, particularly upon conclusion of the negotiations referred to in paragraph 5, for the protection of the private lives and basic freedoms and rights of individuals. Member States shall take the measures necessary to comply with the Commission's decision. |
Spain
Disposición adicional quinta. Autorización judicial en relación con decisiones de la Comisión Europea en materia de transferencia internacional de datos. 1. Cuando una autoridad de protección de datos considerase que una decisión de la Comisión Europea en materia de transferencia internacional de datos, de cuya validez dependiese la resolución de un procedimiento concreto, infringiese lo dispuesto en el Reglamento (UE) 2016/679, menoscabando el derecho fundamental a la protección de datos, acordará inmediatamente la suspensión del procedimiento, a fin de solicitar del órgano judicial autorización para declararlo así en el seno del procedimiento del que esté conociendo. Dicha suspensión deberá ser confirmada, modificada o levantada en el acuerdo de admisión o inadmisión a trámite de la solicitud de la autoridad de protección de datos dirigida al tribunal competente. Las decisiones de la Comisión Europea a las que puede resultar de aplicación este cauce son: a) aquellas que declaren el nivel adecuado de protección de un tercer país u organización internacional, en virtud del artículo 45 del Reglamento (UE) 2016/679; b) aquellas por las que se aprueben cláusulas tipo de protección de datos para la realización de transferencias internacionales de datos, o c) aquellas que declaren la validez de los códigos de conducta a tal efecto. 2. La autorización a la que se refiere esta disposición solamente podrá ser concedida si, previo planteamiento de cuestión prejudicial de validez en los términos del artículo 267 del Tratado de Funcionamiento de la Unión Europea, la decisión de la Comisión Europea cuestionada fuera declarada inválida por el Tribunal de Justicia de la Unión Europea. Disposición final cuarta. Modificación de la Ley Orgánica 6/1985, de 1 de julio, del Poder Judicial. Se modifica la Ley Orgánica, 6/1985, de 1 de julio, del Poder Judicial, en los siguientes términos: Uno. Se añade un apartado tercero al artículo 58, con la siguiente redacción: «Artículo 58. Tercero. De la solicitud de autorización para la declaración prevista en la disposición adicional quinta de la Ley Orgánica de Protección de Datos Personales y Garantía de los Derechos Digitales, cuando tal solicitud sea formulada por el Consejo General del Poder Judicial.» Dos. Se añade una letra f) al artículo 66, con la siguiente redacción: «Artículo 66. f) De la solicitud de autorización para la declaración prevista en la disposición adicional quinta de la Ley Orgánica de Protección de Datos Personales y Garantía de los Derechos Digitales, cuando tal solicitud sea formulada por la Agencia Española de Protección de Datos.» Tres. Se añaden una letra k) al apartado 1 y un nuevo apartado 7 al artículo 74, con la siguiente redacción: «Artículo 74. 1. […] k) De la solicitud de autorización para la declaración prevista en la disposición adicional quinta de la Ley Orgánica de Protección de Datos Personales y Garantía de los Derechos Digitales, cuando tal solicitud sea formulada por la autoridad de protección de datos de la Comunidad Autónoma respectiva. […] 7. Corresponde a las Salas de lo Contencioso-administrativo de los Tribunales Superiores de Justicia autorizar, mediante auto, el requerimiento de información por parte de autoridades autonómicas de protección de datos a los operadores que presten servicios de comunicaciones electrónicas disponibles al público y de los prestadores de servicios de la sociedad de la información, cuando ello sea necesario de acuerdo con la legislación específica.» Cuatro. Se añade un nuevo apartado 7 al artículo 90: «7. Corresponde a los Juzgados Centrales de lo Contencioso-administrativo autorizar, mediante auto, el requerimiento de información por parte de la Agencia Española de Protección de Datos y otras autoridades administrativas independientes de ámbito estatal a los operadores que presten servicios de comunicaciones electrónicas disponibles al público y de los prestadores de servicios de la sociedad de la información, cuando ello sea necesario de acuerdo con la legislación específica.» Disposición final sexta. Modificación de la Ley 29/1998, de 13 de julio, reguladora de la Jurisdicción Contencioso-administrativa. La Ley 29/1998, de 13 de julio, reguladora de la Jurisdicción Contencioso-administrativa, se modifica en los siguientes términos: Uno. Se añade un nuevo apartado 7 al artículo 10: «7. Conocerán de la solicitud de autorización al amparo del artículo 122 ter, cuando sea formulada por la autoridad de protección de datos de la Comunidad Autónoma respectiva.» Dos. Se añade un nuevo apartado 5 al artículo 11: «5. Conocerá de la solicitud de autorización al amparo del artículo 122 ter, cuando sea formulada por la Agencia Española de Protección de Datos.» Tres. Se añade un nuevo apartado 4 al artículo 12: «4. Conocerá de la solicitud de autorización al amparo del artículo 122 ter, cuando sea formulada por el Consejo General del Poder Judicial.» Cuatro. Se introduce un nuevo artículo 122 ter, con el siguiente tenor: «Artículo 122 ter. Procedimiento de autorización judicial de conformidad de una decisión de la Comisión Europea en materia de transferencia internacional de datos. 1. El procedimiento para obtener la autorización judicial a que se refiere la disposición adicional quinta de la Ley Orgánica de Protección de Datos Personales y Garantía de los Derechos Digitales, se iniciará con la solicitud de la autoridad de protección de datos dirigida al Tribunal competente para que se pronuncie acerca de la conformidad de una decisión de la Comisión Europea en materia de transferencia internacional de datos con el Derecho de la Unión Europea. La solicitud irá acompañada de copia del expediente que se encontrase pendiente de resolución ante la autoridad de protección de datos. 2. Serán partes en el procedimiento, además de la autoridad de protección de datos, quienes lo fueran en el procedimiento tramitado ante ella y, en todo caso, la Comisión Europea. 3. El acuerdo de admisión o inadmisión a trámite del procedimiento confirmará, modificará o levantará la suspensión del procedimiento por posible vulneración de la normativa de protección de datos tramitado ante la autoridad de protección de datos, del que trae causa este procedimiento de autorización judicial. 4. Admitida a trámite la solicitud, el Tribunal competente lo notificará a la autoridad de protección de datos a fin de que dé traslado a quienes interviniesen en el procedimiento tramitado ante la misma para que se personen en el plazo de tres días. Igualmente, se dará traslado a la Comisión Europea a los mismos efectos. 5. Concluido el plazo mencionado en la letra anterior, se dará traslado de la solicitud de autorización a las partes personadas a fin de que en el plazo de diez días aleguen lo que estimen procedente, pudiendo solicitar en ese momento la práctica de las pruebas que estimen necesarias. 6. Transcurrido el período de prueba, si alguna de las partes lo hubiese solicitado y el órgano jurisdiccional lo estimase pertinente, se celebrará una vista. El Tribunal podrá decidir el alcance de las cuestiones sobre las que las partes deberán centrar sus alegaciones en dicha vista. 7. Finalizados los trámites mencionados en los tres apartados anteriores, el Tribunal competente adoptará en el plazo de diez días una de estas decisiones: a) Si considerase que la decisión de la Comisión Europea es conforme al Derecho de la Unión Europea, dictará sentencia declarándolo así y denegando la autorización solicitada. b) En caso de considerar que la decisión es contraria al Derecho de la Unión Europea, dictará auto de planteamiento de cuestión prejudicial de validez de la citada decisión ante el Tribunal de Justicia de la Unión Europea, en los términos del artículo 267 del Tratado de Funcionamiento de la Unión Europea. La autorización solamente podrá ser concedida si la decisión de la Comisión Europea cuestionada fuera declarada inválida por el Tribunal de Justicia de la Unión Europea. 8. El régimen de recursos será el previsto en esta ley.» ---- Fifth additional provision. Judicial authorization in relation to decisions of the European Commission on international data transfer. 1. Where a data protection authority considers that a decision of the European Commission on the international transfer of data, on the validity of which the outcome of a specific procedure depends, infringes the provisions of Regulation (EU) 2016/679, undermining the fundamental right to data protection, it shall immediately agree to suspend the procedure, in order to request authorization from the judicial body to declare it so in the proceedings before it. Such suspension shall be confirmed, modified or lifted in the decision to admit or refuse to admit the request of the data protection authority addressed to the competent court. The decisions of the European Commission to which this channel may be applicable are as follows: a) those declaring the adequate level of protection of a third country or international organization, pursuant to Article 45 of Regulation (EU) 2016/679; b) those approving standard data protection clauses for international data transfers, or c) those that declare the validity of the codes of conduct to that effect. 2. The authorization referred to in this provision may only be granted if, after a preliminary ruling on the validity of the decision of the European Commission, as provided for in Article 267 of the Treaty on the Functioning of the European Union, the decision of the European Commission in question is declared invalid by the Court of Justice of the European Union. Fourth final provision: Amendment of Organic Law 6/1985, of July 1, 1985, of the Judiciary. Organic Law 6/1985, of July 1, 1985, of the Judiciary is amended as follows: A third paragraph is added to Article 58, with the following wording: "Article 58. Third. Of the request for authorization for the declaration provided for in the fifth additional provision of the Organic Law on Personal Data Protection and Guarantee of Digital Rights, when such request is made by the General Council of the Judiciary." Two.A letter f) is added to Article 66, with the following wording: "Article 66. f) Of the request for authorization for the declaration provided for in the fifth additional provision of the Organic Law on Personal Data Protection and Guarantee of Digital Rights, when such request is made by the Spanish Data Protection Agency." Three. A letter k) is added to paragraph 1 and a new paragraph 7 to Article 74, with the following wording: "Article 74. 1. [...] k) The request for authorization for the declaration provided for in the fifth additional provision of the Organic Law on Personal Data Protection and Guarantee of Digital Rights, when such request is made by the data protection authority of the respective Autonomous Community. 7. The Contentious-Administrative Chambers of the High Courts of Justice shall be responsible for authorizing, by means of an order, the request for information by the autonomous data protection authorities to operators providing publicly available electronic communications services and providers of information society services, when this is necessary in accordance with specific legislation". A new paragraph 7 is added to Article 90: "7. The Central Contentious-Administrative Courts shall be responsible for authorizing, by means of an order, the request for information by the Spanish Data Protection Agency and other independent administrative authorities at the state level to operators providing publicly available electronic communications services and providers of information society services, when this is necessary in accordance with specific legislation." Sixth final provision: Modification of Law 29/1998, of July 13, 1998, regulating the Contentious-Administrative Jurisdiction. Law 29/1998, of July 13, 1998, regulating the Contentious-Administrative Jurisdiction, is amended as follows: A new paragraph 7 is added to Article 10: "7. They shall hear the request for authorization under Article 122 ter, when it is formulated by the data protection authority of the respective Autonomous Community." Two. A new paragraph 5 is added to Article 11: "5. It shall hear the request for authorization under Article 122 ter, when formulated by the Spanish Data Protection Agency." A new paragraph 4 is added to Article 12: "4. It shall hear the request for authorization under Article 122 ter, when formulated by the General Council of the Judiciary." Four. A new article 122 ter is hereby introduced, which shall read as follows: "Article 122b. Procedure for judicial authorization of conformity of a decision of the European Commission on international data transfer. 1. The procedure for obtaining the judicial authorization referred to in the fifth additional provision of the Organic Law on the Protection of Personal Data and Guarantee of Digital Rights, will begin with the request of the data protection authority addressed to the competent Court to rule on the conformity of a decision of the European Commission on the international transfer of data with the law of the European Union. The request shall be accompanied by a copy of the file pending before the data protection authority. 2. In addition to the data protection authority, the parties to the proceedings shall be those who were parties to the proceedings before it and, in any case, the European Commission. 3. The resolution of admission or inadmissibility of the proceeding will confirm, modify or lift the suspension of the proceeding for possible violation of data protection regulations before the data protection authority, from which this judicial authorization proceeding originates. 4. Once the application has been admitted for processing, the competent Court shall notify the data protection authority so that it may notify those involved in the proceedings before it so that they may appear within a period of three days. Likewise, the European Commission shall be notified to the same effect. 5. At the end of the period mentioned in the preceding paragraph, the request for authorization shall be forwarded to the parties so that within a period of ten days they may present their arguments as they deem appropriate, at which time they may request the taking of any evidence they deem necessary. 6. At the end of the evidentiary period, if either party has so requested and the court deems it appropriate, a hearing shall be held. The Court may decide the scope of the issues on which the parties shall focus their arguments at such hearing. 7. Once the procedures mentioned in the three preceding paragraphs have been completed, the competent Court shall adopt one of these decisions within ten days: a) If it considers that the European Commission's decision is in accordance with European Union law, it will issue a judgment declaring this to be the case and refusing the authorization requested. b) If it considers that the decision is contrary to European Union law, it shall issue an order referring the validity of the decision to the Court of Justice of the European Union for a preliminary ruling under the terms of Article 267 of the Treaty on the Functioning of the European Union. Authorization may only be granted if the European Commission decision in question is declared invalid by the Court of Justice of the European Union. 8. The regime of appeals shall be as provided in this Law." |
Switzerland
|
