April 8, 2013
European Union regulators have taken their first step to making good on their recent threat to take “repressive action” against Google by summer.
But what, exactly, is likely to happen?
Though crystal balls are of little use in predicting what the 27 EU member states may do, a recap of Google’s latest dispute with the EU, and a review of EU data protection enforcement authorities, may provide some clues.
Even before the policy went into effect, the Working Group, comprised of EU member country Data Protection Authorities (“DPAs”), publicly urged Google to delay putting the policy into effect until the Working Group could carefully review it. Google refused to delay implementation of the policy and, at the request of the Working Group, the French national DPA, the CNIL, took the lead in investigating Google’s new policy.
In late February 2012, the CNIL made a preliminary finding that Google’s policy violated the key EU privacy law, the Data Protection Directive ((Directive 95/46/EC, the “DPD”). The CNIL then sent Google several letters of inquiry and asked them not to implement the policy. Google responded to the CNIL’s questions but implemented the new policy over the CNIL’s objections and, at least in the CNIL’s opinion, failed to fully and sufficiently provide the requested information.
After the CNIL’s investigation, the Working Group found that Google’s policy violates a number of provisions of the EU Data Protection Directive and ePrivacy Directive, including requirements that: collection of personal data only be for limited purposes; users be fully informed about the intended uses of their data; and users be given the right to opt out. The regulators asked Google to make significant changes to its policy and threatened regulatory action if Google failed to make such changes in four months.
To date, Google has failed to make any significant changes, leading to the threat of “repressive action.” What might such action look like?
Although the EU strives for integration, the power to impose sanctions for privacy violations is, under current law, left to the member states. Under the DPD, EU member states are required to endow their individual DPAs with the power to investigate violations and impose sanctions and/or initiate legal proceedings. The Working Party itself can advise the EU Commission and issue opinions. Though these are not legally binding, they carry a great deal of weight with the individual Member State DPAs.
In its announcement (18 February), the EU data protection authorities said they would “coordinate their coercive actions… [which] should be implemented before the summer.” Then, after a two-day Working Group meeting, the regulators announced that Google would be called to appear before regulators as they prepare for coordinated enforcement actions.
The regulators have issued so many warnings to Google, and the issues raised are so integral to how Europeans view their fundamental human rights, that it is difficult to see how the EU regulators can back down. They likely will calculate – reasonably – that failure to act now will encourage similar actions by numerous other companies and strike a blow to meaningful deterrence of future privacy violations.
Enforcement and sanctions authorities and activities in EU member states vary widely, from Belgium, where the DPA has limited authority to impose fines, to Spain, which issues substantial fines, to Germany and France, which have substantial authority but use it in widely divergent ways depending in particular cases.
The types and severity of sanctions available to DPAs, depending upon individual national laws, can include, in increasing severity: relatively informal guidance; recommendations; investigations; formal warnings; administrative sanctions (monetary fines); public admonishment; blocking of data processing or transfers; and, finally, criminal sanctions.
It seems likely, then, that, without accommodation by Google, the Article 29 Working Group will coordinate enforcement actions by at least some member states by summer. It is at least possible that some member states will attempt to make an example of Google, and deter other companies, by imposing unusually high fines, and possibly impose injunctive remedies, such as legally prohibiting processing of data found to violate EU privacy law. Given the EU member states’ history, however, it seems highly unlikely that any Google officials will be subjected to criminal process.
Bryan Cunningham is an independent information security and privacy lawyer and a Senior Adviser to the Chertoff Group, where he advises clients on information security, data privacy and data protection programmes. He served previously in senior intelligence and law enforcement positions in the US government in both the Clinton and Bush Administrations.
[NOTE: This article first appeared on euobserver.com.]safegoveu