Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part VIII Addendum

Video download link



Summary: The letter or the press release issued half a year ago explains the severity of the scandal we've been dealing with in recent days and will likely deal with well into April

APPENDICES or addenda typically come at the end of a series, but this time we'd like to interject for a bit, especially when covering pertinent documents alluded to previously albeit not discussed in an in-depth fashion.



"The above text says nothing about security incidents, which may compromise data and render it accessible to virtually everybody in the world."This one merits further emphasis and an explanation of context/s.

The video above is an informal discussion about this press release [PDF] which is only half a year old. It was mentioned in Part VIII and its text is as follows (we also have an HTML version here):



711.424.1

Press Release

17 July 2020

After “Schrems II”: Europe needs digital independence



After the adequacy of the “EU-US Privacy Shield” was invalidated by a recent decision issued by the Court of Justice of the European Union (CJEU), the Berlin Commissioner for Data Protection and the Freedom of Information, Maja Smoltczyk, is now calling on data processors in Berlin to move any personal data stored in the USA to Europe.

In its decision of 16 July 2020 (“Schrems II”, C-311/18), the CJEU stated that the US authorities’ access to data belonging to European citizens is too extensive. As a result, personal data may generally no longer be transferred to the USA until the legal situation changes. There are some exceptions, especially in special cases stipulated by law, such as when booking a hotel room in the USA.

One of the findings noted in the CJEU decision concerns the government surveillance measures in the USA, which involve the mass collection of personal data with no clear limitations. This contradicts the Charter of Fundamental Rights of the European Union (Paragraph 180 et seq. of the Decision). The CJEU also indicates that European citizens are unable to request a judicial review of the surveillance measures carried out by the US authorities. This violates the European fundamental right to effective legal protection.

Personal data may only be transferred to third countries that ensure a level of data protection that is equivalent to the essence of the European fundamental rights. As the findings of the highest European court suggest that is not the case in the USA, the decision issued by the CJEU has invalidated the adequacy of the “EU-US Privacy Shield”, which was previously the basis for many personal data transfers to the USA. By contrast, the CJEU has ruled that “standard contractual clauses” are admissible under certain conditions; standard contractual clauses can be established between European companies and providers in third countries to ensure the European level of data protection abroad. Before the first data transfer, however, the CJEU emphasises that both European data exporters and third-country data importers are obliged to check whether the data could potentially be accessed by government authorities in the third country in a manner that goes beyond the access rights granted under European law (Paragraphs 134 et seq. & 142 of the Decision). If such rights of access are enjoyed by the government authorities, data may not even be exported on the basis of standard contractual clauses. Any data that has already been transferred to any such third countries must be retrieved. Contrary to the prevalent practice to date, data cannot be exported merely on the basis of standard contractual clauses (Paragraph 126 et seq. of the Decision).

Press Officer: Dalia Kues

Office: Cristina Vecchi

Email: presse@datenschutz-berlin.de

Friedrichstr. 219 D-10969 Berlin

Tel.: +49 301 388 9900 Fax: +49 302 155 050




The CJEU emphasises that the data protection supervisory authorities must prohibit unlawful data exports according to these new standards (Paragraphs 135 & 146 of the Decision), and that data subjects may claim damages for the unlawful exportation of personal data (Paragraph 143 of the Decision). This may especially include non-material damage (solatia); the amount of compensation must act as a deterrent in accordance with European law.

The Berlin Commissioner for Data Protection and the Freedom of Information calls on all controllers under her supervision to observe the CJEU’s decision. Controllers who transfer personal data to the USA, especially when using cloud-based services, are now required to switch immediately to service providers based in the European Union or a country that can ensure an adequate level of data protection.

Maja Smoltczyk: “The CJEU has made it refreshingly clear that data exports are not just financial decisions, as people’s fundamental rights must also be considered as a matter of priority. This ruling will put an end to the transfer of personal data to the USA for the sake of convenience or to cut costs. Now is the time for Europe to become digitally independent.

The CJEU has explicitly obliged the supervisory authorities to prohibit all unlawful data transfers, and we gladly accept the challenge. Of course, that not only applies to data transfers to the USA, which have already been outlawed by the CJEU; we must also check whether similar or perhaps even greater problems are involved in data transfers to other countries, such as China, Russia or India”.



The above text says nothing about security incidents, which may compromise data and render it accessible to virtually everybody in the world. It happened many times in the past. The very practice of outsourcing data -- no matter if within one's national jurisdiction or outside it -- is a bad idea. They just need to hire competent security professionals, employed in-house and regulated by rules and regulations of the employer, not only national laws.

In light of new revelations we expect this scandal and its coverage to last well into springtime. This is a very big deal, not just to the EPO and to Microsoft. More people are becoming involved now.

Recent Techrights' Posts

[Meme] Plagiarism Does Not Eliminate Jobs by Replacing Humans, It Replaces Human Knowledge With False Cruft
We need to boycott sites that fake their output
[Meme] Doing Dog's Job (Not God's Job)
The FSF did not advertise the talk by RMS (its founder), who spoke in France almost exactly 23 hours ago
[Meme] Free Software and Socially-Engineered Groupthink (to Serve Big Sponsors Like Google and Microsoft)
They do this to RMS all the time
 
Red Hat Dumps "Inclusive Language", Puts "Master" In Official Communications and Headlines
Red Hat: you CANNOT say "master" (because it is racist). Also Red Hat: we put in it our headlines.
Red Hat Offers DRM, TPM, and Backed Doored 'Confidential' Containers (CoCo) for Microsoft (Proprietary Spyware)
No kidding!
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 21, 2025
IRC logs for Tuesday, January 21, 2025
Gemini Links 21/01/2025: Media Provocations and Nazis Not Tolerated
Links for the day
Slopwatch: BetaNews Plagiarism and LLM Slop by UNIXMen
"state-of-the-art" plagiarism
What Fedora, OpenSUSE, and Debian Elections Teach Us About the State of Weak (or Fake) Communities
They show a total lack of trust in these communities
Links 21/01/2025: Mass Layoffs in "Security" at Microsoft (Despite Microsoft Promising It Would Improve After Many Megabreaches), Skype is Dead (Quietly)
Links for the day
Alternate Version of Daniel Pocock's 2024 Talk, "Technology in European Parliament Election Campaign"
There's loud ovation at the end of the talk
Gemini Links 21/01/2025: London Library, Kobo Sage, and Beyerdynamic DT 48 E
Links for the day
The January 20 Public Talk by Richard Stallman (Around Midday ET), Livestream 'Assassinated' by Google's YouTube
our guess is that the 'cancel mob' sabotaged it, possibly by making a lot of false reports to YouTube
[Video] Daniel Pocock's Public Talk About Free Software Politics, Social Engineering, Debian Deaths and Suicides, Coercion and Exploitation of Women
took many months to get
BetaNews Cannot Survive If Its Fake Articles Are Just SPAM for Companies Like AOHi and Aren't Even Composed by Humans
This is what domains or former "news" sites do when they die and look very desperately for "another way"
Pocock shot in the face, shot in the back, shot on Hitler's birthday saving France, Belgium and FOSDEM
Reprinted with permission from Daniel Pocock
Dr Richard Stallman in Montpellier, Robert Edward Ernest Pocock in France
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 20, 2025
IRC logs for Monday, January 20, 2025
Links 20/01/2025: Conflict, Climate, and More
Links for the day
Gemini Links 20/01/2025: Conflicted Feelings and Politics
Links for the day
Daniel Pocock's ClueCon 2024 Presentation Was Also Streamed Live in YouTube and Later Removed by Google, Citing "Copyrights". Now It's Back.
The talk covers social control media, Debian, politics, and more
Google 'Cancels' RMS
Is the talk happening?
Microsoft Revisionism Debunked by Microsoft's Own Words About “the Failure of OS/2”
The Register on “the failure of OS/2”
Improving Daily Links by Culling Spam, Chaff, and LLM Slop
the Web is getting worse
Links 20/01/2025: Indonesia to Prevents Kids' Access to Social Control Media (Addiction and Worse), Climate News Catchuo
Links for the day
[Meme] EPO Targets
Targets mean nothing if or when you measure the wrong thing
EPO Union Says Monopoly-Granting Targets at EPO "Difficult to Achieve Without Compromising [Staff] Health, Personal Time or the Quality of the Final Products" (Products as in Monopolies, Not Real Products)
To those of us (over 99.999% of people impacted by this) who do not work at the EPO the misuse of words like "products" (monopolies are not products) should be disturbing
The EPO is Nowadays Trying to Trick Staff Into Settling Instead of Solving the Underlying Problems of Corruption and Injustice
This seems like a classic case of "divide-and-rule" or using misled/weak people to harm the whole group (or "the village")
Links 20/01/2025: More PR Stunts by ByteDance and MLK’s Legacy Disrespected
Links for the day
Gemini Links 20/01/2025: Magnetic Fields, NixOS, and Pleroma
Links for the day
BetaNews Spreads Donald Trump Propaganda, Promotes Scams, and Publishes Fake 'Articles' About "Linux"
This is typical BetaNews
Richard Stallman 'Unveils' His January 20 Talk in Montpellier, France
It's free (gratis)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 19, 2025
IRC logs for Sunday, January 19, 2025