Misgivings rise as EU-US agreement unravels under scrutiny
Summary
Simon McGarr, a Dublin solicitor who was part of the case brought by Austrian student Max Schrems that resulted in the striking down of the Safe Harbour agreement in October 2015, argued that Privacy Shield was little more than a stalling tactic. Privacy Shield, he wrote, is a noisy trumpet blast aimed at just one audience, designed to give the European Commission more time, before Europe’s data protection commissioners – represented by the Article 29 working party – start to enforce the law. McGarr raised a crucial question with Computer Weekly: Why has not a single one of the group of 29 EU data controllers, including Christopher Graham the UK information commissioner, done anything to impose the law since the Schrems judgement in October last year? That judgement, in effect, indicted the US for engaging in “indiscriminate mass surveillance” using Prism, a program used by the US National Security Agency to access the private data of UK and European citizens held by nine of the US internet giants. In April 2014, Anthony May, the then investigatory powers commissioner, told David Cameron in his annual report that “warrantless interception of emails is a criminal offence.” The Prism program, which gives the NSA access to data held by Apple, Microsoft (including Outlook), Google, Facebook, Yahoo, YouTube, Paltalk, AOL and Skype, has not obtained warrants from any European government.