觀點Meta

Meta’s fine has repercussions for EU-US data flows

Brussels and Washington need to find a route to a workable legal framework

The €1.2bn fine on Meta this week is the biggest ever imposed under EU data protection rules. The Facebook owner hardly has a blameless record, and has been fined before over lax privacy protections, including $5bn by US regulators in 2019 over the Cambridge Analytica scandal. Yet in this case Meta — like scores of other companies — is caught in a mismatch between EU and US law. The decision against it signals in effect that there is no functioning legal basis for Meta to do what it has been doing: transferring EU user data to the US. Unless a new attempt to create a framework to bridge the legal gap succeeds, the implications for tech firms, consumers and the internet are far-reaching.

The crux is that EU law since 1995 has prohibited transfers of personal data to third countries unless they offer “adequate” levels of data protection. But the EU imposes much higher protections than the US, reinforced by its 2018 General Data Protection Regulation and a charter of fundamental rights. As the Snowden leaks of US intelligence a decade ago exposed, it is easier under US legislation for law enforcement agencies to access users’ data — and more difficult for consumers to seek redress.

The European Court of Justice has struck down two successive EU-US frameworks designed to facilitate legal personal data transfer — Safe Harbor, and Privacy Shield — after challenges to Facebook’s practices by an Austrian privacy activist, Max Schrems.

您已閱讀38%(1448字),剩餘62%(2328字)包含更多重要資訊,訂閱以繼續探索完整內容,並享受更多專屬服務。
版權聲明:本文版權歸FT中文網所有,未經允許任何單位或個人不得轉載,複製或以任何其他方式使用本文全部或部分,侵權必究。
設置字型大小×
最小
較小
默認
較大
最大
分享×