Setting the scene
EU regulatory measures in the field of private law, such as the Unfair Contract Terms Directive, the Mortgage Credit Directive or the Antitrust Damages Directive, have been compared to islands in the ocean of national private law. This metaphor has been used to highlight the difficulties of integrating EU private law into national private law, given their different rationalities. The private law of the Member States has traditionally been primarily concerned with horizontal relationships and justice between private parties. In particular, the individual who has suffered from the breach of a private law norm by another individual can use the characteristic private law enforcement tools, such as a claim for damages. National private law, therefore, is underpinned by relational rationality, even though it may be influenced by policy objectives and have distributive implications. In contrast, EU private law has developed in a piecemeal and uncoordinated fashion across different sectors of the economy as a subset of market regulation to serve various policy goals, notably the establishment of the European internal market. Thus, while this body of law also affects horizontal relations between individuals, it is first and foremost informed by the instrumentalist rationality. Continue reading “Islands and the Ocean: Three Models of the Relationship between EU Market Regulation and National Private Law”
In 2021 members of the European Parliament passed a resolution to endorse the report of the Civil Liberties Committee. The report expresses an opposition to the use of predictive policing tools which operate on artificial intelligence (hereinafter AI) software in order to make predictions about the behaviour of individuals or groups “on the basis of historical data and past behaviour, group membership, location, or any other such characteristics.” (par. 24) This opposition is based on the fact that predictive policing tools cannot make reliable predictions about the behaviour of individuals. (par. 24) Additionally, the report notes that AI applications have a potential for reinforcing bias and discrimination. (par. 8) Although this resolution is non-binding, Melissa Heikkilä believes that it conveys a message of how the European Parliament is likely to vote on the AI Act. There is a need for a legally enforceable ban on the use of AI predictive policing tools in respect of human beings. As discussed below, the use of AI can lead to inaccurate assessments due to the inherent character of the data. The basing of decisions on group data is inconsistent with protecting individuals from discrimination.
Continue reading “A ban on using predictive policing to forecast human behaviour: a step in the right direction”
The CJEU decision in the FBF case involves many crucial elements of EU law, all of which deserve careful consideration. Among the others, the decision touches upon the nature and the justiciability of soft law measures in the EU legal framework, the ESAs’ power to adopt them, and the relationship between corporate governance and product governance in the financial sector. In this blogpost, we concentrate only on some of these implications. In particular, we look at the general impact of the decision on the non-delegation doctrine, at the uncertainties surrounding the delegation of powers concerning broad matters such as corporate governance in the past and in the future regulatory framework and, finally, at how such uncertainties should guide the allocation of the power to review soft law measures. We suggest that the system of controls deserves our attention and reconsideration to adjust to the new realities of proliferation of soft, technical but also shared (enforcement) administration in the EU. This blog post is based upon the discussion speeches that the authors delivered in the online discussion organised by JMN EULEN (RENFORCE) in August 2021.
Continue reading ““The past is the past. The future is all that’s worth discussing” (Lord Baelish, The Game of Thrones). Some reflections on the non-delegation doctrine and its impact on the ESAs powers after the CJEU decision on the FBF case”
The July 2020 judgement of the Court of Justice of the European Union (CJEU) in the so-called Schrems II case has resulted in a great deal of uncertainty for organizations engaging in the transnational transfer of personal data and in particular when those transfers are to entities in the United States. This post will investigate the enforcement issues on which the Schrems II reasoning is based, and discuss the potential effects that the decision has for General Data Protection Regulation (GDPR) enforcement.
Schrems II is the most recent installation of an ongoing litigation that resulted from a complaint that Maximilian Schrems levied against Facebook with the Irish Data Protection Commissioner (DPC) in 2013. Schrems’ complaint objected to Facebook transferring personal data to the United States (US) as contrary to the protections provided by the GDPR. It was based in part on the US National Security Agency (NSA) documents leaked by Edward Snowden in the summer of 2013. These documents revealed a mass surveillance program run by the NSA under Sec. 702 of the Foreign Intelligence Surveillance Act (FISA). This surveillance included direct collection from major US telecommunication providers, internet service providers, and Internet content providers under a program code named PRISM. Schrems’ complaint was rejected by the DPC and Schrems sought judicial review. It eventually led to an assessment of data protection adequacy decisions specifically regarding transfers to the US. The CJEU twice in Schrems I and Schrems II struck down adequacy decisions with the United States.
Continue reading “Schrems II and the Data Protection Enforcement Gap”
Since 2012, the European Commission has taken numerous steps in order to shape to EU’s digital future. One of these steps included the adoption of the General Data Protection Regulation (GDPR) which entered into force in May 2018. The GDPR aims to protect, in particular, the right of natural persons to the protection of personal data. At the end of 2020, the Commission went a step further and published its proposal for the Digital Services Act (DSA). As part of the EU’s Digital Strategy, it contains provisions to update the e-commerce legal framework.
Infringements of both the GDPR and the DSA do not stop at the Member States’ borders. An incident at Twitter, for instance, led to a situation where Twitter users had their Tweets, dating back to 2014, publicly accessible without their knowledge. This breach of the GDPR affected at least 88.726 EU and EEA Twitter users all across the continent. For this reason, it is essential that national authorities of different Member States cooperate in order to adequately enforce such breaches. Cooperation is fundamental here because it enhances the enforcement capacity and quality (van der Heijden 2016) – e.g., when investigating and sanctioning infringements that take place in multiple Member States, authorities can benefit from sharing resources and knowledge, which also speeds up the enforcement process. Keeping enforcement mainly the responsibility of national authorities, also respects the Member States’ desire to keep these competences at national level and it offers functional benefits since national authorities often have better access to information at national level (Hofmann 2008; Coen and Thatcher 2008; Eberlein and Grande 2005. Börzel and Heard-Lauréote 2009). Therefore, both the GDPR and the DSA provide that national authorities of different Member States cooperate, under the coordination of an EU body. Nevertheless, the GDPR experience proved that enforcement of cross-border infringements is not an easy task and the complexity of such structures could even lead to under-enforcement.
This blogpost aims to shed light on the complex enforcement procedures and speculates as to whether the Commission has learnt any lessons from the enforcement challenges that materialize under the GDPR. In order to assess the potential of the DSA enforcement structure, we discuss the horizontal (national authorities cooperating) and vertical (national authorities cooperating with an EU body) enforcement procedures of both systems, and the challenges that arise under the GDPR system.
Continue reading “The DSA Enforcement Framework, Lessons Learned from the GDPR?”
The European arrest warrant, now in force for nearly two decades has continued to show success in the objective supporting judicial cooperation without hindering free movement within the Union. Its successes indicate what may be expected to manifest as a safer Union and safer Member States. However as with any legal instrument, particularly one implemented across 27 individual nations, its use is not without difficulties. In the spirit of the European Law Enforcement blog, this post will highlight a few of the enforcement measures, stemming from various approaches, being invoked to ensure the proper enforcement of this enforcement mechanism.
Continue reading “Assessing and Enforcing Compliance with the Framework Decision on the European Arrest Warrant”
Shared direct enforcement of EU laws is a relatively new phenomenon in the EU. If the default rule of enforcing EU laws at the national level faces challenges, it is logical to enhance the regulation of national enforcement and/or the exercise of enforcement stages at the same level where EU rules are established (functional policy cycle over spillover). Hence, we witness a proliferation of EU enforcement authorities (EEAs) which can enforce EU laws directly vis-à-vis private actors themselves or together with national competent authorities. This development prompts to address the question of control over actions and decisions resulting from this EU shared direct enforcement. This blog post argues that the EU shared enforcement necessitates aligning of the systems of controls (EU-national, national-national) and creating ‘joint controllers’. It uses the logic of the ‘Meroni+’ (non-) delegation doctrine to support its argument. It concludes with three recommendations for assessing and (re)designing controls for EU shared enforcement.
Continue reading “Recommendations for ensuring controls for shared enforcement in the EU”
On January 15, the Dutch government was forced to resign amidst a scandal around its child-care benefits scheme. Systems that were meant to detect misuse of the benefits scheme, mistakenly labelled over 20,000 parents as fraudsters. More crucially, a disproportionate amount of those labelled as fraudsters had an immigration background.
Amongst the upheaval, little attention was brought to the fact that the tax authority was making use of algorithms to guide its decision-making. In a report by the Dutch Data Protection Authority, it became clear that a ‘self-learning’ algorithm was used to classify the benefit claims. Its role was to learn which claims had the highest risk of being false. The risk-classification model served as a first filter; officials then scrutinized the claims with the highest risk label. As it turns out, certain claims by parents with double citizenship were systematically identified by the algorithm as high-risk, and officials then hastily marked those claims as fraudulent.
It is difficult to identify what led the algorithm to such a biased output, and that is precisely one of the core problems. This blogpost argues that the Dutch scandal should serve as a cautionary lesson for agencies who want to make use of algorithmic enforcement tools and stresses the need for dedicated governance structures within such agencies to prevent missteps.
Continue reading “The Dutch benefits scandal: a cautionary tale for algorithmic enforcement”
It seems to be a given by now that shared administrations are increasingly used in the EU to ensure an effective implementation of Union law. However, the administrative reality of shared administrations still seems ahead of the legal and judicial reality. Shared administrations result in decisions based on often complex composite administrative procedures involving administrative authorities from both the EU and national legal orders. However, there is no single uniform set of EU administrative standards and the judicial orders are still relatively separate. The different administrative authorities involved may thus be subject to different administrative standards and, due to the relatively separate judicial orders, it is often uncertain in what manner effective judicial protection can be ensured. The extent to which an effective legal control is possible is thus questionable in case of composite administrative procedures. In this blog post, which is based on my new book ‘Effective Legal Protection in Banking Supervision. An Analysis of Legal Protection in Composite Administrative Procedures in the Single Supervisory Mechanism’ (Europa Law Publishing 2021), I will be addressing this question on the example of the Single Supervisory Mechanism (SSM). I have looked for a middle ground that ensures effective legal protection in composite procedures in such a way that persons’ rights are safeguarded without unnecessarily hampering the supervisors’ effectiveness. Although this is not such an easy task, it seems possible nonetheless.
Continue reading “Effective legal protection in the composite procedures of the SSM”
This blog post is based on the discussion that took place on January 29, 2021, within the JMN EULEN online lunch meetings.
Maciej Bernatt (chairing the discussion): The COVID 19 crisis has brought challenges to the proper functioning of the EU Single Market. These challenges include, among other things, export restrictions among the EU Member States and the closing of borders affecting the free movement of people, products, and food supply. While many of these measures were arguably justifiable, some of them could in practice be protectionist in nature and thus undermine the very foundation of the EU Single Market. The question is how the EU and the EU Member States should deal with the crisis situation and yet ensure the values and freedoms of the EU Single Market. In this context, it is also crucial to ask about the permissibility and the legality of the restrictions imposed by Member States.
Continue reading “To what extent is the EU Single Market resilient?”