1/73 Litigation Chamber Decision on the merits 61/2023 of 24 May 2023 This decision was annulled by the judgment 2023/AR/8010 of 20 December 2023 of the Brussels Court of Appeal (Market Court), which
the processing of personal data (hereinafter LTD); Having regard to the internal regulations as approved by the Chamber of Representatives on 20 December 2018 and published in the Belgian Official Gazette on 15 January 2019; Having regard t o the documents in the file; has made the following decision regarding: The plaintiffs: Mr X, Hereinafter referred to as "the first plaintiff"; 0 By interlocutory judgment 2023/5139 of 28 June 2023, the Brussels Court of Appeal (Market Court) granted the request for suspension of the decision of the FPS Finances. Decision on the merits 61/2023 2/73 The non-profit association Accidental Americans Association of Belgium (AAAB), with registered offices at clos Albert Crommelynck, 4 bte 7, 1160 Brussels, Hereinafter referred to as "the second plaintiff"; Hereinafter referred to jointly as "the plaintiffs"; Both having as their counsel Vincent Wellens, lawyer, with offices at Chaussée de la Hulpe, 120, 1000 Brussels. The defendant: The Federal Public Service Finance (FPS Finance), with registered offices at Boulevard du Roi Albert II, 33, 1030 Brussels, Hereinafter referred to as "the defendant"; Having as its counsel Jean-Marc Van Gyseghem, lawyer, with offices at Boulevard de Waterloo, 34, 1000 Brussels. Decision on the merits 61/2023 3/73 Contents I. FACTS and BACKGROUND to the PROCEDURE ................................................................................ 4 I.A. The relevant facts .................................................................................................................... 4 I.B. Background to the procedure ................................................................................................. 9 I.B.
- Admissibility of the complaint................................................................................................ 9 I.B.
- The subject of the complaint................................................................................................ 10 I.B.
- The investigation of the Inspection Service ......................................................................... 11 I.B.
- The follow-up investigation of the Inspection Service ......................................................... 13 I.B.
- Examination of the merits by the Litigation Chamber ......................................................... 14 I.B.
- The arguments of the parties ............................................................................................... 16 I.B.6.
- Position of the plaintiffs .................................................................................................... 16 I.B.6.
- Position of the defendant .................................................................................................. 22 I.B.6.
- Additional conclusions on the ruling of the Constitutional Court of 9 March 2017 .......... 26 I.B.
- The hearing of the parties .................................................................................................... 28 II. JUSTIFICATION ............................................................................................................................... 28 II.A.
the competence of the Litigation Chamber of the DPA ...................................... 29 II.B.
the sovereign judgment of the Litigation Chamber ............................................ 30 II.C.
the status of the defendant as controller............................................................ 30 II.D.
Article 96
of the GDPR ......................................................................................... 32 II.D.1.
the material scope of Article 96 of the GDPR .............................................. 33 II.D.2.
the temporal scope of Article 96 of the GDPR ............................................ 34 II.E.
the grievances reported ...................................................................................... 39 II.E.1.
the conformity of the transfer of data to the IRS ........................................ 39 II.E.1.1.
the infringements of the principles of purpose, necessity and minimisation .................................................................................................................................. 40 II.E.1.2.
compliance with the rules governing transfers to the IRS ...................... 44 II.E.1.3. Conclusion
the conformity of the transfer of data to the IRS ................. 51 II.E.2.
the reported breach of the obligation to provide information ................... 52 II.E.3.
the reported breach of the obligation to perform a DPIA........................... 59 II.E.4.
the reported breach of accountability ........................................................ 64 II.E.5.
the reported breach of Article 20 of the LTD .............................................. 65 II.F. III. Corrective measures and sanctions ...................................................................................... 67 PUBLICATION AND TRANSPARENCY .......................................................................................... 70 Decision on the merits 61/2023 4/73 I. FACTS and BACKGROUND to the PROCEDURE
- On 22 December 2020, the plaintiffs filed a complaint with the Data Protection Authority (DPA) against the defendant. The complaint denounced the unlawfulness of the transfer of personal data relating to the first plaintiff, as well as relating to accidental Americans in Belgium (whose interests are defended by the second plaintiff) by the defendant to the US tax authorities in the context of the intergovernmental FATCA agreement concluded between Belgium and the United States, as well as other infringements of the GDPR attributable to the defendant in this context.
- The facts giving rise to the complaint are set out below in points 3 to 23, followed by the background to the procedure leading up to this decision (points 24 to 111). I.A. The relevant facts
- The first plaintiff resides in Belgium and holds dual Belgian and American nationality. With regard to the latter nationality, the first plaintiff describes himself as an accidental American, since he has American nationality only by virtue of having been born in the United States, at Stanford, without having subsequently retained any significant ties with that country. The plaintiff resides in Belgium.
- The second plaintiff is a Belgian non-profit association (ASBL) whose purpose is to defend and represent the interests of individuals with Belgian-American nationality - such as the first plaintiff - who reside outside the United States. The purpose of the association is described as follows in article 4 of its articles of association dated 28 September 2019 (paraphrased): "The purpose of the association is to defend the interests of natural persons of American nationality residing outside the United States, against the harmful effects of the extraterritorial nature of US legislation. The association pursues the realisation of its purpose by all means of action and in particular by: - representing the interests of members before the Belgian and American public authorities and before the European institutions - producing communication media - organising events - working with law professors to provide legal information for members' use - legal action to defend the interests of Belgian-American nationals The means listed above are indicative and not exhaustive". Decision on the merits 61/2023 5/73
- On account of his US nationality, the first plaintiff is considered to be subject to the control of the US tax authorities under US tax law. Indeed, this system is based on the principle of taxation based on nationality, and applies to accidental Americans as it does to any other taxpayer based on US territory or having activities in relation with this country; the fact that they do not reside in the United States is irrelevant. Only certain exceptions apply to non-residents on US territory.
- In order to facilitate the collection of relevant information by the Internal Revenue Service (IRS) with a view to the possible taxation of Americans residing abroad (including accidental Americans such as the first plaintiff), the US government has entered into intergovernmental agreements with various states around the world. Under these agreements, domestic financial institutions (such as banks) are required to communicate data relating to these Americans who reside abroad, to the domestic tax authorities (such as the defendant), which are then required to transfer this data to the IRS.
- This is the context of the "Agreement between the Government of the Kingdom of Belgium and the Government of the United States of America to improve International tax compliance and to implement Fatca", signed by representatives of the Governments of the Kingdom of Belgium and the United States of America on 23 April
- This agreement is commonly referred to as the "FATCA agreement".1 It implements the US Foreign Account Tax Compliance Act, from which the acronym FATCA is derived. A comparable bilateral intergovernmental agreement has also been signed with various countries around the world, including the member states of the European Union (hereinafter EU).
- For its part, the Belgian Act of 16 December 2015 regulating the communication of information relating to financial accounts by Belgian financial institutions and the FPS Finance, in the context of an automatic exchange of information at the international level and for tax purposes (hereinafter the Act of 16 December 2015) invoked by the defendants in several aspects, is part of the more general context of the exchange of tax data between countries, including but also - beyond the sole exchanges with the IRS pursuant to the above-mentioned FATCA agreement.
- The purpose of this legislation, as defined in Article 1, is to regulate the obligations of Belgian financial institutions and the defendant with regard to the information which must be communicated to a competent authority of another jurisdiction in the context of an automatic exchange of information relating to financial accounts, organised in accordance with the commitments made by the Belgian State and resulting from the legal texts below: - Council Directive 2014/107/EU of 9 December 2014 amending Directive 2011/16/EU
mandatory automatic exchange of information in the field of taxation 2; 1 This intergovernmental agreement, FATCA, which was signed with Belgium, was the subject of a law of assent on 22 December 2016. 2 Council Directive 2014/107/EU of 9 December 2014 amending Directive 2011/16/EU
mandatory automatic exchange of information in the field of taxation, OJ 2014, L 359/
- Decision on the merits 61/2023 6/73 - The Joint OECD/Council of Europe Convention on Mutual Administrative Assistance in Tax Matters of 25 January 1988 (the Multilateral Convention or "the Convention"); - A bilateral agreement for the avoidance of double taxation on income; - A bilateral treaty on the exchange of tax information (such as the FATCA agreement).
- The Act of 16 December 2015 came into force on 10 January 2016 with regard to information intended for the United States (Article 20)
- On 22 April 2020, the first plaintiff received a letter from Bank Z, with which he has bank accounts. The subject of this letter was (freely translated): "Confirmation of your status as a US Person in the context of Fatca and other regulatory purposes". The plaintiff was requested to confirm that he is neither a US citizen nor resident in the United States, for the purposes of the obligations incumbent on Bank Z under the applicable regulations on the automatic exchange of information. The plaintiff was invited to complete a specific form issued by the US authorities for this purpose. The letter explains that the objectives of the US legislation are to identify all accounts held by US citizens and/or residents with non-US financial institutions, and to exercise greater control over the income and securities held by Americans. The letter specifies that if the signed and completed document is not returned, the law obliges the bank to consider the first plaintiff as a "US Person" by default: consequently, his contact details and information on his assets, income and gross proceeds will continue to be communicated to the relevant tax authorities. Finally, the letter specifies that if the first plaintiff is a US citizen or resident, he must report to the agency to complete the necessary formalities.
- On 12 May 2020, the first plaintiff was informed by Bank Z that since he had several bank accounts in Belgium in 2019, these were subject to the obligation to make a declaration to the defendant, pursuant to the legal obligations incumbent on banking institutions with which tax residents of a country other than Belgium have one or more bank accounts, as is his case.
- In this second letter, Bank Z informs the first plaintiff that it is obliged to declare the following data to the defendant: the name, address, jurisdiction where the person is a resident, tax identification number (TIN) or date of birth of each person subject to a declaration, account number(s), account balance or value as of 31 December (special case: if the account is closed, a zero amount is reported), interest, dividends, proceeds from the sale, redemption or repayment of financial audits and other income from financial assets held in the account.
- Bank Z encloses with this letter the details of the first plaintiff, which will be communicated to the defendant in compliance with this reporting obligation. 3 The Act of 16 December 2015 was published in the Belgian Official Gazette on 31 December
- Article 20 of the Act stipulates that it will come into force 10 days after its publication,
information destined for the United States. Decision on the merits 61/2023 7/73 15. This letter of 12 May 2020 makes no reference to the FATCA agreement. In addition to the list of details cited above and information on the principle of automatic exchange of financial information to which Bank Z risks being subject, the first plaintiff is referred to the defendant for any questions, as follows (freely translated): "For further information on the automatic exchange of financial information, please consult the website of the FPS Finance or the OECD. You can also call us at XXX". 16. In a third letter dated 18 May 2020, Bank Z again contacted the first plaintiff and (
- a)this time explains in general terms the principle of the FATCA agreement, (
- b)lists the information to be communicated in this context and (
- c)indicates that as soon as the plaintiff had one or more accounts subject to the declaration obligation in 2019, it is obliged to communicate them to the competent tax authorities. Bank Z states that for further information on the FATCA agreement, the first plaintiff can call his bank at the telephone number indicated. 17. On 22 December 2020, the same day he filed a complaint with the DPA along with the second plaintiff (complaint no. 1 - point 1), the first plaintiff requested that the defendant delete the personal data it had obtained from the banks pursuant to the FATCA agreement, under Article 17
(1)(d) of the GDPR. The first plaintiff also requested that the defendant take the necessary steps to obtain this erasure from the IRS or, failing that, the restriction of the processing thereof pursuant to Article 18
(1)(b) of the GDPR. In any event, the first plaintiff is calling for the immediate cessation of the exchange of information between the defendant and the IRS that takes place every year pursuant to the FATCA Agreement: in his view, this transfer of personal data concerning him infringes various key principles of personal data protection law as applicable in Belgium and more generally within the EU. The second plaintiff is making the same claim in its own name, for the benefit of accidental Americans in Belgium, in accordance with its articles of association. 18. More specifically, the plaintiffs substantiate their claim on the following grounds: the unlawfulness of the transfer of personal data to the IRS under the FATCA agreement (in breach of Articles 45, 46 and 49 of the GDPR); non-compliance with the principles of purpose limitation (Article 5
(1)(b) of the GDPR), proportionality and data minimisation (Article 5
(1)(c) of the GDPR) and storage limitation (Article 5
(1)(e) of the GDPR); failure to comply with the principle of transparency (Articles 12 to 14 of the GDPR) and a breach of the obligation to carry out a data protection impact assessment (DPIA - Article 35 of the GDPR). The letter details each of the alleged grievances. As these are also the basis of the complaint lodged with the DPA, they will be explained below when the Litigation Chamber discusses the respective viewpoints of the parties, including those of the plaintiffs (points 54 et seq.).
- In its reply of 30 March 2021, the defendant refused to entertain the plaintiffs' request, arguing that there the allegations of unlawfulness were baseless. The defendant thus stated that the legal basis for the transfers it makes is stipulated in the FATCA agreement, as well as in the Act Decision on the merits 61/2023 8/73 of 16 December
- The defendant also invoked Article 96 of the GDPR, and concluded in support of it that, if the plaintiffs cannot demonstrate how the FATCA agreement infringed EU law prior to 24 May 2016, there is no basis for their claims. The defendant also refuted all the other allegations made against it.
- To properly understand the decision, the Litigation Chamber cites Article 96 of the GDPR entitled "Relationship with previously concluded Agreements", which provides as follows: "International agreements involving the transfer of personal data to third countries or international organisations which were concluded by Member States prior to 24 May 2016, and which comply with Union law as applicable prior to that date, shall remain in force until amended, replaced or revoked".
- Following this response from the defendant, only the first plaintiff renewed his demand on 9 July 2021 , emphasising the fact that the said data transfers from the defendant to the IRS were also unlawful under Directive 95/46/EC.4
- In a decision dated 4 October 2021, the defendant refused to entertain the first plaintiff's demands, rejecting the arguments put forward by the latter with regard to the alleged infringements of both the GDPR and Directive 95/46/EC. For a proper understanding of the rest of its decision, the Litigation Chamber specifies that the defendant also considers under the terms of this decision (freely translated) "that in the present case, the condition of a basis resting on important reasons of public interest - within the meaning of Article 49
(1)(d) of the GDPR5 or Article 26
(1)(d)6 of Directive 95/46/EC] - is indeed fulfilled since the basis for the lawfulness of the disputed processing rests on an international agreement [i.e. the FATCA agreement] and the Act of 16 December 2015".
- An action for annulment was brought before the Council of State (CoS) against the administrative decision of the defendant. In their conclusions and at the hearing before the Litigation Chamber, the parties indicated that this action was still pending. They specified that the defendant had argued that the CoS should await the outcome of the procedure with the DPA before making a decision. The plaintiff, for his part, requested that preliminary rulings be referred by the CoS to the Court of Justice of the European Union (hereinafter CJEU) as to the 4 Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, OJ L 281/
- 5 Article 49
(1)(d) of the GDPR: "In the absence of an adequacy decision pursuant to Article 45
(3), or of appropriate safeguards pursuant to Article 46, including binding corporate rules, a transfer or a set of transfers of personal data to a third country or an international organisation shall take place only on one of the following conditions: [..] (d) the transfer is necessary for important reasons of public interest;" 6 Article 26
(1)(d) (Derogations) of Directive 95/46/EC: "By way of derogation from Article 25 and save where otherwise provided by domestic law governing particular cases, Member States shall provide that a transfer or a set of transfers of personal data to a third country which does not ensure an adequate level of protection within the meaning of Article 25
(2)may take place on condition that: [..] (d) the transfer is necessary or legally required on important public interest grounds, or for the establishment, exercise or defence of legal claims". Decision on the merits 61/2023 9/73 legal basis of the transfers made pursuant to the FATCA agreement, as to the admissibility of the application of Article 49
(1)(d) of the GDPR or, where applicable, its equivalent in Directive 95/46/EC, if Article 96 of the GDPR is applied, as well as with regard to compliance with the principles of transparency, purpose limitation, data minimisation and storage limitation as enshrined in the relevant articles of the GDPR or their equivalents in Directive 95/46/EC if the application of Article 96 of the GDPR were to be accepted. I.B. Background to the procedure
- As mentioned in point 1 above, the plaintiffs filed a complaint with the DPA on 22 December 2020 (complaint no. 1). I.B.
- Admissibility of the complaint
- On 22 March 2021, complaint no. 1, as it was filed by the first plaintiff, was declared admissible by the Front Line Service (FLS) of the DPA, pursuant to Articles 58 and 60 of the Act of 3 December 2017 establishing the Data Protection Authority (hereinafter LCA) and the complaint was forwarded to the Litigation Chamber pursuant to Article 62, § 1 of the LCA. 26.
complaint no. 1, as it was filed by the second plaintiff, was declared inadmissible on 12 February 2021 by the FLS of the DPA on the grounds that the second plaintiff did not meet the conditions set out in article 220.2. 3° and 4° of the Act of 30 July 2018 on the protection of natural persons
the processing of personal data (hereinafter LTD)
- The Litigation Chamber can confirm here that on 9 July 2021, the second plaintiff filed a new complaint (complaint no. 2). This complaint consisted of a rewording of its complaint no. 1 of 22 December
- The second plaintiff was more explicit in this complaint about its interest in taking action. It therefore states that it is acting in its own name, in accordance with its articles of association, and not in the name and on behalf of one or more Belgian accidental Americans. The second plaintiff therefore stated that it was not getting involved as a representative within the meaning of Article 80
(1)of the GDPR
- In its view, the conditions for applying this article as 7 Article 220 of the LTD: §
- (freely translated) The person concerned has the right to appoint a body, organisation or nonprofit association to lodge a complaint on their behalf and to exercise on their behalf the administrative or jurisdictional remedies either with the competent supervisory authority or with the judiciary, as provided for by specific laws, the Judicial Code and the Code of Criminal Procedure. §
- In the disputes referred to in paragraph 1, a body, organisation or non-profit association must: 1° be validly incorporated in accordance with Belgian law; 2° have legal personality; 3° have objectives in their articles of association in the public interest; 4° have been active in the field of protecting the rights and freedoms of data subjects in the context of personal data protection for at least three years. §
- The body, organisation or non-profit association shall provide proof, by presenting its activity reports or any other document, that it has actually performed its activity for at least three years, that the activity corresponds to its corporate purpose and that this activity is related to the protection of personal data. 8 Article 80
(1)of the GDPR "Representation of data subjects": The data subject shall have the right to mandate a not-forprofit body, organisation or association which has been properly constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest, and is active in the field of the protection of data subjects' rights and freedoms with regard to the protection of their personal data to lodge the complaint on his or her behalf, to exercise the Decision on the merits 61/2023 10/73 set out in article 220.
- 3° and 4° of the LTD, do not therefore have to be met. The second plaintiff, on the other hand, relies on article 58 of the LCA, which stipulates that (freely translated) "any person may file a written, dated and signed complaint or request with the Data Protection Authority". The second plaintiff considers itself entitled to lodge a complaint with the DPA on this basis, especially as the aim of its complaint is in line with its articles of association. It also argues that in its decision-making practice, the DPA, in support of decision 30/2020 of the Litigation Chamber for example, has recognised that there is broad interest in bringing an action, and that the possibility of lodging a complaint is not restricted to the natural data subjects, and that a complaint can be lodged by associations by virtue of their specific corporate purpose
- On 5 October 2021, this complaint n°2 was declared admissible by the FLS of the DPA on the basis of articles 58 and 60 of the LCA. This complaint was forwarded to the Litigation Chamber pursuant to article 62, § 1 of the LCA.
- In view of the foregoing, the Litigation Chamber specifies that, for the purposes of this decision, the use of the term "the complaint" refers to the two complaints filed (no. 1 and no. 2), which were joined by the Litigation Chamber (see point 47). I.B.
- The subject of the complaint
- The main purpose of the complaint lodged by the plaintiffs is to obtain, pursuant to Article 58
(2)(
- f)and (
- j)of the GDPR, the ban or even suspension of the transfer of data (the data of the first plaintiff and, beyond that, the data of all Belgian accidental Americans whose interests are defended by the second plaintiff) by the defendant to the IRS pursuant to the FATCA agreement. 31. Under the terms of their conclusions in reply (points 54 et seq. below), the plaintiffs added that, in the alternative, they were requesting that the Litigation Chamber order, pursuant to Article 58
(2)(
- f)and (
- j)of the GDPR, that the transfer of data on account balances by the defendant to the IRS in the context of the FATCA agreement be banned, or even suspended,
both the first plaintiff and the Belgian accidental Americans whose interests are defended by the second plaintiff. 32. During the hearing held before the Litigation Chamber10, the plaintiffs clarified that using the terms "ban or even suspension" is based on the exact wording of Article 58
(2)(
- f)and (
- j)of the rights referred to in Articles 77, 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf where provided for by Member State law. 9 In this respect, the Litigation Chamber refers to the note it adopted on the position of the plaintiff (French only) https://www.autoriteprotectiondonnees.be/publications/note-relative-a-la-position-du-plaignant-dans-la-procedure-ausein-de-la-chambre-contentieuse.pdf, in particular point B. (in fine) on page 2. It also refers to its decision 24/2022 and the references cited therein. 10 See point B of the minutes of the hearing of 10 January 2023. Decision on the merits 61/2023 11/73 GDPR, and does not imply a request for a temporary suspension of transfers but rather their outright cessation going forward. I.B.3. The investigation of the Inspection Service 33. On 20 April 2021, the Litigation Chamber commissioned the Inspection Service (hereinafter IS) to conduct an investigation, pursuant to articles 63, 2° and 94, 1° of the LCA. On the same date, in accordance with article 96, § 1 of the LCA, the Litigation Chamber's request to conduct an investigation was forwarded to the IS. 34. On 26 May 2021, the investigation of the IS was closed, the report was attached to the file and was sent by the Inspector General to the President of the Litigation Chamber (Article 91, § 1 and § 2, of the LCA). 35. Under the terms of this report, the IS concluded that there was (freely translated) "no apparent breach of the GDPR" (page 5 of the report). 36. The IS based its conclusion on the fact that the basis for the lawfulness of the transfers of bank details of US nationals (including the first plaintiff) was the FATCA agreement and the Act of 16 December 2015. The IS also highlighted the fact that the above-mentioned Article 96 of the GDPR (point 20) was applicable. 37. In its examination of whether the FATCA agreement was in compliance with the regulatory framework on data protection applicable prior to 24 May 2016, i.e. according to its terms, with Directive 95/46/EC as transposed under the terms of the Act of 8 December 1992 on the protection of privacy with regard to the processing of personal data (hereinafter LVP), the IS noted the following elements: - On 17 December 2014, the Commission for the Protection of Privacy 11 (hereinafter CPP) issued a favourable opinion 61/2014 subject to strict suspensive conditions on the first draft of the future Act of 16 December 2015. In its opinion 28/2015 of 1 July 2015, the CPP then issued a favorable opinion on the second draft law, which implemented the remarks and conditions issued in its opinion 61/2014. - Under the terms of its deliberation AF 52/2016 of 15 December 2016, the Sector Committee for the Federal Authority 12 (hereinafter SCFA) of the CPP authorised the defendant to transmit the financial information of declarable accounts of US taxpayers transmitted to it by financial institutions under the FATCA agreement, to the IRS. The 11 The Commission for the Protection of Privacy (CPP) was the Belgian data protection authority within the meaning of Article 28 of Directive 95/46/EC. It was superseded on 25 May 2018 by the Data Protection Authority (DPA) in implementation of Article 3 of the LCA. 12 Article 36bis of the LVP stipulated that any electronic transfer of personal data by a federal public service or by a public body with legal personality that falls under federal authority requires authorisation in principle from the SCFA, unless the transfer has already been authorised in principle by another sector committee set up within the CPP. The mission of the SCFA is to verify that the transfer complies with legal and regulatory provisions. Decision on the merits 61/2023 12/73 IS stressed that on this occasion, the SCFA assessed the admissibility of the tax purposes of the processing, as well as the proportionality of the data and the security of the processing. In keeping with the principle of transparency, the SCFA also ordered the defendant to inform the public, via accessible and comprehensible text on its website, of the circumstances in which their personal data (including financial data) may be transmitted to the IRS. The IS noted in this respect that a web page dedicated to FATCA was published on the defendant's website. Lastly, the IS points out that, in application of article 111 of the LCA13, authorisations granted by the sector committees of the CPP (such as the SCFA) prior to the entry into force of this law, retain their legal validity in principle14. 38. Finally, the IS ruled out the applicability of the Schrems II ruling15 of the CJEU. It pointed out that this ruling invalidates the Privacy Shield, which concerned the transfer of personal data to the United States for commercial purposes (and not for tax purposes, including the fight against tax fraud and evasion, as in this case). The IS also referred to Article 17 16 of the Act of 16 December 2015, which refers both to the FATCA agreement and to the agreements to which the FATCA itself refers, i.e. the above-mentioned Convention of the OECD and the Council of Europe. 39. At the end of its investigation, the IS considered that, in view of these considerations and in accordance with Article 64.2 of the LCA, it is not appropriate to pursue its investigation further and that there is, as already mentioned (point 35), no apparent infringement of the GDPR. 13 Article 111 of the LCA: (Freely translated) Without prejudice to the supervisory powers of the Data Protection Authority, authorisations granted by the sector committees of the Commission for the Protection of Privacy prior to the entry into force of this Act remain legally valid. Following the entry into force of this Act, adherence to a general authorisation granted by deliberation of a sector committee is only possible if the applicant sends a written and signed undertaking to the Data Protection Authority, in which they confirm that they adhere to the conditions of the deliberation in question, without prejudice to the supervisory powers that the Data Protection Authority may exercise after receipt of this undertaking. Unless otherwise stipulated by law, current authorisation requests submitted before the Act comes into force shall be processed by the data protection officer of the institutions involved in the data exchange. 14 The Litigation Chamber will in general not give any ruling on the validity of these authorisations. It will examine the relevance of the recourse to that invoked by the defendant in the specific context of the complaint leading to the present decision. 15 16 Judgment of the court of 16 July 2020, C-311/18, Facebook Ireland and Schrems (Schrems II), ECLI:EU:C:2020:559. Article 17 of the Act of 16 December 2015: § 1. (freely translated) Information transferred to a jurisdiction subject to declaration is subject to the confidentiality obligations and other protective measures provided for by the treaty on tax matters which permits the automatic exchange of information between Belgium and that jurisdiction and by the administrative agreement which organises this exchange, including the provisions limiting the use of the information exchanged. § 2. However, notwithstanding the provisions of a tax treaty, the competent Belgian authority : - may, as a general rule and subject to reciprocity, authorise a jurisdiction, to which the information is transferred, to use the information as evidence in criminal courts where the information contributes to the opening of criminal proceedings for tax fraud; subject to the first indent, may not authorise a jurisdiction, to which the information is transferred, to use the information for any purpose other than the assessment or collection of, the enforcement or prosecution in respect of, the determination of appeals in relation to, or the oversight of the taxes referred to in the treaty; and - may not authorise a jurisdiction to which the information is transferred to communicate the information to a third jurisdiction. Decision on the merits 61/2023 13/73 I.B.4. The follow-up investigation of the Inspection Service 40. On 24 June 2021, the Litigation Chamber requested that the IS carry out a follow-up investigation pursuant to article 96.2. of the LCA. 41. On examining the report of 26 May 2021 (points 33 et seq.), the Litigation Chamber noted that there was a lack of information on certain points raised by the plaintiffs to substantiate their complaint, including: - Are appropriate safeguards in place for transfers to the United States? - Is there further processing, or not, for other purposes? And are there are any safeguards, where appropriate? - How long will the data be kept, taking into account any further processing? - Which data is communicated exactly, and what is the volume of this data per data subject, as well as the number of data subjects in Belgium? - Is there a reciprocity clause, and if so, how is it implemented in practice? - Has a DPIA within the meaning of Article 35 of the GDPR been carried out (or will one be carried out?), in what form and on what date? - Has the first plaintiff lodged other claims with the same or similar object before other bodies (judicial, administrative) since lodging his complaint? And what was the outcome, if any? 42. On 9 July 2021, during the course of the investigation, the plaintiffs asked the IS to temporarily suspend the transfer of data in the context of FATCA reporting for the year 2020 to the IRS, as a provisional measure taken on the basis of the LCA and until the Litigation Chamber had made a final decision, and at least until 30 September 2021. The plaintiffs argue that the denounced transfers are likely to cause them serious, immediate and difficult-to-repair damage as soon as they are effectuated. 43. On 10 August 2021, the IS replied to the plaintiffs that taking provisional measures is one of the investigative powers conferred on the IS by the LCA, and that it is not an obligation but rather a possibility left to the sole discretion of the IS. The IS also highlighted the fact that, pursuant to article 64.2 of the LCA, it ensures that all useful and appropriate means are used for the purposes of the investigation. It added that it was not about to receive instructions from anyone as to which investigative measures had to be implemented, thereby rejecting the plaintiffs' request. 44. On 14 September 2021, the follow-up investigation of the IS was closed, the report was attached to the file and was sent by the Inspector General to the President of the Litigation Chamber (Article 91.1 and 91.2 of the LCA). Decision on the merits 61/2023 14/73 45. In its follow-up report, the IS noted that there was no evidence to suggest a lack of safeguards concerning the protection of transferred data or of non-reciprocity regarding the exchanges. The IS stated that it could only observe the fairly robust legal framework governing the transfer of US nationals' tax data by the defendant to the IRS. In this respect, it referred to the description of the safeguards surrounding the said transfers given by the defendant's Data Protection Officer (hereinafter DPO), to the parliamentary work of the law assenting to the FATCA agreement and to articles 3.7 17 and 3.818 of the said agreement. The IS also referred to the judgment of the French Council of State of 19 July 2019 referred to by the French sister organisation of the second plaintiff, a judgment in which the claim that Article 46 of the GDPR had been disregarded was rejected 19. In its report, the IS also repeated the elements put forward by the defendant to justify the fact there is no DPIA (point 95). I.B.5. Examination of the merits by the Litigation Chamber 46. On 20 January 2022, the Litigation Chamber decided, pursuant to article 95, § 1, 1° and article 98 of the LCA, that complaints n°1 and n°2 could be addressed on their merits. 47. On the same date, the parties were informed by registered mail of the provisions of article 95, § 2 and article 98 of the LCA. Under the terms of this letter, the Litigation Chamber decided to join complaints no. 1 and no. 2, which relate to the same processing of personal data (data relating to the same facts), both were lodged against the defendant, and both raise the same complaints against the latter. The Litigation Chamber therefore considers them to be so closely correlated that it has an interest in hearing and deciding on them simultaneously, to ensure that its decisions are consistent. 48. In the same letter, the Litigation Chamber granted the parties the following deadlines for concluding: 17 March and 16 May 2022 for the defendant and 15 April 2022 for the plaintiffs. 17 Article 3.7. of the FATCA agreement: "All information exchanged shall be subject to the confidentiality and other protections provided for in the Convention, including the provisions limiting the use of the information exchanged”. "Convention" refers to the Convention on Mutual Administrative Assistance in Tax matters of 25 January 1988. 18 Article 3.8. of the FATCA agreement: Following the entry int force of this Agreement, each Competent Authority shall provide written notification to the other Competent Authority when it is satisfied that the jurisdiction of the other Competent Authority has in place (
- i)appropriate safeguards to ensure that the information received pursuant to this Agreement shall remain confidential and be used solely for tax purposes, and (
- ii)the infrastructure for an effective exchange relationship (including established processes for ensuring timely, accurate, and confidential information exchanges, effective and reliable communications and demonstrated capabilities to promptly resolve questions and concerns about exchanges or requests for exchanges and to administer the provisions of Article 5 of this Agreement). The Competent Authority shall endeavor in good faith to meet, prior to September 2015, to establish that each jurisdiction has such safeguards and infrastructure in place. 19 The French Council of State was referred to by the French Association of Accidental Americans, with a petition to annul, on the grounds of abuse of authority, the decisions refusing its requests for the repeal of a decree and its ministerial order organising the collection and transfer of personal data to the American authorities. In its ruling, the French Council of State concluded that, in view of the specific safeguards applied by the FATCA agreement of 14 November 2013 (agreement concluded with France) to the disputed processing and the level of protection provided by the personal data legislation applicable in the United States through which the tax situation of taxpayers can be ascertained (the French CoS refers to the US Federal Privacy Act of 1974 and the Federal Tax Code), the action claiming infringement of Article 46 of the GDPR and Articles 7 and 8 of the EU Charter of Fundamental Rights must be rejected (points 23 et seq. of the ruling). Decision on the merits 61/2023 15/73 49. In support of the complaint and the reports of the IS, the Litigation Chamber also identified the grievances, regarding which it invited the parties to present their arguments: - The unlawfulness of the defendant's data transfers to the IRS under Articles 45 and 49 of the GDPR and the fact there is no legal basis; - Failure to comply with the principles of purpose limitation, proportionality and data minimisation (Article 5
(1)(
- b)and (
- c)of the GDPR) as well as failure to comply with the principle of storage limitation (Article 5
(1)(e) of the GDPR); - Failure to comply with the principle of transparency and the obligation to provide information (Articles 5
(1)(a), 12 and 14 of the GDPR); - Failure to comply with Article 16 of the GDPR (right of rectification) in that the defendant's procedures do not provide for the possibility for data subjects to have their status corrected with regard to the FATCA legislation; - Failure to carry out a DPIA within the meaning of Article 35 of the GDPR; - Failure to comply with Articles 5
(2)and 24 of the GDPR combined with the breaches detailed above; - Failure to comply with Article 20 of the Act of July 30, 2018 (LTD). 50. The Litigation Chamber also invited the parties to conclude on Article 96 of the GDPR invoked by the defendant in its letter of 4 October 2021 (point 22). 51. On 30 March 2022, the Litigation Chamber sent a supplementary request to the parties. Under the terms of this request, the Litigation Chamber stated that it had become aware, from the press, that the second plaintiff had lodged an appeal in December 2021 with the (Belgian) CoS with regard to the problem of transfers of the data of accidental Americans to the United States. Without prejudice to the respective competences of the CoS and the DPA, the Litigation Chamber requested the second plaintiff to clarify the subject of this appeal to the CoS and, if possible, the related timing, in its future reply or in a separate document, at the latter's discretion. The Litigation Chamber specified that this information was intended to enable it to assess whether (the outcome
- of)this appeal was likely to have an impact on the proceedings underway before the DPA and/or on its future decision. Under the terms of the complaint form, the plaintiff was asked to inform the DPA as to whether there were any complaint(
- s)lodged with other bodies. As this appeal to the CoS had not yet been lodged at the time the complaint was lodged with the DPA, the second plaintiff was asked to kindly clarify the matter to the Litigation Chamber. In this respect, the Litigation Chamber refers to the information provided in point 23 above. 52. On 31 January and 8 February 2022, the defendant requested a copy of the file (art. 95, §2, 3° LCA), which was sent to it on 9 February 2022. Decision on the merits 61/2023 16/73 I.B.6. The arguments of the parties 53. On 16 March 2022, the Litigation Chamber received the defendant's reply. As the defendant has also filed additional conclusions and summary conclusions at a later stage (hereinafter the summary conclusions), a summary of its full arguments will be set out in detail in paragraphs 79 et seq. I.B.6.1. Position of the plaintiffs 54. On 15 April 2022, the Litigation Chamber received the plaintiffs' reply. 55. The plaintiffs' arguments, grievance by grievance, can be summarised as follows. ➢
Article 96of the GDPR 56.
By way of introduction, the plaintiffs state that Article 96 of the GDPR is not applicable since the condition it lays down that the international agreement must, in order to continue to have effect, comply with EU law as applicable prior to 24 May 2016 is not satisfied. Indeed, the plaintiffs consider that the FATCA agreement is neither compliant with Directive 95/46/EC (applicable before 25 May 2016) nor, moreover, compliant with the GDPR. The plaintiffs also state that, in any event, aspects that are not regulated or imposed by or under the FATCA agreement, such as the obligation to inform data subjects (Title II.E.2) are subject to the GDPR without any interference from its Article 96. ➢
compliance with rules governing cross-border transfers 57.
the transfer to the IRS, the plaintiffs note that prior to its reply conclusions of 16 March 2022 in which it stated that it relied on Article 46
(2)(a) of the GDPR (point 82 et seq.), the defendant appeared, as evidenced by its administrative decision of 4 October 2021 (point 22), to rely on Article 49
(1)(d) of the GDPR (or on Article 26
(1)(d) of Directive 95/46/EC) or on the "important reasons of public interest", the basis for the lawfulness of the transfer resting, in its view, on the FATCA agreement and on the Act of 16 December
- For the sake of completeness, the plaintiffs argue that the lack of equivalent reciprocity and the systematic nature of the alleged transfers are obstacles to the defendant's reliance on Article 49
(1)(d) of the GDPR, even though it no longer relies on this provision since its reply conclusions. -
the lack of reciprocity, the plaintiffs cite a number of letters from European authorities and other American positions that attest to this lack of reciprocity; -
the systematic nature, the plaintiffs rely on Guidelines 02/2018 of the European Data Protection Board (hereinafter EDPB) on derogations of Article 49 under Decision on the merits 61/2023 17/73 Regulation EU 679/2016 20, which state that recourse to Article 49
(1)(d) of the GDPR cannot be invoked for recurrent, systematic transfers or transfers taking place on a large scale: derogations must be interpreted restrictively so that the exception "does not become the rule in practice, but must be limited to specific situations (...)". 59. The plaintiffs further point out that Article 49
(1)(d) of the GDPR provides one of the possible derogations to the ban on international transfers where, according to the cascade system set up by Chapter V of the GDPR and before it by Articles 25 and 26 21 of Directive 95/46/EC, no adequacy decision pursuant to Article 45
(3)of the GDPR has been adopted for the country concerned or in the absence of appropriate safeguards pursuant to Article 46 of the GDPR. By using Article 26
(1)(d) of Directive 95/46/EC as specified in Article 16
(2)of the Act of 16 December 201522, the legislator was therefore, in the plaintiffs' view, acknowledging that there were no appropriate safeguards in place. It is therefore pointless for the defendant to rely on CPP opinions 61/2014 and 28/2015 to conclude that the FATCA agreement complied with EU law (including the rules on transfer) on 24 May
- These opinions related to the abovementioned Belgian legislation and did not examine whether there were appropriate safeguards in the FATCA agreement itself.
- The plaintiffs point out that these "appropriate safeguards" must be included in the FATCA agreement itself in order to bind the parties to it. These safeguards are those identified by the EDPB in its Guidelines 02/2020 on Article 46
(2)(a) and
(3)(b) of the GDPR of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies (hereinafter Guidelines 02/2020)
- The plaintiffs point out that the FATCA agreement does provide a scant reference to "confidentiality and other protections provided for in the Convention" (article 3.
- of the agreement). However, it contains nothing in terms of 20 European Data Protection Board (EDPB), Guidelines 02/2018 on derogations of Article 49 under Regulation EU 679/2016 of 25 May 2018: https://edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_2_2018_derogations_en.pdf 21 Article 26
(1)of Directive 95/46/EC states that it applies by way of derogation from Article 25 (on the principle of adequacy) in cases where the third country does not ensure an adequate level of protection within the meaning of Article 25
(2)of the Directive. Article 26
(2)states that "Without prejudice to paragraph 1, a Member State may authorise a transfer or a set of transfers of personal data to a third country which does not ensure an adequate level of protection within the meaning of Article 25
(2), where the controller adduces adequate safeguards with respect to the protection of the privacy and fundamental rights and freedoms of individuals and
the exercise of the corresponding rights; such safeguards may in particular result from appropriate contractual clauses". 22 Article 17 of the Act of 16 December 2015: "§ 2. Insofar as these transfers form part of a reciprocal exchange of information for tax purposes and are conditional on Belgium obtaining comparable information allowing it to improve compliance with the tax obligations to which taxpayers subject to tax in Belgium are subject, these transfers are necessary to safeguard an important public interest in Belgium. To this extent, such transfers are carried out in compliance with article 22, § 1, paragraph 1, of the above-mentioned Act of 8 December 1992 when they are made to a jurisdiction outside the European Union which is not generally considered to ensure an adequate level of protection". Underlined by the Litigation Chamber. 23 European Data Protection Board (EDPB), Guidelines 02/2020 on Article 46
(2)(a) and
(3)(b) of the GDPR of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies of 15 December 2020: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22020-articles-46-2-and-46-3-bregulation_en Decision on the merits 61/2023 18/73 "appropriate safeguards" apart from a few vague objectives and a list of data that does not respect the principles of necessity and data minimisation (see below). 61. More specifically, the plaintiffs believe that the defendant failed to assess the level of protection offered by the United States or at the very least failed to justify the "adequacy" of any safeguards and measures put in place on either side as it was incumbent upon it to do, pursuant to the Schrems II judgment of the CJEU and EDPB Guidelines 02/22020 in order to validly rely on Article 46
(2)(
- a)of the GDPR, which it now invokes. 62. The plaintiffs point out that the following mandatory safeguards are lacking: (
- a)specification of the types of processing, (
- b)the principle of purpose limitation, (
- c)the principle of data minimisation, (
- d)the principle of storage limitation, (
- e)a list of security measures including a mutual notification mechanism for data breaches, (
- f)the rights of data subjects: (
- i)information and transparency, (
- ii)access, rectification, erasure, restriction and objection: the plaintiffs point out that while the US Privacy Act to which the FATCA agreement refers appears to provide for similar rights, these rights are not included in the agreement. Moreover, the IRS does not communicate on these rights that data subjects would have, (iii) Prohibition of automated decisions: according to the plaintiffs, it is not excluded that an automated decision takes place after the transfer to the IRS given the objective pursued by the U.S. authorities, as specified during the draft law that led to the Act of 16 December 2015, as follows (freely translated): "This information will provide the other State with more resources to improve tax compliance by its residents (and citizens in the case of the US) and to make best use of the information provided via automatic cross-checking with domestic intelligence and automated data analysis 24." 63. In conclusion, the plaintiffs are of the opinion that, failing to comply with the prescriptions of Chapter V of the GDPR, the denounced data transfers carried out by the defendant to the IRS are unlawful. ➢
the principles of purpose, necessity and data minimisation 64. With regard to the principle of purpose, the plaintiffs consider that the purposes pursued by the FATCA agreement are not sufficiently defined, in that they are too vaguely and broadly aimed at (
- a)improving compliance with international tax rules and (
- b)implementing the obligations arising from the US FATCA legislation aimed at tackling tax evasion by US nationals (see in particular the introductory recitals to the agreement). The plaintiffs further denounce the fact that the data exchanged may also, via other instruments, be used for non-tax purposes, including purposes such as combating the financing of terrorism where applicable under the conditions of Article 17 of the Act of 16 December 2015 25. 24 Underlined by the Litigation Chamber. 25 See note 16 above. Decision on the merits 61/2023 19/73 65.
the principles of necessity and data minimisation, the plaintiffs denounce the aggressive nature of the data processing implemented by the FATCA agreement, under the terms of which an automatic exchange of data takes place rather than a transfer of data following an adhoc request. In their view, this model raises important questions of necessity and data minimisation: the plaintiffs are of the opinion that the collection of data under the FATCA agreement is not necessary and does not respect the principle of data minimisation. In support of both the relevant work of the Article 29 Working Party (hereinafter Art. 29 WP) and the EDPB and the rulings of the CJEU (points 66 et seq. below), the plaintiffs are of the opinion that, in the absence of specific criteria justifying the processing operations, the collection and transfer of the data concerned to the IRS are disproportionate, contrary to the principle of data minimisation enshrined both in Article 5
(1)(c) of the GDPR and in Article 6
(1)(c) of Directive 95/46/EC already. They also recall Article 52 of the Charter of Fundamental Rights of the Union (hereinafter the Charter), which states that "Any limitation on the exercise of the rights and freedoms recognised by this Charter must be provided for by law and respect the essence of those rights and freedoms. Subject to the principle of proportionality, limitations may be made only if they are necessary and genuinely meet objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others (...)". 26
- The plaintiffs take particular note of the CJEU's27 ruling of 8 April 2014, which annulled Directive 2006/24/EC on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks in that this directive "applies even to persons for whom there is no evidence capable of suggesting that their conduct might have a link, even an indirect or remote one, with serious crime". They also cite the CJEU ruling of 24 February 2022 28, which prohibits the general and undifferentiated collection of personal data for the purpose of combating tax fraud. The plaintiffs believe that the collections and transfers under the FATCA agreement are carried out in the same general and undifferentiated manner, and should be prohibited under the case law cited. In the same vein, the plaintiffs also highlight DPA opinion 122/2020
- With regard to the specific situation of Belgian accidental Americans, the plaintiffs make it clear that they are not saying that before every exchange of information under the FATCA agreement, the defendant must carry out an ex ante check based on its own criteria to determine whether or not a particular account holder represents a low or high risk of tax evasion. They do however specify that, in view of the notion of tax evasion as defined in American law by 26 US Code, section 26 Underlined by the Litigation Chamber. 27 CJEU, judgment of 8 April 2014, joined cases C-293/12 and C-594/12 Digital Rights Ireland, ECLI: EU :C :2014 :238, point
- 28 29 CJEU, judgment of 24 February, 2022, case C-175/20, ECLI :EU :C :2022 :124, points 74 to
- Data Protection Authority, Opinion 122/2020 on Chapter 5 of Title 2 of the draft programme law - articles 22 to 26 inclusive (French only): https://www.autoriteprotectiondonnees.be/publications/avis-n-122-2020.pdf See point
- Decision on the merits 61/2023 20/73 7201, it is incomprehensible that the defendant should, for example, ignore the income threshold below which US citizens living abroad for 330 days (including accidental Americans) can ask the IRS to exclude income earned abroad, via the clause in Annex II of the agreement which allows other categories of accounts to be excluded from the FATCA declaration, even after the agreement has been signed. ➢
information and transparency 67. The plaintiffs address this aspect both as a safeguard to be included in the FATCA agreement pursuant to Article 46
(2)(a) of the GDPR (point 62) and as a stand-alone grievance (Title II.E.2 ). 68. They denounce that contrary to what is requested by the EDPB under its Guidelines 02/2020, neither the FATCA agreement nor the international conventions to which the agreement refers contain provisions on transparency and the provision of information as an "appropriate safeguard" pursuant to Article 46
(2)(a) of the GDPR used by the defendant. 69. The plaintiffs also point out that the defendant does not even attempt to comment on the existence of and compliance with such an obligation of transparency on the part of the IRS, even though this is required by Article 16
(3)of the Act of 16 December
- At most, the IRS would be required to comply with the principle of transparency applicable to it under its domestic legislation, which does not translate into an obligation equivalent to what is required under Article 14 of the GDPR.
- The plaintiffs add that point 2.4.
- of EDPB Guidelines 02/2020 clearly states that "Individual information to data subjects should be made by the transferring public body in accordance with the notification requirements of Articles 13 and 14 GDPR" and concludes that "a general information notice on the website of the public body concerned will not suffice". In this respect, the plaintiffs consider that the defendant's website does not present the required information and that the reference to certain pages of this site does not constitute an active form of communication
- The plaintiffs further complain that since the defendant states that it relies on "appropriate safeguards" within the meaning of Article 46 of the GDPR, it was specifically obliged to comply with Article 14
(1)(f) of the GDPR and to indicate "reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available". 30 Article 16.3 of the Act of 16 December 2015 (freely translated): "Notwithstanding the other provisions of the law, the application of the law is postponed or suspended with regard to a jurisdiction which is not a member of the European Union if it is established that this jurisdiction has not put in place an infrastructure which guarantees that the financial institutions established on its territory and its tax administration sufficiently inform Belgian residents of the information concerning them which will be communicated by this jurisdiction within the framework of an automatic exchange of information relating to financial accounts. (...) ". 31 Article 29 Working Party, Guidelines on transparency under Regulation (EU) 679/2016 (WP 260): https://ec.europa.eu/newsroom/article29/items/622227 These guidelines were taken up by the EDPB at its inaugural meeting on 25 May 2018. Decision on the merits 61/2023 21/73 72. Finally, the plaintiffs consider that the defendant cannot32 rely on Article 14
(5)(c) of the GDPR since the appropriate measures required to be able to resort to this exception are not provided for by Belgian legislation. ➢
the absence of a DPIA
- The plaintiffs believe that the defendant was required to carry out a DPIA even before the GDPR came into force. In their view, this obligation derives implicitly from article 22.
- of the LVP and article 26
(2)of Directive 95/46/EC, and more generally from article 16.4. of the LVP, which transposes article 17
(1)of Directive 95/46/EC. The plaintiffs also cite the Art. 29 WP Guidelines of 16 December 2015, which already recommended that EU member states carry out a DPIA in the context of automatic data exchange for tax purposes
- Finally, the plaintiffs believe that, in any event, Article 35 of the GDPR introduces this obligation for processing operations with a high risk, which is, they believe, the case for the denounced processing operations. On the basis of several criteria drawn from the EDPB Guidelines on data protection impact assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation (EU) 2016/679 (hereinafter the EDPB DPIA Guidelines)34, the plaintiffs conclude that a DPIA was required in this case. The plaintiffs cite the following criteria: systematic monitoring, sensitive data or data of a highly personal nature, data processed on a large scale, cross-referencing or combination of data sets, data concerning vulnerable persons, and, to a certain extent, processing "which prevents the exercise of a right or the benefit of a service or contract".
- By failing to carry out a DPIA within the meaning of Article 35 of the GDPR, the defendant has breached this provision, in the plaintiffs' view. ➢
accountability 76. The plaintiffs point out that the principle of accountability requires the controller to comply with the GDPR but also to be able to demonstrate this compliance at any time. The plaintiffs believe that no EU member state is currently in a position to demonstrate this, including Belgium. ➢
article 20 of the LTD (obligation to conclude a protocol)
- Finally, under the terms of their complaint, the plaintiffs denounce a breach of Article 20 of the LTD, which provides that (freely translated) "unless otherwise provided in specific laws, 32 The plaintiffs anticipate a possible argument from the defendant, which the latter will not raise. 33 Article 29 Working Party, Guidelines for Member States on the criteria to ensure compliance with data protection requirements in the context of automatic exchanges of personal data for tax purposes, WP 234 of 16 December 2015: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2015/wp230_en.pdf 34 Article 29 Working Party, Guidelines on data protection impact assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation (EU) 2016/679 (WP 248): file:///C:/Users/winverbvale/Downloads/20171013_wp248_rev_01_en_D7D5A266-FAE9-3CA1-65B7371E82EE1891_47711-1.pdf These Guidelines were taken up by the EDPB at its inaugural meeting on 25 May
- Decision on the merits 61/2023 22/73 pursuant to Article 6
(2)of the Regulation [i.e. GDPR], the federal public authority that transfers personal data under Article 6
(1)(c) and (e), of the Regulation [i.e. GDPR] to any other public authority or private organisation, shall formalise this transfer for each type of processing in a protocol between the initial controller and the controller receiving the data (§1)". Consequently, according to the plaintiffs, the defendant was obliged to enter into a protocol with the IRS, within the meaning of article 20 of the LTD.
- In their conclusions in reply, however, the plaintiffs state that they have abandoned their argument that this provision has been breached. I.B.6.
- Position of the defendant
- On 16 May 2022, the Litigation Chamber received the defendant's summary conclusions.
- The defendant's arguments, grievance by grievance, can be summarised as follows. ➢
compliance with rules governing cross-border transfers and
Article 96of the GDPR 81. The defendant does not deny that prior to its conclusions (in its decision of 4 October 2021 point 22), it argued that Article 49
(1)(d) of the GDPR allowed it to make the denounced data transfer to the IRS. It adds that, in reality, Article 49
(1)(d) of the GDPR cannot be applied in this case since this transfer is not occasional. 82. As already mentioned, the defendant states that it relies on Article 46
(2)(a) of the GDPR 35since, in its view, the transfer of data to the IRS is based on a "legally binding and enforceable instrument between public authorities or bodies that does not require any specific authorisation from the national supervisory authority" within the meaning of that provision. In this regard, the defendant points out that the binding and enforceable instrument is, on the one hand, the FATCA agreement and, on the other hand, the Act of 16 December 2015, and that these are both national and international legally binding and enforceable instruments over which it has no control and which are, moreover, part of a global international framework recalled in point 9. 83. The defendant further invokes the above-mentioned Article 96 of the GDPR. It argues in support of its application that the FATCA agreement complied with EU law at the time it was concluded and that this is undoubtedly apparent, as the IS points out in its investigation elsewhere (points 37 et seq.): 35 Article 46 of the GDPR: 1. In the absence of a decision pursuant to Article 45
(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.
- The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by (a) a legally binding and enforceable instrument between public authorities or bodies [..] Decision on the merits 61/2023 23/73 - CPP opinions 61/2014 and 28/2015 on the draft Act of 16 December 2015; - The deliberation 52/2016 of the SCFA of the CPP of 15 December 2016 authorising the defendant to transmit the financial information of declarable accounts of US taxpayers transmitted to it by financial institutions under the FATCA agreement, to the IRS, this deliberation is still in effect by virtue of article 111 of the LCA. - The ruling of the Constitutional Court of 9 March 2017, which states that the Act of 16 December 2015 complies with the LVP through Article 22 of the Constitution and Article 8 of the European Convention on Human Rights (ECHR).
- In conclusion, the defendant argues in support of these elements that the FATCA agreement was at the very least consistent with EU law applicable prior to 24 May
- As the conditions of Article 96 of the GDPR had been met, there was no reason for the defendant not to apply the Act of 16 December
- It adds that it cannot be blamed for not having carried out any other compliance assessment, since the legislator had done so itself, by seeking the opinion of the CPP and incorporating the latter's remarks.
- The defendant adds that the fact the plaintiffs invoke the Schrems II judgment of the CJEU is irrelevant, and that they give this decision a scope that it does not have, since the judgment concerned the transfer of personal data for commercial purposes, which is not the case here, since it involves a transfer of data between public authorities for the purposes of taxation and combating tax fraud and evasion, with no commercial scope. Moreover, according to the defendant, there is clearly no large-scale collection of personal data within the meaning of this judgment.
- As to whether there are appropriate safeguards within the meaning of Article 46
(2)(a) of the GDPR, the defendant considers that the essential principles of the GDPR are in any event respected, regardless of Article 96 of the GDPR (see below). The defendant refers in this respect to the notification of the data protection measures and infrastructure required by article 3.8. of the FATCA agreement cited above 36, which attests that it has indeed carried out this analysis of whether there were adequate safeguards. 87.
automated decisions, the defendant maintains that there is no doubt that the processing it carries out under the FATCA agreement does not fall within the scope of Article 22 of the GDPR since it is "neither processing which produces legal effects concerning the data subject" nor "similarly significantly affects him or her". The defendant insists on its exclusively logistical role in this respect. Even supposing that the processing does fall within the scope of Article 22 of the GDPR, quod non according to the defendant, the latter considers itself to be in one of the cases of exception. More specifically, Article 22
(2)(b) of the GDPR would find 36 See note 18 above. Decision on the merits 61/2023 24/73 application in support of Recital 71, which explicitly mentions that "decision-making based on such processing [referred to in Article 22.1.] (...) should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and taxevasion monitoring and prevention purposes (...)".37 88. Finally, as to the retention period, the defendant states that the answer is given by Article 12
(4)of the Act of 16 December 2015, which provides that (freely translated) "reporting financial institutions shall keep the computerised databases that they have communicated to the Belgian competent authority for seven years from 1 January of the calendar year following the calendar year in which they communicated them to that authority. The databases are deleted on expiry of this period", as well as by article 15
(3)of the same Act, which sets the same period of 7 years for the defendant to retain databases transferred to the competent authority of another jurisdiction, i.e. the IRS in this case. In this respect, the defendant rejects the plaintiffs' position, which artificially attempts to separate the FATCA agreement from the Act of 16 December 2015 (with regard to the principle of storage limitation discussed here in particular) and more generally from other rules on automatic exchanges of information in tax matters to which the defendant is bound. ➢
the principles of purpose, necessity and data minimisation 89.
purpose limitation, the defendant refers to Article 3.
- of the FATCA agreement as well as Article 17 of the Act of 16 December
- It also refers to the above-mentioned opinions and authorizations of the CPP (point 83).
- With regard to the principles of necessity and data minimisation, the defendant highlights the following elements which, in its view, demonstrate compliance with the above-mentioned principles:
(1)in compliance with the FATCA agreement, only data concerning US citizens subject to US tax legislation is transmitted to the IRS;
(2)banks are not obliged to consider as declarable bank accounts whose balance or value does not exceed a certain amount (focus of the FATCA agreement on high-value balances);
(3)only the data listed in article 2.
- of the FATCA agreement is transferred, and this data is necessary for the identification of taxpayers and the performance of its duties by the IRS pursuant to articles 4 and 22 of the Multilateral Convention of
- Here again, the defendant relies on the above-mentioned authorisation of the SCFA and the ruling of the Constitutional Court of 9 March 2017, which appears to have validated the proportionality of the data processed. The defendant also considers that the plaintiffs' reference to the ruling of the CJEU of 8 April 2014 is irrelevant, since in this case, 37 Underlined by the Litigation Chamber. 38 See note 16 above. Decision on the merits 61/2023 25/73 unlike the situation referred to in that ruling, there is no general and undifferentiated collection. The defendant points out that the data collection only involves a specific category of people (American nationals) and establishes a threshold below which the declaration is not required. There would therefore be precise criteria justifying collection. ➢
information and transparency
- The defendant states that its website provides comprehensive information combining more theoretical explanations, news, links to relevant documents and an FAQ.
- It adds that under the terms of Article 14 of the Act of 16 December 2015 (freely translated) "each reporting financial institution shall inform each natural person concerned that personal data concerning him or her will be transferred to the competent Belgian authority" and that it is therefore in any event up to the banks to inform the data subjects, such as the first plaintiff and Belgian accidental Americans. This data is the following: - The purposes of the transfer of personal data (a); - The recipients or ultimate recipients of the personal data (b); - The declarable accounts for which personal data are transferred (c); - The existence of a right to obtain, on request, communication of the specific data that will be or has been transferred a declarable account and the procedures for exercising this right (d); - The existence of a right to rectify personal data concerning the individual and how to exercise this right (e).
- The defendant also states that this information was provided to the first plaintiff by its bank Z on 18 May 2020 (point 16). During the hearing, the defendant clarified that it could therefore rely on the information exemption provided for in Article 14
(5)(a) of the GDPR. ➢
the fact there was no DPIA
- Referring to Article 35 of the GDPR, the defendant mentions that its DPO specified in a letter dated 30 June 2021 addressed to the Inspector General that (freely translated) "according to the working methodology adopted by the FPS Finance [i.e. the defendant], and developed by the 'Service de Sécurité de l'information et de Protection de la Vie privée' (SSIPV), a pre-impact assessment had been carried out".
- On the basis of this pre-impact assessment, the defendant's DPO states that it was concluded that a DPIA was not necessary, since: - The Act of 16 December 2015 had incorporated the remarks made by the CPP in its two opinions 61/2014 and 28/2015 cited above; Decision on the merits 61/2023 26/73 - The SCFA had issued a resolution authorising the transmission of data to the IRS and that the conditions of this resolution had been implemented; - The processing complied with the requirements of the AEOI standard on confidentiality and data protection, as well as the defendant's information security policies based on the ISO 27001 standard; - The US authorities are also required to provide the necessary security measures to ensure that the information remains confidential and is stored in a secure environment, as provided for in the FATCA Data safeguard workbook.
- The defendant adds that the contents of this letter were reproduced in extenso in the followup investigation report of the IS (point 40).
- The defendant also believes that the plaintiffs have not demonstrated any elements to justify a DPIA. It is of the opinion that the criteria set out in the EDPB DPIA Guidelines are not met in the context of the processing it carries out. It stresses that it does not analyse the data, but only prepares it for direct transfer to the IRS. ➢
accountability 98. The defendant considers that, in view of the elements reported with regard to the above points, it sufficiently demonstrates that it complies with Article 5
(1)of the GDPR. ➢
article 20 of the LTD (obligation to conclude a protocol)
- The defendant points out that although the plaintiffs claimed that this article had been breached in their complaint, they abandoned it in their conclusions in reply. The defendant, for its part, considers that it is clear from the preparatory work of the LTD that the obligation to conclude such a protocol is not applicable in the case of data transfers to or from third countries within the meaning of the GDPR. Since the transfer in question took place to the United States, the company cannot be accused of any breach. I.B.6.
- Additional conclusions on the ruling of the Constitutional Court of 9 March 2017
- On 17 August 2022, the Litigation Chamber exceptionally authorised the parties to make additional conclusions, on the reference to the ruling of the Constitutional Court of 9 March 2017 made by the defendant in its above-mentioned summary conclusions.
- On 31 August 2022, the Litigation Chamber received the additional conclusions of the plaintiffs. In it, the plaintiffs insist above all on the fact that since the ruling dates back to 2017, the Constitutional Court was unable to take into account the evolution of case law relevant to assessing whether the FATCA agreement complies with data protection rules, in particular the lack of proportionality of the collection of the personal data of data subjects, and the subsequent transfer of this data. In 2017, the CJEU had already initiated its case law on the Decision on the merits 61/2023 27/73 principles to be taken into account when analysing the proportionality of a legislative measure under Article 8 of the ECHR and Articles 7, 8 and 52 of the Charter. According to the plaintiffs, judgment C-175/20 of 24 February (paragraph 66) leaves no doubt as to the unlawfulness of generalised data collection in the specific context of the fight against tax fraud. In this respect, the plaintiffs stress that in this judgment, the CJEU rejects the distinction suggested by the Advocate General between, on the one hand, ex-ante research and detection, for which the proportionality requirement could be assessed more flexibly in his view, and, on the other hand, ex-post verification in a specific case, to be assessed more strictly in his view
- According to the plaintiffs, the data listed in the agreement, as well as the thresholds40 provided for in the agreement (below which the account is not declarable), do not constitute criteria within the meaning of the CJEU's case law; in fact, there is no analysis of the risk of tax evasion or fraud on the part of the persons whose data is processed. Finally, the plaintiffs point out that the Constitutional Court was unable to take into account the study of May 2018 commissioned by the European Parliament41, which states that FATCA reporting obligations are not sufficiently limited with regard to the risk of tax evasion.
- On 21 September 2022, the Litigation Chamber received the defendant's additional conclusions on the same judgment. The defendant's main demand is that the Litigation Chamber set aside those aspects of the plaintiffs' additional conclusions that go beyond the request made by the Litigation Chamber. According to the defendant, the plaintiffs are in fact going beyond the Litigation Chamber's invitation by once again putting forward arguments concerning the minimisation/proportionality of data.
- For the remainder, the defendant also invokes Article 96 of the GDPR with regard to the claim that the principle of data minimisation has been breached, raised by the plaintiffs
- With regard to the ruling of the Constitutional Court itself, the defendant insists, as it did in its summary conclusions, that the ruling has the character of legal/constitutional truth. It adds that, after a precise and comprehensive analysis, the Constitutional Court considered that the Act of 16 December 2015 and, consequently, the FATCA agreement, were not inconsistent with either to Article 22 of the Constitution, or to the LVP, or to Directive 95/46/EC, including the condition of proportionality. There was therefore no reason for it to refuse to apply the Act of December 16,
- 39 See CJEU, case C-175/20 - Opinion of Advocate General Michal Bobek delivered on 2 September 2021, paragraphs 70 et seq. 40 In this respect, the plaintiffs cite CJEU judgment C-184/20, Vyriausioji tarnybinės etikos komisija, ECLI :EU :C :2022 :
- 41 See https://www.europarl.europa.eu/RegData/etudes/STUD/2018/604967/IPOL_STU
(2018)604967_EN.pdf 42 Indeed, the Litigation Chamber notes that in its summary conclusions, given the structuring of the titles used, the defendant appeared to invoke Article 96 of the GDPR only with regard to the appropriate safeguards that must accompany the transfer of data to the IRS. Decision on the merits 61/2023 28/73
- Lastly, the defendant points out that if the Litigation Chamber were somehow to consider the case law of the CJEU cited by the plaintiffs - quod non - it would find that the plaintiffs had drawn erroneous conclusions from it. As such, the defendant argues that in the judgment C-175/20 of 24 February 2022 relied on by the plaintiffs, the CJEU asks the referring court to verify whether the Latvian administration would be able to target advertisements by means of specific criteria. In this respect, the defendant considers that, as the Belgian Constitutional Court has qualified the collection of data - listed by law - in implementation of the FATCA agreement and the Act of 16 December 2015 as proportionate, the CJEU's concern has been addressed. I.B.
- The hearing of the parties
- By e-mails dated 17 August and 8 September 2022, the parties were informed that the hearing would take place on 13 September
- This hearing was subsequently postponed to 7 November 2022 and then to 10 January
- On 23 September 2022, the plaintiffs submitted 2 documents to the Litigation Chamber, which they described as "new documents" in the case. Specifically, these include an opinion of 23 August 2022 from the Slovak Data Protection Authority on the FATCA agreement and whether it was compliant with the GDPR (and its unofficial French translation), as well as the updated report of September 2022 "FATCA legislation and its application at international and EU level an update" of the 2018 report commissioned by the European Parliament.
- This led to an exchange of letters between the parties concerning the admissibility of these documents, which had been sent outside the deadlines set for the submission of their respective conclusions and documents.
- On 3 October 2022, the Litigation Chamber informed the parties that it would give them the opportunity to comment on these documents at the start of the hearing.
- On 10 January 2023, the parties were heard by the Litigation Chamber. At the hearing, and as reflected in the minutes, the Litigation Chamber indicated that it was authorised to inspect all relevant documents. No document is excluded from the proceedings, provided that it is possible to exercise the rights of defence with regard to them, either during the hearing or, if necessary, afterwards. The parties did not return to this point.
- On 27 January 2023, the minutes of the hearing were submitted to the parties. The Litigation Chamber received no comments from the latter on these minutes. * II. JUSTIFICATION Decision on the merits 61/2023 29/73 II.A.
the competence of the Litigation Chamber of the DPA 112. Among other things, the GDPR has entrusted European data protection authorities ("supervisory authorities") with the task of handling complaints submitted to them (Article 57
(1)(f) of the GDPR). These authorities must investigate such complaints with all due diligence
- In carrying out their duties, including handling complaints, data protection authorities must strive to consistently apply the GDPR throughout the EU. To this end, they cooperate with each other in accordance with Chapter VII of the GDPR (Article 51
(2)of the GDPR). 114. In this case, the complaint submitted to the Litigation Chamber for examination concerns the transfer (i.e. processing within the meaning of Article 4
(2)of the GDPR) of personal data (within the meaning of Article 4
(1)of the GDPR) by a Belgian public authority (the defendant) to a foreign public authority (the IRS) pursuant to the FATCA agreement and the Belgian Act of 16 December 2015. The single point of contact mechanism provided for in Article 56 of the GDPR does not find application in view of Article 55
(2)of the GDPR, which provides that "2. Where processing is carried out by public authorities or private bodies acting on the basis of point (c) or (e)44 of Article 6
(1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply. The DPA is nonetheless unquestionably competent to process it pursuant to Article 55 of the GDPR and Article 4 of the LCA.
- As this transfer takes place in execution of an intergovernmental agreement, admittedly a bilateral one between Belgium and the United States, but similar in content to other bilateral agreements signed by the United States with other EU member states, whether the transfer of this data is compliant with the GDPR based on this agreement, even bilateral (and supplemented by national legislation), must be assessed with the same consistency in the various EU member states to the extent possible.
- To this end, the Litigation Chamber will take account in particular of the Guidelines relevant to this case issued by both the Art 29 WP45 and the EDPB46, as well as the relevant judgments of the CJEU. 43 Judgment of the court of 16 July 2020, C-311/18, Facebook Ireland and Schrems (Schrems II), ECLI:EU:C:2020:559, point
- 44 The defendant processes the data pursuant to an international agreement and Belgian legislation. 45 Article 30
(1)(a) of Directive 95/46/EC entrusted the Article 29 Working Party (Art. 29 WP) with the task of examining all questions relating to the implementation of national provisions adopted pursuant to this directive, with a view to striving toward the uniform application thereof. Under article 30
(1)(b), Art. 29 WP was tasked with advising the European Commission on the level of protection in third countries. 46 As set out in Recital 139 of the GDPR, the EDPB is set up for the purpose of promoting the consistent application of the GDPR in the EU through its various activities. It follows both from this Recital 139 and from the tasks entrusted to it under Article 70 of the GDPR that the EDPB has an essential role to play with regard to the consistent application of the rules laid down by the GDPR with regard to cross-border data flows. See in this respect, in addition to the reference to its task of Decision on the merits 61/2023 30/73 II.B.
the sovereign judgment of the Litigation Chamber
- As set out in the background to the procedure, the defendant repeatedly stresses in its conclusions that the inspection reports did not find any failures on its part, and that the arguments it gave during the investigation are the basis for the conclusion reached in the reports of the IS.
- As it had already done in its decision 81/2020, the Litigation Chamber specifies that recourse to the Inspection Service is not systematically required by the LCA. In fact, it is up to the Litigation Chamber to determine whether or not an investigation is necessary following the lodging of a complaint (article 63, 2° LCA - article 94, 1° LCA). The Litigation Chamber may therefore decide to deal with the complaint without referring it to the IS (art. 94, 3° LCA).
- When a case is referred to the IS, its findings will undoubtedly enlighten the Litigation Chamber as to the facts of the complaint and how these facts should be qualified under data protection regulations. As such, they can be used to support one or other of the breaches ultimately upheld by the Litigation Chamber in its decision. Nevertheless, the Litigation Chamber remains free to conclude, with reasons, that there are shortcomings in the case which the inspection report(s) would not have raised, based on all the documents produced during the proceedings, including the arguments developed during the adversarial debate following its decision to deal with the case on the merits (article 98 of the LCA). II.C.
the status of the defendant as controller 120. The Litigation Chamber notes that the defendant claims the status of controller 47 in support of article 13
(2)of the Act of 16 December 2015, which explicitly qualifies it as such, both in its conclusions and at the hearing48. 121. Article 13
(2)stipulates that (freely translated) "§ 2. For the purposes of the Act of 8 December 1992, each reporting financial institution and the FPS Finance [i.e. the defendant] are considered to be "controllers" of "personal data"
the information referred to in this law which relates to natural persons 49". advising the European Commission on the level of protection in third countries, litera (c), (i), (
- j)and (
- s)of Article 70 as well as Article 64(
- e)and (
- f)of the GDPR, all of which specifically relate to the role of the EDPB with regard to such flows. 47 See for example page 3 of the minutes of the hearing of 10 January 2023. 48 As the Litigation Chamber points out in paragraph 208, the FATCA agreement does not provide for any qualification or definition in the area of data protection. 49 Underlined by the Litigation Chamber. Decision on the merits 61/2023 31/73 122. The defendant is therefore expressly qualified as a controller under the terms of the Act of 16 December 2015. This Act obviously refers to the LVP repealed by the LTD (article 280 of the LTD). However, the definition of "controller" in Article 1.4. of the LVP and that used in Article 4
(7)of the GDPR are identical. 123. Article 4
(7)of the GDPR therefore states that the controller is "any natural or legal person, public authority, service or other organisation which, alone or jointly with others, determines the purpose and methods of processing". Article 4
(7)adds that "where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law"50. This is the case for the defendant under Article 13
(2)of the above-mentioned Act of 16 December
- In its Guidelines on the concepts of controller and processor in the GDPR51, the EDPB considers that where the controller has been specifically identified by law, this will be determinative for establishing who is acting as controller. This presupposes that the legislator has designated as controller the entity that has a genuine ability to exercise control.
- On several occasions in its conclusions and at the hearing (see minutes of the hearing), the defendant also pointed out that it did not have access to the contents of the "bundle" of data it received from the financial institutions (in this case from Bank Z) for transfer to the IRS, as an organisational measure to guarantee the security and integrity of the data
- As already mentioned, the defendant does not deny that it is a controller (point 120).
- Insofar as necessary, the Litigation Chamber wishes to point out that the fact that the defendant does not have access to the transferred data is irrelevant. Indeed, this element has no bearing on its status as controller, as the CJEU clarified in its Google Spain and Google judgment of 13 May 2014.53 50 Underlined by the Litigation Chamber. 51 European Data Protection Board (EDPB), Guidelines 07/2020 on the concepts of controller and processor in the GDPR, https://edpb.europa.eu/system/files/2021-07/eppb_guidelines_202007_controllerprocessor_final_en.pdf (point 23). 52 See the minutes of the hearing: the defendant's response to Mr. C. Boeraeve's question about the technical and organisational measures taken. 53 CJEU judgment of 13 May 2014, C-131/12, Google Spain and Google, ECLI :EU :C :2014 :317, points 22 - 41, and especially points 22 and 34: "
- According to Google Spain and Google Inc., the activity of search engines cannot be regarded as processing of the data which appear on third parties’ web pages displayed in the list of search results, given that search engines process all the information available on the internet without effecting a selection between personal data and other information. Furthermore, even if that activity must be classified as ‘data processing’, the operator of a search engine cannot be regarded as a ‘controller’ in respect of that processing since it has no knowledge of those data and does not exercise control over the data". "
- Furthermore, it would be contrary not only to the clear wording of that provision but also to its objective— which is to ensure, through a broad definition of the concept of ‘controller’, effective and complete protection of data subjects — to exclude the operator of a search engine from that definition on the ground that it does not exercise control over the personal data published on the web pages of third parties". Decision on the merits 61/2023 32/73
- In conclusion, and in support of the combined reading of Article 4
(7)of the GDPR and Article 13
(2)of the Act of 16 December 2015, the Litigation Chamber upholds the defendant's qualification as a controller with regard to the data processing challenged by the plaintiffs, namely the transfer of data to the IRS. 128.
the financial institutions (in this case, Bank Z, with which the first plaintiff held bank accounts), they were deliberately not implicated by the plaintiffs
- They nonetheless play an important role in the chain of data processing that takes place in the context of the implementation of the FATCA agreement and the Act of 16 December
- In fact, they are the ones who first check the status of the account holders concerned by the obligation to provide data to the defendant. They are the ones who collect the data required under Article 2.
- of the FATCA agreement and Article 5 of the Act of 16 December 2015 and transfer it to the defendant who in turn performs the transfer to the IRS. As such, financial institutions are also qualified as controllers by the Belgian legislator for the purposes of the Act of 16 December
- II.D.
Article 96of the GDPR 129.
As set out in paragraph 83, the defendant, relying on Article 96 of the GDPR, argues (taking into account favorable opinions from the CPP, a transfer authorisation from the SCFA of the CPP and the ruling of the Constitutional Court of 9 March 2017) that the FATCA agreement applied in combination with the Act of 16 December 2015 complies with EU law as applicable on 24 May
- The defendant therefore considers itself entitled to base the transfer of the first plaintiff's data in particular on these texts.
- In view of this argument, the Litigation Chamber considers it necessary to clarify the scope of Article 96 of the GDPR. It sets out to do just that in the following paragraphs.
- By opting for a regulation to replace Directive 95/46/EC, the European co-legislators chose to strengthen the harmonisation of personal data protection rules in the EU. The regulation is directly applicable in the domestic legal order of each Member State, and although it contains See also CJEU judgment C-25/17, Jehovan Todistajat, EU:C:2018:551, paragraph 69 and CJEU judgment C-210/16, Wirtschaftsakademie Schleswig-Holstein, C-210/16, EU:C:2018:388, paragraph 38, as well as the EDPB Guidelines 7/2020, cited above, on the concepts of controller and processor in the GDPR, paragraph
- 54 See the minutes of the hearing on this point. 55 As mentioned in point 121, article 13
(2)states that (freely translated) "§ 2. For the purposes of the Act of 8 December 1992, each reporting financial institution and the FPS Finance [i.e. the defendant] are considered to be "controllers" of "personal data"
the information referred to in this law which relates to natural persons". Underlined by the Litigation Chamber. In the context of this decision, the Litigation Chamber will not examine the question of whether or not the financial institutions and the defendant should be qualified as joint controllers within the meaning of Article 4
(7)of the GDPR and, consequently, whether or not the conditions of Article 26 of the GDPR had to be complied with. In view of the grievances raised against the defendant, a possible qualification as joint controller is not likely to lead to a different decision by the Litigation Chamber. Decision on the merits 61/2023 33/73 a number of references to the national legislator, these do not call into question the objective of robust harmonisation.
- By providing for the GDPR to apply two years after its entry into force, i.e. on 25 May 2018 (Article 99 of the GDPR), the European co-legislators not only granted a two-year compliance period for the new obligations of the GDPR, they also made it clear that on this same date of 25 May 2018, data processing already under way on 24 May 2016 had to comply with all of the GDPR's provisions.
- In this regard, Recital 171 of the GDPR provides that "Processing already under way on the date of application of this Regulation should be brought into conformity with this Regulation within the period of two years after which this Regulation enters into force".
- This compliance is essential if the regulation's objective of robust harmonisation was to be achieved. If processing which was under way before the GDPR came into force was not brought into line with it, two protection regimes would have coexisted. In essence, this would be contrary to the very nature of the regulation and, a fortiori, to that of a fundamental right enshrined in the Charter (article 8).
- It is in the light of this ratio legis of the transitional provisions of the GDPR that Article 96 must be understood and applied, both in its material scope (rationae materiae) and in its temporal scope (rationae temporis).
- Article 96 of the GDPR does not exempt controllers who perform data processing operations pursuant to international agreements concluded before 24 May 2016 either totally or indefinitely from both the material and temporal scope of the GDPR. Article 96, "Relationship with previously concluded Agreements" provides for a transitional regime subject to conditions, the objective pursued by Article 96 of the GDPR being "to ensure comprehensive and consistent protection of personal data in the Union" and to avoid any legal vacuum .56 II.D.1.
the material scope of Article 96 of the GDPR
- Only the content of the international agreement concluded by the Member State is covered by Article 96 of the GDPR, the wording of which unequivocally targets "international agreements involving the transfer of personal data to third countries". The material scope of article 96 must be interpreted in strict compliance with this wording.
- The Litigation Chamber notes here from the outset that Article 96 of the GDPR is invoked by the defendant only with regard to
(1)the grievance alleging non-compliance with the 56 This objective is expressly explained in Recital 95 of Directive 2016/680/EU, with regard to Article 61 of this Directive, which is identical to Article 96 of the GDPR. Recital 95 provides that "In order to ensure a comprehensive and consistent protection of personal data in the Union, international agreements which were concluded by Member States prior to the date of entry into force of this Directive and which comply with the relevant Union law applicable prior to that date should remain in force until amended, replaced or revoked. "(emphasis added by the Litigation Chamber). Decision on the merits 61/2023 34/73 framework for the transfer of data to the IRS 57 as well as with regard to
(2)the grievance alleging breach of the principles of purpose, necessity and data minimisation. It does not appear to the Litigation Chamber that the defendant would invoke this Article 96 of the GDPR in light of all the data protection obligations incumbent on it. According to the Litigation Chamber's examination, Article 96 of the GDPR is therefore not invoked by the defendant with regard to the grievance based on a breach of the obligation to provide information, which is asserted against it by the plaintiffs, for example, nor is it invoked with regard to the applicability, where applicable, of Article 35 of the GDPR.
- The Litigation Chamber shares this analysis. In fact, as the FATCA agreement does not contain any specific provisions concerning the obligation to provide information, for example, this is excluded from the scope of Article 96 of the GDPR. The application of Articles 12 and 14 of the GDPR by the defendant is therefore beyond doubt (see. Title II. E.2 below).
- In addition, the new obligations arising from the GDPR will find full application: they are in fact non-existent in Directive 95/46/EC and therefore a fortiori not regulated in the FATCA agreement from
- To assert the contrary would be the same, for example, as admitting that a data breach on the part of the defendant does not have to be notified in compliance with the conditions laid down by Article 33 of the GDPR, or that the transfers denounced by the complaint do not have to be covered by the defendant's register of processing activities (Article 30 of the GDPR). This cannot be the case. The application of Article 96 of the GDPR is circumscribed to the content of the agreement alone. The letter of Article 96 is clear on this point, and this reading is moreover consistent with the ratio legis of Article 96 which, as the Litigation Chamber will explain below (point 143), aims to safeguard the rights acquired by third countries under the terms of the said agreements.
- The Litigation Chamber will therefore assess whether or not the defendant was required to carry out a DPIA in the light of Article 35 of the GDPR without interference from Article 96 of the GDPR (see. Title II. E.3 below). The Litigation Chamber points out that the obligation of accountability also applies. Whether this was complied with by the defendant will be examined by the Litigation Chamber solely in the light of Articles 5
(2)and 24 of the GDPR read together, without interference from Article 96 of the GDPR (see. Title II. E.4 below). Finally, the Litigation Chamber will assess whether the defendant is in compliance with article 20 of the LTD under the same conditions (see. Title II. E.5 below). II.D.2.
the temporal scope of Article 96 of the GDPR
- Article 96 of the GDPR provides for the continued application of international agreements involving transfers of personal data to third countries "until amended, replaced or revoked". Even if no specific deadline is set for such amendment, replacement or revocation, the fact they 57 Point 6.
- of its summary conclusions and point 103 above. Decision on the merits 61/2023 35/73 are mentioned constitutes a time limit in itself. By these terms, the co-legislators mean that keeping in place such international agreements is intrinsically limited in time. This reading is also the only one that, according to the Litigation Chamber, reconciles the GDPR's harmonisation objective (points 131 et seq. above), safeguarding the rights of third countries with which an international agreement has been concluded (point 143) and the principle of sincere cooperation of the Union's member states (point 144).
- Article 96 of the GDPR in fact aims to preserve the rights of third countries. It is clear that negotiating an international agreement takes time, and that the rights acquired by a third country party to an international agreement cannot simply be annulled immediately as a result of new legislation coming into force, even though the agreement was in line with EU law at the time it was concluded.
- Without prejudice to the above, EU Member States are nonetheless obliged to comply with EU law. This obligation derives from article 4
(3)of the Treaty on European Union (TEU), which enshrines the principle of sincere cooperation between member states 58. Article 4
(3)of the TEU is binding on member states, including their independent data protection authorities entrusted with tasks based on applicable European law (Article 8
(3)of the Charter and Articles 51 et seq. of the GDPR).59
- In this respect, Article 96 of the GDPR is in line with Article 351 of the Treaty on the Functioning of the EU (TFEU)60, with regard to which the CJEU has already ruled that: - On the one hand, "the rights and obligations arising from an agreement concluded before the date of accession of a Member State between it and a third country are not affected by the provisions of the Treaty. The purpose of that provision [i.e. Article 351 TFEU] is to make it clear, in accordance with the principles of international law, that application of the Treaty is not to affect the duty of the Member State concerned to respect the rights of third countries under a prior agreement and to perform its obligations thereunder61". 58 Article 4.
- TUE: Pursuant to the principle of sincere cooperation, the Union and the Member States shall, in full mutual respect, assist each other in carrying out tasks which flow from the Treaties. The Member States shall take any appropriate measure, general or particular, to ensure fulfilment of the obligations arising out of the Treaties or resulting from the acts of the institutions of the Union. The Member States shall facilitate the achievement of the Union's tasks and refrain from any measure which could jeopardise the attainment of the Union's objectives. 59 See in this sense: Judgment of the CJEU of 15 June 2021, Facebook Ireland e.a. v. Gegevensbeschermingsautoriteit, C645/19, ECLI:EU:C:2021:483, para
- 60 Article 351 of the TFUE: The rights and obligations arising from agreements concluded before 1 January 1958 or, for acceding States, before the date of their accession, between one or more Member States on the one hand, and one or more third countries on the other, shall not be affected by the provisions of the Treaties. To the extent that such agreements are not compatible with the Treaties, the Member State or States concerned shall take all appropriate steps to eliminate the incompatibilities established. 61 CJEU, Judgment of 3 March 2009, C-205/06, ECLI:EU:C:2009:118, Commission v. Austria, para
- This judgment relates to the second paragraph of Article 307 of the Treaty establishing the European Community (repealed by Article 351 TFEU). Article 307: "The rights and obligations arising from agreements concluded before 1 January 1958 or, for acceding States, before the date of their accession, between one or more Member States on the one hand, and one or more third Decision on the merits 61/2023 36/73 - On the other hand, practices must be brought into line with European law "unless that practice is necessary in order for the Member State concerned to comply with obligations towards non-member States laid down in an agreement concluded prior to entry into force of the Treaty or to accession by that Member State 62".
- The Litigation Chamber therefore shares the view that it follows from this position of the CJEU that "the meaning of the two paragraphs have been reconciled, and it is now safe to affirm that art. 351
(1)TFEU provides temporary protection to allow the Member States not to incur international responsibility while the ultimate goal established by art. 351
(2)TFEU (that is, the removal of all incompatibilities) is achieved in a sustainable (for the Member State involved) and lawful (from an international law perspective) manner63".
- The Litigation Chamber cannot therefore subscribe to an interpretation according to which Article 96 of the GDPR would authorise, without any time limit, the continued application of international agreements concluded before 24 May 2016 - even if they complied with Directive 95/46/EC and EU law on that same date - without further compliance with the GDPR. Following such an interpretation, the co-legislators would have allowed, in defiance of the European case law cited above, for international agreements that complied with the state of Union law suspended on 24 May 2016 (including Directive 95/46/EC, which incidentally was repealed on 24 May 2018) to coexist without any time limit, on the one hand, and international agreements concluded after that date that were obligatorily compliant with the GDPR, on the other.
- This reading of Article 96 of the GDPR would also imply that data protection authorities assess the compliance of these international agreements with regard to the state of the law on 24 May 2016 many years after that date, in particular in the light of a Directive 95/46/EC that has been repealed for a number of years that will only increase over time and without in any way taking into account developments in the case law of the CJEU with regard to key concepts of data protection that may be common to Directive 95/46/EC and the GDPR or with regard to the Charter.
- On the contrary, the Litigation Chamber is of the opinion that the fact that Article 96 of the GDPR does not provide for a defined time limit (with reference to a cut-off date or with reference to a number of years elapsed, for example) does not exempt EU 64 member states, controllers or data protection authorities from their respective obligations. countries on the other, shall not be affected by the provisions of this Treaty. To the extent that such agreements are not compatible with this Treaty, the Member State or States concerned shall take all appropriate steps to eliminate the incompatibilities established". 62 CJEU, Judgment of 28 March 1995, C-324/93 The Queen / Secretary of State for the Home Department, ex parte Evans Medical and Macfarlan Smith, ECLI:EU:C:1995:84, p
- 63 Emphasis added by the Litigation Chamber: https://www.europeanpapers.eu/es/europeanforum/court-of-justice-finallyrules-on-analogical-application-art-351-tfeu 64 Nor, more generally, states subject to the GDPR. Decision on the merits 61/2023 37/73
- As far as EU member states are concerned, Article 96 of the GDPR does not exempt them from (re)negotiating, in fulfillment of their duty of sincere cooperation, a GDPR-compliant agreement. The more time passes, the less acceptable the inertia of governments in this respect. As early as 2021, data protection authorities - including the DPA - therefore invited EU member states to review their international agreements in light of the GDPR. 65
- The Litigation Chamber clarifies here that it is of the opinion that it is up to the Belgian State to negotiate a GDPR-compliant agreement, in fulfillment of its duty of sincere cooperation (Article 4
(3)TEU - point 144). It points out that on the date of adoption of this decision, 7 years have passed since the GDPR came into force. In this respect, the Litigation Chamber notes that no indication of the Belgian government's willingness to request a revision of the FATCA agreement has been brought to its attention in the context of this case. 152. The role of the Belgian State (like that of any other Member State that has signed a FATCA agreement comparable to the one signed by the Belgian State) does not, however, exempt the controller who, like the defendant, intends to rely on Article 96 of the GDPR, from examining whether the conditions for recourse to Article 96 are met. Indeed, independently even of the accountability obligation (Title II.E.4), recourse to Article 96 of the GDPR intrinsically implies, by the condition it lays down (i.e. the compliance of the agreement with EU law as applicable on 24 May 2016), that the controller must carry out this assessment. 153.
the data protection authorities, the Litigation Chamber is also of the opinion that the more time passes, the less acceptable it is for them to be restricted in the exercise of the role entrusted to them by the GDPR since 25 May 2018, a role which consists exactly as emphasised in points 113 et seq. in contributing to the effective and uniform application of the GDPR. In its Schrems II judgment cited above, the CJEU stresses in this regard the following with regard to the competence of supervisory authorities as enshrined in Articles 8
(3)of the Charter and 57
(1)(a) of the GDPR: - "(...) Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation (...) The exercise of that responsibility is of particular importance where personal data is transferred to a third country since, as is 65 Statement 04/2021 on international agreements including transfers of 13 April 2021: https://edpb.europa.eu/our-worktools/our-documents/statements/statement-042021-international-agreements-including_en In it, the EDPB ( EDPB) considers "that, in order to ensure that the level of protection of natural persons guaranteed by the GDPR [..] is not undermined when personal data is transferred outside the Union, consideration should be given to the aim of bringing these agreements in line with the GDPR [..] for data transfers where this is not yet the case. The EDPB therefore invites the Member States to assess and, where necessary, review their international agreements that involve international transfers of personal data, such as those relating to taxation (e.g. to the automatic exchange of personal data for tax purposes), [..] which were concluded prior to 24 May 2016 (for the agreements relevant to the GDPR) [..] The EDPB recommends that Member States take into account for this review the GDPR [..], the relevant EDPB guidelines applicable to international transfers, as well as the case-law of the European Court of Justice, including the Schrems II judgment of 16 July 2020". Decision on the merits 61/2023 38/73 clear from recital 116 of that regulation, ‘when personal data moves across borders outside the Union it may put at increased risk the ability of natural persons to exercise data protection rights in particular to protect themselves from the unlawful use or disclosure of that information" (points 107 and 108 of the judgment). 154. The Litigation Chamber will also pay particular attention to the following points: - The CJEU imposes very strict conditions on international agreements that have an impact on the exercise of the rights to privacy and personal data protection enshrined in Articles 7 and 8 of the Charter. More specifically, it follows from Opinion 1/15 of the CJEU on the draft PNR agreement between Canada and the EU (as well as Judgment C817/19 of 21 June 2022 66) and the Schrems II judgment67 that "the communication of personal data to a third party, such as a public authority, constitutes an interference with the fundamental right enshrined in Article 7 of the Charter, whatever the subsequent use of the information communicated. The same is true of the retention of personal data and access to that data with a view to its use by public authorities. In this connection, it does not matter whether the information in question relating to private life is sensitive or whether the persons concerned have been inconvenienced in any way on account of that interference" (point 124)68. - Any limitation on the fundamental rights enshrined in the Charter (including the fundamental right to data protection under Article 8) must satisfy the conditions of the above-mentioned Article 52
(1)of the Charter, which states that "Any limitation on the exercise of the rights and freedoms recognised by this Charter must be provided for by law and respect the essence of those rights and freedoms. Subject to the principle of proportionality, limitations may be made only if they are necessary and genuinely meet objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others". 155. It follows from all of the above, both
(1)the ratio legis of Article 96 of the GDPR, and
(2)the obligation of sincere cooperation which is imposed on Member States and, by extension, on supervisory authorities such as the DPA (of which the Litigation Chamber is the administrative litigation body), t