Popular Posts

Showing posts with label Europe. Show all posts
Showing posts with label Europe. Show all posts

Monday, September 4, 2017

Why you should be concerned by the GDPR even if your company is not located in the EU


The European personal data protection directive of 24 October 1995 applied to data processing carried out by companies, i.e. data controllers, located within the European Union. Data processing activities carried out by data controllers located outside of the EU were generally not subject to the provisions of the European directive as transposed into the national laws of the Member States. (1) With the development of technology and of online services around data, many companies located outside of the European Union, such as Google, Amazon, Facebook or Apple (the “GAFA”) for example, collect and process data from Europeans and “escape” the European regulations, even though data transfers to these American companies can be subject to the Privacy Shield principles.

Now, data and more specifically personal data is at the core of the digital economy. It then became necessary to update the European personal data laws to take into account the technology developments that have occurred since the 1995 directive, and assure a high and homogenous level of protection to personal data. This was done with the General Data Protection Regulation (GDPR). This European text was adopted on 27 April 2016 after over four years of intensive debates. It will become applicable on 25 May 2018. (2)

One of the purposes of the GDPR is to take into account, cases where several data controllers and/or processors located in different regions in the world are involved in data processing; but also cloud computing and big data services (with servers installed and data collected in several regions); and the activities carried out by the GAFA, so that the personal data of the people living in Europe remain protected regardless of where the data controller is located in the world.

The scope of the regulation covers not only businesses in the European Union but also non-EU companies targeting the European market. These non-EU companies are therefore concerned by the GDPR and must get compliant with these new rules.


1. The GDPR is applicable in Europe and beyond

The 1995 directive had to be transposed into national law of the Member States. These national data protection laws did however include differences between the Member States, certain countries having opted for a strict transposition of the European directive, whereas other countries chose a more liberal approach.

The GDPR will become enforceable directly in all the European Union. Its provisions will apply almost identically in all the Member States, except for a few provisions which may differ slightly among the Member States. (3)

But where the directive had moderate impact outside of the EU, the regulation will apply not only within the EU but will also produce extra-territorial effects, beyond the EU borders. (4)

    1.1 Application within the European Union

The regulation shall apply to any processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing itself takes place within the EU.

The establishment located in the EU implies the effective and real exercise of activity through “stable arrangements”. However the establishment is not subject to any particular legal form. It may be the headquarters, or a subsidiary or even a branch of a company itself located outside of the Union.

The processing may be carried out in or outside the EU. With this provision databases hosted via a cloud computing service can be governed by the GDPR, regardless of where the servers are actually installed in the world.

    1.2 Extra-territorial application

The regulation shall also apply to processing regarding individuals located in the EU, carried out by a data controller or a processor not established in the Union where the processing activities are related to offering goods (e.g. e-commerce activity) or services (e.g. mobile applications, cloud hosting services) to such data subjects, whether connected to a payment or free of charge.

To establish whether the data controller or the processor is actually targeting the European market by proposing goods or services to persons located in the EU, one must gather a number of elements such as the use of a European language or of a currency such as the euro and the fact that the products or services can be delivered in Europe. The mere accessibility of the web site of the company in Europe, or an email address are not sufficient to establish that that company targets the European market.

The data processing of persons located in the Union by a company, controller or processor, which is not established in the Union is also subject to the GDPR when the purpose of such processing is to monitor the behaviour of these persons, if such behaviour takes place in the EU. This provision is mainly about online profiling, “particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.” (5)

One should also note that these provisions shall apply to data controllers and to processors. The latter should also take all necessary measures to comply with the GDPR.

The GDPR is not limited to controllers and processors located in the European Union. Its geographical scope reaches beyond the EU borders whenever personal data of European data subjects are processed.


2. What are the consequences for non-European businesses?

Companies that have no establishments in the European territory but that target the EU for their commercial activities (see criteria above), and that in doing so collect and process personal data of European subjects will therefore have to comply with the GDPR, the deadline being 25 May 2018.

    2.1 The designation of a representative in the Union

Beyond the GDPR compliance work to be carried out, controllers and processors that have no establishment in the EU must designate a representative in the EU, “in writing”. (6)

This representative must be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are located. The representative, as the agent of the controller or processor shall be the point of contact for the supervisory authority and for the data subjects having questions about the processing. The controller and processor shall however remain primarily legally liable with regards to GDPR compliance and its due application.

It must be noted that no representative must be designated in the following cases:
processing which is occasional,
which does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in article 10, and
and is unlikely to require a privacy impact assessment (PIA) subject to article 35 of the GDPR.

Also, non-European public authorities or bodies are not concerned by the designation of a representative.

    2.2 The United Kingdom after Brexit

Once the United Kingdom is no longer a Member State, the European regulation will no longer apply to it. However, the UK government has declared that they wanted to pass a new law, repealing the Data Protection Act 1998 currently in effect, so as to include the GDPR into English law.

The purpose of this Bill is to reassure businesses after Brexit, on the ability to keep transferring personal data between the UK and the EU. In doing so, the UK wants to ensure that its Data protection law will be considered as offering an adequate level of protection by the Brussels Commission, allowing businesses to keep transferring personal data between the UK and the EU without restrictions. (7)

    2.3 GDPR compliance

The European regulation includes several new principles and existing rights that were reinforced. These principles and rights must be integrated in the internal procedures of businesses processing personal data of Europeans. This can be a costly, burdensome and time consuming process. These principles can be divided up between the rights of data subjects and the obligations of the controllers and processors.

a) The rights of data subjects
    - The conditions to obtain consent from the data subjects are reinforced (art. 7): the terms regarding consent must be drafted in clear and explicit language;
    - The right to be informed is modified toward more transparency and simplification (art. 12, 13 and 14)
    - Data portability (art. 20) permits data subjects to request the controller to recover or to transfer their collected data to a new data controller;
    - For online services targeting children (i.e. children below 16, or 13 in certain Member States), processing children data will be subject to the consent or authorisation of the person having parental authority. (art. 8)

b) The obligations of the controllers and processors
    - Automated process and profiling techniques will be regulated. (art. 22) Such process will be authorised under certain conditions and provided the data subject has given his consent;
    - According to the accountability principle, the controller must implement clear and accessible internal rules to guarantee and demonstrate compliance with the regulation (art. 5 and 24);
    - During the development of new products or services, the controller must include personal data protection by default in the definition of the processing system and within the data process  (“privacy by design” principle) (art. 5 and 25);
    - The GDRP imposes stronger data protection security rules. Security breaches must be notified by all controllers, regardless of their main activity (art. 5 and 32 to 34);
    - A data protection officer (DPO) must be appointed in all companies where the core activities of the controller or processor consist of processing data which require monitoring of data subjects on a “large scale” or processing of specific categories of data on a “large scale” (art. 37, 38 and 39).

Finally, the GDPR includes the possibility for the supervisory authorities to impose more stringent sanctions. (art. 83) Depending on the type of infringement, the supervisory authorities can impose administrative fines up to 10 million euros or 2% of the total worldwide turnover of the company during the preceding financial year, whichever is higher, or up to 20 million euros or 4% of the total worldwide turnover of the company during the preceding financial year.
                                                                * * * * * * * * * * * *


(1) See article 4 “National law applicable” of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data

(2) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

(3) For example, each Member State can choose the minimum age for a child to give his/her consent, between 13 and 16 years (art.8).

(4) See GDPR, recitals 22 to 24 and article 3 “Territorial scope”

(5) Recital 24

(6) GDPR, article 27

(7) “UK Government announces proposals for a new Data Protection Bill”, in Technology Law Dispatch, 16 August 2017

(8) For a more detailed analysis of the GDPR, see our previous articles on this matter: New European General Data Protection Regulation (GDPR): the compliance clock is ticking, How to prepare for GDPR compliance and be ready by May 2018



Bénédicte DELEPORTE
Avocat

Deleporte Wentz Avocat
www.dwavocat.com

September 2017

Friday, August 11, 2017

How to prepare for GDPR compliance and be ready by May 2018


The General Data Protection Regulation (GDPR) will come into effect in the European Union in less than a year from now, on 25th May 2018. (1) The GDPR is a thorough and complex reform of data privacy law, which means that companies have to get organised to be compliant and ready by May 2018.

There are many differences between the existing European data privacy legal system based on the 1995 Data Protection directive and the new GDPR. Whereas, the 1995 Data Protection directive had to be transposed into the legal systems of each member-state, with national data protection laws which didn’t come into effect at the same time (France transposed the 1995 directive in 2004!) and with some differences between the national data protection laws, the GDPR will apply (almost) identically across the European Union from 25th May 2018.

The 1995 Directive was outdated regarding certain processing activities not available at the time, or regarding the development of the role of processors, especially those providing cloud computing services. The GDPR takes into account the evolution of technology and of data processing activities and aims to reinforce the rights of the individuals (data subjects) on their personal data with clearer rules regarding consent for data collection and processing and more stringent obligations on the data controllers and processors.

With the GDPR, companies will be subject to a new “accountability” regime. Accountability under the GDPR includes the implementation of new procedures such as the privacy-by-design principle which implies that data privacy must be included into the design stage of a new product or service; data privacy impact assessments when new data processing is likely to result in a high risk for the rights of the data subjects; the obligation to maintain a record of processing activities listing the processing and procedures implemented and the obligation to notify personal data breaches to the supervisory authority (following a security breach or a cyber attack for example).

The fines for breaching GDPR obligations will be much higher than before since depending on the nature of the breach, administrative fines may reach between 10 million euros or 2% of the worldwide revenue of the company and 20 million euros or 4% of the worldwide revenue of the company…

The data privacy agencies of the member-states, and the members of the Article 29 Working Party (representatives of the data privacy agencies of the member-states) are working actively to help companies get prepared for GDPR. For example, the French data privacy commission (CNIL) has published a plan to help companies get organised to prepare GDPR compliance. And the members of the Article 29 Working Party (WP29) have adopted guidelines providing more detailed information on the new principles of the GDPR.


1. The compliance plan recommended by the French data privacy commission


The French data privacy commission (CNIL) has published a plan to help companies work on GDPR compliance. (2) This plan is comprised of six steps, as follows:

    - Step 1: Appoint a “compliance pilot”
Given the complexity of implementing a GDPR compliance plan, an individual - or depending on the size of the organisation, a dedicated task force - should be specifically appointed to drive this phase. This individual, who may be an existing or future data privacy officer (DPO), or an external consultant, shall have several tasks, including informing, advising and consulting the internal teams. He/she should also perform internal audits and should be key in organising and coordinating the compliance tasks to be performed.

    - Step 2: Map out the processing activities
The compliance team should carry out an inventory of the data processing activities carried out by the company and record them. This will allow the compliance team to assess the practical impacts of the GDPR on the data processed by the company.

    - Step 3: Prioritise the tasks to be carried out
Based on the types of data processing activities, the team will then be able to identify the compliance tasks to be implemented. These tasks should be prioritised, taking into account the risks of the processing on the rights and freedoms of the data subjects.

    - Step 4: Manage risk
If the team has identified data processing activities that are likely to generate high risk on the rights and freedoms of the data subjects, a data privacy impact assessment (DPIA or PIA) must be carried out for each such processing. Companies can use the PIA guidelines to help them implement these new procedures (see below).

    - Step 5: Develop or update your internal procedures
The company’s internal procedures will have to be updated to be able to apply a high level of protection to personal data. These procedures must protect data at any time taking into account all the events which may happen during data processing (such as a data breach, managing  correction or access requests, modification of the data collected, etc.).

    - Step 6: Document compliance
To be able to prove that the company complies with the GDPR, the necessary documents must be drafted and regularly updated. These documents shall include the company’s internal procedures, data privacy impact assessment, internal audit reports, etc.


2. The Article 29 Working Party guidelines

The WP29 has published several support documents to help with GDPR compliance. The purpose of these documents is to clarify the new principles that must be implemented by the companies by May 2018. At the end of June 2017, the following guidelines were published:

    - Guidelines on Data Protection Impact Assessment (“DPIA” or “PIA”) and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679
These guidelines provide details on the types of processing activities that should trigger a privacy impact assessment, the existing methods to carry out a PIA, the rules governing the release of a PIA and/or notification to the supervisory authority and when the supervisory authority should be consulted in case of a potentially risky processing. Typically, a PIA will include the following four features: i) a description of the proposed processing and its purpose; ii) an assessment of the necessity and proportionality of the processing; iii) an assessment of risks to data subjects; and iv) the measures to address the risks and demonstrate compliance with the GDPR.

The data protection impact assessment principle is defined under article 35 of the GDPR. PIAs are one of the mechanisms included in the principle of accountability. When performing a PIA, data controllers adhere to the GDPR and can demonstrate that appropriate measures have been developed to ensure GDPR compliance. Failure to carry out a PIA is subject to an administrative fine of up to 10 million euros or 2% of the worldwide revenue of the company for the preceding year.

    - Guidelines on Data Protection Officers (“DPOs”)
These guidelines provide details on how a Data protection officer should be appointed, as well as the role and responsibilities of the DPO.

Although this role is not new, the appointment of a DPO was not mandatory under the 1995 Directive. To be compliant with the GDPR, certain companies, data controllers and processors, will have to appoint a DPO. The role and responsibilities of the DPO are described under articles 37 to 39 of the GDPR.

The DPO allows companies to ensure GDPR compliance (including, for instance, for internal audits, to act as a liaison between the different internal departments, and with the data subjects). However, DPOs are not liable in case of non-compliance to the GDPR. The data controller or the processor are responsible for GDPR compliance and implementation.

    - Guidelines on the right to data portability
These guidelines define the data portability principle, identify the main aspects of this new right, identify when this right should apply, define how the rules concerning the data subjects apply to data portability, and define how the data should be conveyed to the data subject or to a new data controller.

Data portability is slightly different from the right of access under the 1995 directive. Data portability allows the data subjects to receive the data provided to the data controller in a structured and machine-readable format, and to transfer this data to a new data controller. The right to data portability will typically be used when a consumer switches service providers. The right to data portability is defined under article 20 of the GDPR.

    - Guidelines for identifying a controller or processor’s lead supervisory authority
The GDPR set up another new principle: the lead supervisory authority, to take into account transborder data processing.

These guidelines identify the supervisory authority competent for transborder processing, especially when the principal place of business of the data controller is different from its European headquarters, when several companies within a multinational group of companies are concerned or when there are several joint data controllers. The issue of data processors is also addressed by the guidelines.


     Other guidelines are being developed and should be published before the end of 2017. These include guidelines on certification, guidelines on data privacy breach notifications, guidelines on consent by the data subjects, and guidelines on profiling.
 
                                                                   * * * * * * * * * * * *

(1) Regulation (EU) 2016/619 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

(2) Available on the CNIL website (in French)

(3) The WP29 Guidelines are available on the CNIL website (in English) : Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679 ; Guidelines on Data Protection Officers (“DPOs”) ; Guidelines on the right to data portability ; Guidelines for identifying a controller or processor’s lead supervisory authority



Bénédicte DELEPORTE
Avocat

Deleporte Wentz Avocat
www.dwavocat.com

August 2017

Friday, June 10, 2016

New European General Data Protection Regulation (GDPR): the compliance clock is ticking


After over four years of debates at the European level, the General data protection regulation (GDPR) was finally passed on 27 April 2016. The new regulation will apply in all the European member states in two years, as from 25 May 2018. (1) The compliance countdown is now running for all organisations processing personal data.

The GDPR is part on a more global reform of European data protection law - the “data protection package”, which also includes a directive on data transfers for policing and judicial purposes, i.e. personal data processed by the European police and judiciary authorities.

The GDPR will repeal Directive 95/46/EC of 24 October 1995 on the protection of personal data. The new text will be the base of our regulation of personal data protection in Europe, with a single set of rules (with a few exceptions).

The regulation is based on existing data protection law. The main principles regarding the processing of personal data, such as the principles of lawfulness, fairness and transparency of the data process, the principles of specified and legitimate purpose, of adequacy of the process, of data conservation for a limited duration and of data security are preserved. (art. 5) But because of the technical and behavioural evolutions that have occurred in our society since the 1995 Directive, it was important to adapt and complement the existing principles and implement more homogenous rules within the European Union. This is however a complex text comprised of 173 recitals and 99 articles, when the directive included only 34 articles.

We summarise below the main provisions of the GDPR regarding the rights of natural persons, followed by the rights of corporations (as data controllers or processors).


1. The rights of natural persons under the GDPR

Several provisions of the GDPR reinforce the existing rights on the data of natural persons (“data subjects”). We identified the major evolutions as follows:

    - The conditions to obtain consent from the data subjects are reinforced (Art. 7): the terms regarding consent must be drafted in clear and explicit language. The data subject must be able to withdraw his consent at any time. The burden of proof of obtaining the data subject’s consent rests on the data controller who must be able to show that the data subject did give his consent to the process.

    - The right to be informed is modified toward more transparency and simplification (art. 12, 13 and 14): the information must be concise, clear, intelligible and easily accessible. It must be drafted in clear and legible terms, especially when targeting children.

    - The GDPR confirms the “digital right to be forgotten” (or right to erasure) as defined by the European court of justice (ECJ) in the Google Spain decision of 13 May 2014. (art. 17) The data subject can request the controller to erase his personal data without undue delay. Data erasure is however subject to certain conditions -including regarding the right to information, and is not automatic. These conditions and limitations to the right to be forgotten have been further defined since 2014 by subsequent case law.

    - Data portability is a new right for the data subjects. (art. 20) Except in certain situations, data subjects can request the controller to recover or to transfer their collected data to a new data controller (e.g. transfer to a similar service proposed by a competitor). To prevent blocking or circumventing this obligation, the controller must transfer the data in a structured, commonly used, machine-readable format.

    - Finally, the GDPR includes the principle of specific data protection rules for children below 16 years of age. (art 8) Children are intensive users of internet services (social networks, chat, SMS, MMS) but are not necessarily aware of the concept of personal data and of how their data can be used by third parties. The GDPR identifies children as a distinct category of data subjects and recognises the need to provide specific protection to their data. The 38th recital provides that children must receive specific protection from organisations using their personal data for marketing purposes or user profile set ups. For online services targeting children (i.e. children below 16, or 13 in certain member states), the processing of children data will be subject to the consent or authorisation of the person having parental authority. The controller must implement “reasonable” means, taking into account available technology, to ensure the effectiveness of such parental consent.


2. The rights of data controllers and processors under the GDPR


Regarding the rights of the controllers and processors (corporations and any organisation processing personal data), we note a tendency toward simplification of formalities, but also toward more stringent obligations. Also, the level of the financial penalties was raised substantially. The major evolutions are as follows:

    - Automated process and profiling techniques - which are used increasingly with big data projects for example, will be regulated. (art. 22) Such process will be authorised under certain conditions and provided the data subject has given his consent.

    - According to the accountability principle, the controller must implement clear and accessible internal rules to guarantee and demonstrate compliance with the regulation on process inventory, security, and if applicable, compliance with the preliminary formalities and with the appointment of a data protection officer. (art. 5 and 24)

    - During the development of new products or services, the controller must include personal data protection by default in the definition of the processing means and within the data process  (“privacy by design” principle). (art. 5 and 25)

    - The GDPR creates a new “joint controllers” concept (art. 26), to take into account the technical evolutions, especially with cloud computing services under which the entity collecting the data no longer controls the technical data process. Two data controllers may then co-exist, i.e. the entity collecting and using the data, and the entity which determines the technical means of the data process (often the hosting service provider or the cloud service provider, as a subcontractor of the data collector/controller). In case of joint liability, the joint controllers must define the respective scopes of their liability in performing their obligations, especially concerning the data subjects. The liability of the subcontractor is now acknowledged at the same level as its client’s.

    - The GDPR withdrew the preliminary filing obligation for new data processing (art. 30) except for data transfers outside of the European Union which are subject to a specific regime. In return, the controller must (i) either keep an internal record of processing activities listing the data process implemented, (ii) or consult the supervisory authority prior to launching a new data process if such process requires an impact assessment and includes specific risks.

    - The GDRP imposes stronger data protection security rules. Security breaches must be notified by all controllers, regardless of their main activity. (art. 5 and 32 to 34) For example in France, this notification duty is currently limited to communications operators and to “vitally important operators” (OIV) i.e. operators of critical infrastructures or services.

    - A data protection officer (DPO) must be appointed in all companies where the core activities of the controller or processor consist of processing data which require monitoring of data subjects on a “large scale” or processing of specific categories of data on a “large scale”. (art. 37, 38 and 39) The data protection officer (which in France will replace the current “correspondant informatique et libertés” - CIL) must be a competent law and personal data protection professional. This person may be employed by that organisation or be a third party consultant.

    - The rules regarding data transfers outside of the European Union won’t change substantially. (art. 44 to 50) As a principle, all data transfers outside of the EU remain prohibited. This prohibition may be waived for transfers to a third country offering an adequate level of protection, as defined by the European Commission and for transfers to companies in third countries, provided one of the available contractual tools has been implemented between the exporting controller and the importing processor (EU model contractual clauses, Binding corporate rules (BCRs) or code of conduct). It is still unclear whether existing adequacy decisions will be upheld for all third countries currently listed. Since the GDPR includes new and more stringent provisions, the Commission may decide to reassess whether these countries are still providing an adequate level of protection under the new Regulation.

    - Companies that operate in several member states will designate a supervisory authority as the lead competent authority, for cross-border processing and to handle complaints. (art. 56) This lead supervisory authority shall be the authority of the seat of the main establishment, construed as the place where the main decisions regarding the data process purpose, conditions and means are made.

    - The GDPR includes the possibility for the supervisory authorities to impose more stringent sanctions. (art. 83) Depending on the type of infringement, the supervisory authorities can impose administrative fines up to 10 million euros or 2% of the total worldwide turnover of the company during the preceding financial year, whichever is higher, or up to 20 million euros or 4% of the total worldwide turnover of the company during the preceding financial year.

Finally, the GDPR will apply not only within the European Union, but will also produce extra-territorial effects. (art. 3 and 27) The GDPR will apply:
    - to controllers located within the European Union, whether or not the data process is performed in the EU, and
    - to the data of EU citizens and residents processed by a controller or a processor (subcontractor) located outside the EU, if the products or services target the European market. Certain non-European companies may then have to comply with the GDPR.


Businesses should use this two-year transition period to work on their legal and operational compliance with the GDPR. This compliance exercise should include a legal review of their existing commercial terms and conditions and privacy policies applicable to their products and services, and a review of their internal corporate privacy policies. Certain types of data process will also require technical and/or operational review and upgrade (such as collecting the proof of consent by the data subject, especially for the processing of children’s data).


                                                                    * * * * * * * * * * * *


(1) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General data protection regulation)

Bénédicte DELEPORTE – Avocat

Deleporte Wentz Avocat
www.dwavocat.com

June 2016

Monday, October 12, 2015

Drone use regulation: legal perspectives from France and Singapore


 
In January 2014, an 18 year-old used a drone (or unmanned aircraft system - UAS) equipped with a GoPro camera to fly over and record a video of the city of Nancy, in eastern France. He then posted his video on the internet. The video received more than 400,000 views! Unfortunately, this young man didn’t realize that the use of a drone with a camera over a populated area is regulated in France.

The video was identified by the authorities, who contacted the young man. The regional department of civil aviation (Direction régionale de l’aviation civile - DRAC) notified the rules applicable to the use of a UAS and required him to get all necessary authorizations. The young man was then subpoenaed before the criminal court for endangering third parties’ lives.(1)

A few weeks before in the US, Amazon had announced its drone delivery project, engaging a battle on flight regulation and safety with the Federal Aviation Administration (FAA).(2)

Earlier this month in Singapore, SingPost announced the first 2km test flight using an unmanned aircraft to deliver mail and a small parcel to an identified recipient.(3)

Although the drone market is developing fast not only in Europe, but in many other regions in the world, there are still few drone-specific laws regulating their use and the level of skills requested to operate these aircrafts. Issues with public safety and privacy are also surfacing with the increasing use of drones. France was the first country to issue a regulatory framework for the use of civilian drones in 2012. Singapore enacted its own drones regulation in May this year.

In this article, we review the issues of public safety and privacy, followed by the French and new Singapore UAS regulations.


1. The development of drone use: public safety and privacy concerns

Drones are commonly defined as aircrafts without on-board pilots that are operated by remote control or with a smartphone.

There are many types of drones, from lightweight devices of a few hundred grams with limited flight radius and battery life, usually used for recreational activities, to larger, professional, aircrafts which can weigh up to a few hundred kilos and are able to fly long distances at high altitudes (several hundred meters).

Drones can be equipped with photo or video cameras, temperature or air sensors, or be used to launch pesticides or other types of loads.

Unmanned aircrafts have been used for many years for a wide variety of purposes, including for public safety (surveillance of demonstrations in public areas, firefighting, securing areas after industrial accidents - such as the Fukushima nuclear disaster -, monitoring infrastructures and buildings, filming or for recreational purposes). New uses are also emerging, such as parcel or medication delivery in emergency situations or to remote areas, or simply to cut costs.

The use of civil drones has soared in recent years, with a whole new market open to consumers. However, their use raises a number of legal issues in areas such as public safety and privacy.

    - Public safety : uncontrolled use of drones can interfere with other categories of aircrafts, such as ultralights, helicopters and airplanes at take-off and landing. No actual accidents have been reported so far, but several drones have been reported flying around airports, in restricted areas, in the past months.

A drone flying over a crowded area may crash down and injure people in the public. And one cannot ignore the possibility of using drones for illegal or terrorist activities. In 2014, drones were detected flying over nuclear plants and military facilities in France and over the presidential Elysée palace in Paris. In January 2015, a drone landed on the lawn in front of the White House in Washington DC.

Although these areas are no-flight zones, the operators are seldom identified and it is hard to know whether these incidents were merely provocative, or test cases for future attacks.

Patrick Ky, Executive director of the European Aviation Safety Agency (AESA) has expressed concerns regarding the use of drones in Europe and the increasing number of incidents. After collating the comments of a public consultation closed a few days ago, AESA should publish a “technical opinion” by the end of 2015. This document should then be used as preliminary work for a future regulation of drones under 25kgs (currently, AESA is only comptent for aircrafts above 150kgs).(4)

    - Privacy : drones can be used to invade one’s privacy if equipped with high performance cameras or video recorders, challenging the right to privacy and personal data protection.

Right to privacy
French law has a strict regulation regarding the right to privacy, whether one is an “anonymous” person or a celebrity. In theory, the publication of photographs taken with a photo camera placed on a drone is subject to the prior consent of the person concerned. However, consent is usually impossible to collect when using a drone.

The right to privacy is waived when people are in a public setting (e.g. attending a concert, a tennis or a football game) and when the photograph or the video doesn’t focus on a single person, but is a global photograph of the public, is not degrading and is within the scope of the right to inform the public. Unless these general principles are applied, the person appearing on a photograph or a video made via a drone may sue the aircraft operator (or the company employing the operator) for violating his/her right to privacy.

So far, Singapore has no laws regulating the use of drones invading people’s personal spaces (such as a drone video-recording a person in his/her garden or at a private party without that person’s knowledge).

Personal data regulation
The act of taking a photograph or a video of a given person is deemed personal data collection under French and European personal data regulation. Under French law, personal data treatments, i.e. the collection of data relating to a natural person, who is either identified or identifiable, must be filed with the French data commission (“Commission de l’informatique et des libertés” or CNIL). Such data treatment is subject to the French data protection law (Loi informatique et libertés).(5)

Drone use was unforeseen when the French data protection law was first enacted in 1978, and again with the European directive of 1995. Applying these legal requirements to the use of drones is therefore quite problematic. However, the European data protection authorities are starting to tackle this issue: the French CNIL has been working on the issue of drones and privacy since 2012 and last June the European G29 working group issued a list of recommendations on this topic.(6)

The recent Singapore Personal Data Protection Act doesn’t provide any drone-specific provisions either.(7) The Personal Data Protection Act requires the subject’s consent before taking photographs or a video for commercial use. However, this applies to private space only and not public space.

The use of drones for civil purposes is not prohibited but is beginning to be regulated.


2. French law and the use of civil drones in the airspace

France was the first country to issue specific regulation for the use of unmanned aircrafts. Two administrative orders (“arrêtés”) were published on 11 April 2012 relating respectively to the design, use and capacity required to operate such devices, and to the use of the airspace by unmanned aircrafts.(8)

These two complementary texts have a common purpose: to guarantee public safety. They classify unmanned aircrafts in different categories, define the types of authorized activities, and provide rules regarding the use of the airspace based on the different purposes for operating unmanned aircrafts.

Although these rules don’t solve all the legal issues raised by the use of drones, they provide a useful framework for the companies designing and distributing new aircraft models and for users to operate the drones within the legal boundaries.

Civil drones are classified (categories A to G) according to weight, type of propulsion, limitations, and types of activities contemplated. The resulting obligations depend upon the proposed use of the drone: speed, altitude (in-sight flights or out-of-sight flights), zones flown over and purpose.

Only category A aircrafts, i.e. drones weighing less than 25kgs, with a single propulsion system, without a camera and only flying in-sight are exempted from the airworthiness document and are therefore authorized to fly without any restrictions regarding the capacity of their operator.

All other unmanned aircraft categories are subject to a preliminary authorization issued by the Minister in charge of civil aviation, and to the following requirements: the installation of specific devices to allow the operator to monitor the altitude of the aircraft and a fail-crash system for forced landing, a minimum skill level of the operator and the possession of specific documents (user and maintenance manuals, airworthiness document, etc.).

Finally, the operator of an unmanned aircraft is responsible for implementing all necessary safety procedures to ensure third party safety and for complying with all applicable regulations.

Using a drone outside of these legal boundaries is subject to criminal penalties set forth in the French Code of transport, the Code of civil aviation and the Criminal code. For example, using an unmanned aircraft without the required airworthiness documents or with expired documents, or if the drone does not comply with the technical airworthiness document or with the general safety rules is subject to one year prison term and/or a fine of €75,000.(9)


3. The new Singapore Unmanned Aircraft Act

Drones are also becoming very popular in Singapore and the same concerns regarding public safety and privacy are being raised. Several incidents involving drones were reported in the past 12 months, including drones crashing on the MRT (metro) tracks and drones seen flying over prohibited or restricted zones.

Singapore enacted the Unmanned Aircraft (Public Safety and Security) Act 2015 in May, with an aim to clarify the rules regarding drone use. The unmanned aircraft act amended the existing Air Navigation and Public Order Acts.

Permits are required for drones used for professional or commercial purposes, usually equipped with a photo or a video camera, as well as for drones weighing more than 7kgs and drones to be flown over sensitive or restricted areas (“protected areas”).

Unmanned aircrafts used for recreational or private purposes and weighing less than 7kgs are exempted.

Two types of permits, an operator permit and an activity permit, are required for operating drones weighing more than 7kgs, for any purpose (private or professional), and for operating drones for commercial purposes regardless of the weight. An activity permit is required to operate an unmanned aircraft in a restricted area, or within 5kms of a military base.

A list of security-sensitive areas (special outdoors events, certain public facilities and government buildings, the Istana Presidential palace, military bases, etc.) is to be published.

Permits are issued by the Civil Aviation Authority of Singapore (CAAS).

Using a drone illegally in Singapore is subject to a fine of S$20,000 and/or one year prison term. However, if the drone carries dangerous materials (such as weapons or hazardous chemicals), the operator or the owner is subject to a fine of S$100,000 and/or five years prison term.


     Despite the growing interest of both the public and businesses in using drones for recreational purposes but also for more and more diverse commercial purposes, such as short distance delivery, there is no European or international concerted approach on drone use regulation (and on the related issues of privacy and personal data protection). A number of countries (including the United States and Japan) are beginning to regulate the use of drones, limiting or prohibiting their use. We may see a first effort at producing regional rules with the latest position of the European Aviation Safety Agency on this matter, and increased pressure from the commercial airline pilots.

                                                       * * * * * * * * * * * *

(1) “Poursuivi en justice pour avoir filmé Nancy avec un drone”, published on 13 February 2014 in le Figaro (http://etudiant.lefigaro.fr)

(2) “Amazon unveils futuristic plan: Delivery by drone”, published on 1st December 2013 on cbsnews.com

(3) “Mail sent to Pulau Ubin by drone in world-first SingPost trial”, published on 8 October 2015 on Channel NewsAsia (www.channelnewsasia.com)

(4) “Les drones volent n'importe où, n'importe comment en Europe" (AESA), published on 9 October 2015 in La Tribune (www.latribune.fr)

(5) French data protection law n°78-17 of 6 January 1978 referred to as “Loi informatique et libertés”. The law was amended in 2004 when the 1995 European directive on personal data protection was transposed into French law. The national data protection laws will be replaced by the future European data protection regulation, which should become effective by the end of 2015 and enforceable within 2 years thereafter.

(6) Article 29 Data Protection Working Party, Opinion 01/2015 on Privacy and Data Protection Issues relating to the Utilisation of Drones, 16 June 2015 (WP 231).

(7) Singapore Personal Data Protection Act (2012) ; see also the Personal Data Protection Commission of Singapore website, at www.pdpc.gov.sg

(8) Administrative order of 11 April 2012 regarding the use of the airspace by unmanned aircrafts (“Arrêté relatif à l’utilisation de l’espace aérien par les aéronefs qui circulent sans personne à bord”)  ; Administrative order of 11 April 2012 regarding the design of unmanned aircrafts, to the conditions of their use and to the required capacities of their operators (“Arrêté du 11 avril 2012 relatif à la conception des aéronefs civils qui circulent sans aucune personne à bord, aux conditions de leur emploi et sur les capacités requises des personnes qui les utilisent”) ; Articles R.133-1-2 and D.131-1 to D.133-10 of the French Code of civil aviation.

(9) Article L.6232-4 of the French Code of transport.



Bénédicte DELEPORTE
Avocat

Deleporte Wentz Avocat
www.dwavocat.com

October 2015