NETHERLANDS Law and Practice Contributed by: Friederike Henke, Ingrid Cools, Philip ter Burg, IJsbrand Uljée, Suzan van de Kam and Epke Spijkerman, BUREN
• if they are public authorities; • if their core activities consist of the regular and systematic monitoring of data subjects on a large scale; or • if their core activities consist of processing sensi - tive personal data on a large scale (including pro - cessing information about criminal offences). The ePrivacy Directive and the Dutch Cookie Act Additional provisions regarding data protection and privacy in the context of telecommunications are set out in Directive 2002/58/EC of the European Parlia - ment and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector in the EU (ePrivacy Directive) and in the Dutch Cookie Act. The ePrivacy Directive has been implemented in the Dutch Telecommunications Act, which prohibits unso - licited communication by email (as well as faxes and automated communication systems) for commercial, non-commercial or charitable purposes, unless send - ers can demonstrate the recipient’s prior consent. Under the Cookie Act, informed consent is required for the use of cookies, unless the cookies are: • needed to facilitate communication; • strictly necessary for the service requested by users; or • aimed at obtaining information about the quality and/or effectiveness of the services provided and have little or no impact on the users’ personal lives. These rules apply to both first-party cookies and third- party cookies. 8.2 Geographical Scope Pursuant to Article 3 (1), the GDPR applies to the pro - cessing of personal data in the context of the activities of an establishment of a controller or a processor in the EEA, regardless of whether or not the process - ing takes place in the EEA. The term “establishment” extends to any real and effective activity – even a mini - mal one – exercised through stable arrangements in the EEA.
Businesses not established in the EEA will also be subject to the GDPR if they offer goods and services to individuals in the EEA, or if they monitor the behav - iour of data subjects who are in the EEA. Non-EEA businesses that do this on a regular basis or in com - bination with certain high-risk activities will have to designate a representative in the EEA. Under these rules, websites directed at an EEA audience or track - ing visitors from the EEA must comply with the GDPR. No special requirements apply to data transfers from the Netherlands to other EEA countries. Transfers of personal data to countries outside the EEA, however, require – with just a few exceptions – either a deci - sion of the European Commission that the destination country ensures an adequate level of protection (this is the case for the UK, Switzerland, Canada, Israel and Japan, for example), or appropriate safeguards to protect the data subjects’ rights (such as the Commis - sion’s standard contractual clauses (SCCs) or binding corporate rules approved by a supervisory authority). On 16 July 2020, the Court of Justice of the Euro - pean Union (CJEU) issued its decision in Data Pro- tection Commissioner v Facebook Ireland , Maximillian Schrems , commonly referred to as “ Schrems II ”. The decision invalidated the EU–US Privacy Shield Frame - work, which was designed to provide companies on both sides of the Atlantic with a mechanism to comply with data protection requirements when transferring personal data from the European Union to the United States in support of transatlantic commerce. Following the Executive Order on “Enhancing Safe - guards for United States Signals Intelligence Activi - ties” by US President Biden on 7 October 2022 and a Regulation issued by the US Attorney General on 10 July 2023, the European Commission adopted its adequacy decision for the EU–US Data Privacy Framework. The decision concludes that the United States ensures an adequate level of protection – com - parable to that of the European Union – for personal data transferred from the EU to US companies under the framework. The EU–US Data Privacy Framework introduces new binding safeguards to address all the concerns raised by the European Court of Justice, including limiting
746 CHAMBERS.COM
Powered by FlippingBook