Boston College Law Review, Jun 2018

When foreign parties involved in U.S. litigation are ordered to produce information that is protected by EU data privacy law, they are caught in an unfortunate “Catch-22.” Historically, U.S. courts have pointed to the unlikelihood of sanctions for data privacy law violations to justify these orders. EU data privacy law, however, has recently undergone several shifts in favor of tougher rules and significantly increased sanctions. Additionally, EU regulators are now more vigilant and active in enforcing these laws. These developments, combined with the benefits of international judicial respect and the intrinsic value of privacy, mean that U.S. courts should more strongly consider EU data privacy law in discovery deliberations. This Note argues that courts should more heavily weigh the interests of foreign nations and the hardship on foreign litigants when contemplating discovery orders and, when appropriate, order discovery to be conducted through the Hague Evidence Convention rather than by the foreign party.

COMM’N, [] (pointing out that individuals entrust their personal information to third parties for everyday actions). 2 See McKay Cunningham, Complying with International Data Protection Law, 84 U. CIN. L. REV. 421, 421 (2016) (explaining how businesses with even negligible foreign relationships may In U.S. litigation, discovery orders often run up against data privacy laws.4 Foreign litigants can find themselves in a quandary when they are ordered to produce information that is protected by foreign data privacy laws.5 U.S. courts have frequently dismissed the consequences of ordering litigants to violate EU data privacy laws by pointing to the unlikelihood of their enforcement.6 This Note discusses the increasing importance of EU data privacy law in discovery deliberations.7 Part I provides a brief history of EU data privacy law, including the development of more stringent rules and sanctions8. It then highlights the recent increase in EU enfocrement actions for data pirvacy violations.9 Part II discusses the conflict between EU data privacy law and U.S. discovery procedures.10 Part III argues that U.S. courts should adjust their approach to discovery orders that contravene EU data privacy law by more strongly considering the hardship placed on foreign litigants, as well as the intrinsic value of privacy.11 I. THE DEVELOPMENT OF DATA PRIVACY LAW IN THE EUROPEAN UNION Data privacy law governs the collection, use, processing, preservation, and divulgence of personal informatio1n2. Personal information is defined broadly, so data privacy law applies to most U.S. businesses1.3 Rather than a single law, a continually broadening assemblage of statutes, regulations, common law duties, contractual commitments, industry norms, andinternational obligations govern U.S. data privacy practices1.4 Agreements between the United States and the European Union are an important source of data privacy law.15 Despite differing approaches to protecting personal informationth,e United States and the European Union have deliberately and continuously endeavored to cooperate with one anothe1r6. As an economic region with significant market power and a hub for U.S. trade and investment, theuEropean Union has substantial negotiatni g power on data privacy matters1.7 U.S. businesses with operations in theEuropean Union rely on EU-U.S. information exchanges, so any possible limitations on those exchanges are highly consequential.18 Despite the European Union’s strong position, the United States pr-e sists as a powerful adversary at the negotiating table because the U.S. economy is the largest international arena for EUcompanies.19 Both the United States and the European Union had good reason to negotiate a solution to data like names, birth dates, and contact information, or more obscure data like financial or health information, fingerprints, license plate numbers, or Internet Protoco“lIP(”) addresses. 101: Data Protection, supra. A person can be “identified”—even if a data collector does not know his or her name—by singling them out, tracking their activity, and creating a detailed profile. Consequently, from 1998 to 2000, officials engaged in negotiations to construct a legal framework by which U.S. entities could satisfy the EU Data Protection Directive’s (“EU Directive”) standards.21 This Part explores the evolution of EU data privacy l2a2wS.ection A provides a summary of the EU Directive and the EU-U.S. Safe Harbor Privacy Principles (“Safe Harbor”) framework.23 Section B explains the impact of Schrems v. Irish Data Protection Commissioner on the data privacy law land scape.24 Section C describes the EU-U.S. Privacy Shield (“Privacy Shield”) framework.25 Section D highlights some of the changes the General Data Protection Regulation (“GDPR”) will bring.26 Section E highlights examples of the recent increase in EU enforcement actions for data privacy violations.27 A. Safe Harbor: A Solution to the EU Directive The EU legislature issued the EU Directive in 192985T.he EU Directive governs data movement into and out of the European Un2i9onI.t also forbids transfers of personal information to n-oEnU countries unless the country guarantees an “adequate level of protection.”30 The European Union found that the United States did not provide “adequate” data privacy protection for EU citizens and prohibited rpsoenal data transfers to the United States3.1 In 2000, the United States and the European Union agreed to Safe Harbor, which the European Commission deemed com2018] pliant with the EU Directive’s requirements3.2 Safe Harbor embodied seven core principles for U.S. organizations to adhere to in their data privacy practices: notice, choice, onward transfer, access, security, data integrity, and enforcement.33 Under Safe Harbor, businesses voluntarily chose to enact certain data protection safeguards and they se-lcfertified compliance with the core principles.34 B. The Schrems Decision’s Pivotal Impact on Data Privacy In October 2015, the European Court of Justice (“ECJ”) found Safe Harbor invalid in Schrems because it did not ensure adequate protection for EU personal data.35 The ECJ interpreted “adequate level of protection” under the EU Directive asa degree of security for basic rights and liberties that is substantially similar to the protection guaranteed within the European Union.36 In finding Safe Harbor inadequate,the ECJ largely concentrated on the absence of legal remedies available to EU citizens to vindicate their basic rights to privacy under Safe Harbor3.7 The court further observed the deficiency of enforcement methods and liability under Safe Harbor, largely because U.S. entities self-certified their compliance.38 Following Schrems, the EU Data Protection Authorities (“DPAs”) edclared that organizations could no longer rely on Safe Harbor to conduct EU-U.S. data transfers.39 Consequently, all U.S. organizations that engaged in data transfers with the European Union could no longer self-certify under Safe Harbor.40 In order to continue transferring data across the Atlantic, these organizations had to take additional steps to separately validate that they protected personal information adequately under the EU Directive.41 C. The European Union Means Business: EU Regulators Are Doling Out Serious Punishments for Data Privacy Violations The heightened focus and tougher stance on data privacy in the European Union in recent years has hinted that EU regulators might start cracking down on prominent companies, especially ones that process large amounts of EU citizens’ data.67 Predictions of such sort have proven to be true.68 60 See Meriani, supra note 55, at 94 (inculding information collected byonline identifiers, device identifiers, cookie IDs, and IP addresses.) Online data processors are resistant to the idea of systematically gaining consent for every instance of data collection. Id. It is therefore believed that this expansion of the legal requirements for consent may not be very consequential in practice; companies typically meet the consent requirement by notifying their users of their data practices in “Terms and Conditions” agreements that few users look at or comprehend. Id. 61 GDPR, supra note 53, at 34; Callahan-Slaughter, supra note 56, at 251. 62 GDPR, supra note 53, at 43; Callahan-Slaughter, supra note 56, at 251. 63 GDPR, supra note 53, at 16–17. According to the GDPR, a data breach necessitates immediate notification because it can cause harm to the data subjects.Id. THE DISCOVERY DILEMMA: WHEN U.S. DISCOVERY REQUESTS CONTRAVENE EU DATA PRIVACY PROTECTION Discovery is the official process dictated by the Federal Rules of Civil Procedure through which litigants request and provide information for the purpose of deciphering the facts of a case and what may come to light at it-r al.85 The discovery process in the United States can be extremely- time consuming and in-depth, especially when compared to the rest of the world.86 Notably, even when requested discovery materials are located outside of the United States or revealing them is limited or illegal under foreign law, U.S. courts have the power to compel parties to provide them87. If a litigant does not comply with a discovery order, the court can impose sanctions.88 This Part explores the conflict between EU data privacy law and the dsicovery process in U.S. litigation8.9 Section A explains the intersection of U.S. discovery procedures and foreign law, including how U.S. courts approach the issue.90 Section B explores the specific problem posed when a party in posssesion of personal information of EU citizens, protected by EU data privacy law, 83 Id. 2018] is asked to produce that information during litigation in a U.S cour9t1. Kessler et aslu.,pra note 123, at 602–03; Zambrano, supra note 103, at 177; see, e.g., In re Payment Card Interchange Fee & Merch. Disc. Antitrust Litig., No. 05-MD-1720(JG)(JO), 2010 U.S. Dist. LEXIS 89275, at *29 (E.D.N.Y. Aug. 27, 2010);In re Perrier Bottled Water Litig., 138 F.R.D. 348, 356 (D. Conn. 1991); Volkswagen, A.G. v. Valdez, 909 S.W.2d 900, 903 (Tex. 2015). B. The Intersection Between EU Data Privacy Obligations and U.S. Civil Procedure Discovery Rules Foreign data privacy law oftentimes protects information requested during the discovery phase of litigation1.27 U.S. courts, however, have the power to compel the production of requestedinformation, despite the fact that disclosing it may be constrained or forbidden by foreign law12.8 While courts do take the party’s subjugation to foreign data privacy law into consideration, the possibility of foreign civil or criminal sanctions against the party is not determinative of a court’s decision to require produc1t2i9on. Therefore, companies engaged in litigation in the United States may be forced to respond to discovery requests that place them directly in breach of EU data privacy law.130 International comity for discovery purposes often comes up in the context of the Hague Convention and blocking statutes.131 Blocking statutes are data privacy laws enacted with the distinct purpose of shielding a country’s nationals from broad discovery orders in foreign court proceedings.132 Thus, 127 SEDONA CONFERENCE, supra note 4, at *2. 128 Id. 129 See Aerospatiale, 482 U.S. at 544 n.29 (explaining that the French blocking statutes’applicability to the defendants was relevant to the Cour’ts evaluation of international comity merely insofar as it demonstrated the foreign interests in the security of certain information, afactor to be weighed). 130 SEDONA CONFERENCE, supra note 4, at 3; see, e.g., In re Air Cargo Shipping Serv. Antitrust Litig., 278 F.R.D. 51, 54–55 (E.D.N.Y. 2010) (noting that neither party disputed the fact that compliance by the French litigant with an order to produce the relevant documents would amount to violating the French blocking statute and give rise to the possibility of criminal sanctions)A.lthough U.S. sanctions are normally not imposed when the litigant has made an“active, good-faith effort” to obey a discovery order, a litigant merely pointing to data privacy laws, such as blocking statutes, or to the existence of the Hague Convention, is not enough to forestall sanctions; litigants would have to demonstrate a sincere attempt to comply, suchas seeking an exception from their home government authority or producing as much information as possible. Graco, Inc. v. Kremlin, Inc., 101 F.R.D. 503, 526 (N.D. Ill. 1984); Robert F. Koets, AnnotationS,anctions for Failure to Make Discovery Under Federal Civil Procedure Rule 37 as Affected by Defaulting Partys’ Good Faith Efforts to Comply, 134 A.L.R. Fed. 257 at § 2[a], 4 (1996). 131 See, e.g., Air Cargo, 278 F.R.D. at 52 (deciding whether to compel discovery through the Hague Convention when the discovery order would contravene Fsranbcleo’cking statute); Strauss, 242 F.R.D. at 206 (deciding whether to compel discovery through the Hague Convention when the discovery order would contravene Frances’ blocking statute); see also supra notes 98– 102 and accompanying text (explaining the Hague Convention). 132 Bennett, supra note 86, at 31–32. Some countries have instituted blocking statutes toerstrain the expansive or“intrusive” scope of U.S. discovery.Sedona Conference Discovery and Data Protection, supra note 86, at 407; John T. Yip,Addressing the Costs and Comity Concerns of International E-Discovery, 87 WASH. L. REV. 595, 615 (2012). Countries such as France, China, Malaysia, the Netherlands, and Switzerland have enacted blocking statutes. Yip, supra. Blocking statutes are commonly met with skepticism in American courts.Sedona Conference Discovery and Data Protection, supra note 86, at 407. blocking statutes create a clash between foreign data privacy law and U.S. discovery rules.133 When faced with a conflict between discovery needs and EU data pirvacy law, U.S. courts have sometimes decided to not require forneiglitigants to produce evidence that would violate privacy law1s3.4 Overwhelmingly, however, U.S. courts have disregarded EU data privacy laws and rodered the relevant discovery.135 Even after a French citizen was criminally prosecuted and fined €10,000 for complying with a U.S. court order to produce documents in violation of a French blocking statute in 2007, seu-bs quent cases dismissed such sanctions as unrealistic.136 C. Stepping into the Unknown: The GDPR’s Potential Effect on Discovery In Article 48, the GDPR imposes specific conditions for transfers to third-party countries.137 Article 48 stipulates that any nonE-U court, tribunal, or administrative decision which orders a data controller to provide or divulge personal information can be acknowledged or enofrced only if the order is based on an international agreement, such as a judicial assistance treaty.138 The U.S. Supreme Court inAerospatiale noted that for international comity purposes, substantive foreign laws should be given more dfe133 Sedona Conference Discovery and Data Protection, supra note 86, at 407. 134 See SEDONA CONFERENCE, supra note 4, at 3 (explaining that in some instances courts have decided against ordering discovery because of significant privacy interseesets,);e.g., Volkswagen, 909 S.W.2d at 903 (holding that a German company was not required to produce a phone book that contained personal information in violation of German data privacy law because Germany’s interests in privacy rights would be subverted, alternative means of obtaining the- r quested information existed, and the phone book was not significant to the case). 135 See Kessler et al., supra note 123, at 600 (stating that the majority of courts have decided to compel discovery under U.S. rules rather than the Hague Convention);see, e.g., Laydon, 183 F. Whether courts view Article 48 of the GDPR as substantive data privacy law or as more similar to a blocking statute will heavily affect their decision to compel discovery.140 Furthermore, the mere anticipation of the GDPR seems to have encouraged the EU DPAs to sanction large multinational companies for data privacy violations.141 The atmosphere of EU data privacy is therefore clearly trending towards a toughening of data privacy protection.142 III. INCREASED ENFORCEMENT AND EXPANSION OF EU DATA PRIVACY LAW JUSTIFY MORE DEFERENCE IN U.S. DISCOVERY DELIBERATIONS The purpose of the international comity analysis is to determine whether, and to what extent, foreign interests outweighhotse of the United States1.43 While it is not appropriate in every case to rule that discovery should be conducted pursuant to the Hague Convention, foreign interests in the right to privacy should not be dismissed merely because it seems unlikely that a foerign litigant will be prosecuted for violations of data privacy la1w44. In order to duly respect EU data privacy law, U.S. courts must be willing to consider how important the right to privacy is in the European Union and the fact that litigants face an increasing risk of sanctions for data privacy violati1o4n5s. Dismissing foreign interests as inherently less important than U.S. interests runs counter to the concept of international comity and the purpose of the 2018] Hague Convention.146 Section A of this Part discusses how U.S. courts should adjust their international comity analysis to properly respect EU data privacy law, and contends that courts should heavily weigh both EU interests in the right to privacy and the increased risk to litigants for violating EU dataprivacy law in favor of ordering discovery through the Hague Convention1.47 Section A also explains alternative methods for protecting information governed by EU data privacy law1.48 Section B provides policy arguments in favor of deferring to EU data privacy law when appropriate.149 A. Policy Reasons for Respecting EU Data Privacy Law There are rationales for deferring to foreign law in some instances ebyond mere legal arguments.170 For instance, courts looking to the principle of international comity for guidance would be beneficial in many way1s7.1 Additionally, privacy is an important right and courts should aspire to portect it whenever possible.172 This section discusses policy rationales for respecting the EU’s data privacy laws and its interest in privacy righ17ts3. Subsubsection One explains the benefits of international comity and the harm that could result from dismissing it.174 Subsubsection Two explains why the right to privacy is important and should be protected. 175 1. International Comity in Discovery: An Argument for Respecting Foreign Law and Limiting Court-Ordered Law Breaking The central purpose of international comity in the discovery context is to facilitate harmony in the lgobal legal system.176 A lack of international comity can, therefore, cause undesirable results.177 U.S. court orders to violate the laws of foreign nations have surged astronomically in the lastf-fi teen years.178 These cases usually involve discovery requests and thus apply the five-factor Aerospatiale test.179 The Aerospatiale comity analysis is highly criticized, in part because it strongly depends on subjective evaal-u tions by the court, and its application has resulted in an undeniable “-pro forum bias” in favorof U.S. interests.180 Not only is it disconcerting that U.S. courts are in effect making decisions based on litigants’ nationalities, but this pro-forum bias has directly corresponded to a dramatic rise in discovery requests involving court-ordered foreign law violation and, possibly, abusive discovery.181 Furthermore, U.S. foreign relations suffer from the “legal imperialism” of expansive cross-border discovery orders denounced 176 Zambrano, supra note 103, at 160. Data privacy law protects an important individual right, and the Hague Convention provides a viable alternative ttha achieves the goal of obtaining discovery while simultaneously respecting foreign law and harmonizing the international legal sphere. The recurring justification of courts that EU data privacy law is unlikely to be enforced can no longer be argued with certainty. Recent hcanges in EU data privacy law in favor of more stringent rules, the potential for massive sanctions, and the increased data privacy law enforcement actions taken by EU member states makes EU enforcement a more serious possibility. The principle of international comity, furthermore, calls on courts to consider any laws or interests of foreign nations that are implicated. Additionally, privacy in and of itself is a valuable right that should be protected when practicable to do so. U.S. courts should more strongly consider data privacy law, EU inrt-e ests, and the hardship placed on foreign parties when making discovery deliberations. 