Business
GDPR: some reflections
Two law students share their thoughts on GDPR.

GDPR: reflections from two law students
Through our work as legal advisers for Link Utvikling we were, as practising lawyers, introduced for the first time to the question that has troubled every company processing data as part of its work: is this lawful?
The answer to that question was far harder than we had imagined, and got us digging into problems that could not be solved with a simple yes or no, but that also had an overarching legal-policy, global and international aspect to them. At first that was daunting for us, having never touched the subject during our studies, but it turned out to have legally interesting and unsettled aspects that invited a deep dive and a lot of learning.
While the questions that arose are dealt with in the other post, there are some experiences and reflections that have given us pause. Particularly around how we think the law in this field ought to be. In what follows we therefore set out certain problems and areas for improvement that we think could make it easier for anyone who has to find their way through the EU legal jungle that is the GDPR.
GDPR: starting from scratch
The first problem was accessibility. The GDPR was hard to navigate and had unclear provisions on what you should do and what you must do. Where the regulation does impose duties on you as a processor, it is further uncertain what has to be done to comply. An example of the latter is article 28 of the GDPR, which requires a controller using a processor to ensure that sufficient guarantees are in place that the requirements of the regulation are met.
What constitutes sufficient guarantees, however, is not defined. While the Norwegian Data Protection Authority gives general guidelines on what may be relevant in such an assessment, it is still emphasised that the responsibility ultimately falls on the controller.
The greatest difficulty arose, however, with the question of whether it was permissible to use a processor subject to foreign legislation, in our case American. In light of the Schrems II ruling (C-311/18), a requirement was added to the standard contractual clauses that anyone using foreign processors must satisfy themselves that the legislation of the respective states the processors are subject to gives protection equivalent to the GDPR. It therefore falls on individual companies to carry out an individual assessment of the legislation of those states before they can even consider using such processors.
Two problems arise immediately. First, very few start-ups have the competence, the insight or the resources to assess foreign national legislation and whether it gives a level of protection equivalent to the GDPR. Second, American processors make up the bulk of the available and relevant processors for Norwegian companies, so it will often be inconvenient and resource-intensive to switch to a Norwegian or European processor if you were to conclude that the level of protection is inadequate.
Thoughts on the GDPR and the future of the regulation
The situation as it stands today makes it difficult for companies to relate to and operate in line with the GDPR. What this has led to in practice is that this unresolved grey-zone question either forces you to use American processors without carrying out an individual assessment, or to use European processors out of fear of carrying out one. Both situations are equally hopeless in a modern digitalised society where the use of foreign, and particularly American, processors is a precondition for digital businesses, not a privilege.
While the question is of course complex, with international, supranational, legal and political dimensions, we have still thought of some solutions to the problems above.
One of them is that the individual assessments, and the responsibility for them, should be lifted to the level of an institution. An EU body that continuously assesses foreign national legislation would move the legal responsibility to where, in our view, it belongs: the EU. While that may appear to overlap with the power of the Commission to make adequacy decisions under article 45 of the GDPR, we would stress that these would be reviewable, temporary and rolling assessments. In the absence of Commission adequacy decisions, and where a Court of Justice ruling sets them aside (see Schrems), they would give controllers a way to use foreign processors with a greater degree of certainty and without fear of legal liability. That would eliminate the grey-zone doubt and leave us with a more absolute, but also more followable, legal position.
In light of recent agreements between the EU and the USA, however, it looks as though the need for such a solution may be smaller in the future:
While it has been an instructive and interesting experience to work with the GDPR, and one that has undoubtedly left us wanting more, the legal situation after the Schrems rulings leaves both lawyers and anyone who has to comply with the rules wishing for pan-European legislation that gives more clarity and predictability than the current position does.
Written by:
Håvard Sveier Ottemo and Marthe Hella