by Christopher Knabe MBL-HSG, Loomion AG
A discussion on the benefits of such board management portals and the risks of choosing the right provider in light of the ECJ's decision on the Privacy Shield of July 16, 2020
The practical use of board management portals
The use of digital board management portals has now found its way into 50% (1) of companies with a supervisory board. None of these companies can imagine working in a board without such a portal. The advantages of enterprise level board portals (there are actually only 3 to 4 providers in this class) have already been discussed many times and will only be highlighted here:
- Extremely high increase in efficiency for the work of the Supervisory Board Secretary and the members of the Supervisory Board thanks to the real-time availability of data.
- Highly secure solutions for the storage, long-term provision and distribution of data.
- Complete control over the history and whereabouts of data and information.
The fact that almost 50% of companies do not yet use any of the board management portals seems negligent. In its meetings, the supervisory board not only deals with matters that must be classified as business secrets, but in many cases also with personal data that is also subject to special protection. The widespread practice of sending such highly sensitive and confidential information to the private Google e-mail address of members of the Supervisory Board is always speechless.
However, for both groups of companies - those already using one of the board management portals and those in the selection process - the world changed dramatically on July 16, 2020. Both will have to completely reassess or re-evaluate the selection of their current or future provider. More on this below.
The Facebook verdict of the European Court of Justice
Almost to the day, on July 16, 2020, four years after the EU-US Privacy Shield 20216/1250 came into force, the European Court of Justice (ECJ) overturned the EU Commission's decision in Case C-311/18 and declared it invalid for the second time. What is explosive here is that the ECJ overturned the aforementioned Privacy Shield decision due to the same shortcomings as the Safe Harbor decision in 2015. In both cases, the Austrian lawyer and data protection expert Maximilian Schrems had asked Facebook in Ireland to stop transferring his data stored on Irish Facebook servers to Facebook servers in the USA. Facebook did not want to comply on the grounds of the Privacy Shield, which is why the Irish data protection authority referred the case to the CJEU for review.
The ECJ has now largely followed Schrems' concerns regarding the far too far-reaching access possibilities of US intelligence services and triggered an earthquake with its verdict.
«The US surveillance practice is not limited to what is strictly necessary», the judges emphasized. Furthermore, those affected could not enforce their rights provided for in the EU in court in the USA.
In a further step, the ECJ reprimanded the Irish Data Protection Authority, which is responsible for Facebook as the supervisory authority in this case. Facebook already knew what to expect and tried to create its own legal certainty with the so-called standard contractual clauses. Standard contractual clauses are always used when there is insufficient legal certainty from the provider's point of view, in this case Facebook, and they want to protect themselves with bilateral contracts in the absence of a law. In this context, the ECJ found that the basic application of standard contractual clauses is permissible, but that the content chosen by Facebook in its standard contractual clauses was also far too inadequate and insufficiently monitored by the Irish Data Protection Authority.
What are the implications of the verdict for the selection of a portal?
As already mentioned, there are actually only 3 or 4 providers in the field of enterprise level board management portals, depending on how you want to assess the corporate structures. Three of the four providers are US providers who offer their board management portals exclusively as cloud solutions and therefore have the same status as Facebook. Only one provider at this level of board management portals is not controlled by US shareholders and demonstrably does not operate servers in the USA. It is also not surprising that this European provider is the only one on the market to offer an on-premises version in addition to its cloud servers, which allows customers to avoid this entire discussion and store and secure their board data on their own servers.
Until now, users of US providers of board management portals have been able to invoke the Privacy Shield and thus at least pretend that they have fulfilled their auditing obligations in connection with the GDPR and other laws to protect their data. Until now, US providers have always assured us in the form of a mantra that they have a company headquarters and servers in Germany or other EU member states and are therefore subject to local, national data protection laws. Facebook has also repeatedly emphasized this statement and yet now, after 2015 and the failure of the Safe Harbour Agreement, it has once again been determined that these statements simply have no value. After 2015, the court once again found that there is actually no way for a provider of US board management portals to store data on its servers in the USA in compliance with EU law, and, on closer inspection, not even on servers in Germany or anywhere else in the world. There is simply no data protection law in the USA that is comparable or compatible with EU laws. There is a whole battery of laws in the USA that force a US board management portal provider to cooperate with the US authorities tacitly and under threat of punishment, regardless of where the server is operated in the world. Here is a brief description of each:
Foreign Intelligence Surveillance Act, 2001 (FISA)
Among other things, this law provides for the operation of secret courts. Their hearings are never public and the person or organization actually being tried is never present or aware that a US court is trying them. It is therefore not surprising that the number of decisions has been increasing for years and that not a single decision by a FISA court has yet rejected an application from a US authority.
National Security Letters
These are issued directly by the investigating authority and are not subject to court approval, which is certainly problematic from a rule of law perspective. National Security Letters are more common in practice than court-authorized, secret searches. According to statistics from the Electronic Privacy Information Center (EPIC), around 1,600 court orders were issued under the Foreign Intelligence Surveillance Act (FISA) in 2010, while the number of National Security Letters is said to be around 24,000. (2)
Stored Communications Act, 1986 (SCA)
In particular, this law provides for the secret surveillance of metadata of users of electronic communication devices both at home and abroad. However, it also authorizes US authorities to access other extended data sets if the metadata substantiates the initial suspicion of origin, which can be very simple and broad.
International Communications Privacy Act, 2017 (ICPA)
This law also stipulates that US authorities may access data from US companies, regardless of where their servers are located in the world.
Clarifying Lawful Oversees Use of Data Act, 2018 (CLOUD Act.)
This latest masterpiece can definitely be seen as the bazooka of all the above-mentioned laws in terms of data protection. It stipulates that any national data protection law is deemed invalid by the USA and that a US cloud provider, which also includes US board portal operators, must tacitly hand over all data requested, regardless of which server in the world it is stored on.
Conclusion
It is clear that it has actually been made impossible to select providers of US board management portals without a valid legal framework (Ex-Privacy Shield). However, even with the previous legal basis, it has now been decided for the second time that this is not possible in accordance with the law. The company should now carry out a very complex Data Protection Impact Assessment (DPIA) on its own responsibility and reassess its situation. As a result of the removal of the Privacy Shield, the company should next agree the aforementioned standard contractual clauses with the board portal operator in order to obtain a legally compliant agreement on the handling of data on German servers with the provider. Both the DPIA and the negotiation of standard contractual clauses are likely to fail in 100% of all cases because the board portal operator will not be able to meet the strict legal requirements of the individual company and the data protection authorities. In addition, the company should ensure that the provider complies with the standard contractual clauses by constantly reviewing the agreement. This will not succeed either and will continue to leave considerable legal uncertainty, because operators of board management portals are not allowed to answer truthfully even when asked by the company, as they ultimately have to pass on the data in secret. The German company's knowledge that US providers of board management portals are subject to the above-mentioned laws and must disclose data in case of doubt despite standard contractual clauses, especially in times of «Make America Great Again» (MAGA), leads to considerable effort and risks and makes a decision impossible. The positive knowledge of the above-mentioned risks in advance of commissioning a US board portal operator can, under certain circumstances, even lead to consequences in connection with Section 85 of the German Limited Liability Companies Act (GmbHG) and constitute a breach of the duty of confidentiality. In the coming days, companies in the European Economic Area (EEA) that continue to use American cloud services may face measures including sanctions from data protection supervisory authorities and warnings from affected persons as well as competitors and consumer protection organizations. And for all those companies who are now saying that this does not affect us, we are not that important, we have nothing to hide, I would just like to say: I look forward to receiving your next meeting minutes, you have nothing to hide.
1 Source: Dadael Research 2019
2 Quelle: Arnd Böken, Patriot Act und Cloud Computing – Zugriff auf Zuruf?
Article first published in BOARD, Das Aufsichtsratsbüro 4/2020

Christopher Knabe
CEO Loomion AG
+41 61 500 16 25
knabe@loomion.com
