{"id":42367,"date":"2021-08-19T13:37:36","date_gmt":"2021-08-19T13:37:36","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=739acb0000bc7f22b526b15ced78602e"},"modified":"2021-08-19T13:37:36","modified_gmt":"2021-08-19T13:37:36","slug":"zoom-is-no-longer-compatible-with-gdpr-hamburg-data-watchdog","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/zoom-is-no-longer-compatible-with-gdpr-hamburg-data-watchdog\/","title":{"rendered":"Zoom is no longer compatible with GDPR, Hamburg data watchdog"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/bobby-hellard\">Bobby Hellard<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">19 Aug, 2021<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p>A German data protection commissioner has officially warned Hamburg&#8217;s Senate Chancellery to avoid using <a href=\"https:\/\/www.itpro.co.uk\/software\/355486\/zoom-review-are-we-alone-now\"  data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/software\/355486\/zoom-review-are-we-alone-now\">Zoom<\/a> as it is no longer compatible with <span class=\"scayt-misspell-word\" data-scayt-word=\"GDPR\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysvnpmlqigjxui\">GDPR<\/span>.<\/p>\n<p>Hamburg&#8217;s acting Commissioner for Data Protection and Freedom of Information, Ulrich <span class=\"scayt-misspell-word\" data-scayt-word=\"K\u00fchn\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysvqwtgne19imc\">K\u00fchn<\/span>, said in a press release that the on-demand version of the video conferencing platform does not meet the legislation&#8217;s criteria when it comes to data transfers.<\/p>\n<p>He cites the European Court of Justice&#8217;s (<span class=\"scayt-misspell-word\" data-scayt-word=\"CJEU\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysvu8hkmu7ue04\">CJEU<\/span>) <a href=\"https:\/\/www.itpro.co.uk\/security\/privacy-shield\/356470\/european-court-invalidates-primary-eu-us-data-transfer-mechanism\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/security\/privacy-shield\/356470\/european-court-invalidates-primary-eu-us-data-transfer-mechanism\">Schrems II decision<\/a><a href=\"https:\/\/www.itpro.co.uk\/security\/privacy\/359128\/google-accused-of-illegally-tracking-android-users-with-advertising-codes\"  data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/security\/privacy\/359128\/google-accused-of-illegally-tracking-android-users-with-advertising-codes\">,<\/a> announced in July 2020, which invalidated the EU-US data transfer mechanism known as <a href=\"https:\/\/www.itpro.co.uk\/safe-harbour\/34529\/what-is-eu-us-privacy-shield\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/safe-harbour\/34529\/what-is-eu-us-privacy-shield\">Privacy Shield<\/a> and required alternative mechanisms to be more rigorous.<\/p>\n<p>&#8220;All employees have access to a tried and tested video conference tool that is unproblematic with regard to third-country transmission,&#8221; <span class=\"scayt-misspell-word\" data-scayt-word=\"K\u00fchn\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysvxkayzzpwou7\">K\u00fchn<\/span> wrote. &#8220;As the central service provider, <span class=\"scayt-misspell-word\" data-scayt-word=\"Dataport\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysvxfm4690rup9\">Dataport<\/span> also provides additional video conference systems in its own data centres. These are used successfully in other countries such as <span class=\"scayt-misspell-word\" data-scayt-word=\"Schleswig\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiyswdb781p18y1d\">Schleswig<\/span>-Holstein. It is therefore incomprehensible why the Senate Chancellery insists on an additional and legally highly problematic system.&#8221;<\/p>\n<p>The issue appears to relate to a dispute over the way Zoom has used standard contractual clauses (<span class=\"scayt-misspell-word\" data-scayt-word=\"SCCs\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiyswgddtkg069rb\">SCCs<\/span>) to justify its data transfers. On it&#8217;s <a href=\"https:\/\/zoom.us\/gdpr\"  data-cke-saved-href=\"https:\/\/zoom.us\/gdpr\">website<\/a>, Zoom says its services feature &#8220;an explicit consent mechanism for EU users&#8221; on its platform and that the firm has implemented &#8220;zero-load&#8221; cookies for users whose <a href=\"https:\/\/www.itpro.co.uk\/virtual-private-network-vpn\/30351\/how-do-you-hide-an-ip-address\"  data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/virtual-private-network-vpn\/30351\/how-do-you-hide-an-ip-address\">IP address<\/a> show they are visiting the site from an EU member state. Specifically, the firm states: &#8220;we ensure that the transfer is governed by the European Commission&#8217;s standard contractual clauses (<span class=\"scayt-misspell-word\" data-scayt-word=\"SCC\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiyswjgzubr1lcd0\">SCC<\/span>)&#8221;.<\/p>\n<p>However, following the <span class=\"scayt-misspell-word\" data-scayt-word=\"Schrems\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysw0xsch3r4y8c\">Schrems<\/span> II decision in July 2020, companies are now required to perform additional steps to justify their use of <span class=\"scayt-misspell-word\" data-scayt-word=\"SCCs\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysw0uzjtaks26o\">SCCs<\/span>, including performing additional risk assessments &#8211; something that Zoom appears not to have done.<\/p>\n<p>Neil Brown, the director of virtual English law firm decoded.legal, told <a href=\"https:\/\/www.theregister.com\/2021\/08\/17\/zoom_incompatible_with_gdpr_hamburg_warning\/\"  data-cke-saved-href=\"https:\/\/www.theregister.com\/2021\/08\/17\/zoom_incompatible_with_gdpr_hamburg_warning\/\"><em>The Register<\/em><\/a> that the press release was &#8220;somewhat oblique&#8221; but suggested that the Hamburg <a href=\"https:\/\/www.itpro.co.uk\/data-protection-0\"  data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/data-protection-0\">Data Protection<\/a> Authority considers that Zoom does not ensure a level of protection for personal data which is &#8220;essentially equivalent&#8221; to that afforded by the <span class=\"scayt-misspell-word\" data-scayt-word=\"GDPR\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysw423zkrwhya1\">GDPR<\/span>.<\/p>\n<p>&#8220;Many businesses used to address the international transfers aspect of the <a href=\"https:\/\/www.itpro.co.uk\/general-data-protection-regulation-gdpr\"  data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/general-data-protection-regulation-gdpr\">GDPR<\/a> by incorporating the model contract clauses\/<span class=\"scayt-misspell-word\" data-scayt-word=\"SCCs\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysw7ajy3bhgzwr\">SCCs<\/span> into their contracts with organisations in non-adequate jurisdictions,&#8221; Brown told <em>The Register<\/em>. &#8220;In <span class=\"scayt-misspell-word\" data-scayt-word=\"Schrems\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysw79zylfacf2n\">Schrems<\/span> II, the <span class=\"scayt-misspell-word\" data-scayt-word=\"CJEU\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiysw77cc7iewy4l\">CJEU<\/span> said that these were not, in themselves, sufficient, and that a transferring controller must do a comprehensive risk assessment, and put appropriate additional measures in place to ensure &#8216;essentially equivalent&#8217; protection.<\/p>\n<p>&#8220;And that came as a shock to a lot of people, since it rather suggested that the model clauses were not fit for purpose. And, lo and behold, there is a new European set, which is a heck of a lot more complicated.&#8221;<\/p>\n<p>In a statement, Zoom said it was proud to work with the City of Hamburg and many other leading German organisations, businesses and education institutions.<\/p>\n<p>&#8220;The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us,&#8221; \u00a0the firm said. &#8220;Zoom is committed to complying with all applicable privacy laws, rules, and regulations in the jurisdictions within which it operates, including the <span class=\"scayt-misspell-word\" data-scayt-word=\"GDPR\" data-wsc-lang=\"en_GB\" data-wsc-id=\"ksiyswaa64o513rve\">GDPR<\/span>.&#8221; <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>      Bobby Hellard<\/p>\n<p>        19 Aug, 2021    <\/p>\n<p>      A German data protection commissioner has officially warned Hamburg&#8217;s Senate Chancellery to avoid using Zoom as it is no longer compatible with GDPR.<br \/>\nHamburg&#8217;s acting Commissioner for Data Prot&#8230;<\/p>\n","protected":false},"author":403,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-42367","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/403"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=42367"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42367\/revisions"}],"predecessor-version":[{"id":42368,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42367\/revisions\/42368"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=42367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=42367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=42367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}