Covington Team

Contact:Email

On February 24, 2022, the Irish Data Protection Commission (“DPC”) published its 2021 annual report setting out its activities and outcomes for last year (see press release here and the full report here).  At 120 pages long, it is detailed and specific, and in places, comes with a targeted and reflective commentary.  Overall, it provides readers with useful insights into the work of a supervisory authority at the forefront of Europe’s data protection whirlwinds.

Addressing the Critics

The DPC introduces the report with commentary that is critical of the narrative that equates the size of fines imposed under the EU General Data Protection Regulation (“GDPR”) with regulatory efficacy.  This is the elephant in the room tackled up front.  It is a narrative that has been repeated against the DPC in recent times by critics complaining about the level of control (or lack thereof) that the DPC exercises over large technology platforms, many of which have established their center of EU operations in Ireland.  In response to this sentiment, the DPC refers to the ongoing work of European data protection authorities to identify a set of performance metrics to quantity regulatory output across all Member States, stating that “such metrics must, however, move past both superficial totting exercises and assumptions to the effect that the bigger the fine, the greater the change of behaviour it will herald.”

Further, to illustrate the varying levels of complexity that the report refers to, the DPC cites to the example of a decision that ran to “several hundred pages and touch[ed] on the complex operating processes of large multinational organisations, impacting on millions of people” in contrast with another decision comprising “a two-line treatment of a comparatively simple issue that has minimal ramifications for data subjects in general.”

About More Than The GDPR

While cognizant that the control enjoyed by large technology platforms may need to be tackled by more than a single regulatory discipline, whether “data protection, competition law or content regulation”, there is, according to the DPC, “no question” that the GDPR is and will remain the best-available framework in Europe for protecting personal data.  However, in recognizing the limitations of the GDPR, the DPC goes on to say it is not the role of the DPC or any other supervisory authority to “target all manifestations” of platform power.

Given the suite of forthcoming EU laws and frameworks seeking to address data-related issues, the DPC also emphasizes the importance of cross-regulatory structures to deal with the type of issues already escalated by the one-stop-shop mechanism under the GDPR.
Continue Reading Irish Data Protection Commission Publishes 2021 Annual Report

This alert provides a further update on the rapidly evolving sanctions landscape with regard to the Ukraine crisis, further to our alerts on February 22 and February 25. On 25 February 2022, the European Union adopted an additional package of targeted and sectoral sanctions against Russia in response to its military actions in Ukraine. Those measures, which were announced earlier last week, include a range of new asset-freezing designations, financial sector restrictions, export controls, and other measures. The UK has also announced further economic sanctions against Russian individuals.

According to a joint statement issued by Canada, France, Germany, Italy, the UK, the U.S., and the European Commission on 26 February, further economic sanctions yet will be introduced in the coming days. Those measures will include the removal of selected Russian banks from the SWIFT messaging system using to facilitate global financial transactions.

New EU Targeted and Sectoral Sanctions

Additional Asset-freezing Designations

Council Implementing Regulation (EU) 2022/332 adds 98 people to the EU asset-freezing list. The list notably includes the Russian President Vladimir Putin and the Minister of Foreign Affairs Sergey Lavrov, as well as other members of the Russian National Security Council. Sanctions will also be extended to the remaining members of the Russian State Duma, who ratified the government decision of the Treaty of Friendship, Cooperation and Mutual Assistance between the Russian Federation and the two Ukrainian non-government controlled regions of the Donetsk and Luhansk oblasts. The Regulation also targets individuals who facilitated the Russian military action from Belarus.

New EU Sectoral Sanctions

The most far-reaching measures are introduced in Council Regulation (EU) 2022/328 (the “Regulation”). The Regulation amends Regulation (EU) 833/2014, first issued in August 2014, which set out the EU’s existing Russia sectoral sanctions regime, and introduces new measures targeting various sectors of the Russian economy.

As with regard to the original version of Regulation 833/2014, the restrictions summarized below extend to the worldwide conduct of EU persons and entities, conduct aboard EU-flagged vessels and aircraft, and to non-EU parties with regard to business occurring in whole or in part within the EU.

The Regulation introduces the following new export and related services restrictions:

  • Restrictions on exports of dual-use goods and technology: The Regulation replaces the pre-existing prohibition on exports of dual-use goods and technology under Council Regulation 833/2014. The pre-existing prohibition was limited to the export of dual-use goods and technology that were intended for military use or for a military end-user; the amended Regulation expands that prohibition to restrict the export of dual-use goods and technology and the provision of related services to persons in Russia regardless of the intended end-use or end user.

While exports of dual-use items always required licensing for Russia pursuant to the EU Dual Use Regulation, these new restrictions expand on those measures in important ways. In particular, as the jurisdictional scope of the Regulation extends to the conduct abroad of EU persons and entities, dual-use export controls on Russia are no longer limited to exports from the EU – the Regulation’s dual-use controls could apply with regard to actions by EU persons and entities in connection with the sale, supply, or transfer of dual-use items to Russia from anywhere in the world.
Continue Reading EU and UK Adopt Additional Sanctions Against Russia, with Further International Sanctions Measures Announced

On February 23, 2022, the European Commission published its long-awaited proposal—first announced in April 2020—for a Directive that is expected to require a significant number of EU and non-EU companies to conduct human rights and environmental due diligence across their operations and value chains.

The Commission’s Proposal for a Directive on corporate sustainability due diligence (the “Proposal”) is robust and signals that companies will need to make meaningful investments in effective due diligence programs. The Proposal also contemplates a significant expansion of directors’ duties, which would require directors of EU companies subject to the law to oversee the implementation of sustainability due diligence programs and take into account sustainability matters—including human rights, climate change, and environmental consequences—in the discharge of their duty to act in the best interest of the company.

The Proposal follows calls from the European Council (in December 2020) and the European Parliament (in January 2021) for a mandatory corporate due diligence and accountability law and extensive public consultation. It will now go through the EU’s legislative procedure, which requires agreement on the final text among the Commission, Parliament, and Council. Once passed, the law will represent a significant addition to the global legal landscape on business and human rights.

This alert summarizes key takeaways for companies established or doing business in the EU.

Which Companies Will Be Subject To The Law?

The Proposal sets forth application thresholds for EU and non-EU companies, with staggered implementation dates based on employee and turnover thresholds.

The proposed Directive’s due diligence obligations would initially apply (two years from the date it enters into force) to:

  • EU companies with an average of more than 500 employees and net worldwide turnover exceeding EUR 150 million; and
  • Non-EU companies with net turnover in the EU exceeding EUR 150 million in the financial year preceding the last financial year.

Continue Reading European Commission Publishes Proposal for a Corporate Sustainability Due Diligence Law

Overview

On January 25, 2022, the House of Representatives unveiled the America Creating Opportunities for Manufacturing, Pre-Eminence in Technology, and Economic Strength Act of 2022 (H.R. 4521) (“America COMPETES”), which is companion legislation to the United States Innovation and Competition Act (S. 1260) (“USICA”) passed by the Senate last summer. At over 2,900 pages, the legislation is an omnibus package of incentives and proposed funding for technology areas (principally semiconductors), supply chain proposals, investments in science, technology, engineering, and mathematics (“STEM”), and other pieces of legislation—all directed squarely at enhancing the United States’ competitive position against China.

Nestled within America COMPETES is a 25-page legislative proposal to create an inter-agency process—National Critical Capabilities Reviews—to review and regulate outbound investment (the “Outbound Review Process”). If enacted, the United States would become the first major Western advanced economy to adopt a broad-gauged outbound investment screening process, raising the prospect of a new era in national security-based reviews and restrictions of international investment flows.

To be sure, the concept of an outbound review process in the United States is not new—it first arose in early drafts of what ultimately became the Foreign Investment Risk Review Modernization Act of 2018 (“FIRRMA”), which updated the statutory authorities governing the Committee on Foreign Investment in the United States (“CFIUS”). More recently, both Senators and House Members have pushed legislation nearly identical to the proposal in America COMPETES, including an attempt last summer by Senators Bob Casey (D-PA) and John Cornyn (R-TX) to add an outbound investment review process as an amendment to USICA. The Casey-Cornyn proposal ultimately was not included in USICA, partly because of pushback by the U.S. business community based on its breadth, but the Biden Administration, notably in a speech last summer by National Security Advisor Jake Sullivan, has signaled potential support for an outbound review process. Thus, while it is by no means certain that the Outbound Review Process will be enacted, the prospect is more real than ever given potential bipartisan support within Congress and alignment between Congress and the Executive Branch.

Outbound Review Process

The stated rationale for an outbound screening process is to safeguard against the U.S. becoming dependent on China for critical parts of the supply chain and production capabilities. The concerns that motivated earlier attempts to regulate outbound investment, however, were centered on technology transfers to China, especially through joint ventures. Among some policymakers, there is a broader view that investments by U.S. companies in China that can help China advance its own capabilities, even if only through financing, should be curbed.

Against that backdrop, the Outbound Review Process, as proposed, is both sweeping in scope and lacking in specifics. As proposed, the legislation would establish a new committee—the “Committee on National Critical Capabilities” (the “Committee”)—that would be chaired by the U.S. Trade Representative (“USTR”) and composed of a number of Executive Branch Agencies.[1]  Modeled to an extent on CFIUS, the Committee would have the authority to review certain transactions that may impact “national critical capabilities.” Specifically, the Committee could review any transaction by a United States business that “shifts or relocates to a country of concern, or transfers to an entity of concern, the design, development, production, manufacture, fabrication, supply, servicing, testing, management, operation, investment, ownership, or any other essential elements involving one or more national critical capabilities,” or “could result in an unacceptable risk to a national critical capability” (a “Covered Transaction”).

As a definitional matter:

  • Much like in the CFIUS regime, the term “United States business” means a “person engaged in interstate commerce in the United States.” The full scope of this is not clear and is a source of ambiguity and tension in CFIUS. This ambiguity would be more acute in legislation that, unlike CFIUS, does not have a 30-plus year history of practice, and that screens outbound capital flows. For example, as drafted, the legislation could arguably capture investments by U.S.-headquartered companies or financial sponsors that are made out of their foreign-based subsidiaries or funds.
  • “Country of concern” means any foreign government or foreign nongovernment person engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons, or any non-market economy that is later identified by the Committee.
  • “Entity of concern” means any entity “the ultimate parent entity of which is domiciled in a country of concern; or that is directly or indirectly controlled by, owned by, or subject to the influence of a foreign person that has a substantial nexus with a country of concern.” Thus, for example, the definition could capture companies from allied countries that have substantial minority shareholdings from, or operations in, China or Russia (or other foreign adversaries). (The term “substantial nexus” is not defined.)
  • While the legislation would defer the full definition of “national critical capabilities” to implementing regulations, it suggests that at a minimum the term would mean “systems and assets… so vital to the United States that the inability to develop such systems and assets or the incapacity or destruction of such systems or assets would have a debilitating impact on national security or crisis preparedness” and could include articles in the following general categories, along with any others identified through implementing regulations:
    • medical supplies, medicines, and personal protective equipment;
    • articles essential to the operation, manufacture, supply, service, or maintenance of critical infrastructure;
    • articles critical to infrastructure construction after a natural or manmade disaster;
    • components of systems critical to the operation of weapons systems, intelligence collection systems, or items critical to the conduct of military or intelligence operations; and
    • services critical to each of the foregoing.

Moreover, the legislation requires a study of the following additional industries to identify other critical capabilities:

  • Energy
  • Medical
  • Communications, including electronic and communications components
  • Defense
  • Transportation
  • Aerospace, including space launch
  • Robotics
  • Artificial intelligence
  • Semiconductors
  • Shipbuilding
  • Water, including water purification

Continue Reading National Security Update—The House of Representatives Proposes an Outbound Investment Review Regime as Part of the America COMPETES Act

Since Covington’s last global update in June 2021, there have been several legal and policy developments affecting the business and human rights landscape that will impact companies in 2022. This update provides an overview of key legal and policy developments.

I.  Forced Labor Import Bans

A.  United States

1. Uyghur


Continue Reading Business and Human Rights: Developments and What to Watch For

On 22 December 2021, the conference of German data protection supervisory authorities (“DSK”) published its Guidance for Providers of Telemedia Services (Orientierungshilfe für Anbieter von Telemedien).  Particularly relevant for providers of websites and mobile applications, the Guidance is largely devoted to the “cookie provision” of the German Telecommunication
Continue Reading German Regulators Publish Cookie Guidance

When he was running to win the White House, President Joe Biden’s campaign committed to implement a “bold strategy” toward Africa, and one that would be based on a “mutually respectful engagement” and a reinvigorated diplomacy, if elected. Indeed, the campaign was the first-ever to outline how it would promote
Continue Reading Will Biden deliver on his commitment to Africa in 2022?

Senate Majority Leader Chuck Schumer (D-NY) is trying to modify the Senate’s Rules so that voting rights legislation can pass with just support from 50 Democratic Senators. It is clear that all of the Senate’s 50 Republicans take issue with the need for any Rules reform at all. And though
Continue Reading Senate Rules Reform:  No Middle Ground Between Modest Changes and Majority Rules

The fragility of Northern Ireland politics continues to prove problematic in dealing with Brexit. The on-going efforts of the UK government to redefine the Northern Ireland Protocol agreed with the EU last December is testament to that. Such efforts may be politically appealing in advance of UK local elections next
Continue Reading New EU Proposals for Northern Ireland Brexit Difficulties

The European Commission Vice President and Co-Chair of the Europe-UK Joint Committee, Maroš Šefčovič,  spoke to a meeting of the Irish Institute of International and European Affairs yesterday about the Ireland/Northern Ireland protocol.  He spoke of the political risk and the efforts being made to reach a compromise between the
Continue Reading EU Brexit negotiator comments on the Ireland/Northern Ireland Protocol