Short Reads

A new framework for data transfers to the US: the EU-US Privacy Shield

A new framework for data transfers to the US: the EU-US Privacy Shield

A new framework for data transfers to the US: the EU-US Privacy Shield

05.02.2016

After the European Court of Justice (“ECJ”) declared the Safe Harbour Decision invalid in its judgement of 6 October 2016, the European Commission and the United States now have agreed on a new framework for transatlantic data flow: the EU-US Privacy Shield. The new framework aims to protect the fundamental rights of European citizens where their data is transferred to the United States and to ensure legal certainty for businesses.

According to yesterday's press release of the European Commission, the new framework includes:

  • Strong obligations on companies handling Europeans’ personal data and robust enforcement;
  • Clear safeguards and transparency obligations on U.S. government access;
  • Effective protection of EU citizen’s rights with several redress possibilities.

Although an agreement has been reached on the principles, nothing is finalised yet. A draft “adequacy decision” will be prepared in the coming weeks, after which the Article 29 Working Party and a committee composed of representatives of the EU Member States will be consulted before submission of the arrangement for approval of the College of Commissioners of the European Commission and the US. In the meantime, the US will make the necessary preparations to put the new framework in place.

The Article 29 Working Party announced today that it welcomes the EU-US Privacy Shield and that Model Clauses and Binding Corporate Rules remain valid for the time being.

Read more about the new framework in the press release of the European Commission. We will keep you posted.

Team

Related news

19.08.2019 EU law
Enable “likes” and bear joint-controllership

Articles - The Court of Justice of the European Union recently ruled, in Case C-40/14 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV,  that a website operator that features “Like” social-media plugin from Facebook likely qualifies as joint-controller with Facebook for its website visitors’ personal data collection and transmission to Facebook.

Read more

22.07.2019 NL law
HagaZiekenhuis beboet voor datalek

Short Reads - Enkele maanden geleden vierden we de eerste verjaardag van de Algemene Verordening Gegevensbescherming (AVG) met een uitgebreide beschouwing  over de belangrijkste  ontwikkelingen uit  het eerste jaar van de verordening. We concludeerden daarin onder meer dat de door sommigen voorspelde hoge bestuurlijke boetes voor overtredingen van de AVG tot dan toe  - zowel in Nederland als in de andere EU-lidstaten - grotendeels waren uitgebleven.

Read more

15.07.2019 EU law
ICO to impose record-breaking fines for inadequate security measures and data breaches

Short Reads - Though the European data protection authorities have taken their time in enforcing the GDPR, two announcements by the ICO in the UK regarding proposed fines for British Airways and Marriott demonstrate that large fines are about to start landing regularly. Both of the substantial fines are to be handed out as a result of shortcomings in handling data breaches caused by cyber-attacks.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring