Privacy Shield: what is it and what does it mean for users?

The name “EU-US Privacy Shield” or EU-US Privacy Shield is how the successor to the old “safe harbour” framework (Safe Harbor), in force until 2015, is known. This new framework, officially agreed in mid-2016, is meant to serve as guarantor of compliance with European privacy protection rules in data exchanges with the United States, as occurs, to give one example, on the various social networks used every day.

In February 2016, the European Commission officially announced the conclusion of a new agreement to protect the data protection rights of Europeans. Following the rejection of the “safe harbour” directive in force until then by the European Court of Justice in October 2015, it was in December of that same year that the European Commission, the European Parliament and the Council reached an agreement whose final text was adopted at the beginning of 2016. As a consequence, during this period data transfers to the United States went unchecked, which produced a wave of discontent and insecurity among many companies (data transfers not in accordance with the law could result in the imposition of fines by this same Committee). This led to intense negotiations between companies and the Commission in which the former demanded transparency and clarity. The outcome of these meetings is reflected in the final text adopted by the Commission in February 2016.

EU-US Privacy Shield: a hardened version of the “safe harbour” framework?

On 25 February 2016, former President Barack Obama signed the Judicial Redress Act (Judicial Reddress Act), which represented a fundamental step prior to the signing of the EU-US Privacy Shield and allowed citizens of the European Union to file a claim in the US against a US company in the event of a breach of European data protection rules. Once the framework agreement was confirmed, by early July 2016 some members of the Union had already defined the conditions of this protective privacy shield.

The recognition by the European institutions of a common level of data protection lays the legal foundations for data traffic on both sides of the Atlantic. Specifically, this means that digital services such as Facebook, Amazon or Google are authorised to legally store the data of their European users and to send these packages of information to the United States. The basis for the Union’s ultimate acceptance of the treaty, following the adequacy decision on the level of protection, is constituted by the so-called Privacy Shield agreements. Under them, the US Government undertakes to comply with certain standards that involve bringing the level of protection of the personal data of European citizens stored in the North American country into line with European standards in this area.

How does the United States guarantee compliance with these standards?

Former US Secretary of State John Kerry pledged in 2016 the creation of the figure of an Ombudsperson, a mediation mechanism within the State Department but independent of the national security agencies, to which European citizens could turn in the event of complaints or enquiries. This figure, already well known in Europe (Ombudsman) and Latin America, is to handle requests from individuals, following up on their enquiries and reporting on whether or not a breach of the applicable law occurred.

European citizens would also have various options for legal recourse. In the event of a dispute, the companies involved must respond to the claim submitted by the user and resolve it within 45 days. To this end, both parties would have access to a free out-of-court dispute resolution system, but there would also be another alternative arbitration procedure. All European citizens will also be able to turn to their respective national data protection authorities, which would pursue the investigation of unresolved claims in collaboration with the US Federal Trade Commission (FTC). If no resolution of the dispute were reached through either of the two channels, it would still be possible to resort as a last instance to an additional arbitration mechanism with an enforceable legal remedy. Companies could commit to acting in accordance with the recommendations advised by the European data protection authorities. For companies working with human resources data, this is mandatory.

The US executive also committed to conducting an annual review of the functioning of the privacy shield and of access to data by the security agencies. This review would be carried out jointly by the European Commission and the US Department of Commerce with the inclusion of national experts. At an annually scheduled summit, the latest developments in US data protection law and their consequences for citizens of the European Union would be discussed, to be followed by a publicly accessible report addressed to the European Parliament and the Council.

The agreement establishes the six areas in which mass surveillance and the collection of private data are legally permitted, although the boundaries between them are subject to interpretation:

  • the fight against terrorism
  • the disclosure of activities of foreign powers
  • the fight against the distribution of weapons of mass destruction
  • cybersecurity
  • the protection of US and allied armed forces
  • the fight against transnational criminal threats

EU-US Privacy Shield: 1456 US companies certified so far

US companies wishing to subscribe to the Privacy Shield rules have had, since August 2016, the possibility of committing to its principles through self-certification. A large part of the regulations underpinning the EU-US Privacy Shield were already among the components of the “safe harbour” agreement, although some requirements have been hardened or expanded so that the new shield imposes stricter demands than its predecessor on recipient companies in transatlantic data exchange. Nevertheless, one cannot speak here of equivalence with European security standards, since compliance with European standards is only mandatory for those companies that process personal data.

A list published on the website of the Federal Trade Commission enumerates all the companies certified so far for data collection under the shield, although it must be considered with reservations, since it does not include the numerous subsidiaries that many of the listed companies have — for example, Microsoft with its 20 subsidiary companies.

Privacy Shield: arguments for and against

The EU-US Privacy Shield brings certain advantages for European users. A good example is the principle of collecting data only for the purpose for which it is gathered, which will be an integral component of the underlying European regulation for the protection of personal data. This means that data may only be recorded and processed for a legal, unequivocal and previously agreed purpose. It is above all the rights of European citizens that have been strengthened by the agreement, since, in the event of specific data protection violations by US companies, they can turn to various bodies, such as the Ombudsperson.

However, critics of the agreement do not consider it sufficiently comprehensive, since the demands of the European Court of Justice reflected in the declaration of invalidity of the “safe harbour” agreement in October 2015 have not been fully satisfied: the deficiencies have merely been papered over. This would prevent a favourable ruling by the Court in a detailed examination of the agreement’s clauses. Open criticisms also include the visibly minimal differences from Safe Harbor, and many opponents suspect that Privacy Shield has failed to close certain legal loopholes.

Mass surveillance measures are likewise not subject to any proportionality test, which violates European law. The United States continues to figure as the central supervisory instance, without recognising oversight by national bodies. As a result, the necessary and urgent control of the large US digital companies is lacking, which for critical sectors leads to the conclusion that the resolution is yet another failure.

The consequences of the Privacy Shield decisions

For many companies within the European Union, the privacy shield does not represent a real solution, since the new regulation contributes to legal certainty only in part. In a legal setting, such as judicial proceedings, many digital companies depend on transatlantic data transmission. Even though the recipients of data packages in the US can self-certify thanks to this new regulation, they are not safe from subsequent adverse rulings.

This makes it plausible that many companies will avoid the EU-US Privacy Shield and thereby forgo data exchange on the basis of this new resolution. A safer alternative, namely implementing the EU standard contractual clauses, does not guarantee absolute legal certainty either. The Irish data protection authorities have already announced that they will subject these guidelines to an in-depth legal examination.

The discussion about the meaning of the framework does not seem likely to die down in the short term. Any company that had harboured hopes of unequivocal rules with full legal guarantees will have to wait for a conclusive judicial examination of the agreement.

And relying on the standard contractual clauses in the Union for data exchange is no guarantee of legal compliance either, since these are no safer than the erstwhile “safe harbour”. This is why data protection advocates emphasise that the critical arguments valid for Safe Harbor could also apply to the clauses of the guidelines that are currently valid under European law — and, consequently, these guidelines would not withstand a thorough legal examination either.

In conclusion

In light of all the above, it can be affirmed that data exchange with the United States will not cease to constitute an insecure field for companies in the future. Under the regulations in force today, the transfer of data to the US remains legally a grey area. For companies, this means never losing sight of how the legal situation on this issue evolves. At the beginning of 2017, as the Trump administration was getting under way, the European Justice Commission announced a more detailed evaluation of the Privacy Shield regulations. So it is clear that the story continues.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.