Site navigation

Landmark EU-US Data Privacy Framework Adopted

Elizabeth Greenberg

,

eu-us data
The adequacy decision claims to offer more protection for EU data that is transferred to the US.

In a major move for data transfer capabilities, The European Commission has adopted its adequacy decision for the EU-US Data Privacy Framework.

The decision by the EU has concluded that the United States ensures an adequate level of protection – comparable to that of the European Union – for personal data transferred from the EU to US companies under a new framework.

On the basis of the new adequacy decision, personal data can flow safely from the EU to US companies participating in the Framework, without having to put in place additional data protection safeguards.

According to the EU Commission, the framework introduces new binding safeguards to address all the concerns raised by the European Court of Justice, including limiting access to EU data by US intelligence services to what is necessary and proportionate, and establishing a Data Protection Review Court (DPRC), to which EU individuals will have access.

The EU says that this decision offers “significant improvements” compared to the Privacy Shield, which existed up until the Shrems II decision sparked by whistleblower Edward Snowden which revealed the surveillance of peopel’s digital data by US authorities.

The revelation triggered Max Shrems, a data privacy advocate, to call on the EU to withdraw the adequacy agreement with the US as EU citizen data could be under surveillance by the US state, which was against the EU’s GDPR.

When this adequacy agreement was withdrawn, companies attempting to transfer data between the EU and the US had different contractual obligations to ensure data was transferred safely, often leading to hefty fines if they were not found to be compliant. This lead to the record £1.2 billion fine against Meta for transferring EU data to the US without a proper contractural basis.

Under the new agreement, if the DPRC finds that data was collected in violation of the new safeguards, it will be able to order the deletion of the data. Further, the new safeguards in the area of government access to data will complement the obligations that US companies importing data from EU will have to subscribe to.

EU President Ursula von der Leyen said: “The new EU-U.S. Data Privacy Framework will ensure safe data flows for Europeans and bring legal certainty to companies on both sides of the Atlantic. Following the agreement in principle I reached with President Biden last year, the US has implemented unprecedented commitments to establish the new framework.

“Today we take an important step to provide trust to citizens that their data is safe, to deepen our economic ties between the EU and the US, and at the same time to reaffirm our shared values. It shows that by working together, we can address the most complex issues.”

US companies will be able to join the EU-US Data Privacy Framework by committing to comply with a detailed set of privacy obligations, for instance the requirement to delete personal data when it is no longer necessary for the purpose for which it was collected, and to ensure continuity of protection when personal data is shared with third parties.

EU individuals will have access to several redress avenues in case their data is wrongly handled by US companies, including free of charge independent dispute resolution mechanisms and an arbitration panel.

In addition, the US legal framework provides for a number of safegaurds regarding the access to data transferred under the framework by US public authorities, in particular for criminal law enforcement and national security purposes.

A new executive order has made access to data limited to what is necessary and proportionate to protect national security.

EU individuals will have access to an independent and impartial redress mechanism regarding the collection and use of their data by US intelligence agencies, which includes a newly created Data Protection Review Court (DPRC).

The court will independently investigate and resolve complaints, including by adopting binding remedial measures.

The safeguards put in place by the US will also facilitate transatlantic data flows more generally, since they also apply when data is transferred by using other tools, such as standard contractual clauses and binding corporate rules.

While this is a major step towards streamlined international data transferred, the Framework will be subject to periodic reviews carried out by the European Commission, together with representatives of European data protection authorities and competent US authorities.

The first review will take place within a year of the entry into force of the adequacy decision, in order to verify that all relevant elements have been fully implemented in the US legal framework and are functioning effectively in practice.

Privacy advocate remain unconvinced by the new framework. Activists at NYOB (None of Your Business), the data privacy advocacy group, have said there is little to no different in the new framework from past EU-US agreements including Safe Harbour and the Privacy Shield, both of which did not protect EU data from US surveillance.


Recommended


NYOB, in a response to the agreement,  say that “the US will attribute another meaning to the word ‘proportionate'” than the EU courts so they can continue their surveillance measures.

Max Shrems, founder of NYOB said: “Just announcing that something is ‘new’, ‘robust’ or ‘effective’ does not cut it before the Court of Justice. We would need changes in US surveillance law to make this work – and we simply don’t have it.”

NYOB is already preparing to challenge the new agreement in the EU Court of Justice.

Currently, the UK is in talks with the US to create its own data-bridge with the US to ensure safer and easier data transfers between the new countries. To keep its own data adequacy with the EU, the UK plans to “piggy-back” on the EU-US agreement.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data