The EU-US Privacy Shield may soon be a thing of the past after the European Parliament passed a
resolution
on July 5th
, calling on the European Commission to suspend the agreement unless the U.S. takes further action by September 1st
of this year to become compliant with the Privacy Shield requirements. The data transfer agreement bridges the gap between EU and US data protection law and enables over
3,300 companies to transfer the personal data of EU citizens to the US for processing without breaching fundamental European privacy rights, allowing organizations to self-certify their compliance in order to receive and process data from the EU. This agreement replaced the
Safe Harbor arrangement, which was invalidated in the wake of the Edward Snowden revelations. The European Parliament cited several areas in which the U.S. has not addressed prior EU concerns and concluded, “the current Privacy Shield arrangement does not provide the adequate level of protection required by Union data protection law and the EU Charter as interpreted by the European Court of Justice.” While the parliamentary vote is not a binding measure, it is a further warning sign that the Privacy Shield will not be renewed at the next renewal vote in October. Note that the European Court of Justice currently has the opportunity to strike down Privacy Shield in the
Schrems
II case. Companies currently certifying under the Privacy Shield should consider alternative measures to support data transfers. Under GDPR, transfers must be able to demonstrate appropriate safeguards (security measures) in the absence of a framework such as Privacy Shield. In addition, the use of standard contractual clauses (also subject to European Court of Justice review) or approved codes of conduct is suggested.
Let’s Get Started
Curious about alternative mechanisms for data transfer or dealing with the complexities of EU Privacy law? Contact us for more information, and be sure to check out our GDPR whitepaper series.
Philip Brudney
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)