The new EU-US Data Privacy Framework 

31st July 2023US EU Privacy Framework

The new EU-US Data Privacy Framework 

The long-anticipated adequacy decision concerning the EU-U.S. Data Privacy Framework (EU-U.S. DPF) has been officially adopted by the European Commission.

As of July 10th, 2023, organisations in the U.S. that have obtained certification under the EU-U.S. DPF can securely transfer personal data from the EU without the need for additional transfer tools like SCCs or BCRs.

This decision also eliminates the requirement for conducting transfer impact assessments or implementing supplementary measures.

Background to the Decision

The EU-U.S. DPF replaces the Privacy Shield Framework, which the European Court of Justice (CJEU) invalidated as a valid mechanism for EU-U.S. data transfers in July 2020 (C-311/2 “Schrems II”).

The CJEU identified significant concerns with U.S. laws that hindered recipients in the U.S. from ensuring an equivalent level of data protection as in the EU. These concerns included the extensive authority of U.S. intelligence agencies to access personal data under section 702 of the Foreign Intelligence Surveillance Act (FISA 702) and Executive Order 12333, without adequate oversight or legal recourse for EU data subjects.

In October 2022, President Biden issued Executive Order (EO) 14086, “Enhancing Safeguards for United States Signals Intelligence Activities,” which established new rules and safeguards to limit data access by U.S. intelligence agencies to what is necessary and proportionate for national security. This EO also created a two-tier redress system to address complaints from EU individuals regarding U.S. intelligence agency access. An independent Data Protection Review Court was formed to oversee these matters.

Developed primarily based on EO 14086, the EU-U.S. DPF was jointly created by the U.S. Department of Commerce (DoC) and the European Commission to offer reliable mechanisms for personal data transfers from the EU to the U.S. while maintaining EU-equivalent data protection standards.

How Does the EU-U.S. Data Privacy Framework Work?

To benefit from the Framework, U.S. organisations must certify their commitment to adhere to the underlying privacy principles of the EU-U.S. DPF. These principles closely align with concepts from the EU GDPR, encompassing purpose limitation, data accuracy, data minimisation, and security, among others. Organisations processing sensitive personal data must adopt specific safeguards to protect this information. Certified organisations are obliged to publicly confirm their participation in the EU-U.S. DPF’s principles through their privacy notices and outline the rights of EU individuals for redress, among other information.

Certification can be completed online via the Data Privacy Framework website. Although it is a self-certification process, each application requires approval from the DoC and becomes effective only after review and acceptance.

Organisations must re-certify annually and pay the applicable fees, which vary based on their size, similar to the previous Privacy Shield arrangement.

The application process is now open, and it is yet to be seen how many organisations will opt to participate and the potential backlog in DoC’s application reviews.

You can see a list of organisations on the new Data Privacy Framework list here.

Implications for Standard Contractual Clauses (SCCs) for U.S. Transfers

Certification under the EU-U.S. DPF is voluntary. Organisations that do not participate in the EU-U.S. DPF cannot rely on the adequacy decision for U.S. data transfers. Such organisations must implement appropriate safeguards like SCCs or Binding Corporate Rules and perform transfer impact assessments (TIAs) when using SCCs. However, the European Data Protection Board (EDPB) recently stated that “all the safeguards implemented by the U.S. Government in the area of national security (including the redress mechanism) apply to all data transferred to the U.S., regardless of the transfer tool used.” This means that when conducting a TIA and evaluating the effectiveness of SCCs, companies exporting data from the EU to the U.S. can consider the Commission’s assessment in the adequacy decision. There is still some uncertainty about whether additional safeguards are necessary when using SCCs for U.S. data transfers, but the EDPB’s guidance suggests that the recent reforms to U.S. laws could benefit organisations relying on SCCs.

Impact on the EU-U.S. Privacy Shield Framework

Organisations that are current Privacy Shield participants and have maintained their certifications can now rely on the EU-U.S. DPF. However, these organisations must ensure compliance with the EU-U.S. DPF principles and update their privacy notices accordingly by October 10th, 2023. Any data processing agreements referencing the Privacy Shield will also need amendments.

Switching to the EU-U.S. DPF will not alter an organisation’s re-certification due date, and their Privacy Shield re-certification will continue to apply under the EU-U.S. DPF. Organisations that do not wish to comply with the EU-U.S. DPF principles must go through a withdrawal process. Letting the certification lapse will not be considered a withdrawal and may lead to enforcement actions under the Privacy Shield.

Considerations for the UK and Switzerland

The EU’s adequacy decision on the EU-U.S. DPF does not extend to the UK.

The UK has expressed its commitment to a UK-U.S. Data Bridge, and U.S. organisations can already certify for the UK Extension to the EU-U.S. DPF. However, such organisations cannot rely on the UK Extension for data transfers from the UK and Gibraltar to the U.S. until the UK issues its own adequacy decision. Participation in the UK Extension requires prior participation in the EU-U.S. DPF.

The Swiss-U.S. DPF operates as a separate framework that requires its own self-certification, following a process similar to the EU-U.S. DPF. It is already in effect, allowing members of the Swiss-U.S. Privacy Shield Framework to transition to the Swiss-U.S. DPF, with new organisations also eligible to participate. However, similar to the UK, transfers to Switzerland cannot rely on the Swiss-U.S. DPF until Switzerland announces its adequacy decision.

Looking Ahead

While the EU-U.S. DPF presents a step forward in EU-U.S. data privacy relations, concerns regarding its longevity remain. NOYB’s response to the EU-U.S. DPF indicates the potential for legal challenges in the future, and Max Schrems has likened recent events to “groundhog day.” The possibility of future invalidation may influence organisations’ decisions on whether to participate in the EU-U.S. DPF.

As always, if you need any help or advice, please take advantage of your complimentary thirty-minute consultation with one of our data protection specialists.  Book yours here.

 

 

Thank you to our colleagues at Prighter for the source material for this article.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details