Transatlantic data transfer mechanism latest [Update]
28th February 2023
Transatlantic data transfer mechanism latest
You might be aware that until 2020 companies based in the U.K. and Europe could share personal data with organisations in the U.S. if they were signed up to and adhering to the ‘Privacy Shield’ framework. However, in July of that year, in a court case brought by Max Schrems, the privacy campaigner, the Privacy Shield Framework was invalidated, due to concerns that the protection of personal data in the U.S., even within the Privacy Shield Framework, was not as robust as that provided by the GDPR in Europe.
Since then, the legal basis on which most organisations rely to transfer data to the U.S. is the cumbersome Standard Contractual Clauses (SCCs).
However, in March 2022, President Biden issued an Executive Order committing the U.S. to new privacy rules, coined the Transatlantic Data Privacy Framework – these were ‘acknowledged’ by the European Commission, which issued a Draft Adequacy Decision in December 2022. Since that time, we have been awaiting the European Parliament’s opinion on this – which, whilst non-binding, holds sway over the decisions that would follow from each of the E.U. Member states who need to approve the decision.
It should also be noted that at the time draft was issued, Max Schrems stated that he was not happy that the U.S. commitments went far enough, primarily due to the access that the intelligence agencies are given to personal data.
European Parliament’s initial response
February 14th 2023, did not bring any love for the Draft Adequacy Decision from the European Parliament. In their response to the ‘protection afforded by the EU-US Data Privacy Framework, they identified a number of deficiencies, and this adverse opinion is unlikely to lead the way to an easy passage for the transatlantic data agreement.
Their conclusion goes so far as to say that the Draft Adequacy Decision fails and urges the Commission to refrain from adopting the Framework. To quote from their report:
“Concludes that the EU-US Data Privacy Framework fails to create actual equivalence in the level of protection; calls on the Commission to continue negotiations with its U.S. counterparts with the aim of creating a mechanism that would ensure such equivalence and which would provide the adequate level of protection required by Union data protection law and the Charter as interpreted by the CJEU; urges the Commission not to adopt the adequacy finding.” European Parliament, Committee on Civil Liberties, Justice and Home Affairs. 14.2.2023
Ultimately the European Data Protection Board must decide if the new Framework is EQUIVALENT to the protection offered by the EU GDPR. This non-binding report from the E.P. Committee stated that the U.S. needs to commit to more protection for individuals, particularly concerning ‘meaningful reforms [being] introduced, in particular for national security and intelligence purposes’. The committee also raised issues regarding the potential for the order to be ‘amended at any time by the U.S. President and the lack of transparency of the proposed Data Protection Review Court (the public’s vehicle for redress).
If you have any concerns about transferring personal data to the U.S., please contact one of our specialists by taking advantage of your complimentary thirty-minute consultation.