Safe Harbour replaced with EU-US Privacy Shield
The new agreement may take effect from July if both parties agree on its directions


The EU-US Privacy Shield, arranged to replace Safe Harbour, may come into effect from July, the EU and US have agreed.
The EU-US Privacy Shield has been tweaked slightly from its original specification to include a promise from the White House regarding the treatment of data.
It states that bulk collection of data sent from the EU to the US can only happen if conditions have been agreed prior to the transfer and it must be "as targeted and focused" as possible.
Other new clauses integrated into the agreement include that companies have to delete data that no longer serves the purpose for which it was originally collected. Additionally, the ombudsman that oversees the agreement will be independent from national security services to make it as fair and transparent as possible.
The US will create the ombudsman that deals with complaints from EU citizens about Americans misusing or spying on their data.
A spokesman for the European Commission said: "This new framework for transatlantic data flows protects the fundamental rights of Europeans and ensures legal certainty for businesses."
Other existing key points of the EU-US Privacy Shield include promises that the US Office of the Director of National Intelligence will give written commitment that data collected from EU citizens will not be used in mass surveillance exercises and an annual review will be performed by both the EU and US to ensure the system is running correctly.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However, now the UK has voted to leave the EU, this means the UK would need to independently negotiate a similar law in line with the EU's regulations that protects the data of businesses should they choose to trade with the UK and vice versa.

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
EU and US reach agreement on Privacy Shield replacement
News Privacy campaigner Max Schrems suggests the deal amounts to a "patchwork approach" that will ultimately fail
By Bobby Hellard
-
Zoom is no longer compatible with GDPR, Hamburg data watchdog claims
News Regulator claims city officials are using a "legally highly problematic system"
By Bobby Hellard
-
Microsoft promises to challenge all government requests for customer data
News Stance taken following EU advice to firms on complying with a ruling invalidating the EU-US data transfer mechanism
By Keumars Afifi-Sabet
-
European court invalidates primary EU-US data transfer mechanism
News Privacy Shield ruled to be incompatible with GDPR in landmark case
By Dale Walker
-
What is EU-US Privacy Shield?
In-depth A look at the now invalidated framework US companies relied on to transfer data to and from the European Union
By Dale Walker
-
Privacy Shield should be suspended, say MEPs
News Committee cites Cambridge Analytica scandal and CLOUD Act as obstacles
By Joe Curtis
-
EU seeks Privacy Shield changes in its first annual review
News Proposals include tougher rules around non-compliance and greater cooperation between US and EU authorities
By Dale Walker
-
European data protection supervisor says Privacy Shield not robust enough
News Giovanni Buttarelli said the European Commission needs to develop a longer-term solution for sharing data across continents
By Joe Curtis