<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/privacy-shield"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Privacy-shield ]]></title>
                <link>https://www.itpro.com/uk/tag/privacy-shield</link>
        <description><![CDATA[ All the latest privacy-shield content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Fri, 25 Mar 2022 13:04:12 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ EU and US reach agreement on Privacy Shield replacement ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The European Union and the US government have reached an agreement, in principle, on a deal for transatlantic data flows.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/363776/aws-says-customers-dont-have-to-use-privacy-shield" data-original-url="/security/privacy/363776/aws-says-customers-dont-have-to-use-privacy-shield">AWS says customers don’t have to use Privacy Shield</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu" data-original-url="/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu">EU and UK reach post-Brexit data flows deal</a></p></div></div><p>A new agreement potentially signals an end to years of legal uncertainty that has hung over the US, particularly its <a href="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal" target="_blank" data-original-url="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal">tech industry</a>, since the EU-US Privacy Shield mechanism was invalidated in a <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">2020 court ruling</a>.</p><p>EU president Ursula von der Leyen revealed the proposed deal during a joint briefing with US president Joe Biden, who is in Europe mainly to discuss the Russian invasion of Ukraine. Von der Leyen gave special thanks to EU justice commissioner Didier Reynders and US secretary of commerce Gina Raimondo for their efforts in finding an effective solution. However, the exact details of the agreement, specifically what each party has agreed to, have not been clearly explained.</p><p>"I am very pleased that we have found an agreement in principle on a new framework for transatlantic data flows," said von der Leyen. "This will enable predictable and trustworthy data flows between the EU and US, safeguarding privacy and civil liberties."</p><p><a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> was deemed incompatible with the EU's data protection laws, largely due to the American government's own regulations for surveillance. A European Court of Justice ruling in 2020 found the act was unable to uphold the levels of privacy that data subjects in Europe are legally entitled to.</p><p>"We managed to balance security and the right to privacy and data protection," von der Leyen suggested during the briefing.</p><p>However, some have criticised what's seen as an impossible task of reconciling two different data protection approaches, particularly as the US has yet to enact a federal data protection policy.</p><p>In response, Max Schrems, the privacy lawyer and campaigner behind the <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">Schrems I and Schrems II legal cases</a>, took to Twitter to question the weight of the deal.</p><p>"Seems we do another Privacy Shield especially in one respect: Politics over law and fundamental rights," he tweeted. "This failed twice before. What we heard is another 'patchwork' approach but no substantial reform on the US side. Let's wait for a text but my bet is it will fail again."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement</link>
                                                                            <description>
                            <![CDATA[ Privacy campaigner Max Schrems suggests the deal amounts to a "patchwork approach" that will ultimately fail ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6Y4J1e8n5Z9JSfK4aKtuM6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Mar 2022 13:04:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing EU and US flags tiled together]]></media:description>                                                            <media:text><![CDATA[Abstract image showing EU and US flags tiled together]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing EU and US flags tiled together]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Union and the US government have reached an agreement, in principle, on a deal for transatlantic data flows.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/363776/aws-says-customers-dont-have-to-use-privacy-shield" data-original-url="/security/privacy/363776/aws-says-customers-dont-have-to-use-privacy-shield">AWS says customers don’t have to use Privacy Shield</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu" data-original-url="/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu">EU and UK reach post-Brexit data flows deal</a></p></div></div><p>A new agreement potentially signals an end to years of legal uncertainty that has hung over the US, particularly its <a href="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal" target="_blank" data-original-url="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal">tech industry</a>, since the EU-US Privacy Shield mechanism was invalidated in a <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">2020 court ruling</a>.</p><p>EU president Ursula von der Leyen revealed the proposed deal during a joint briefing with US president Joe Biden, who is in Europe mainly to discuss the Russian invasion of Ukraine. Von der Leyen gave special thanks to EU justice commissioner Didier Reynders and US secretary of commerce Gina Raimondo for their efforts in finding an effective solution. However, the exact details of the agreement, specifically what each party has agreed to, have not been clearly explained.</p><p>"I am very pleased that we have found an agreement in principle on a new framework for transatlantic data flows," said von der Leyen. "This will enable predictable and trustworthy data flows between the EU and US, safeguarding privacy and civil liberties."</p><p><a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> was deemed incompatible with the EU's data protection laws, largely due to the American government's own regulations for surveillance. A European Court of Justice ruling in 2020 found the act was unable to uphold the levels of privacy that data subjects in Europe are legally entitled to.</p><p>"We managed to balance security and the right to privacy and data protection," von der Leyen suggested during the briefing.</p><p>However, some have criticised what's seen as an impossible task of reconciling two different data protection approaches, particularly as the US has yet to enact a federal data protection policy.</p><p>In response, Max Schrems, the privacy lawyer and campaigner behind the <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">Schrems I and Schrems II legal cases</a>, took to Twitter to question the weight of the deal.</p><p>"Seems we do another Privacy Shield especially in one respect: Politics over law and fundamental rights," he tweeted. "This failed twice before. What we heard is another 'patchwork' approach but no substantial reform on the US side. Let's wait for a text but my bet is it will fail again."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom is no longer compatible with GDPR, Hamburg data watchdog claims ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A German data protection commissioner has officially warned Hamburg's Senate Chancellery to avoid using <a href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" target="_blank" data-original-url="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now">Zoom</a> as it is no longer compatible with GDPR.</p><p>Hamburg's acting Commissioner for Data Protection and Freedom of Information, Ulrich Kühn, said in a press release that the on-demand version of the video conferencing platform does not meet the legislation's criteria when it comes to data transfers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Schrems strikes again, filing GDPR complaints against Facebook and Google</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" data-original-url="/software/355486/zoom-review-are-we-alone-now">Zoom review: Are we alone now?</a></p></div></div><p>He cites the European Court of Justice's (CJEU) <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">Schrems II decision</a><a href="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes" target="_blank" data-original-url="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes">,</a> announced in July 2020, which invalidated the EU-US data transfer mechanism known as <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> and required alternative mechanisms to be more rigorous.</p><p>"All employees have access to a tried and tested video conference tool that is unproblematic with regard to third-country transmission," Kühn wrote. "As the central service provider, Dataport also provides additional video conference systems in its own data centres. These are used successfully in other countries [sic] such as Schleswig-Holstein. It is therefore incomprehensible why the Senate Chancellery insists on an additional and legally highly problematic system."</p><p>The issue appears to relate to a dispute over the way Zoom has used standard contractual clauses (SCCs) to justify its data transfers. On it's <a href="https://zoom.us/gdpr" target="_blank">website</a>, Zoom says its services feature "an explicit consent mechanism for EU users" on its platform and that the firm has implemented "zero-load" cookies for users whose <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address" target="_blank" data-original-url="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP address</a> show they are visiting the site from an EU member state. Specifically, the firm states: "we ensure that the transfer is governed by the European Commission's standard contractual clauses (SCC)".</p><p>However, following the Schrems II decision in July 2020, companies are now required to perform additional steps to justify their use of SCCs, including performing additional risk assessments - something that Zoom appears not to have done.</p><p>Neil Brown, the director of virtual English law firm decoded.legal, told <a href="https://www.theregister.com/2021/08/17/zoom_incompatible_with_gdpr_hamburg_warning" target="_blank"><em>The Register</em></a> that the press release was "somewhat oblique" but suggested that the Hamburg Data Protection Authority considers that Zoom does not ensure a level of protection for personal data which is "essentially equivalent" to that afforded by the GDPR.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>"Many businesses used to address the international transfers aspect of the GDPR by incorporating the model contract clauses/SCCs into their contracts with organisations in non-adequate jurisdictions," Brown told <em>The Register</em>. "In Schrems II, the CJEU said that these were not, in themselves, sufficient, and that a transferring controller must do a comprehensive risk assessment, and put appropriate additional measures in place to ensure 'essentially equivalent' protection.</p><p>"And that came as a shock to a lot of people, since it rather suggested that the model clauses were not fit for purpose. And, lo and behold, there is a new European set, which is a heck of a lot more complicated."</p><p>In a statement, Zoom said it was proud to work with the City of Hamburg and many other leading German organisations, businesses and education institutions.</p><p>"The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us," the firm said. "Zoom is committed to complying with all applicable privacy laws, rules, and regulations in the jurisdictions within which it operates, including the GDPR."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360625/zoom-incompatible-with-gdpr</link>
                                                                            <description>
                            <![CDATA[ Regulator claims city officials are using a "legally highly problematic system" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o4NNuCpLcZpL2E2sv1KBrn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ktKXC2YoUx6J7bNNgh7muK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Aug 2021 10:55:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ktKXC2YoUx6J7bNNgh7muK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom&amp;#039;s white camera on blue background logo]]></media:description>                                                            <media:text><![CDATA[Zoom&amp;#039;s white camera on blue background logo]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom&amp;#039;s white camera on blue background logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ktKXC2YoUx6J7bNNgh7muK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A German data protection commissioner has officially warned Hamburg's Senate Chancellery to avoid using <a href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" target="_blank" data-original-url="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now">Zoom</a> as it is no longer compatible with GDPR.</p><p>Hamburg's acting Commissioner for Data Protection and Freedom of Information, Ulrich Kühn, said in a press release that the on-demand version of the video conferencing platform does not meet the legislation's criteria when it comes to data transfers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Schrems strikes again, filing GDPR complaints against Facebook and Google</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" data-original-url="/software/355486/zoom-review-are-we-alone-now">Zoom review: Are we alone now?</a></p></div></div><p>He cites the European Court of Justice's (CJEU) <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">Schrems II decision</a><a href="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes" target="_blank" data-original-url="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes">,</a> announced in July 2020, which invalidated the EU-US data transfer mechanism known as <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> and required alternative mechanisms to be more rigorous.</p><p>"All employees have access to a tried and tested video conference tool that is unproblematic with regard to third-country transmission," Kühn wrote. "As the central service provider, Dataport also provides additional video conference systems in its own data centres. These are used successfully in other countries [sic] such as Schleswig-Holstein. It is therefore incomprehensible why the Senate Chancellery insists on an additional and legally highly problematic system."</p><p>The issue appears to relate to a dispute over the way Zoom has used standard contractual clauses (SCCs) to justify its data transfers. On it's <a href="https://zoom.us/gdpr" target="_blank">website</a>, Zoom says its services feature "an explicit consent mechanism for EU users" on its platform and that the firm has implemented "zero-load" cookies for users whose <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address" target="_blank" data-original-url="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP address</a> show they are visiting the site from an EU member state. Specifically, the firm states: "we ensure that the transfer is governed by the European Commission's standard contractual clauses (SCC)".</p><p>However, following the Schrems II decision in July 2020, companies are now required to perform additional steps to justify their use of SCCs, including performing additional risk assessments - something that Zoom appears not to have done.</p><p>Neil Brown, the director of virtual English law firm decoded.legal, told <a href="https://www.theregister.com/2021/08/17/zoom_incompatible_with_gdpr_hamburg_warning" target="_blank"><em>The Register</em></a> that the press release was "somewhat oblique" but suggested that the Hamburg Data Protection Authority considers that Zoom does not ensure a level of protection for personal data which is "essentially equivalent" to that afforded by the GDPR.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>"Many businesses used to address the international transfers aspect of the GDPR by incorporating the model contract clauses/SCCs into their contracts with organisations in non-adequate jurisdictions," Brown told <em>The Register</em>. "In Schrems II, the CJEU said that these were not, in themselves, sufficient, and that a transferring controller must do a comprehensive risk assessment, and put appropriate additional measures in place to ensure 'essentially equivalent' protection.</p><p>"And that came as a shock to a lot of people, since it rather suggested that the model clauses were not fit for purpose. And, lo and behold, there is a new European set, which is a heck of a lot more complicated."</p><p>In a statement, Zoom said it was proud to work with the City of Hamburg and many other leading German organisations, businesses and education institutions.</p><p>"The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us," the firm said. "Zoom is committed to complying with all applicable privacy laws, rules, and regulations in the jurisdictions within which it operates, including the GDPR."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft promises to challenge all government requests for customer data ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has vowed to challenge all requests that any government or security agency makes to access its customers’ data, and will even compensate firms where it’s forced to legally grant access.</p><p>Cross-border transfers have come under litigation and regulatory action in recent months, especially after a European court <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">invalidated the key EU-US data transfer mechanism</a> under the terms of GDPR. July’s ruling meant the long-established <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> was deemed unsuitable for protecting EU residents’ data from extensive US surveillance mechanisms, with concerns US authorities can extract customer data as and when desired, without adequate safeguards and protections.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/355570/swiping-and-scrolling-is-not-consent-edpb-says" data-original-url="/policy-legislation/data-protection/355570/swiping-and-scrolling-is-not-consent-edpb-says">Swiping and scrolling is not consent, says EU data watchdog</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/356344/eu-institutions-warned-against-purchasing-any-further" data-original-url="/policy-legislation/data-protection/356344/eu-institutions-warned-against-purchasing-any-further">EU institutions told to avoid Microsoft software after licence spat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/public-cloud/357185/what-is-gaia-x-a-guide-to-the-eus-unified-cloud-ecosystem" data-original-url="/cloud/public-cloud/357185/what-is-gaia-x-a-guide-to-the-eus-unified-cloud-ecosystem">What is Gaia-X? A guide to the EU’s unified cloud ecosystem</a></p></div></div><p>In light of recommendations issued by the European Data Protection Board (EDPB) on how companies can comply with the ruling, Microsoft has now committed to challenging every request for data.</p><p>The firm will challenge every government request for public sector or enterprise customer data, from any government, where there’s a lawful basis for doing so. Where customer data is handed to authorities in violation of GDPR, Microsoft will provide financial compensation to affected customers, it has said. These are commitments that Microsoft claims go beyond the recommendations of the EDPB.</p><p>“With today’s announcement, we are moving to be the first company to respond to the EDPB’s guidance with new commitments that demonstrate the strength of our conviction to defend our customers’ data,” said Microsoft’s corporate vice president for global privacy and regulatory affairs and chief privacy officer, Julie Brill.</p><p>“Microsoft has already demonstrated that we provide strong protections for our customers’ data, we are transparent about our practices and we defend our customers’ data. We believe the new steps we’re announcing today go beyond the law and the EDPB draft recommendations, and we hope these additional steps will give our customers added confidence about their data.”</p><p>The company’s position on this matter is a statement of support for the EU’s position - and represents another example of Microsoft increasingly aligning itself with its <a href="https://www.itpro.com/policy-legislation/34075/eu-plotting-to-overhaul-rules-governing-tech-giants" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/34075/eu-plotting-to-overhaul-rules-governing-tech-giants">desires on tech policy</a>.</p><p>For example, towards the end of last year, Microsoft committed to <a href="https://docs.microsoft.com/en-us/archive/msdn-magazine/2004/november/cryptography-employing-strong-encryption-in-your-apps">implementing ‘strong encryption’</a> in its products as opposed to <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">‘end-to-end encryption’</a>, which public authorities around the world, including Interpol, have <a href="https://www.itpro.com/encryption/34832/interpol-to-support-the-breaking-of-end-to-end-encryption" target="_blank" data-original-url="https://www.itpro.com/encryption/34832/interpol-to-support-the-breaking-of-end-to-end-encryption">railed against</a>.</p><p>The EU has, incidentally, earlier this month edged closer to a full ban on end-to-end encryption in platforms such as WhatsApp and Signal, according to a <a href="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent" data-original-url="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent">leaked document</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/data-protection/357847/microsoft-to-challenge-all-government-requests-for</link>
                                                                            <description>
                            <![CDATA[ Stance taken following EU advice to firms on complying with a ruling invalidating the EU-US data transfer mechanism ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nHQat2EUeFmzRcjspZJTak</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LJdoKqfuA7B8dZaTaii8pF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Nov 2020 13:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LJdoKqfuA7B8dZaTaii8pF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Microsoft logo as seen in large print fixed onto a glass building]]></media:description>                                                            <media:text><![CDATA[The Microsoft logo as seen in large print fixed onto a glass building]]></media:text>
                                <media:title type="plain"><![CDATA[The Microsoft logo as seen in large print fixed onto a glass building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LJdoKqfuA7B8dZaTaii8pF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has vowed to challenge all requests that any government or security agency makes to access its customers’ data, and will even compensate firms where it’s forced to legally grant access.</p><p>Cross-border transfers have come under litigation and regulatory action in recent months, especially after a European court <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">invalidated the key EU-US data transfer mechanism</a> under the terms of GDPR. July’s ruling meant the long-established <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> was deemed unsuitable for protecting EU residents’ data from extensive US surveillance mechanisms, with concerns US authorities can extract customer data as and when desired, without adequate safeguards and protections.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/355570/swiping-and-scrolling-is-not-consent-edpb-says" data-original-url="/policy-legislation/data-protection/355570/swiping-and-scrolling-is-not-consent-edpb-says">Swiping and scrolling is not consent, says EU data watchdog</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/356344/eu-institutions-warned-against-purchasing-any-further" data-original-url="/policy-legislation/data-protection/356344/eu-institutions-warned-against-purchasing-any-further">EU institutions told to avoid Microsoft software after licence spat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/public-cloud/357185/what-is-gaia-x-a-guide-to-the-eus-unified-cloud-ecosystem" data-original-url="/cloud/public-cloud/357185/what-is-gaia-x-a-guide-to-the-eus-unified-cloud-ecosystem">What is Gaia-X? A guide to the EU’s unified cloud ecosystem</a></p></div></div><p>In light of recommendations issued by the European Data Protection Board (EDPB) on how companies can comply with the ruling, Microsoft has now committed to challenging every request for data.</p><p>The firm will challenge every government request for public sector or enterprise customer data, from any government, where there’s a lawful basis for doing so. Where customer data is handed to authorities in violation of GDPR, Microsoft will provide financial compensation to affected customers, it has said. These are commitments that Microsoft claims go beyond the recommendations of the EDPB.</p><p>“With today’s announcement, we are moving to be the first company to respond to the EDPB’s guidance with new commitments that demonstrate the strength of our conviction to defend our customers’ data,” said Microsoft’s corporate vice president for global privacy and regulatory affairs and chief privacy officer, Julie Brill.</p><p>“Microsoft has already demonstrated that we provide strong protections for our customers’ data, we are transparent about our practices and we defend our customers’ data. We believe the new steps we’re announcing today go beyond the law and the EDPB draft recommendations, and we hope these additional steps will give our customers added confidence about their data.”</p><p>The company’s position on this matter is a statement of support for the EU’s position - and represents another example of Microsoft increasingly aligning itself with its <a href="https://www.itpro.com/policy-legislation/34075/eu-plotting-to-overhaul-rules-governing-tech-giants" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/34075/eu-plotting-to-overhaul-rules-governing-tech-giants">desires on tech policy</a>.</p><p>For example, towards the end of last year, Microsoft committed to <a href="https://docs.microsoft.com/en-us/archive/msdn-magazine/2004/november/cryptography-employing-strong-encryption-in-your-apps">implementing ‘strong encryption’</a> in its products as opposed to <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">‘end-to-end encryption’</a>, which public authorities around the world, including Interpol, have <a href="https://www.itpro.com/encryption/34832/interpol-to-support-the-breaking-of-end-to-end-encryption" target="_blank" data-original-url="https://www.itpro.com/encryption/34832/interpol-to-support-the-breaking-of-end-to-end-encryption">railed against</a>.</p><p>The EU has, incidentally, earlier this month edged closer to a full ban on end-to-end encryption in platforms such as WhatsApp and Signal, according to a <a href="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent" data-original-url="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent">leaked document</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European court invalidates primary EU-US data transfer mechanism ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The European Union’s top court has ruled that the data transfer mechanism many companies use to transfer data between the EU and the US is no longer valid under GDPR.</p><p>In a highly anticipated ruling on 16 July that many believed would have profound implications for data transfers, the European Court of Justice decided that Privacy Shield was unable to protect EU residents' data from extensive US surveillance mechanisms.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">Businesses worldwide brace for ECJ ruling on data transfers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> General Data Protection Regulation (GDPR)</p></div></div><p><a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a>, itself a replacement for the invalidated Safe Harbour Principles, was introduced in 2016 to reconcile the problem of sending data from the EU, an area with robust data protection mechanisms, to the US, a country known for relatively invasive surveillance laws.</p><p><a href="https://www.privacyshield.gov/list">Some 5,300 businesses</a>, many of which are small to medium-sized, have come to rely on Privacy Shield to transfer data, as it was by far the easiest mechanism to use when securing legal justification under GDPR.</p><p>However, the ECJ ruled that Privacy Shield prioritised US law enforcement and national security over the fundamental rights of data subjects, something that now conflicts with the notion that so called ‘third countries’ have equivalent data protections as those set out by GDPR. In other words, Privacy Shield simply isn’t compatible with today's EU data rules.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1283668810374021121"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1283668810374021121"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The court also found that surveillance laws in the US do not appear to have any limitations in how they are implemented, nor do they provide guarantees that non-US data subjects would be excluded or protected from such surveillance.</p><p>It also argued that the Ombudsperson, a position that provides EU citizens an additional point of redress when raising complaints against a company, but which sat vacant until 2019, does not provide data subjects with a cause of action for complaints that is equivalent to powers in the EU.</p><p>The case was originally brought by privacy activist Max Schrems against Facebook. He claimed that the company was unjustified in its use of so called ‘standard contractual clauses’ for the transfer of data between its EU headquarters and its US base in Silicon Valley. SCCs as a mechanism <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">allow EU businesses to bake data protection rules into their contracts</a> with companies outside of the EU and outside the scope of GDPR.</p><p>After Schrems complained to the Irish data protection regulator, the case was then sent to the Irish High Court and eventually the top court in Europe. However, the Irish High Court expanded the initial case to also challenge the validity of all standard contractual clauses as a data transfer mechanism, as well as challenge the validity of Privacy Shield, over which it had concerns.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1283669789181960197"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1283669789181960197"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Thursday’s ruling found that SCCs were valid as a data transfer mechanism, although it stated that data controllers are required to assess whether it’s possible for these contractual terms to be upheld in any country where invasive surveillance laws exist.</p><p>The invalidation of Privacy Shield, but the protection of SCCs, is a clear win for Schrems, who always argued that SCCs should be enforced more rigorously rather than scrapped altogether, particularly as so many businesses rely on their use.</p><p>“I am very happy about the judgment. It seems the Court has followed us in all aspects,” said Schrems, commenting on the ruling. “This is a total blow to the Irish DPC and Facebook. It is clear that the US will have to seriously change their surveillance laws, if US companies want to continue to play a major role on the EU market.”</p><p>The invalidation of Privacy Shield creates a difficult moment for the European Commission, as it will now be tasked with creating an alternative mechanism for the transfer of data to the US. It took nine months for the Commission to replace Safe Harbour with Privacy Shield and, given the added complexities of GDPR, creating a new framework could take even longer.</p><p>The ruling makes it clear that any new mechanism will need to maintain GDPR principles, something that may be incredibly difficult in the context of US surveillance laws. If anything, it may require the US to adjust its own laws to provide guarantees for EU data, which may be unlikely.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="herSpxCjgjwEyNWcYESAd5" name="herSpxCjgjwEyNWcYESAd5.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/herSpxCjgjwEyNWcYESAd5.png" mos="https://cdn.mos.cms.futurecdn.net/herSpxCjgjwEyNWcYESAd5.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Go digital to meet today’s critical compliance and security requirements</strong></p><p class="fancy-box__body-text">Digital transformation helps companies meet critical compliance and security requirements</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/355876/go-digital-to-meet-todays-critical-compliance-and" data-original-url="/business-strategy/digital-transformation/355876/go-digital-to-meet-todays-critical-compliance-and">FREE DOWNLOAD</a></p></div></div><p>"This is pretty much a solid victory for Schrems, and it will be interesting to see how the regulators (and businesses) reacts," says Renzo Marchini, privacy and security partner at law firm Fieldfisher. "This will be a big shock in EU-US relationships. The Privacy Shield had been painstakingly put together to deal with criticism of oversight under the old regime that was killed in the first Schrems case back in 2015 (Safe Harbor). This is now also found to be invalid and cannot be relied upon.</p><p>"In the light of that, it will be difficult for the regulators to allow SCCs for transfers to the US. If there is too much scope for intrusion into European individuals' privacy under Privacy Shield, how can there not be for SCCs?"</p><p>Caitlin Fennessy, research director at the International Association of Privacy Professionals (IAPP), said the scrapping of Privacy Shield "will undoubtedly leave tens of thousands of U.S. companies scrambling and without a legal means to conduct transatlantic business, worth trillions of dollars annually".</p><p>"IAPP’s 2019 Governance Survey found that 88 percent of respondents moving data out of Europe rely on standard contracts. This decision cuts off legal means to transfer personal data to the United States and will demand immediate attention by policymakers and U.S. companies doing business in Europe.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism</link>
                                                                            <description>
                            <![CDATA[ Privacy Shield ruled to be incompatible with GDPR in landmark case ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oP2vC4CjoTJyScwsVD9yhW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2020 09:33:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing EU and US flags tiled together]]></media:description>                                                            <media:text><![CDATA[Abstract image showing EU and US flags tiled together]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing EU and US flags tiled together]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Union’s top court has ruled that the data transfer mechanism many companies use to transfer data between the EU and the US is no longer valid under GDPR.</p><p>In a highly anticipated ruling on 16 July that many believed would have profound implications for data transfers, the European Court of Justice decided that Privacy Shield was unable to protect EU residents' data from extensive US surveillance mechanisms.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">Businesses worldwide brace for ECJ ruling on data transfers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> General Data Protection Regulation (GDPR)</p></div></div><p><a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a>, itself a replacement for the invalidated Safe Harbour Principles, was introduced in 2016 to reconcile the problem of sending data from the EU, an area with robust data protection mechanisms, to the US, a country known for relatively invasive surveillance laws.</p><p><a href="https://www.privacyshield.gov/list">Some 5,300 businesses</a>, many of which are small to medium-sized, have come to rely on Privacy Shield to transfer data, as it was by far the easiest mechanism to use when securing legal justification under GDPR.</p><p>However, the ECJ ruled that Privacy Shield prioritised US law enforcement and national security over the fundamental rights of data subjects, something that now conflicts with the notion that so called ‘third countries’ have equivalent data protections as those set out by GDPR. In other words, Privacy Shield simply isn’t compatible with today's EU data rules.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1283668810374021121"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1283668810374021121"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The court also found that surveillance laws in the US do not appear to have any limitations in how they are implemented, nor do they provide guarantees that non-US data subjects would be excluded or protected from such surveillance.</p><p>It also argued that the Ombudsperson, a position that provides EU citizens an additional point of redress when raising complaints against a company, but which sat vacant until 2019, does not provide data subjects with a cause of action for complaints that is equivalent to powers in the EU.</p><p>The case was originally brought by privacy activist Max Schrems against Facebook. He claimed that the company was unjustified in its use of so called ‘standard contractual clauses’ for the transfer of data between its EU headquarters and its US base in Silicon Valley. SCCs as a mechanism <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">allow EU businesses to bake data protection rules into their contracts</a> with companies outside of the EU and outside the scope of GDPR.</p><p>After Schrems complained to the Irish data protection regulator, the case was then sent to the Irish High Court and eventually the top court in Europe. However, the Irish High Court expanded the initial case to also challenge the validity of all standard contractual clauses as a data transfer mechanism, as well as challenge the validity of Privacy Shield, over which it had concerns.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1283669789181960197"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1283669789181960197"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Thursday’s ruling found that SCCs were valid as a data transfer mechanism, although it stated that data controllers are required to assess whether it’s possible for these contractual terms to be upheld in any country where invasive surveillance laws exist.</p><p>The invalidation of Privacy Shield, but the protection of SCCs, is a clear win for Schrems, who always argued that SCCs should be enforced more rigorously rather than scrapped altogether, particularly as so many businesses rely on their use.</p><p>“I am very happy about the judgment. It seems the Court has followed us in all aspects,” said Schrems, commenting on the ruling. “This is a total blow to the Irish DPC and Facebook. It is clear that the US will have to seriously change their surveillance laws, if US companies want to continue to play a major role on the EU market.”</p><p>The invalidation of Privacy Shield creates a difficult moment for the European Commission, as it will now be tasked with creating an alternative mechanism for the transfer of data to the US. It took nine months for the Commission to replace Safe Harbour with Privacy Shield and, given the added complexities of GDPR, creating a new framework could take even longer.</p><p>The ruling makes it clear that any new mechanism will need to maintain GDPR principles, something that may be incredibly difficult in the context of US surveillance laws. If anything, it may require the US to adjust its own laws to provide guarantees for EU data, which may be unlikely.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="herSpxCjgjwEyNWcYESAd5" name="herSpxCjgjwEyNWcYESAd5.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/herSpxCjgjwEyNWcYESAd5.png" mos="https://cdn.mos.cms.futurecdn.net/herSpxCjgjwEyNWcYESAd5.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Go digital to meet today’s critical compliance and security requirements</strong></p><p class="fancy-box__body-text">Digital transformation helps companies meet critical compliance and security requirements</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/355876/go-digital-to-meet-todays-critical-compliance-and" data-original-url="/business-strategy/digital-transformation/355876/go-digital-to-meet-todays-critical-compliance-and">FREE DOWNLOAD</a></p></div></div><p>"This is pretty much a solid victory for Schrems, and it will be interesting to see how the regulators (and businesses) reacts," says Renzo Marchini, privacy and security partner at law firm Fieldfisher. "This will be a big shock in EU-US relationships. The Privacy Shield had been painstakingly put together to deal with criticism of oversight under the old regime that was killed in the first Schrems case back in 2015 (Safe Harbor). This is now also found to be invalid and cannot be relied upon.</p><p>"In the light of that, it will be difficult for the regulators to allow SCCs for transfers to the US. If there is too much scope for intrusion into European individuals' privacy under Privacy Shield, how can there not be for SCCs?"</p><p>Caitlin Fennessy, research director at the International Association of Privacy Professionals (IAPP), said the scrapping of Privacy Shield "will undoubtedly leave tens of thousands of U.S. companies scrambling and without a legal means to conduct transatlantic business, worth trillions of dollars annually".</p><p>"IAPP’s 2019 Governance Survey found that 88 percent of respondents moving data out of Europe rely on standard contracts. This decision cuts off legal means to transfer personal data to the United States and will demand immediate attention by policymakers and U.S. companies doing business in Europe.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is EU-US Privacy Shield? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Privacy Shield was a regulatory framework that governed the transfer of data between the European Union and the United States. Its principal purpose was to act as a mechanism for US companies to receive data from the EU, thereby ensuring smooth data transfers despite the fact that the two countries operated in separate data protection jurisdictions.</p><p>In effect, Privacy Shield fulfiled the same purpose as an adequacy agreement, required by any third status country that is outside of the regulatory reach of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">EU's General Data Protection Regulation (GDPR)</a>. Such an agreement signals that the EU recognises the data protection laws of the third country as being robust enough to protect the data of EU citizens, and therefore eligible to receive EU data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">Businesses worldwide brace for ECJ ruling on data transfers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31296/privacy-shield-should-be-suspended-say-meps" data-original-url="/data-protection/31296/privacy-shield-should-be-suspended-say-meps">Privacy Shield should be suspended, say MEPs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a></p></div></div><p>​Privacy Shield <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">was ruled invalid by the European Court of Justice</a> on 16 July 2020 as part of the <em>Facebook Ireland vs Max Schrems</em> case. The ECJ argued that the creation of Privacy Shield gave primacy to US surveillance laws, with its current form being unable to provide adequate protections for EU resident data. It was also ruled that the mechanism did not provide data subjects with an adequate point of redress or cause of action when issuing complaints.</p><h3 class="article-body__section" id="section-where-did-privacy-shield-come-from"><span>Where did Privacy Shield come from?</span></h3><p>The ‘International Safe Harbour Privacy Principles’, referred to commonly as Safe Harbour, were in force between 2000 and 2015, eventually being deemed insufficient following a challenge by Max Schrems. Privacy Shield, which suffered the same fate, replaced Safe Harbour, and once again tried to ease data flows between the US and the EU.</p><p>The history of both frameworks actually stretches back to the 1980s when the EU started to pursue policies to raise the level of data protection offered to citizens throughout its member states. To guarantee these protections were universal, the EU needed to ensure that citizens were safeguarded by the same protections not only in the EU but when their data was sent to other countries, such as the US.</p><p>The EU eventually signed the Data Protection Directive in 1995, which was the first set of meaningful data protection regulations, and the legislation that would eventually evolve into what we know as GDPR today. Although it covered a variety of issues, one of its main functions was to ensure companies sending data belonging to EU data subjects to non-EEA countries couldn’t process the data by weaker standards.</p><p>The EU’s appetite for raising the level of data protection for its citizens wasn’t matched by legislators in the US, especially considering how security agencies <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">such as the NSA</a> were known to operate. However, because it was vital to ensure that data continued to flow undisrupted between EU territories and the US, the two entities came together to build a specific architecture to ensure that businesses could seamlessly move data while data subjects would rest easy knowing their rights would continue to apply. This would replace the need for any mechanisms such as formal adequacy agreements, standard contractual clauses (SCCs) or binding corporate rules.</p><p>Developed between 1998 and 2000, the Safe Harbour Privacy Principles were initially designed to prevent organisations in the US and the EU from accidentally disclosing personal information by providing clear guidelines on how to collect and manage data. These principles incorporated some of the requirements set out by the Data Protection Directive, including the need for better security, relevant data collection, and the restrictions on third-country transfers, only these were voluntary for US companies. However, by July 2000, it was decided that any US company that was able to demonstrate its commitment to these Safe Harbor Principles would be permitted to send and receive data from the EU – known as the "Safe Harbor Decision".</p><p>US companies operated under the provisions of the Safe Harbor Decision for over 15 years but in October 2015, the European Court of Justice <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">ruled that the process of the Safe Harbour Decision was invalid</a>. The reason for this ruling was mainly because the act of giving public authorities access to EU individuals' data through the adherence of general principles was in direct conflict with <a href="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge" data-original-url="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge">the right to privacy</a> as enshrined in Article 8 of the European Convention on Human Rights (ECHR). In essence, the ECJ found that the Safe Harbour Principles were incompatible with EU data laws given that the framework lacked any operational oversight from US or EU agencies.</p><h3 class="article-body__section" id="section-enter-privacy-shield"><span>Enter Privacy Shield</span></h3><p>Privacy Shield, introduced in early 2016, was an attempt to rectify these issues, promising to enforce tougher obligations on US companies – namely the requirement to monitor and enforce data protections more robustly, and cooperate with European data protection authorities.</p><p>As with Safe Harbor, it was a voluntary mechanism that US companies could use to legally send and receive data from the EU. Those that agreed to process data under Privacy Shield were required to publicly advertise their compliance – a notice that said they were committed to providing higher standards of data protection and that they were liable to strict fines if found to be in breach of them.</p><p>As part of this compliance, organisations were required to give European users a means to opt out of having their data sold to third parties, as well as rigorously protect any data they do collect. EU data subjects were also protected from any misuse of data beyond its originally advertised processing purpose and had the right to access, correct, amend or delete any data that an organisation held on them, provided it was inaccurate or had been used in a way that breached Privacy Shield principles.</p><p>These protections only existed for EU citizens – US citizens were only protected by federal or state US laws.</p><h3 class="article-body__section" id="section-privacy-shield-fines-amp-sanctions"><span>Privacy Shield fines & sanctions</span></h3><p>The <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc" data-original-url="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">US Federal Trade Commission</a>, the agency overseeing Privacy Shield enforcement, had the power to bring fines against any company found to be in breach of Privacy Shield standards.</p><p>Any US organisation that failed to abide by their commitments to upholding Privacy Shield principles could face a number of different penalties. Firstly, the FTC could issue administrative or court orders to compel an organisation to fix any violations. Failure to abide by these orders could result in civil penalties of up to $40,000 for each violation, or $40,000 per day for ongoing violations.</p><p>Any organisation found to be in persistent violation of Privacy Shield standards would have its eligibility revoked, which prevented it from using the mechanism for data transfers. This includes any company that had been found to be in regular breach of the standards even if those breaches were unrelated. The Department of Commerce would then remove the company's name from the Privacy Shield List.</p><h3 class="article-body__section" id="section-what-did-privacy-shield-require-of-us-businesses"><span>What did Privacy Shield require of US businesses?</span></h3><p>Privacy Shield was voluntary for US businesses, however, it was strongly advised that organisations sign up to the laws, particularly if they planned to expand into Europe in the future.</p><p>Those that sign up were required to do the following:</p><ul><li>Present a detailed public facing statement showing its commitment to the Privacy Shield Principles and how it is ensuring its processes are compliant.</li><li>Ensure that mechanisms are in place to restrict data sharing with third parties where a user has opted-out. All third parties that receive such data must also publicly display their commitment to Privacy Shield.</li><li>Respond to all access and deletion requests from users, and provide a means for users to change their data, provided the request is feasible.</li><li>Ensure that all systems are maintained and are protected from unauthorised access.</li></ul><h3 class="article-body__section" id="section-criticisms-of-privacy-shield"><span>Criticisms of Privacy Shield</span></h3><p>Both Safe Harbour and Privacy Shield highlighted an ongoing clash between the US and the EU over data protection rights.</p><p>The European Union has worked to increase protections, and now operates one of the world's most robust data laws in the world. Data processing is heavily scrutinised under GDPR, with companies facing the prospect of <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">crippling fines for any loss of data</a>.</p><p>The US, meanwhile, has increased the surveillance powers of its intelligence agencies over the years, particularly following the introduction of the US Patriot Act in 2001. Intelligence agencies are able to use <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">programmes such as PRISM</a> to collect data from US internet companies, as well as the Foreign Intelligence Surveillance Act (FISA) to gather data on US citizens. Perhaps most importantly for EU authorities, the US has yet to work towards a centralised federal data protection regime, let alone one that begins to mirror GDPR. Aside from <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">states such as California</a>, there have been few attempts to expand data protection rights.</p><p>Privacy Shield was, therefore, an attempt at a compromise on the part of the EU to overcome this ongoing contradiction – a mechanism that allows US companies to prove they can operate under GDPR-like controls.</p><p>Not everyone agreed that the EU's good faith is reciprocated, however. Most notably, as part of the relationship, the US had the duty of appointing an ombudsperson to act as an additional point of redress for any EU citizens raising complaints against a company. This position sat vacant until June 2019, when Keith Krach was confirmed as the US' first permanent Privacy Shield Ombudsperson, leaving many to question whether the country was taking its role seriously enough.</p><p>Concerns had also been raised over the years about the framework's ability to protect EU data. In 2016, <a href="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough" data-original-url="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough">European data protection supervisor, Giovanni Buttarelli, argued</a> that "significant improvements" were needed and that, as it stood, Privacy Shield was simply "not robust enough to withstand future legal scrutiny before the court". He also added that it was "time to develop a longer-term solution in the transatlantic dialogue".</p><p><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Max Schrems</a>, the Austrian legal activist that brought the case to the ECJ that would ultimately lead to Privacy Shield’s downfall, argued that Privacy Shield was hastily put together in order to fill the gap left by the previous framework and that those behind it.</p><p>"Sometimes I call it Safe Harbour 1.0.1 because basically most of the text is exactly the same, most of the structure is exactly the same," said Schrems, speaking at a data protection summit in London in June 2019, adding that he often referred to it instead as "lipstick on a pig".</p><p>Speaking on the speed at which it was negotiated, he said: "There was a deadline on January 31. What happened was that they failed to come to any kind of agreement. I was asking later and apparently, the Europeans stood off the table and said there was no way we're ever going to get it. 48 hours later and there was [suddenly] a deal. Another 24 hours later and we got this logo."</p><h3 class="article-body__section" id="section-what-will-replace-privacy-shield"><span>What will replace Privacy Shield?</span></h3><p>Now that Privacy Shield has been invalidated, businesses are, technically, no longer allowed to transfer data using the mechanism. Despite the disruption the judgement caused, there was no grace period announced that would allow businesses to continue using the mechanism until a replacement is devised. In the case of the invalidation of Safe Harbour, businesses were initially given a grace period of three months, although it would take six months before Privacy Shield was introduced. </p><p>Although Privacy Shield was struck down last year, a replacement still hasn't been established, and it's not clear how long a replacement to Privacy Shield might take. Given that Privacy Shield and Safe Harbour were invalidated for very similar reasons, however, it’s likely a more robust system will be demanded by advocates in the EU Commission. The European Data Protection Supervisor <a href="https://iapp.org/news/a/edps-says-privacy-shield-replacement-unlikely-for-a-while" target="_blank">indicated in December 2020 that a replacement would be unlikely 'for a while'</a>. To facilitate a new arrangement, the EU could ask the US to commit to far greater protections for EU resident data, or move towards greater regulatory alignment. Whatever the detail of the agreement, any friction between the two sides will almost certainly cause delay.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield</link>
                                                                            <description>
                            <![CDATA[ A look at the now invalidated framework US companies relied on to transfer data to and from the European Union ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vTqv7Zuec9Lmg5LddXjA78</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d94Jb4AAqmmhNckiXGvaYe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Sep 2019 13:30:00 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Jul 2021 14:30:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d94Jb4AAqmmhNckiXGvaYe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Privacy Shield security concept]]></media:description>                                                            <media:text><![CDATA[Privacy Shield security concept]]></media:text>
                                <media:title type="plain"><![CDATA[Privacy Shield security concept]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d94Jb4AAqmmhNckiXGvaYe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy Shield was a regulatory framework that governed the transfer of data between the European Union and the United States. Its principal purpose was to act as a mechanism for US companies to receive data from the EU, thereby ensuring smooth data transfers despite the fact that the two countries operated in separate data protection jurisdictions.</p><p>In effect, Privacy Shield fulfiled the same purpose as an adequacy agreement, required by any third status country that is outside of the regulatory reach of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">EU's General Data Protection Regulation (GDPR)</a>. Such an agreement signals that the EU recognises the data protection laws of the third country as being robust enough to protect the data of EU citizens, and therefore eligible to receive EU data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">Businesses worldwide brace for ECJ ruling on data transfers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31296/privacy-shield-should-be-suspended-say-meps" data-original-url="/data-protection/31296/privacy-shield-should-be-suspended-say-meps">Privacy Shield should be suspended, say MEPs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a></p></div></div><p>​Privacy Shield <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">was ruled invalid by the European Court of Justice</a> on 16 July 2020 as part of the <em>Facebook Ireland vs Max Schrems</em> case. The ECJ argued that the creation of Privacy Shield gave primacy to US surveillance laws, with its current form being unable to provide adequate protections for EU resident data. It was also ruled that the mechanism did not provide data subjects with an adequate point of redress or cause of action when issuing complaints.</p><h3 class="article-body__section" id="section-where-did-privacy-shield-come-from"><span>Where did Privacy Shield come from?</span></h3><p>The ‘International Safe Harbour Privacy Principles’, referred to commonly as Safe Harbour, were in force between 2000 and 2015, eventually being deemed insufficient following a challenge by Max Schrems. Privacy Shield, which suffered the same fate, replaced Safe Harbour, and once again tried to ease data flows between the US and the EU.</p><p>The history of both frameworks actually stretches back to the 1980s when the EU started to pursue policies to raise the level of data protection offered to citizens throughout its member states. To guarantee these protections were universal, the EU needed to ensure that citizens were safeguarded by the same protections not only in the EU but when their data was sent to other countries, such as the US.</p><p>The EU eventually signed the Data Protection Directive in 1995, which was the first set of meaningful data protection regulations, and the legislation that would eventually evolve into what we know as GDPR today. Although it covered a variety of issues, one of its main functions was to ensure companies sending data belonging to EU data subjects to non-EEA countries couldn’t process the data by weaker standards.</p><p>The EU’s appetite for raising the level of data protection for its citizens wasn’t matched by legislators in the US, especially considering how security agencies <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">such as the NSA</a> were known to operate. However, because it was vital to ensure that data continued to flow undisrupted between EU territories and the US, the two entities came together to build a specific architecture to ensure that businesses could seamlessly move data while data subjects would rest easy knowing their rights would continue to apply. This would replace the need for any mechanisms such as formal adequacy agreements, standard contractual clauses (SCCs) or binding corporate rules.</p><p>Developed between 1998 and 2000, the Safe Harbour Privacy Principles were initially designed to prevent organisations in the US and the EU from accidentally disclosing personal information by providing clear guidelines on how to collect and manage data. These principles incorporated some of the requirements set out by the Data Protection Directive, including the need for better security, relevant data collection, and the restrictions on third-country transfers, only these were voluntary for US companies. However, by July 2000, it was decided that any US company that was able to demonstrate its commitment to these Safe Harbor Principles would be permitted to send and receive data from the EU – known as the "Safe Harbor Decision".</p><p>US companies operated under the provisions of the Safe Harbor Decision for over 15 years but in October 2015, the European Court of Justice <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">ruled that the process of the Safe Harbour Decision was invalid</a>. The reason for this ruling was mainly because the act of giving public authorities access to EU individuals' data through the adherence of general principles was in direct conflict with <a href="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge" data-original-url="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge">the right to privacy</a> as enshrined in Article 8 of the European Convention on Human Rights (ECHR). In essence, the ECJ found that the Safe Harbour Principles were incompatible with EU data laws given that the framework lacked any operational oversight from US or EU agencies.</p><h3 class="article-body__section" id="section-enter-privacy-shield"><span>Enter Privacy Shield</span></h3><p>Privacy Shield, introduced in early 2016, was an attempt to rectify these issues, promising to enforce tougher obligations on US companies – namely the requirement to monitor and enforce data protections more robustly, and cooperate with European data protection authorities.</p><p>As with Safe Harbor, it was a voluntary mechanism that US companies could use to legally send and receive data from the EU. Those that agreed to process data under Privacy Shield were required to publicly advertise their compliance – a notice that said they were committed to providing higher standards of data protection and that they were liable to strict fines if found to be in breach of them.</p><p>As part of this compliance, organisations were required to give European users a means to opt out of having their data sold to third parties, as well as rigorously protect any data they do collect. EU data subjects were also protected from any misuse of data beyond its originally advertised processing purpose and had the right to access, correct, amend or delete any data that an organisation held on them, provided it was inaccurate or had been used in a way that breached Privacy Shield principles.</p><p>These protections only existed for EU citizens – US citizens were only protected by federal or state US laws.</p><h3 class="article-body__section" id="section-privacy-shield-fines-amp-sanctions"><span>Privacy Shield fines & sanctions</span></h3><p>The <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc" data-original-url="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">US Federal Trade Commission</a>, the agency overseeing Privacy Shield enforcement, had the power to bring fines against any company found to be in breach of Privacy Shield standards.</p><p>Any US organisation that failed to abide by their commitments to upholding Privacy Shield principles could face a number of different penalties. Firstly, the FTC could issue administrative or court orders to compel an organisation to fix any violations. Failure to abide by these orders could result in civil penalties of up to $40,000 for each violation, or $40,000 per day for ongoing violations.</p><p>Any organisation found to be in persistent violation of Privacy Shield standards would have its eligibility revoked, which prevented it from using the mechanism for data transfers. This includes any company that had been found to be in regular breach of the standards even if those breaches were unrelated. The Department of Commerce would then remove the company's name from the Privacy Shield List.</p><h3 class="article-body__section" id="section-what-did-privacy-shield-require-of-us-businesses"><span>What did Privacy Shield require of US businesses?</span></h3><p>Privacy Shield was voluntary for US businesses, however, it was strongly advised that organisations sign up to the laws, particularly if they planned to expand into Europe in the future.</p><p>Those that sign up were required to do the following:</p><ul><li>Present a detailed public facing statement showing its commitment to the Privacy Shield Principles and how it is ensuring its processes are compliant.</li><li>Ensure that mechanisms are in place to restrict data sharing with third parties where a user has opted-out. All third parties that receive such data must also publicly display their commitment to Privacy Shield.</li><li>Respond to all access and deletion requests from users, and provide a means for users to change their data, provided the request is feasible.</li><li>Ensure that all systems are maintained and are protected from unauthorised access.</li></ul><h3 class="article-body__section" id="section-criticisms-of-privacy-shield"><span>Criticisms of Privacy Shield</span></h3><p>Both Safe Harbour and Privacy Shield highlighted an ongoing clash between the US and the EU over data protection rights.</p><p>The European Union has worked to increase protections, and now operates one of the world's most robust data laws in the world. Data processing is heavily scrutinised under GDPR, with companies facing the prospect of <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">crippling fines for any loss of data</a>.</p><p>The US, meanwhile, has increased the surveillance powers of its intelligence agencies over the years, particularly following the introduction of the US Patriot Act in 2001. Intelligence agencies are able to use <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">programmes such as PRISM</a> to collect data from US internet companies, as well as the Foreign Intelligence Surveillance Act (FISA) to gather data on US citizens. Perhaps most importantly for EU authorities, the US has yet to work towards a centralised federal data protection regime, let alone one that begins to mirror GDPR. Aside from <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">states such as California</a>, there have been few attempts to expand data protection rights.</p><p>Privacy Shield was, therefore, an attempt at a compromise on the part of the EU to overcome this ongoing contradiction – a mechanism that allows US companies to prove they can operate under GDPR-like controls.</p><p>Not everyone agreed that the EU's good faith is reciprocated, however. Most notably, as part of the relationship, the US had the duty of appointing an ombudsperson to act as an additional point of redress for any EU citizens raising complaints against a company. This position sat vacant until June 2019, when Keith Krach was confirmed as the US' first permanent Privacy Shield Ombudsperson, leaving many to question whether the country was taking its role seriously enough.</p><p>Concerns had also been raised over the years about the framework's ability to protect EU data. In 2016, <a href="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough" data-original-url="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough">European data protection supervisor, Giovanni Buttarelli, argued</a> that "significant improvements" were needed and that, as it stood, Privacy Shield was simply "not robust enough to withstand future legal scrutiny before the court". He also added that it was "time to develop a longer-term solution in the transatlantic dialogue".</p><p><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Max Schrems</a>, the Austrian legal activist that brought the case to the ECJ that would ultimately lead to Privacy Shield’s downfall, argued that Privacy Shield was hastily put together in order to fill the gap left by the previous framework and that those behind it.</p><p>"Sometimes I call it Safe Harbour 1.0.1 because basically most of the text is exactly the same, most of the structure is exactly the same," said Schrems, speaking at a data protection summit in London in June 2019, adding that he often referred to it instead as "lipstick on a pig".</p><p>Speaking on the speed at which it was negotiated, he said: "There was a deadline on January 31. What happened was that they failed to come to any kind of agreement. I was asking later and apparently, the Europeans stood off the table and said there was no way we're ever going to get it. 48 hours later and there was [suddenly] a deal. Another 24 hours later and we got this logo."</p><h3 class="article-body__section" id="section-what-will-replace-privacy-shield"><span>What will replace Privacy Shield?</span></h3><p>Now that Privacy Shield has been invalidated, businesses are, technically, no longer allowed to transfer data using the mechanism. Despite the disruption the judgement caused, there was no grace period announced that would allow businesses to continue using the mechanism until a replacement is devised. In the case of the invalidation of Safe Harbour, businesses were initially given a grace period of three months, although it would take six months before Privacy Shield was introduced. </p><p>Although Privacy Shield was struck down last year, a replacement still hasn't been established, and it's not clear how long a replacement to Privacy Shield might take. Given that Privacy Shield and Safe Harbour were invalidated for very similar reasons, however, it’s likely a more robust system will be demanded by advocates in the EU Commission. The European Data Protection Supervisor <a href="https://iapp.org/news/a/edps-says-privacy-shield-replacement-unlikely-for-a-while" target="_blank">indicated in December 2020 that a replacement would be unlikely 'for a while'</a>. To facilitate a new arrangement, the EU could ask the US to commit to far greater protections for EU resident data, or move towards greater regulatory alignment. Whatever the detail of the agreement, any friction between the two sides will almost certainly cause delay.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU seeks Privacy Shield changes in its first annual review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The European Commission has given the green light to the EU-US Privacy Shield agreement following the deal's first annual review, but has urged improvements including a more aggressive approach to tackling non-compliance.</p><p>Today's report compiles the findings of a review conducted last month into the effectiveness of the year-old data-sharing agreement, which was designed to guarantee equivalent levels of privacy for EU citizens' personal data when it is transferred to the US, which has weaker privacy laws than the EU's forthcoming <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulation (GDPR)</a>.</p><p>However, the report found that improvements need to be made to ensure the deal functions effectively in the coming years, including a call for the US Department of Commerce to conduct more proactive and regular monitoring of companies' compliance, and to be more aggressive in the hunting of companies falsely claiming to be signed up to the agreement.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a> General Data Protection Regulation (GDPR)</p></div></div><p>It also recommended closer cooperation between the Department of Commerce, the Federal Trade Commission, and EU data protection authorities, which act as Privacy Shield's main compliance enforcers, including the joint development of official guidance for companies.</p><p>Commissioner Vra Jourov said in a press conference today: "Transatlantic data transfers are essential for our economy, but the fundamental right to data protection must be ensured also when personal data leaves the EU. Our first review shows that the Privacy Shield works well, but there is some room for improving its implementation.</p><p>"The Privacy Shield is not a document lying in a drawer," added Jourov. "It's a living arrangement that both the EU and US must actively monitor to ensure we keep guard over our high data protection standards."</p><p>Privacy Shield was first launched in August 2016 after the previous data sharing agreement, Safe Harbour, was struck down by the European Court of Justice in 2015. In light of the Edward Snowden revelations of widespread US surveillance, the previous agreement was deemed inadequate at protecting the data of EU citizens.</p><p>The new rules aim to enshrine legal rights for EU citizens in the event that their personal data is transferred to a US company, such as a US branch of a social media company collecting profile data, althoughJourov acknowledged that more needs to be done to raise awareness of the rights citizens are afforded.</p><p>Since its launch, more than 2,400 companies have been certified compliant under Privacy Shield obligations. New elements have also been added over the year, including new tools that allow for greater cooperation between law enforcement agencies on both sides of the Atlantic, as well as the creation of an online platform that is able to handle complaints from the EU.</p><p>Today's report has also called for Congress to enshrine the protections offered by former president Obama's Presidential Policy Directive 28 (PPD-28) into the Foreign Intelligence Surveillance Act (FISA), an act which forms the main legal basis for US authorities seeking to access personal data of non-US citizens.</p><p>These would limit the scope of FISA, including a clause that limits US surveillance of non-Americans by ensuring it is as tailored and targeted as feasibly possible.The EU is currently working with lobby groups to push this proposal through Congress, butJourovexplained a decision is unlikely to be addressed until the end of the year.</p><p>The report will be delivered to the European Parliament, the European Council, and the Article 29 Working Party - a collection of EU member states' data protection regulators. A copy will also be sent to authorities in the US, where the recommendations will be considered over the coming months.</p><p><em>Image: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/29748/eu-seeks-privacy-shield-changes-in-its-first-annual-review</link>
                                                                            <description>
                            <![CDATA[ Proposals include tougher rules around non-compliance and greater cooperation between US and EU authorities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fUG9CgsFZV31fjb58FtrHs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/etpe4UP8WgygBuSCGSeZ8W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Oct 2017 11:56:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/etpe4UP8WgygBuSCGSeZ8W-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/etpe4UP8WgygBuSCGSeZ8W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has given the green light to the EU-US Privacy Shield agreement following the deal's first annual review, but has urged improvements including a more aggressive approach to tackling non-compliance.</p><p>Today's report compiles the findings of a review conducted last month into the effectiveness of the year-old data-sharing agreement, which was designed to guarantee equivalent levels of privacy for EU citizens' personal data when it is transferred to the US, which has weaker privacy laws than the EU's forthcoming <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulation (GDPR)</a>.</p><p>However, the report found that improvements need to be made to ensure the deal functions effectively in the coming years, including a call for the US Department of Commerce to conduct more proactive and regular monitoring of companies' compliance, and to be more aggressive in the hunting of companies falsely claiming to be signed up to the agreement.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a> General Data Protection Regulation (GDPR)</p></div></div><p>It also recommended closer cooperation between the Department of Commerce, the Federal Trade Commission, and EU data protection authorities, which act as Privacy Shield's main compliance enforcers, including the joint development of official guidance for companies.</p><p>Commissioner Vra Jourov said in a press conference today: "Transatlantic data transfers are essential for our economy, but the fundamental right to data protection must be ensured also when personal data leaves the EU. Our first review shows that the Privacy Shield works well, but there is some room for improving its implementation.</p><p>"The Privacy Shield is not a document lying in a drawer," added Jourov. "It's a living arrangement that both the EU and US must actively monitor to ensure we keep guard over our high data protection standards."</p><p>Privacy Shield was first launched in August 2016 after the previous data sharing agreement, Safe Harbour, was struck down by the European Court of Justice in 2015. In light of the Edward Snowden revelations of widespread US surveillance, the previous agreement was deemed inadequate at protecting the data of EU citizens.</p><p>The new rules aim to enshrine legal rights for EU citizens in the event that their personal data is transferred to a US company, such as a US branch of a social media company collecting profile data, althoughJourov acknowledged that more needs to be done to raise awareness of the rights citizens are afforded.</p><p>Since its launch, more than 2,400 companies have been certified compliant under Privacy Shield obligations. New elements have also been added over the year, including new tools that allow for greater cooperation between law enforcement agencies on both sides of the Atlantic, as well as the creation of an online platform that is able to handle complaints from the EU.</p><p>Today's report has also called for Congress to enshrine the protections offered by former president Obama's Presidential Policy Directive 28 (PPD-28) into the Foreign Intelligence Surveillance Act (FISA), an act which forms the main legal basis for US authorities seeking to access personal data of non-US citizens.</p><p>These would limit the scope of FISA, including a clause that limits US surveillance of non-Americans by ensuring it is as tailored and targeted as feasibly possible.The EU is currently working with lobby groups to push this proposal through Congress, butJourovexplained a decision is unlikely to be addressed until the end of the year.</p><p>The report will be delivered to the European Parliament, the European Council, and the Article 29 Working Party - a collection of EU member states' data protection regulators. A copy will also be sent to authorities in the US, where the recommendations will be considered over the coming months.</p><p><em>Image: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Safe Harbour replaced with EU-US Privacy Shield ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The EU-US Privacy Shield, arranged to replace Safe Harbour, may come into effect from July, the EU and US have agreed.</p><p>The EU-US Privacy Shield has been tweaked slightly from its original specification to include a promise from the White House regarding the treatment of data.</p><p>It states that bulk collection of data sent from the EU to the US can only happen if conditions have been agreed prior to the transfer and it must be "as targeted and focused" as possible.</p><p>Other new clauses integrated into the agreement include that companies have to delete data that no longer serves the purpose for which it was originally collected. Additionally, the ombudsman that oversees the agreement will be independent from national security services to make it as fair and transparent as possible.</p><p>The US will create the ombudsman that deals with complaints from EU citizens about Americans misusing or spying on their data.</p><p>A spokesman for the European Commission said: "This new framework for transatlantic data flows protects the fundamental rights of Europeans and ensures legal certainty for businesses."</p><p>Other existing key points of the EU-US Privacy Shield include promises that the US Office of the Director of National Intelligence will give written commitment that data collected from EU citizens will not be used in mass surveillance exercises and an annual review will be performed by both the EU and US to ensure the system is running correctly.</p><p>However, now the UK has voted to leave the EU, this means the UK would need to independently negotiate a similar law in line with the EU's regulations that protects the data of businesses should they choose to trade with the UK and vice versa.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield</link>
                                                                            <description>
                            <![CDATA[ The new agreement may take effect from July if both parties agree on its directions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uvFfGDseXVBC6jtp7VCpd4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hEYxZFh9YMNmZg3bQy9YhU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jun 2016 07:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hEYxZFh9YMNmZg3bQy9YhU-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US Capitol Building]]></media:description>                                                            <media:text><![CDATA[US Capitol Building]]></media:text>
                                <media:title type="plain"><![CDATA[US Capitol Building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hEYxZFh9YMNmZg3bQy9YhU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU-US Privacy Shield, arranged to replace Safe Harbour, may come into effect from July, the EU and US have agreed.</p><p>The EU-US Privacy Shield has been tweaked slightly from its original specification to include a promise from the White House regarding the treatment of data.</p><p>It states that bulk collection of data sent from the EU to the US can only happen if conditions have been agreed prior to the transfer and it must be "as targeted and focused" as possible.</p><p>Other new clauses integrated into the agreement include that companies have to delete data that no longer serves the purpose for which it was originally collected. Additionally, the ombudsman that oversees the agreement will be independent from national security services to make it as fair and transparent as possible.</p><p>The US will create the ombudsman that deals with complaints from EU citizens about Americans misusing or spying on their data.</p><p>A spokesman for the European Commission said: "This new framework for transatlantic data flows protects the fundamental rights of Europeans and ensures legal certainty for businesses."</p><p>Other existing key points of the EU-US Privacy Shield include promises that the US Office of the Director of National Intelligence will give written commitment that data collected from EU citizens will not be used in mass surveillance exercises and an annual review will be performed by both the EU and US to ensure the system is running correctly.</p><p>However, now the UK has voted to leave the EU, this means the UK would need to independently negotiate a similar law in line with the EU's regulations that protects the data of businesses should they choose to trade with the UK and vice versa.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European data protection supervisor says Privacy Shield not robust enough ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The European data protection supervisor has published a report, saying Privacy Shield is not robust enough to withstand sharing of data across the world.</p><p>Giovanni Buttarelli said a number of changes need to be made in order for data to be shared reliably between countries without it putting that data or others' privacy at risk.</p><p>He said any solution used to replace Safe Harbour must provide "adequate" protection against surveillance by authorities and should be transparent, allowing</p><p>Any new legislation should also take into account data protection rights already considered by both governments and private companies in Europe. This is particularly important as the new General Data Protection Regulation (GDPR) is set to come into force in May 2018.</p><p>The European Commission needs to ensure that anything introduced to replace Safe Harbour adheres to guidelines set out in the new European legislation so there is no confusion between parties sharing data.</p><p>"I appreciate the efforts made to develop a solution to replace Safe Harbour but the Privacy Shield as it stands is not robust enough to withstand future legal scrutiny before the Court," Buttarelli said in a statement.</p><p>"Significant improvements are needed should the European Commission wish to adopt an adequacy decision, to respect the essence of key data protection principles with particular regard to necessity, proportionality and redress mechanisms. Moreover, it's time to develop a longer term solution in the transatlantic dialogue."</p><p><strong>13/04/2016: Europe data watchdogs find flaws in Privacy Shield</strong></p><p>Europe's data protection authorities have called for urgent amendments to <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield</a>, the proposed agreement to safeguard EU data transferred to the US.</p><p>The watchdogs, who form the Article 29 Working Party, do not believe the legislation is up to scratch, identifying several changes they believe need to be made.</p><p>The group is still concerned about US agencies undertaking mass surveillance on European citizens' data, after Privacy Shield's predecessor, Safe Harbour, being scrapped because it was not deemed to protect personal data adequately.</p><p>Privacy Shield would rely on assurances from the US government that it would not spy indiscriminately on EU data, but the Article 29 Working Party does not think these are enough.</p><p>It also called into question the impartiality of Privacy Shield's proposed ombudsperson, a US position that would be responsible for tackling EU citizens' complaints about misuse of their data.</p><p>The group's chairwoman, Isabelle Falque-Pierrotin, said (via the <a href="http://www.bbc.co.uk/news/technology-36036531"><em>BBC</em></a>): "We believe that we don't have enough security [or] guarantees in the status of the ombudsperson and in their effective powers to be sure that this is really an independent authority."</p><p>However, it called the document a "great step forward" compared to Safe Harbour, reported <a href="http://arstechnica.co.uk/tech-policy/2016/04/privacy-shield-us-surveillance-eu-article-29-working-party"><em>Ars Technica</em></a>.</p><p>While the Working Party's conclusion does not mean the European Commission cannot approve Privacy Shield, its findings could become the basis of future legal challenges if the Commission decides not to address them.</p><p>It comes after <a href="http://www.cloudpro.co.uk/leadership/cloud-essentials/5931/box-explores-alternatives-to-privacy-shield-to-transfer-eu-data-to">both Microsoft and Box endorsed Privacy Shield</a>, though Box admitted it does not plan to rely on it, exploring alternatives like binding corporate rules as ways to transfer EU data outside of the US securely. </p><p>The watchdogs' conclusions should be published online later today.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough</link>
                                                                            <description>
                            <![CDATA[ Giovanni Buttarelli said the European Commission needs to develop a longer-term solution for sharing data across continents ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7X3PZqYnmPjie64B1MuEUu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jun 2016 11:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European data protection supervisor has published a report, saying Privacy Shield is not robust enough to withstand sharing of data across the world.</p><p>Giovanni Buttarelli said a number of changes need to be made in order for data to be shared reliably between countries without it putting that data or others' privacy at risk.</p><p>He said any solution used to replace Safe Harbour must provide "adequate" protection against surveillance by authorities and should be transparent, allowing</p><p>Any new legislation should also take into account data protection rights already considered by both governments and private companies in Europe. This is particularly important as the new General Data Protection Regulation (GDPR) is set to come into force in May 2018.</p><p>The European Commission needs to ensure that anything introduced to replace Safe Harbour adheres to guidelines set out in the new European legislation so there is no confusion between parties sharing data.</p><p>"I appreciate the efforts made to develop a solution to replace Safe Harbour but the Privacy Shield as it stands is not robust enough to withstand future legal scrutiny before the Court," Buttarelli said in a statement.</p><p>"Significant improvements are needed should the European Commission wish to adopt an adequacy decision, to respect the essence of key data protection principles with particular regard to necessity, proportionality and redress mechanisms. Moreover, it's time to develop a longer term solution in the transatlantic dialogue."</p><p><strong>13/04/2016: Europe data watchdogs find flaws in Privacy Shield</strong></p><p>Europe's data protection authorities have called for urgent amendments to <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield</a>, the proposed agreement to safeguard EU data transferred to the US.</p><p>The watchdogs, who form the Article 29 Working Party, do not believe the legislation is up to scratch, identifying several changes they believe need to be made.</p><p>The group is still concerned about US agencies undertaking mass surveillance on European citizens' data, after Privacy Shield's predecessor, Safe Harbour, being scrapped because it was not deemed to protect personal data adequately.</p><p>Privacy Shield would rely on assurances from the US government that it would not spy indiscriminately on EU data, but the Article 29 Working Party does not think these are enough.</p><p>It also called into question the impartiality of Privacy Shield's proposed ombudsperson, a US position that would be responsible for tackling EU citizens' complaints about misuse of their data.</p><p>The group's chairwoman, Isabelle Falque-Pierrotin, said (via the <a href="http://www.bbc.co.uk/news/technology-36036531"><em>BBC</em></a>): "We believe that we don't have enough security [or] guarantees in the status of the ombudsperson and in their effective powers to be sure that this is really an independent authority."</p><p>However, it called the document a "great step forward" compared to Safe Harbour, reported <a href="http://arstechnica.co.uk/tech-policy/2016/04/privacy-shield-us-surveillance-eu-article-29-working-party"><em>Ars Technica</em></a>.</p><p>While the Working Party's conclusion does not mean the European Commission cannot approve Privacy Shield, its findings could become the basis of future legal challenges if the Commission decides not to address them.</p><p>It comes after <a href="http://www.cloudpro.co.uk/leadership/cloud-essentials/5931/box-explores-alternatives-to-privacy-shield-to-transfer-eu-data-to">both Microsoft and Box endorsed Privacy Shield</a>, though Box admitted it does not plan to rely on it, exploring alternatives like binding corporate rules as ways to transfer EU data outside of the US securely. </p><p>The watchdogs' conclusions should be published online later today.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Has the US forced Reddit to secretly hand over user data? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Reddit users may no longer be safe from government spying.</p><p>The message forum site has removed a "warrant canary" from its latest transparency report, suggesting it has now received at least one classified request for user data.</p><p>National security letters and Foreign Intelligence Surveillance Act requests come to companies in secret requests for users' information, and the nature of these requests is such that companies are forbidden from even saying they have received them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7FeJLaUZ4CD9ZFfwgTaREo" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo.png" mos="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The "warrant canary"</em></p><p>Reddit got around that last year by including a "warrant canary" for its <a href="https://www.reddit.com/wiki/transparency/2014" target="_blank">Transparency Report 2014</a>, that read: "As of January 29, 2015, reddit has never received a National Security Letter, an order under the Foreign Intelligence Surveillance Act, or any other classified request for user information. If we ever receive such a request, we would seek to let the public know it existed."</p><p>The idea works as a tacit admission, if the statement ever disappeared from future reports, that Reddit had received such a request.</p><p>After releasing its <a href="https://www.reddit.com/wiki/transparency/2015" target="_blank">Transparency Report 2015</a> yesterday, one user spotted that the statement was no longer included.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tY8Wunw3QX6qFfd656nD93" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93.png" mos="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This led Reddit admin Spez <a href="https://www.reddit.com/r/announcements/comments/4cqyia/for_your_reading_pleasure_our_2015_transparency" target="_blank">to say</a>: "Even with the canaries, we're treading a fine line. The whole thing is icky, which is why we joined Twitter in pushing back."</p><p>Twitter is suing the US Department of Justice for a violation of free speech in an ongoing court case, after the department prevented the tech giant from revealing how many secret requests for user data it receives.</p><p>Reddit's apparent admission comes after <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">data protection campaigner Max Schrems sued Facebook</a> over allegedly transferring EU citizens' data to the NSA, something Facebook denied.</p><p>The court case eventually led to the European Court of Justice scrapping the Safe Harbour agreement in October 2015, saying it could not be relied upon to protect EU data transferred to the US. </p><p>A replacement agreement <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">dubbed Privacy Shield</a> is currently being considered by various parts of the EU.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26285/has-the-us-forced-reddit-to-secretly-hand-over-user-data</link>
                                                                            <description>
                            <![CDATA[ Disappearance of "warrant canary" seen as tacit admission of government data request ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rwMajcECkXVPVScd8ghEER</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6rkyQLvPU7LqhydJ5wUSfF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Apr 2016 13:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6rkyQLvPU7LqhydJ5wUSfF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6rkyQLvPU7LqhydJ5wUSfF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Reddit users may no longer be safe from government spying.</p><p>The message forum site has removed a "warrant canary" from its latest transparency report, suggesting it has now received at least one classified request for user data.</p><p>National security letters and Foreign Intelligence Surveillance Act requests come to companies in secret requests for users' information, and the nature of these requests is such that companies are forbidden from even saying they have received them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7FeJLaUZ4CD9ZFfwgTaREo" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo.png" mos="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The "warrant canary"</em></p><p>Reddit got around that last year by including a "warrant canary" for its <a href="https://www.reddit.com/wiki/transparency/2014" target="_blank">Transparency Report 2014</a>, that read: "As of January 29, 2015, reddit has never received a National Security Letter, an order under the Foreign Intelligence Surveillance Act, or any other classified request for user information. If we ever receive such a request, we would seek to let the public know it existed."</p><p>The idea works as a tacit admission, if the statement ever disappeared from future reports, that Reddit had received such a request.</p><p>After releasing its <a href="https://www.reddit.com/wiki/transparency/2015" target="_blank">Transparency Report 2015</a> yesterday, one user spotted that the statement was no longer included.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tY8Wunw3QX6qFfd656nD93" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93.png" mos="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This led Reddit admin Spez <a href="https://www.reddit.com/r/announcements/comments/4cqyia/for_your_reading_pleasure_our_2015_transparency" target="_blank">to say</a>: "Even with the canaries, we're treading a fine line. The whole thing is icky, which is why we joined Twitter in pushing back."</p><p>Twitter is suing the US Department of Justice for a violation of free speech in an ongoing court case, after the department prevented the tech giant from revealing how many secret requests for user data it receives.</p><p>Reddit's apparent admission comes after <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">data protection campaigner Max Schrems sued Facebook</a> over allegedly transferring EU citizens' data to the NSA, something Facebook denied.</p><p>The court case eventually led to the European Court of Justice scrapping the Safe Harbour agreement in October 2015, saying it could not be relied upon to protect EU data transferred to the US. </p><p>A replacement agreement <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">dubbed Privacy Shield</a> is currently being considered by various parts of the EU.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Would a Brexit weaken data privacy in the UK? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>This week politicians blew lots of political FUD out of their collective nether regions around the EU 'Brexit' debate, but failed to consider how a stay' or leave' decision would affect data privacy.</p><p>All the wafty hot air from Iain Duncan Smith about staying in the EU making us more vulnerable to a Paris-style terror attack is, frankly, just that. I'd have been more impressed if he had taken the time out to examine how our EU status might impact data protection.</p><p>When industry trade body techUK asked its members <a href="https://www.techuk.org/member-eu-survey/eu_membership_survey" target="_blank">if they wanted in or out of the EU</a> last year, 71 per cent were in the stay camp, if the UK's agreement with the EU was reformed.</p><p>A total 78 per cent insisted that a UK outside the EU would have less influence on tech industry issues.</p><p>These issues include data protection, specifically <a href="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations" target="_blank" data-original-url="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations">the EU's General Data Protection Regulations (GDPR)</a>, which are set to come into force between now and 2018.</p><p>Only a complete fool would argue that leaving the EU would mean these rules no longer apply to us.</p><p>But what worries me is that if we do vote to leave the EU, then the UK will have to come up with a variant of <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">the new Privacy Shield data-transfer agreement</a> that replaced the defunct Safe Harbour deal, which ostensibly stopped the US spying on EU data.</p><p>I was no fan of the so-called Safe Harbour agreement. It was evident from the get-go that the USA was more interested in data snooping under the national security banner than any meaningful measure of privacy. What's more, it was also evident that the EU and the UK knew that and turned a blind eye to it.</p><p>Nothing will change under the Privacy Shield agreement, which requires the US to promise not to participate 'on its mum's life' in mass surveillance of EU citizens. Yeah right. I've called that <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">laudable in principle and laughable in practice</a>.</p><p>If I'm so against this, then surely I should support a Brexit in order to escape such regulation? Well, no, because the alternative is likely to be much worse.</p><p>Look at what Prime Minister David Cameron and Home Secretary Theresa May's Investigator Powers Bill. Earlier this month <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products"><em>IT Pro</em> reported</a> how this "risks destroying UK technology firms' reputations on cybersecurity and privacy, according to experts, civil liberties campaigners and industry trade bodies". This directly opposes the GDPR, which are designed to give citizens more control over who can see and access their data.</p><p>If we do leave the EU, we would have to obey the GDPR anyway if we want to continue doing trade with the rest of Europe, as well as demonstrate an adequate level of data protection.</p><p>But, depending on the nature of the government at the time, I suspect there will come a point where the 'all your data belongs to us' mentality that underpins the Investigatory Powers Bill shines through and trumps meaningful GDPR implementation.</p><p>That will leave the EU having to decide how it deals with a UK that resists GDPR when dealing with EU citizen data, and UK PLC suffering the consequences of the almost inevitable trading fallout.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/26119/would-a-brexit-weaken-data-privacy-in-the-uk</link>
                                                                            <description>
                            <![CDATA[ Data privacy should be a central issue in debate of EU referendum pros and cons ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ5Hn9oAdYKCn3M23QzWEj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Feb 2016 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This week politicians blew lots of political FUD out of their collective nether regions around the EU 'Brexit' debate, but failed to consider how a stay' or leave' decision would affect data privacy.</p><p>All the wafty hot air from Iain Duncan Smith about staying in the EU making us more vulnerable to a Paris-style terror attack is, frankly, just that. I'd have been more impressed if he had taken the time out to examine how our EU status might impact data protection.</p><p>When industry trade body techUK asked its members <a href="https://www.techuk.org/member-eu-survey/eu_membership_survey" target="_blank">if they wanted in or out of the EU</a> last year, 71 per cent were in the stay camp, if the UK's agreement with the EU was reformed.</p><p>A total 78 per cent insisted that a UK outside the EU would have less influence on tech industry issues.</p><p>These issues include data protection, specifically <a href="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations" target="_blank" data-original-url="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations">the EU's General Data Protection Regulations (GDPR)</a>, which are set to come into force between now and 2018.</p><p>Only a complete fool would argue that leaving the EU would mean these rules no longer apply to us.</p><p>But what worries me is that if we do vote to leave the EU, then the UK will have to come up with a variant of <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">the new Privacy Shield data-transfer agreement</a> that replaced the defunct Safe Harbour deal, which ostensibly stopped the US spying on EU data.</p><p>I was no fan of the so-called Safe Harbour agreement. It was evident from the get-go that the USA was more interested in data snooping under the national security banner than any meaningful measure of privacy. What's more, it was also evident that the EU and the UK knew that and turned a blind eye to it.</p><p>Nothing will change under the Privacy Shield agreement, which requires the US to promise not to participate 'on its mum's life' in mass surveillance of EU citizens. Yeah right. I've called that <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">laudable in principle and laughable in practice</a>.</p><p>If I'm so against this, then surely I should support a Brexit in order to escape such regulation? Well, no, because the alternative is likely to be much worse.</p><p>Look at what Prime Minister David Cameron and Home Secretary Theresa May's Investigator Powers Bill. Earlier this month <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products"><em>IT Pro</em> reported</a> how this "risks destroying UK technology firms' reputations on cybersecurity and privacy, according to experts, civil liberties campaigners and industry trade bodies". This directly opposes the GDPR, which are designed to give citizens more control over who can see and access their data.</p><p>If we do leave the EU, we would have to obey the GDPR anyway if we want to continue doing trade with the rest of Europe, as well as demonstrate an adequate level of data protection.</p><p>But, depending on the nature of the government at the time, I suspect there will come a point where the 'all your data belongs to us' mentality that underpins the Investigatory Powers Bill shines through and trumps meaningful GDPR implementation.</p><p>That will leave the EU having to decide how it deals with a UK that resists GDPR when dealing with EU citizen data, and UK PLC suffering the consequences of the almost inevitable trading fallout.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy Shield hammers another nail in the coffin of data protection ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Safe Harbour is dead, long live the Privacy Shield. Although, to be honest, <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">the all-new US data transfer agreement</a> is already a dead man walking if you ask me. Indeed, a better name for it would be the Privacy Coffin.</p><p>Why the hostility? Consider this: <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">the European Court of Justice (ECJ) killed Safe Harbour in October</a> when it ruled that, essentially, the US was more interested in national security and law enforcement matters (also known as snooping the bejesus out of everyone) over and above any guarantees of meaningful privacy.</p><p>Since then, absolutely nothing has changed.</p><p>The Privacy Shield framework requires the US to give a written promise, on a yearly basis, that hand-on-heart it won't participate in mass surveillance of EU citizens.</p><p>This is laudable in principle and laughable in practice.</p><p>Any talk of 'clear limitations and safeguards', and most of all 'oversight mechanisms', in the context of the NSA is, frankly, a crock. Not least because the US explicitly allows mass surveillance of the very kind it's promising not to carry out.</p><p>The NSA doesn't consider it mass surveillance if they collect the data, only if they analyse it. But calling it something different does not mean it's not happening. </p><p>Seriously, replacing one fundamentally flawed framework with another and giving it a new X-Men movie name does not fix the problem. That problem being that neither the EU, UK nor the US actually gives a flying feck about your privacy.</p><p>At best, this optimistically-named Privacy Shield is nothing more than a stop-gap solution. It will enable the transatlantic data flow to, erm, flow once more. But not for long. I imagine the ECJ will take a long, hard look at the agreement and announce it, too, as invalid.</p><p>What really worries me, and should worry you as well, if this is a stop-gap, a temporary measure to ensure that data keeps flowing; is what comes next? </p><p>If, as I suspect, it will be more of the same political manoeuvring rather than something that really addresses the matter of data privacy in the post-Snowden era, then we are all screwed. Or, more accurately, we will continue to be screwed.</p><p>As long as we continue to take government agencies on both sides of the pond at their word when it comes to what they can and cannot spy upon, then nothing will change.</p><p>My advice, therefore, remains the same as it has always been: encrypt your data up the wazoo and manage your own keys to close the snooping opportunity window.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection</link>
                                                                            <description>
                            <![CDATA[ Safe Harbour’s replacement is based entirely on trust - what a big mistake ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c8pr9DZBprbDK9UCtmferk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MG97BpWbwHcRm9oGh8g4b4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Feb 2016 15:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MG97BpWbwHcRm9oGh8g4b4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MG97BpWbwHcRm9oGh8g4b4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Safe Harbour is dead, long live the Privacy Shield. Although, to be honest, <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">the all-new US data transfer agreement</a> is already a dead man walking if you ask me. Indeed, a better name for it would be the Privacy Coffin.</p><p>Why the hostility? Consider this: <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">the European Court of Justice (ECJ) killed Safe Harbour in October</a> when it ruled that, essentially, the US was more interested in national security and law enforcement matters (also known as snooping the bejesus out of everyone) over and above any guarantees of meaningful privacy.</p><p>Since then, absolutely nothing has changed.</p><p>The Privacy Shield framework requires the US to give a written promise, on a yearly basis, that hand-on-heart it won't participate in mass surveillance of EU citizens.</p><p>This is laudable in principle and laughable in practice.</p><p>Any talk of 'clear limitations and safeguards', and most of all 'oversight mechanisms', in the context of the NSA is, frankly, a crock. Not least because the US explicitly allows mass surveillance of the very kind it's promising not to carry out.</p><p>The NSA doesn't consider it mass surveillance if they collect the data, only if they analyse it. But calling it something different does not mean it's not happening. </p><p>Seriously, replacing one fundamentally flawed framework with another and giving it a new X-Men movie name does not fix the problem. That problem being that neither the EU, UK nor the US actually gives a flying feck about your privacy.</p><p>At best, this optimistically-named Privacy Shield is nothing more than a stop-gap solution. It will enable the transatlantic data flow to, erm, flow once more. But not for long. I imagine the ECJ will take a long, hard look at the agreement and announce it, too, as invalid.</p><p>What really worries me, and should worry you as well, if this is a stop-gap, a temporary measure to ensure that data keeps flowing; is what comes next? </p><p>If, as I suspect, it will be more of the same political manoeuvring rather than something that really addresses the matter of data privacy in the post-Snowden era, then we are all screwed. Or, more accurately, we will continue to be screwed.</p><p>As long as we continue to take government agencies on both sides of the pond at their word when it comes to what they can and cannot spy upon, then nothing will change.</p><p>My advice, therefore, remains the same as it has always been: encrypt your data up the wazoo and manage your own keys to close the snooping opportunity window.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU throws US data transfers into doubt – again ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Companies that transfer European data to the US may be open to legal challenges after the EU refused to extend a grace period in the absence of any agreement guaranteeing that data's safety.</p><p>EU and US officials this week touted <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">Privacy Shield</a> as a successor to the now-defunct Safe Harbour deal, which had guaranteed adequate protection for European data transferred abroad.</p><p>But with months to go until Privacy Shield is officially approved, EU data regulators yesterday declined to extend a policy of no active enforcement against companies continuing to transfer data to the US without the protection of any valid deal.</p><p>Around 4,000 companies relied on the Safe Harbour agreement, and those who have not moved to an alternative data transfer mechanism are now at risk of enforcement actions.</p><p>Vinod Bange, head of UK data protection and privacy practice at law firm Taylor Wessing, told <em>IT Pro</em>: "UK PLC deserves better than this, Europe deserves better than this."</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid last October</a>, when the European Court of Justice decided that America valued anti-terrorist measures such as data surveillance above people's privacy.</p><p>While Europe and the US renegotiated the agreement, the EU announced a three-month grace period in which companies could carry on moving data to the US.</p><p>Some opted to use methods like model contract clauses and binding corporate rules, but others still worked under the umbrella of the invalid Safe Harbour agreement.</p><p>The Article 29 Working Party, a group of EU data protection regulators, <a href="http://united-kingdom.taylorwessing.com/en/article-29-working-party-cautious-about-eu-us-privacy-shield" target="_blank">said</a> those companies yet to adopt an alternative transfer mechanism could now be punished for transferring data to the US.</p><p>Head of the group, Isabelle Falque-Pierrotin, said in a press conference, quoted by <a href="http://www.out-law.com/en/articles/2016/february/deal-on-eu-us-privacy-shield-leads-eu-watchdogs-to-extend-moratorium-on-data-transfers-enforcement-action" target="_blank"><em>Out-Law.com</em></a>: "If companies are using the former Safe Harbour framework, it is illegal because this has clearly been invalidated by the judges."</p><p>Member states' own data watchdogs could now decide whether or not to take action against companies if they receive complaints.</p><p>But Bange said: "What happens to all those companies that were covered by Safe Harbour and have been left stranded in this abyss, and those who haven't found the right mechanism yet?</p><p>"There won't be an extended grace period. She said it would be up to individual states' regulators on how to respond to complaints."</p><p>While the Working Party claims many companies have shifted to using alternative data transfer methods, Bange said many have yet to migrate to a different mechanism, calling some of them unsuitable.</p><p>"Many are still grappling with this fundamental issue - how do they resolve their situation without using model clauses that were drafted a long time ago without considering the cloud scenario we are in now?" the lawyer said.</p><p>Whether they are suitable or not, the Working Party said these transfer mechanisms will remain valid until it has completed its assessment of Privacy Shield - likely by the middle of April.</p><p>It has asked the European Commission to provide all relevant Privacy Shield documents by the end of February.</p><p><a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield aims to offer stronger data protection to EU citizens</a>, with the US providing written assurances it will not undertake mass surveillance of European data.</p><p>It also plans to set up an Ombudsperson to investigate accusations of spying, and force companies to respond to data complaints by certain deadlines.</p><p>The agreement drew a mixed reaction from businesses and privacy campaigners, with the latter group saying the agreement is not backed up by US law, which does allow mass surveillance.</p><p>Jim Killock, executive director of Open Rights Group said: "The rights we have under data protection, such as the right to obtain and correct our personal data, need to be legally enforceable in the USA, for every EU citizen. There seems to be great reluctance to introduce these rights in full in the USA for Europeans.</p><p>"The EU Commission is making matters worse by failing to communicate how serious the EU Court of Justice's demands are. Unless both the EU and USA face up to the need to protect our individual data protection rights, it will end up back in court.</p><p>"That will be no good for citizens or industry."</p><p>UK cloud firm Skyhigh Networks welcomed the agreement, however.</p><p>Kamal Shah, senior VP of products, said: "We are thrilled with the news from Brussels. The data flows between the USA and EU are so important to global business that it could have been a disaster if the previous confused situation was extended. Here's hoping that the full text is acceptable to all sides and businesses can transfer data across the Atlantic without fear of legal challenge."</p><p>The EU is now drafting an "adequacy decision" for the coming weeks, which the European Commission could adopt after receiving the Working Party's advice, and after consulting all member states.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/25986/eu-throws-us-data-transfers-into-doubt-again</link>
                                                                            <description>
                            <![CDATA[ Europe’s data watchdog refuses to extend Safe Harbour grace period ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">scjeZvFXkXA8iwuwXBWzLD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Feb 2016 10:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies that transfer European data to the US may be open to legal challenges after the EU refused to extend a grace period in the absence of any agreement guaranteeing that data's safety.</p><p>EU and US officials this week touted <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">Privacy Shield</a> as a successor to the now-defunct Safe Harbour deal, which had guaranteed adequate protection for European data transferred abroad.</p><p>But with months to go until Privacy Shield is officially approved, EU data regulators yesterday declined to extend a policy of no active enforcement against companies continuing to transfer data to the US without the protection of any valid deal.</p><p>Around 4,000 companies relied on the Safe Harbour agreement, and those who have not moved to an alternative data transfer mechanism are now at risk of enforcement actions.</p><p>Vinod Bange, head of UK data protection and privacy practice at law firm Taylor Wessing, told <em>IT Pro</em>: "UK PLC deserves better than this, Europe deserves better than this."</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid last October</a>, when the European Court of Justice decided that America valued anti-terrorist measures such as data surveillance above people's privacy.</p><p>While Europe and the US renegotiated the agreement, the EU announced a three-month grace period in which companies could carry on moving data to the US.</p><p>Some opted to use methods like model contract clauses and binding corporate rules, but others still worked under the umbrella of the invalid Safe Harbour agreement.</p><p>The Article 29 Working Party, a group of EU data protection regulators, <a href="http://united-kingdom.taylorwessing.com/en/article-29-working-party-cautious-about-eu-us-privacy-shield" target="_blank">said</a> those companies yet to adopt an alternative transfer mechanism could now be punished for transferring data to the US.</p><p>Head of the group, Isabelle Falque-Pierrotin, said in a press conference, quoted by <a href="http://www.out-law.com/en/articles/2016/february/deal-on-eu-us-privacy-shield-leads-eu-watchdogs-to-extend-moratorium-on-data-transfers-enforcement-action" target="_blank"><em>Out-Law.com</em></a>: "If companies are using the former Safe Harbour framework, it is illegal because this has clearly been invalidated by the judges."</p><p>Member states' own data watchdogs could now decide whether or not to take action against companies if they receive complaints.</p><p>But Bange said: "What happens to all those companies that were covered by Safe Harbour and have been left stranded in this abyss, and those who haven't found the right mechanism yet?</p><p>"There won't be an extended grace period. She said it would be up to individual states' regulators on how to respond to complaints."</p><p>While the Working Party claims many companies have shifted to using alternative data transfer methods, Bange said many have yet to migrate to a different mechanism, calling some of them unsuitable.</p><p>"Many are still grappling with this fundamental issue - how do they resolve their situation without using model clauses that were drafted a long time ago without considering the cloud scenario we are in now?" the lawyer said.</p><p>Whether they are suitable or not, the Working Party said these transfer mechanisms will remain valid until it has completed its assessment of Privacy Shield - likely by the middle of April.</p><p>It has asked the European Commission to provide all relevant Privacy Shield documents by the end of February.</p><p><a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield aims to offer stronger data protection to EU citizens</a>, with the US providing written assurances it will not undertake mass surveillance of European data.</p><p>It also plans to set up an Ombudsperson to investigate accusations of spying, and force companies to respond to data complaints by certain deadlines.</p><p>The agreement drew a mixed reaction from businesses and privacy campaigners, with the latter group saying the agreement is not backed up by US law, which does allow mass surveillance.</p><p>Jim Killock, executive director of Open Rights Group said: "The rights we have under data protection, such as the right to obtain and correct our personal data, need to be legally enforceable in the USA, for every EU citizen. There seems to be great reluctance to introduce these rights in full in the USA for Europeans.</p><p>"The EU Commission is making matters worse by failing to communicate how serious the EU Court of Justice's demands are. Unless both the EU and USA face up to the need to protect our individual data protection rights, it will end up back in court.</p><p>"That will be no good for citizens or industry."</p><p>UK cloud firm Skyhigh Networks welcomed the agreement, however.</p><p>Kamal Shah, senior VP of products, said: "We are thrilled with the news from Brussels. The data flows between the USA and EU are so important to global business that it could have been a disaster if the previous confused situation was extended. Here's hoping that the full text is acceptable to all sides and businesses can transfer data across the Atlantic without fear of legal challenge."</p><p>The EU is now drafting an "adequacy decision" for the coming weeks, which the European Commission could adopt after receiving the Working Party's advice, and after consulting all member states.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Will the new Safe Harbour deal really protect your data? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The EU and US have reached a last-minute deal to ensure companies can transfer European data to American soil.</p><p>The new agreement provides guarantees that personal data from the EU will receive adequate protection when processed by US firms, and replaces a defunct deal that around 4,000 businesses relied on.</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid</a> by the EU last October when it decided the US valued national security and law enforcement over the guarantee of privacy.</p><p>Its replacement, <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">the EU-US Privacy Shield</a>, was hailed by the EU as a way of resolving the issue.</p><p>European Commission vice president Andrus Ansip said: "We have agreed with our US partners a new framework that will ensure the right checks and balances for our citizens.</p><p>"We have for the first time received detailed written assurances from the US on the safeguards and limitations applicable to US surveillance programmes."</p><p>In some ways it is stronger than Safe Harbour though. Where the former agreement did not check companies were meeting their obligations to protect data, the new deal forces companies to publish their commitments, making them enforceable under US law.</p><p>The US has also given the EU written assurances that it will not carry out "indiscriminate mass surveillance" on data transferred under the scheme.</p><p>Companies will have deadlines by which they must respond to complaints from people who feel their data has been misused, while data watchdogs can refer those complaints to US authorities.</p><p>Furthermore, any accusations of spies accessing people's data will be investigated by a new Ombudsperson.</p><p>However, the new agreement has been met with mixed reaction from businesses and data protection campaigners.</p><p>TechUK, an industry trade body representing more than 800 companies, welcomed Privacy Shield.</p><p>Deputy CEO Anthony Walker said: "Today's announcement of a new deal for EU - US data transfers is extremely important. The European Commission and US Administration must now show total commitment to implementing this and getting transatlantic data flows back onto a secure and stable legal footing.</p><p>"Businesses large and small across Europe need reliable and affordable legal mechanisms to enable the data transfers that underpin their operations and ability to serve customers."</p><p>The Information Technology and Innovation Foundation (ITIF), also welcomed the agreement, and criticised the decision to revoke Safe Harbour.</p><p>Vice president Daniel Castro said: "We commend US and European negotiators for completing an agreement that avoids disrupting the transatlantic digital economy in the near term by ensuring continuity for the thousands of US and European companies providing services across the two markets."</p><p>But others are more sceptical, with one lawyer claiming Privacy Shield's reputation is already "shot to pieces".</p><p>Phil Lee, data protection partner at European law firm Fieldfisher, said: "Keeping in mind that this new Safe Harbour will almost certainly be challenged by civil liberties groups (and possibly even some data protection authorities) pretty much immediately, only the foolhardy would place want to place their trust in a new Safe Harbour right now. Whether legal or not, its reputation is already shot to pieces."</p><p>Privacy campaigner Max Schrems, <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">whose lawsuit against Facebook</a> led to the original Safe Harbour being ruled invalid, also spoke out against the new agreement.</p><p>He claimed that despite the US' written assurances of not spying on EU data, there have thus far been no changes to its legal system to reflect this.</p><p>"A couple of letters by the outgoing Obama administration is by no means a legal basis to guarantee the fundamental rights of 500 million European users in the long run, when there is explicit US law allowing mass surveillance," <a href="http://europe-v-facebook.org/PS_update.pdf" target="_blank">he wrote</a>.</p><p>"I doubt that a European can walk to a US court and claim his fundamental rights based on a letter by someone. The Commission could to be en route to issuing a round-trip to the European Court in Luxembourg and back. This would also not provide any legal certainty for businesses - at the most it would provide a couple more months to adapt."</p><p>He ended his evaluation by warning that people will challenge the new agreement, adding that he may be among them.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data</link>
                                                                            <description>
                            <![CDATA[ Businesses and campaigners react to Privacy Shield, the new EU-US data transfer agreement ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jW8GRc32LkeDd4spmZRRur</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fS272S763cqVUYJ89d39RQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Feb 2016 18:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fS272S763cqVUYJ89d39RQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flag]]></media:description>                                                            <media:text><![CDATA[EU flag]]></media:text>
                                <media:title type="plain"><![CDATA[EU flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fS272S763cqVUYJ89d39RQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU and US have reached a last-minute deal to ensure companies can transfer European data to American soil.</p><p>The new agreement provides guarantees that personal data from the EU will receive adequate protection when processed by US firms, and replaces a defunct deal that around 4,000 businesses relied on.</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid</a> by the EU last October when it decided the US valued national security and law enforcement over the guarantee of privacy.</p><p>Its replacement, <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">the EU-US Privacy Shield</a>, was hailed by the EU as a way of resolving the issue.</p><p>European Commission vice president Andrus Ansip said: "We have agreed with our US partners a new framework that will ensure the right checks and balances for our citizens.</p><p>"We have for the first time received detailed written assurances from the US on the safeguards and limitations applicable to US surveillance programmes."</p><p>In some ways it is stronger than Safe Harbour though. Where the former agreement did not check companies were meeting their obligations to protect data, the new deal forces companies to publish their commitments, making them enforceable under US law.</p><p>The US has also given the EU written assurances that it will not carry out "indiscriminate mass surveillance" on data transferred under the scheme.</p><p>Companies will have deadlines by which they must respond to complaints from people who feel their data has been misused, while data watchdogs can refer those complaints to US authorities.</p><p>Furthermore, any accusations of spies accessing people's data will be investigated by a new Ombudsperson.</p><p>However, the new agreement has been met with mixed reaction from businesses and data protection campaigners.</p><p>TechUK, an industry trade body representing more than 800 companies, welcomed Privacy Shield.</p><p>Deputy CEO Anthony Walker said: "Today's announcement of a new deal for EU - US data transfers is extremely important. The European Commission and US Administration must now show total commitment to implementing this and getting transatlantic data flows back onto a secure and stable legal footing.</p><p>"Businesses large and small across Europe need reliable and affordable legal mechanisms to enable the data transfers that underpin their operations and ability to serve customers."</p><p>The Information Technology and Innovation Foundation (ITIF), also welcomed the agreement, and criticised the decision to revoke Safe Harbour.</p><p>Vice president Daniel Castro said: "We commend US and European negotiators for completing an agreement that avoids disrupting the transatlantic digital economy in the near term by ensuring continuity for the thousands of US and European companies providing services across the two markets."</p><p>But others are more sceptical, with one lawyer claiming Privacy Shield's reputation is already "shot to pieces".</p><p>Phil Lee, data protection partner at European law firm Fieldfisher, said: "Keeping in mind that this new Safe Harbour will almost certainly be challenged by civil liberties groups (and possibly even some data protection authorities) pretty much immediately, only the foolhardy would place want to place their trust in a new Safe Harbour right now. Whether legal or not, its reputation is already shot to pieces."</p><p>Privacy campaigner Max Schrems, <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">whose lawsuit against Facebook</a> led to the original Safe Harbour being ruled invalid, also spoke out against the new agreement.</p><p>He claimed that despite the US' written assurances of not spying on EU data, there have thus far been no changes to its legal system to reflect this.</p><p>"A couple of letters by the outgoing Obama administration is by no means a legal basis to guarantee the fundamental rights of 500 million European users in the long run, when there is explicit US law allowing mass surveillance," <a href="http://europe-v-facebook.org/PS_update.pdf" target="_blank">he wrote</a>.</p><p>"I doubt that a European can walk to a US court and claim his fundamental rights based on a letter by someone. The Commission could to be en route to issuing a round-trip to the European Court in Luxembourg and back. This would also not provide any legal certainty for businesses - at the most it would provide a couple more months to adapt."</p><p>He ended his evaluation by warning that people will challenge the new agreement, adding that he may be among them.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>