<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/safe-harbour"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Safe-harbour ]]></title>
                <link>https://www.itpro.com/uk/tag/safe-harbour</link>
        <description><![CDATA[ All the latest safe-harbour content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Mon, 30 Sep 2019 13:30:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ What is EU-US Privacy Shield? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Privacy Shield was a regulatory framework that governed the transfer of data between the European Union and the United States. Its principal purpose was to act as a mechanism for US companies to receive data from the EU, thereby ensuring smooth data transfers despite the fact that the two countries operated in separate data protection jurisdictions.</p><p>In effect, Privacy Shield fulfiled the same purpose as an adequacy agreement, required by any third status country that is outside of the regulatory reach of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">EU's General Data Protection Regulation (GDPR)</a>. Such an agreement signals that the EU recognises the data protection laws of the third country as being robust enough to protect the data of EU citizens, and therefore eligible to receive EU data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">Businesses worldwide brace for ECJ ruling on data transfers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31296/privacy-shield-should-be-suspended-say-meps" data-original-url="/data-protection/31296/privacy-shield-should-be-suspended-say-meps">Privacy Shield should be suspended, say MEPs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a></p></div></div><p>​Privacy Shield <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">was ruled invalid by the European Court of Justice</a> on 16 July 2020 as part of the <em>Facebook Ireland vs Max Schrems</em> case. The ECJ argued that the creation of Privacy Shield gave primacy to US surveillance laws, with its current form being unable to provide adequate protections for EU resident data. It was also ruled that the mechanism did not provide data subjects with an adequate point of redress or cause of action when issuing complaints.</p><h3 class="article-body__section" id="section-where-did-privacy-shield-come-from"><span>Where did Privacy Shield come from?</span></h3><p>The ‘International Safe Harbour Privacy Principles’, referred to commonly as Safe Harbour, were in force between 2000 and 2015, eventually being deemed insufficient following a challenge by Max Schrems. Privacy Shield, which suffered the same fate, replaced Safe Harbour, and once again tried to ease data flows between the US and the EU.</p><p>The history of both frameworks actually stretches back to the 1980s when the EU started to pursue policies to raise the level of data protection offered to citizens throughout its member states. To guarantee these protections were universal, the EU needed to ensure that citizens were safeguarded by the same protections not only in the EU but when their data was sent to other countries, such as the US.</p><p>The EU eventually signed the Data Protection Directive in 1995, which was the first set of meaningful data protection regulations, and the legislation that would eventually evolve into what we know as GDPR today. Although it covered a variety of issues, one of its main functions was to ensure companies sending data belonging to EU data subjects to non-EEA countries couldn’t process the data by weaker standards.</p><p>The EU’s appetite for raising the level of data protection for its citizens wasn’t matched by legislators in the US, especially considering how security agencies <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">such as the NSA</a> were known to operate. However, because it was vital to ensure that data continued to flow undisrupted between EU territories and the US, the two entities came together to build a specific architecture to ensure that businesses could seamlessly move data while data subjects would rest easy knowing their rights would continue to apply. This would replace the need for any mechanisms such as formal adequacy agreements, standard contractual clauses (SCCs) or binding corporate rules.</p><p>Developed between 1998 and 2000, the Safe Harbour Privacy Principles were initially designed to prevent organisations in the US and the EU from accidentally disclosing personal information by providing clear guidelines on how to collect and manage data. These principles incorporated some of the requirements set out by the Data Protection Directive, including the need for better security, relevant data collection, and the restrictions on third-country transfers, only these were voluntary for US companies. However, by July 2000, it was decided that any US company that was able to demonstrate its commitment to these Safe Harbor Principles would be permitted to send and receive data from the EU – known as the "Safe Harbor Decision".</p><p>US companies operated under the provisions of the Safe Harbor Decision for over 15 years but in October 2015, the European Court of Justice <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">ruled that the process of the Safe Harbour Decision was invalid</a>. The reason for this ruling was mainly because the act of giving public authorities access to EU individuals' data through the adherence of general principles was in direct conflict with <a href="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge" data-original-url="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge">the right to privacy</a> as enshrined in Article 8 of the European Convention on Human Rights (ECHR). In essence, the ECJ found that the Safe Harbour Principles were incompatible with EU data laws given that the framework lacked any operational oversight from US or EU agencies.</p><h3 class="article-body__section" id="section-enter-privacy-shield"><span>Enter Privacy Shield</span></h3><p>Privacy Shield, introduced in early 2016, was an attempt to rectify these issues, promising to enforce tougher obligations on US companies – namely the requirement to monitor and enforce data protections more robustly, and cooperate with European data protection authorities.</p><p>As with Safe Harbor, it was a voluntary mechanism that US companies could use to legally send and receive data from the EU. Those that agreed to process data under Privacy Shield were required to publicly advertise their compliance – a notice that said they were committed to providing higher standards of data protection and that they were liable to strict fines if found to be in breach of them.</p><p>As part of this compliance, organisations were required to give European users a means to opt out of having their data sold to third parties, as well as rigorously protect any data they do collect. EU data subjects were also protected from any misuse of data beyond its originally advertised processing purpose and had the right to access, correct, amend or delete any data that an organisation held on them, provided it was inaccurate or had been used in a way that breached Privacy Shield principles.</p><p>These protections only existed for EU citizens – US citizens were only protected by federal or state US laws.</p><h3 class="article-body__section" id="section-privacy-shield-fines-amp-sanctions"><span>Privacy Shield fines & sanctions</span></h3><p>The <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc" data-original-url="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">US Federal Trade Commission</a>, the agency overseeing Privacy Shield enforcement, had the power to bring fines against any company found to be in breach of Privacy Shield standards.</p><p>Any US organisation that failed to abide by their commitments to upholding Privacy Shield principles could face a number of different penalties. Firstly, the FTC could issue administrative or court orders to compel an organisation to fix any violations. Failure to abide by these orders could result in civil penalties of up to $40,000 for each violation, or $40,000 per day for ongoing violations.</p><p>Any organisation found to be in persistent violation of Privacy Shield standards would have its eligibility revoked, which prevented it from using the mechanism for data transfers. This includes any company that had been found to be in regular breach of the standards even if those breaches were unrelated. The Department of Commerce would then remove the company's name from the Privacy Shield List.</p><h3 class="article-body__section" id="section-what-did-privacy-shield-require-of-us-businesses"><span>What did Privacy Shield require of US businesses?</span></h3><p>Privacy Shield was voluntary for US businesses, however, it was strongly advised that organisations sign up to the laws, particularly if they planned to expand into Europe in the future.</p><p>Those that sign up were required to do the following:</p><ul><li>Present a detailed public facing statement showing its commitment to the Privacy Shield Principles and how it is ensuring its processes are compliant.</li><li>Ensure that mechanisms are in place to restrict data sharing with third parties where a user has opted-out. All third parties that receive such data must also publicly display their commitment to Privacy Shield.</li><li>Respond to all access and deletion requests from users, and provide a means for users to change their data, provided the request is feasible.</li><li>Ensure that all systems are maintained and are protected from unauthorised access.</li></ul><h3 class="article-body__section" id="section-criticisms-of-privacy-shield"><span>Criticisms of Privacy Shield</span></h3><p>Both Safe Harbour and Privacy Shield highlighted an ongoing clash between the US and the EU over data protection rights.</p><p>The European Union has worked to increase protections, and now operates one of the world's most robust data laws in the world. Data processing is heavily scrutinised under GDPR, with companies facing the prospect of <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">crippling fines for any loss of data</a>.</p><p>The US, meanwhile, has increased the surveillance powers of its intelligence agencies over the years, particularly following the introduction of the US Patriot Act in 2001. Intelligence agencies are able to use <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">programmes such as PRISM</a> to collect data from US internet companies, as well as the Foreign Intelligence Surveillance Act (FISA) to gather data on US citizens. Perhaps most importantly for EU authorities, the US has yet to work towards a centralised federal data protection regime, let alone one that begins to mirror GDPR. Aside from <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">states such as California</a>, there have been few attempts to expand data protection rights.</p><p>Privacy Shield was, therefore, an attempt at a compromise on the part of the EU to overcome this ongoing contradiction – a mechanism that allows US companies to prove they can operate under GDPR-like controls.</p><p>Not everyone agreed that the EU's good faith is reciprocated, however. Most notably, as part of the relationship, the US had the duty of appointing an ombudsperson to act as an additional point of redress for any EU citizens raising complaints against a company. This position sat vacant until June 2019, when Keith Krach was confirmed as the US' first permanent Privacy Shield Ombudsperson, leaving many to question whether the country was taking its role seriously enough.</p><p>Concerns had also been raised over the years about the framework's ability to protect EU data. In 2016, <a href="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough" data-original-url="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough">European data protection supervisor, Giovanni Buttarelli, argued</a> that "significant improvements" were needed and that, as it stood, Privacy Shield was simply "not robust enough to withstand future legal scrutiny before the court". He also added that it was "time to develop a longer-term solution in the transatlantic dialogue".</p><p><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Max Schrems</a>, the Austrian legal activist that brought the case to the ECJ that would ultimately lead to Privacy Shield’s downfall, argued that Privacy Shield was hastily put together in order to fill the gap left by the previous framework and that those behind it.</p><p>"Sometimes I call it Safe Harbour 1.0.1 because basically most of the text is exactly the same, most of the structure is exactly the same," said Schrems, speaking at a data protection summit in London in June 2019, adding that he often referred to it instead as "lipstick on a pig".</p><p>Speaking on the speed at which it was negotiated, he said: "There was a deadline on January 31. What happened was that they failed to come to any kind of agreement. I was asking later and apparently, the Europeans stood off the table and said there was no way we're ever going to get it. 48 hours later and there was [suddenly] a deal. Another 24 hours later and we got this logo."</p><h3 class="article-body__section" id="section-what-will-replace-privacy-shield"><span>What will replace Privacy Shield?</span></h3><p>Now that Privacy Shield has been invalidated, businesses are, technically, no longer allowed to transfer data using the mechanism. Despite the disruption the judgement caused, there was no grace period announced that would allow businesses to continue using the mechanism until a replacement is devised. In the case of the invalidation of Safe Harbour, businesses were initially given a grace period of three months, although it would take six months before Privacy Shield was introduced. </p><p>Although Privacy Shield was struck down last year, a replacement still hasn't been established, and it's not clear how long a replacement to Privacy Shield might take. Given that Privacy Shield and Safe Harbour were invalidated for very similar reasons, however, it’s likely a more robust system will be demanded by advocates in the EU Commission. The European Data Protection Supervisor <a href="https://iapp.org/news/a/edps-says-privacy-shield-replacement-unlikely-for-a-while" target="_blank">indicated in December 2020 that a replacement would be unlikely 'for a while'</a>. To facilitate a new arrangement, the EU could ask the US to commit to far greater protections for EU resident data, or move towards greater regulatory alignment. Whatever the detail of the agreement, any friction between the two sides will almost certainly cause delay.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield</link>
                                                                            <description>
                            <![CDATA[ A look at the now invalidated framework US companies relied on to transfer data to and from the European Union ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vTqv7Zuec9Lmg5LddXjA78</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d94Jb4AAqmmhNckiXGvaYe-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Sep 2019 13:30:00 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Jul 2021 14:30:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d94Jb4AAqmmhNckiXGvaYe-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Privacy Shield security concept]]></media:description>                                                            <media:text><![CDATA[Privacy Shield security concept]]></media:text>
                                <media:title type="plain"><![CDATA[Privacy Shield security concept]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d94Jb4AAqmmhNckiXGvaYe-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy Shield was a regulatory framework that governed the transfer of data between the European Union and the United States. Its principal purpose was to act as a mechanism for US companies to receive data from the EU, thereby ensuring smooth data transfers despite the fact that the two countries operated in separate data protection jurisdictions.</p><p>In effect, Privacy Shield fulfiled the same purpose as an adequacy agreement, required by any third status country that is outside of the regulatory reach of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">EU's General Data Protection Regulation (GDPR)</a>. Such an agreement signals that the EU recognises the data protection laws of the third country as being robust enough to protect the data of EU citizens, and therefore eligible to receive EU data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally" data-original-url="/general-data-protection-regulation-gdpr/33991/uk-firms-may-soon-find-it-impossible-to-legally">Businesses worldwide brace for ECJ ruling on data transfers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31296/privacy-shield-should-be-suspended-say-meps" data-original-url="/data-protection/31296/privacy-shield-should-be-suspended-say-meps">Privacy Shield should be suspended, say MEPs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a></p></div></div><p>​Privacy Shield <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">was ruled invalid by the European Court of Justice</a> on 16 July 2020 as part of the <em>Facebook Ireland vs Max Schrems</em> case. The ECJ argued that the creation of Privacy Shield gave primacy to US surveillance laws, with its current form being unable to provide adequate protections for EU resident data. It was also ruled that the mechanism did not provide data subjects with an adequate point of redress or cause of action when issuing complaints.</p><h3 class="article-body__section" id="section-where-did-privacy-shield-come-from"><span>Where did Privacy Shield come from?</span></h3><p>The ‘International Safe Harbour Privacy Principles’, referred to commonly as Safe Harbour, were in force between 2000 and 2015, eventually being deemed insufficient following a challenge by Max Schrems. Privacy Shield, which suffered the same fate, replaced Safe Harbour, and once again tried to ease data flows between the US and the EU.</p><p>The history of both frameworks actually stretches back to the 1980s when the EU started to pursue policies to raise the level of data protection offered to citizens throughout its member states. To guarantee these protections were universal, the EU needed to ensure that citizens were safeguarded by the same protections not only in the EU but when their data was sent to other countries, such as the US.</p><p>The EU eventually signed the Data Protection Directive in 1995, which was the first set of meaningful data protection regulations, and the legislation that would eventually evolve into what we know as GDPR today. Although it covered a variety of issues, one of its main functions was to ensure companies sending data belonging to EU data subjects to non-EEA countries couldn’t process the data by weaker standards.</p><p>The EU’s appetite for raising the level of data protection for its citizens wasn’t matched by legislators in the US, especially considering how security agencies <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">such as the NSA</a> were known to operate. However, because it was vital to ensure that data continued to flow undisrupted between EU territories and the US, the two entities came together to build a specific architecture to ensure that businesses could seamlessly move data while data subjects would rest easy knowing their rights would continue to apply. This would replace the need for any mechanisms such as formal adequacy agreements, standard contractual clauses (SCCs) or binding corporate rules.</p><p>Developed between 1998 and 2000, the Safe Harbour Privacy Principles were initially designed to prevent organisations in the US and the EU from accidentally disclosing personal information by providing clear guidelines on how to collect and manage data. These principles incorporated some of the requirements set out by the Data Protection Directive, including the need for better security, relevant data collection, and the restrictions on third-country transfers, only these were voluntary for US companies. However, by July 2000, it was decided that any US company that was able to demonstrate its commitment to these Safe Harbor Principles would be permitted to send and receive data from the EU – known as the "Safe Harbor Decision".</p><p>US companies operated under the provisions of the Safe Harbor Decision for over 15 years but in October 2015, the European Court of Justice <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">ruled that the process of the Safe Harbour Decision was invalid</a>. The reason for this ruling was mainly because the act of giving public authorities access to EU individuals' data through the adherence of general principles was in direct conflict with <a href="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge" data-original-url="https://www.itpro.com/policy-legislation/34101/liberty-defeated-in-snooper-s-charter-legal-challenge">the right to privacy</a> as enshrined in Article 8 of the European Convention on Human Rights (ECHR). In essence, the ECJ found that the Safe Harbour Principles were incompatible with EU data laws given that the framework lacked any operational oversight from US or EU agencies.</p><h3 class="article-body__section" id="section-enter-privacy-shield"><span>Enter Privacy Shield</span></h3><p>Privacy Shield, introduced in early 2016, was an attempt to rectify these issues, promising to enforce tougher obligations on US companies – namely the requirement to monitor and enforce data protections more robustly, and cooperate with European data protection authorities.</p><p>As with Safe Harbor, it was a voluntary mechanism that US companies could use to legally send and receive data from the EU. Those that agreed to process data under Privacy Shield were required to publicly advertise their compliance – a notice that said they were committed to providing higher standards of data protection and that they were liable to strict fines if found to be in breach of them.</p><p>As part of this compliance, organisations were required to give European users a means to opt out of having their data sold to third parties, as well as rigorously protect any data they do collect. EU data subjects were also protected from any misuse of data beyond its originally advertised processing purpose and had the right to access, correct, amend or delete any data that an organisation held on them, provided it was inaccurate or had been used in a way that breached Privacy Shield principles.</p><p>These protections only existed for EU citizens – US citizens were only protected by federal or state US laws.</p><h3 class="article-body__section" id="section-privacy-shield-fines-amp-sanctions"><span>Privacy Shield fines & sanctions</span></h3><p>The <a href="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc" data-original-url="https://www.itpro.com/it-regulation/34479/what-is-the-federal-trade-commission-ftc">US Federal Trade Commission</a>, the agency overseeing Privacy Shield enforcement, had the power to bring fines against any company found to be in breach of Privacy Shield standards.</p><p>Any US organisation that failed to abide by their commitments to upholding Privacy Shield principles could face a number of different penalties. Firstly, the FTC could issue administrative or court orders to compel an organisation to fix any violations. Failure to abide by these orders could result in civil penalties of up to $40,000 for each violation, or $40,000 per day for ongoing violations.</p><p>Any organisation found to be in persistent violation of Privacy Shield standards would have its eligibility revoked, which prevented it from using the mechanism for data transfers. This includes any company that had been found to be in regular breach of the standards even if those breaches were unrelated. The Department of Commerce would then remove the company's name from the Privacy Shield List.</p><h3 class="article-body__section" id="section-what-did-privacy-shield-require-of-us-businesses"><span>What did Privacy Shield require of US businesses?</span></h3><p>Privacy Shield was voluntary for US businesses, however, it was strongly advised that organisations sign up to the laws, particularly if they planned to expand into Europe in the future.</p><p>Those that sign up were required to do the following:</p><ul><li>Present a detailed public facing statement showing its commitment to the Privacy Shield Principles and how it is ensuring its processes are compliant.</li><li>Ensure that mechanisms are in place to restrict data sharing with third parties where a user has opted-out. All third parties that receive such data must also publicly display their commitment to Privacy Shield.</li><li>Respond to all access and deletion requests from users, and provide a means for users to change their data, provided the request is feasible.</li><li>Ensure that all systems are maintained and are protected from unauthorised access.</li></ul><h3 class="article-body__section" id="section-criticisms-of-privacy-shield"><span>Criticisms of Privacy Shield</span></h3><p>Both Safe Harbour and Privacy Shield highlighted an ongoing clash between the US and the EU over data protection rights.</p><p>The European Union has worked to increase protections, and now operates one of the world's most robust data laws in the world. Data processing is heavily scrutinised under GDPR, with companies facing the prospect of <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">crippling fines for any loss of data</a>.</p><p>The US, meanwhile, has increased the surveillance powers of its intelligence agencies over the years, particularly following the introduction of the US Patriot Act in 2001. Intelligence agencies are able to use <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">programmes such as PRISM</a> to collect data from US internet companies, as well as the Foreign Intelligence Surveillance Act (FISA) to gather data on US citizens. Perhaps most importantly for EU authorities, the US has yet to work towards a centralised federal data protection regime, let alone one that begins to mirror GDPR. Aside from <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">states such as California</a>, there have been few attempts to expand data protection rights.</p><p>Privacy Shield was, therefore, an attempt at a compromise on the part of the EU to overcome this ongoing contradiction – a mechanism that allows US companies to prove they can operate under GDPR-like controls.</p><p>Not everyone agreed that the EU's good faith is reciprocated, however. Most notably, as part of the relationship, the US had the duty of appointing an ombudsperson to act as an additional point of redress for any EU citizens raising complaints against a company. This position sat vacant until June 2019, when Keith Krach was confirmed as the US' first permanent Privacy Shield Ombudsperson, leaving many to question whether the country was taking its role seriously enough.</p><p>Concerns had also been raised over the years about the framework's ability to protect EU data. In 2016, <a href="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough" data-original-url="https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough">European data protection supervisor, Giovanni Buttarelli, argued</a> that "significant improvements" were needed and that, as it stood, Privacy Shield was simply "not robust enough to withstand future legal scrutiny before the court". He also added that it was "time to develop a longer-term solution in the transatlantic dialogue".</p><p><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Max Schrems</a>, the Austrian legal activist that brought the case to the ECJ that would ultimately lead to Privacy Shield’s downfall, argued that Privacy Shield was hastily put together in order to fill the gap left by the previous framework and that those behind it.</p><p>"Sometimes I call it Safe Harbour 1.0.1 because basically most of the text is exactly the same, most of the structure is exactly the same," said Schrems, speaking at a data protection summit in London in June 2019, adding that he often referred to it instead as "lipstick on a pig".</p><p>Speaking on the speed at which it was negotiated, he said: "There was a deadline on January 31. What happened was that they failed to come to any kind of agreement. I was asking later and apparently, the Europeans stood off the table and said there was no way we're ever going to get it. 48 hours later and there was [suddenly] a deal. Another 24 hours later and we got this logo."</p><h3 class="article-body__section" id="section-what-will-replace-privacy-shield"><span>What will replace Privacy Shield?</span></h3><p>Now that Privacy Shield has been invalidated, businesses are, technically, no longer allowed to transfer data using the mechanism. Despite the disruption the judgement caused, there was no grace period announced that would allow businesses to continue using the mechanism until a replacement is devised. In the case of the invalidation of Safe Harbour, businesses were initially given a grace period of three months, although it would take six months before Privacy Shield was introduced. </p><p>Although Privacy Shield was struck down last year, a replacement still hasn't been established, and it's not clear how long a replacement to Privacy Shield might take. Given that Privacy Shield and Safe Harbour were invalidated for very similar reasons, however, it’s likely a more robust system will be demanded by advocates in the EU Commission. The European Data Protection Supervisor <a href="https://iapp.org/news/a/edps-says-privacy-shield-replacement-unlikely-for-a-while" target="_blank">indicated in December 2020 that a replacement would be unlikely 'for a while'</a>. To facilitate a new arrangement, the EU could ask the US to commit to far greater protections for EU resident data, or move towards greater regulatory alignment. Whatever the detail of the agreement, any friction between the two sides will almost certainly cause delay.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GitHub build out its bug bounty programme and increases reward for spotted flaws ]]></title>
                                                                                                <dc:content><![CDATA[ <p>GitHub is to build up its bug bounty programme, with plans to remove maximum award limits and increase the extent of what its program covers.</p><p>The programme has been running five years with the organisation paying out $165,000 to researchers through the public bug bounty program. In total, it has paid out $250,000 to security researchers in 2018 through its programme, research grants, private bug bounty programs, and a live-hacking event</p><p>In a <a href="https://github.blog/2019-02-19-five-years-of-the-github-bug-bounty-program">blog post</a>, GitHub's Philip Turnbull said that his company would increase reward amounts at all levels. The new rewards are: Critical: $20,000 $30,000+, High: $10,000 $20,000, Medium: $4,000 $10,000, and Low: $617 $2,000.</p><p>"Although we've listed $30,000 as a guideline amount for critical vulnerabilities, we're reserving the right to reward significantly more for truly cutting-edge research," said Turnbull. He added that finding higher-severity vulnerabilities in GitHub's products is becoming increasingly difficult for researchers and they should be rewarded for their efforts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/open-source/31833/what-is-github" data-original-url="/open-source/31833/what-is-github">What is GitHub?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32781/microsoft-launches-20000-azure-devops-bug-bounty-programme" data-original-url="/security/32781/microsoft-launches-20000-azure-devops-bug-bounty-programme">Microsoft launches $20,000 Azure DevOps bug bounty programme</a></p></div></div><p>He also said the GitHub would expand the scope of the program to reward vulnerabilities in all first-party services hosted under its github.com domain. his includes GitHub Education, GitHub Learning Lab, GitHub Jobs, and our GitHub Desktop application.</p><p>"It's not just about our user-facing systems. The security of our users' data also depends on the security of our employees and our internal systems. That's why we're also including all first-party services under our employee-facing githubapp.com and github.net domains," said Turnbull.</p><p>GitHub has also added a set of Legal Safe Harbor terms to its site policy based on CC0-licensed templates. This addresses three potential areas of risk and extends protections and authorisations if researchers accidentally overstep the bounty program's scope.</p><p>"Our safe harbor now includes a firm commitment not to pursue civil or criminal legal action, or support any prosecution or civil action by others, for participants' bounty program research activities. You remain protected even for good faith violations of the bounty policy," said Turnbull.</p><p>There is also a commitment to protect researchers against legal risk from third parties who won't commit to the same level of safe harbor protections.</p><p>"We will share only non-identifying information with third parties, and only after notifying you and getting that third party's written commitment not to pursue legal action against you. Unless we get your written permission, we will not share identifying information with a third party," said Turnbull.</p><p>Lastly, GitHub's safe harbour now provides a limited waiver for relevant parts of its site terms and policies, and Turnbull noted: "This protects against legal risk from DMCA anti-circumvention rules or similar contract terms that could otherwise prohibit necessary research tasks like reverse engineering or deobfuscating code."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/safe-harbour/33040/github-build-out-its-bug-bounty-programme-and-increases-reward-for-spotted-flaws</link>
                                                                            <description>
                            <![CDATA[ Code repository now offers up to £30,000 for the discovery of critical vulnerabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7dwAT8XHhZjVAF67kHdYgS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/udBGAhuZpkqnKSFJivKPpN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Feb 2019 11:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/udBGAhuZpkqnKSFJivKPpN-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GitHub code on a dark background]]></media:description>                                                            <media:text><![CDATA[GitHub code on a dark background]]></media:text>
                                <media:title type="plain"><![CDATA[GitHub code on a dark background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/udBGAhuZpkqnKSFJivKPpN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GitHub is to build up its bug bounty programme, with plans to remove maximum award limits and increase the extent of what its program covers.</p><p>The programme has been running five years with the organisation paying out $165,000 to researchers through the public bug bounty program. In total, it has paid out $250,000 to security researchers in 2018 through its programme, research grants, private bug bounty programs, and a live-hacking event</p><p>In a <a href="https://github.blog/2019-02-19-five-years-of-the-github-bug-bounty-program">blog post</a>, GitHub's Philip Turnbull said that his company would increase reward amounts at all levels. The new rewards are: Critical: $20,000 $30,000+, High: $10,000 $20,000, Medium: $4,000 $10,000, and Low: $617 $2,000.</p><p>"Although we've listed $30,000 as a guideline amount for critical vulnerabilities, we're reserving the right to reward significantly more for truly cutting-edge research," said Turnbull. He added that finding higher-severity vulnerabilities in GitHub's products is becoming increasingly difficult for researchers and they should be rewarded for their efforts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/open-source/31833/what-is-github" data-original-url="/open-source/31833/what-is-github">What is GitHub?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32781/microsoft-launches-20000-azure-devops-bug-bounty-programme" data-original-url="/security/32781/microsoft-launches-20000-azure-devops-bug-bounty-programme">Microsoft launches $20,000 Azure DevOps bug bounty programme</a></p></div></div><p>He also said the GitHub would expand the scope of the program to reward vulnerabilities in all first-party services hosted under its github.com domain. his includes GitHub Education, GitHub Learning Lab, GitHub Jobs, and our GitHub Desktop application.</p><p>"It's not just about our user-facing systems. The security of our users' data also depends on the security of our employees and our internal systems. That's why we're also including all first-party services under our employee-facing githubapp.com and github.net domains," said Turnbull.</p><p>GitHub has also added a set of Legal Safe Harbor terms to its site policy based on CC0-licensed templates. This addresses three potential areas of risk and extends protections and authorisations if researchers accidentally overstep the bounty program's scope.</p><p>"Our safe harbor now includes a firm commitment not to pursue civil or criminal legal action, or support any prosecution or civil action by others, for participants' bounty program research activities. You remain protected even for good faith violations of the bounty policy," said Turnbull.</p><p>There is also a commitment to protect researchers against legal risk from third parties who won't commit to the same level of safe harbor protections.</p><p>"We will share only non-identifying information with third parties, and only after notifying you and getting that third party's written commitment not to pursue legal action against you. Unless we get your written permission, we will not share identifying information with a third party," said Turnbull.</p><p>Lastly, GitHub's safe harbour now provides a limited waiver for relevant parts of its site terms and policies, and Turnbull noted: "This protects against legal risk from DMCA anti-circumvention rules or similar contract terms that could otherwise prohibit necessary research tasks like reverse engineering or deobfuscating code."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Government’s online safety council for children will now look after adults ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The government has announced it will expand the scope of the UK Council for Child Internet Safety (UKCCIS) to cover the wider UK population.</p><p>Focusing on reinforcing digital safety for everyone across the country, the new UK Council for Internet Safety (UKCIS) will prioritise areas of online harm such as cyberbullying and sexual exploitation, as well as tackle the spread of radicalism and extremism across the internet.</p><p>Also trying to mitigate violence against girls and women, hate crime and hate speech, as well as discrimination that contravenes the Equality Act 2010 manifesting online, the UKCIS will encourage collaboration between more than 200 organisations representing the government, regulators, the digital industry, law enforcement, academia and charities.</p><p>"Only through collaborative action will the UK be the safest place to be online," said Margot James, minister for digital and the creative industries.</p><p>"By bringing together key stakeholders, from the tech giants to the third sector, UKCIS will be the cornerstone of this effort; driving the development of technical solutions and equipping UK citizens to tackle online harms."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31560/government-accidentally-leaks-counter-terrorism-tools-via-trello" data-original-url="/data-protection/31560/government-accidentally-leaks-counter-terrorism-tools-via-trello">Government accidentally leaks counter-terrorism tools via Trello</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31163/uk-government-draws-up-new-laws-after-social-media-firms-spurn-abuse-talks" data-original-url="/policy-legislation/31163/uk-government-draws-up-new-laws-after-social-media-firms-spurn-abuse-talks">UK government draws up new laws after social media firms spurn abuse talks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/30622/it-s-time-to-regulate-social-media-it-s-too-powerful" data-original-url="/policy-legislation/30622/it-s-time-to-regulate-social-media-it-s-too-powerful">It’s time to regulate social media – it’s too powerful</a></p></div></div><p>Since its conception in 2008, the UKCCIS has run a wide array of campaigns and put forward policy proposals that aim to improve the online safety and welfare for children in schools and colleges across the UK.</p><p>Notable work includes infamous proposals for the default filtering of online pornography, introduced in 2012, while more recently the organisation has issued <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/647389/Overview_of_Sexting_Guidance.pdf" target="_blank">guidance on 'sexting'</a>.</p><p>Plans to expand the UKCCIS were first outlined in the government's <a href="https://www.gov.uk/government/consultations/internet-safety-strategy-green-paper" target="_blank">Internet Safety Strategy green paper</a> in October last year, with an application process now underway to appoint board members to the new, beefier organisation. The consultation also covered introducing a social media code of practice, a social media levy, examining young people's use of dating websites, and exploring how new technology can be used to curb online home.</p><p>Comprising co-ministerial chairs from the department for culture, media and sport, the home office and the department for education, the board will retain an interest in combating online threats posed to the safety and welfare of children. Its remit will also expand, however, in a variety of areas to improve the online experience for the adult population.</p><p>The <a href="https://www.gov.uk/government/groups/uk-council-for-child-internet-safety-ukccis#ukcis-executive-board-application-now-open-deadline-3-september-2018" target="_blank">deadline for applications</a> to sit on the UKCIS' executive board will close on 3 September.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/policy-legislation/31585/government-s-online-safety-council-for-children-will-now-look-after-adults</link>
                                                                            <description>
                            <![CDATA[ The council will focus on combating online harm, extremism, and violence against women, among other areas ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sjrzvtethrWTJjpNK9qw8s</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cSv2dLVU3k72yfXMrPKH25-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Jul 2018 10:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cSv2dLVU3k72yfXMrPKH25-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[child using a smartphone possibly in an abusive situation]]></media:description>                                                            <media:text><![CDATA[child using a smartphone possibly in an abusive situation]]></media:text>
                                <media:title type="plain"><![CDATA[child using a smartphone possibly in an abusive situation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cSv2dLVU3k72yfXMrPKH25-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government has announced it will expand the scope of the UK Council for Child Internet Safety (UKCCIS) to cover the wider UK population.</p><p>Focusing on reinforcing digital safety for everyone across the country, the new UK Council for Internet Safety (UKCIS) will prioritise areas of online harm such as cyberbullying and sexual exploitation, as well as tackle the spread of radicalism and extremism across the internet.</p><p>Also trying to mitigate violence against girls and women, hate crime and hate speech, as well as discrimination that contravenes the Equality Act 2010 manifesting online, the UKCIS will encourage collaboration between more than 200 organisations representing the government, regulators, the digital industry, law enforcement, academia and charities.</p><p>"Only through collaborative action will the UK be the safest place to be online," said Margot James, minister for digital and the creative industries.</p><p>"By bringing together key stakeholders, from the tech giants to the third sector, UKCIS will be the cornerstone of this effort; driving the development of technical solutions and equipping UK citizens to tackle online harms."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31560/government-accidentally-leaks-counter-terrorism-tools-via-trello" data-original-url="/data-protection/31560/government-accidentally-leaks-counter-terrorism-tools-via-trello">Government accidentally leaks counter-terrorism tools via Trello</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31163/uk-government-draws-up-new-laws-after-social-media-firms-spurn-abuse-talks" data-original-url="/policy-legislation/31163/uk-government-draws-up-new-laws-after-social-media-firms-spurn-abuse-talks">UK government draws up new laws after social media firms spurn abuse talks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/30622/it-s-time-to-regulate-social-media-it-s-too-powerful" data-original-url="/policy-legislation/30622/it-s-time-to-regulate-social-media-it-s-too-powerful">It’s time to regulate social media – it’s too powerful</a></p></div></div><p>Since its conception in 2008, the UKCCIS has run a wide array of campaigns and put forward policy proposals that aim to improve the online safety and welfare for children in schools and colleges across the UK.</p><p>Notable work includes infamous proposals for the default filtering of online pornography, introduced in 2012, while more recently the organisation has issued <a href="https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/647389/Overview_of_Sexting_Guidance.pdf" target="_blank">guidance on 'sexting'</a>.</p><p>Plans to expand the UKCCIS were first outlined in the government's <a href="https://www.gov.uk/government/consultations/internet-safety-strategy-green-paper" target="_blank">Internet Safety Strategy green paper</a> in October last year, with an application process now underway to appoint board members to the new, beefier organisation. The consultation also covered introducing a social media code of practice, a social media levy, examining young people's use of dating websites, and exploring how new technology can be used to curb online home.</p><p>Comprising co-ministerial chairs from the department for culture, media and sport, the home office and the department for education, the board will retain an interest in combating online threats posed to the safety and welfare of children. Its remit will also expand, however, in a variety of areas to improve the online experience for the adult population.</p><p>The <a href="https://www.gov.uk/government/groups/uk-council-for-child-internet-safety-ukccis#ukcis-executive-board-application-now-open-deadline-3-september-2018" target="_blank">deadline for applications</a> to sit on the UKCIS' executive board will close on 3 September.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy Shield should be suspended, say MEPs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Privacy Shield, the agreement underpinning data transfers from Europe to America, must be suspended if the US does not fully meet its obligations come 1 September, MEPs voted last night.</p><p>The Civil Liberties (Libe) Committee's decision isn't binding, but puts pressure on the European Commission to ensure the data-transfer arrangement is being honoured by US authorities.</p><p>Drawn up to replace the abandoned Safe Harbor agreement in 2016 after that deal was brought down by a legal challenge, <a href="http://www.cloudpro.co.uk/leadership/6177/eu-data-watchdogs-will-wait-to-challenge-privacy-shield" target="_blank">Privacy Shield now faces obstacles of its own</a>.</p><p>Designed to extend EU-like data protection to European residents' data transferred to the US, now the Libe Committee believes the new agreement fails to provide that protection as well.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" data-original-url="/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Will the new Safe Harbour deal really protect your data?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" data-original-url="/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">Privacy Shield hammers another nail in the coffin of data protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute" data-original-url="/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute">CLOUD Act ends Microsoft's US data privacy dispute</a></p></div></div><p>"While progress has been made to improve on the Safe Harbor agreement, the Privacy Shield in its current form does not provide the adequate level of protection required by EU data protection law and the EU Charter," <a href="http://www.europarl.europa.eu/news/en/press-room/20180611IPR05527/eu-us-privacy-shield-data-exchange-deal-us-must-comply-by-1-september-say-meps" target="_blank">said</a> Libe Committee member Claude Moraes.</p><p>"It is therefore up to the US authorities to effectively follow the terms of the agreement and for the Commission to take measures to ensure that it will fully comply with the GDPR."</p><p>MEPs raised their concerns following the Cambridge Analytica scandal affecting Facebook, about which the social network's CEO, Mark Zuckerberg, <a href="https://www.itpro.com/data-protection/31144/zuckerberg-sails-through-european-parliaments-questioning" target="_blank" data-original-url="https://www.itpro.com/data-protection/31144/zuckerberg-sails-through-european-parliaments-questioning">gave evidence to the European Parliament recently</a>.</p><p>While the incident pre-dates Privacy Shield, it was concerned about US authorities' ability to monitor US firms' compliance with the agreement, given both Cambridge Analytica's affiliate company, SCL Elections, and Facebook are both still listed on Privacy Shield.</p><p><em>SCL Elections still listed on Privacy Shield</em></p><p>MEPs also said they're concerned about a new US law called <a href="http://www.cloudpro.co.uk/collaboration/email/7410/cloud-act-brings-microsofts-us-data-privacy-court-spat-to-an-end" target="_blank">the CLOUD Act</a>, which gives US authorities the right to access data stored in foreign locations, as long as the organisation storing it is American.</p><p>The Libe Committee said this could clash with EU law on data protection.</p><p><em>Picture: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/31296/privacy-shield-should-be-suspended-say-meps</link>
                                                                            <description>
                            <![CDATA[ Committee cites Cambridge Analytica scandal and CLOUD Act as obstacles ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">erhWiVkxfFERQUsgEVpLku</guid>
                                                                                                                            <pubDate>Wed, 13 Jun 2018 13:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                                        <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy Shield, the agreement underpinning data transfers from Europe to America, must be suspended if the US does not fully meet its obligations come 1 September, MEPs voted last night.</p><p>The Civil Liberties (Libe) Committee's decision isn't binding, but puts pressure on the European Commission to ensure the data-transfer arrangement is being honoured by US authorities.</p><p>Drawn up to replace the abandoned Safe Harbor agreement in 2016 after that deal was brought down by a legal challenge, <a href="http://www.cloudpro.co.uk/leadership/6177/eu-data-watchdogs-will-wait-to-challenge-privacy-shield" target="_blank">Privacy Shield now faces obstacles of its own</a>.</p><p>Designed to extend EU-like data protection to European residents' data transferred to the US, now the Libe Committee believes the new agreement fails to provide that protection as well.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield" data-original-url="/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield">Safe Harbour replaced with EU-US Privacy Shield</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" data-original-url="/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Will the new Safe Harbour deal really protect your data?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" data-original-url="/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">Privacy Shield hammers another nail in the coffin of data protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute" data-original-url="/it-governance/30886/cloud-act-ends-microsofts-us-data-privacy-dispute">CLOUD Act ends Microsoft's US data privacy dispute</a></p></div></div><p>"While progress has been made to improve on the Safe Harbor agreement, the Privacy Shield in its current form does not provide the adequate level of protection required by EU data protection law and the EU Charter," <a href="http://www.europarl.europa.eu/news/en/press-room/20180611IPR05527/eu-us-privacy-shield-data-exchange-deal-us-must-comply-by-1-september-say-meps" target="_blank">said</a> Libe Committee member Claude Moraes.</p><p>"It is therefore up to the US authorities to effectively follow the terms of the agreement and for the Commission to take measures to ensure that it will fully comply with the GDPR."</p><p>MEPs raised their concerns following the Cambridge Analytica scandal affecting Facebook, about which the social network's CEO, Mark Zuckerberg, <a href="https://www.itpro.com/data-protection/31144/zuckerberg-sails-through-european-parliaments-questioning" target="_blank" data-original-url="https://www.itpro.com/data-protection/31144/zuckerberg-sails-through-european-parliaments-questioning">gave evidence to the European Parliament recently</a>.</p><p>While the incident pre-dates Privacy Shield, it was concerned about US authorities' ability to monitor US firms' compliance with the agreement, given both Cambridge Analytica's affiliate company, SCL Elections, and Facebook are both still listed on Privacy Shield.</p><p><em>SCL Elections still listed on Privacy Shield</em></p><p>MEPs also said they're concerned about a new US law called <a href="http://www.cloudpro.co.uk/collaboration/email/7410/cloud-act-brings-microsofts-us-data-privacy-court-spat-to-an-end" target="_blank">the CLOUD Act</a>, which gives US authorities the right to access data stored in foreign locations, as long as the organisation storing it is American.</p><p>The Libe Committee said this could clash with EU law on data protection.</p><p><em>Picture: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Safe Harbour replaced with EU-US Privacy Shield ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The EU-US Privacy Shield, arranged to replace Safe Harbour, may come into effect from July, the EU and US have agreed.</p><p>The EU-US Privacy Shield has been tweaked slightly from its original specification to include a promise from the White House regarding the treatment of data.</p><p>It states that bulk collection of data sent from the EU to the US can only happen if conditions have been agreed prior to the transfer and it must be "as targeted and focused" as possible.</p><p>Other new clauses integrated into the agreement include that companies have to delete data that no longer serves the purpose for which it was originally collected. Additionally, the ombudsman that oversees the agreement will be independent from national security services to make it as fair and transparent as possible.</p><p>The US will create the ombudsman that deals with complaints from EU citizens about Americans misusing or spying on their data.</p><p>A spokesman for the European Commission said: "This new framework for transatlantic data flows protects the fundamental rights of Europeans and ensures legal certainty for businesses."</p><p>Other existing key points of the EU-US Privacy Shield include promises that the US Office of the Director of National Intelligence will give written commitment that data collected from EU citizens will not be used in mass surveillance exercises and an annual review will be performed by both the EU and US to ensure the system is running correctly.</p><p>However, now the UK has voted to leave the EU, this means the UK would need to independently negotiate a similar law in line with the EU's regulations that protects the data of businesses should they choose to trade with the UK and vice versa.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26796/safe-harbour-replaced-with-eu-us-privacy-shield</link>
                                                                            <description>
                            <![CDATA[ The new agreement may take effect from July if both parties agree on its directions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uvFfGDseXVBC6jtp7VCpd4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hEYxZFh9YMNmZg3bQy9YhU-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jun 2016 07:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hEYxZFh9YMNmZg3bQy9YhU-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US Capitol Building]]></media:description>                                                            <media:text><![CDATA[US Capitol Building]]></media:text>
                                <media:title type="plain"><![CDATA[US Capitol Building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hEYxZFh9YMNmZg3bQy9YhU-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU-US Privacy Shield, arranged to replace Safe Harbour, may come into effect from July, the EU and US have agreed.</p><p>The EU-US Privacy Shield has been tweaked slightly from its original specification to include a promise from the White House regarding the treatment of data.</p><p>It states that bulk collection of data sent from the EU to the US can only happen if conditions have been agreed prior to the transfer and it must be "as targeted and focused" as possible.</p><p>Other new clauses integrated into the agreement include that companies have to delete data that no longer serves the purpose for which it was originally collected. Additionally, the ombudsman that oversees the agreement will be independent from national security services to make it as fair and transparent as possible.</p><p>The US will create the ombudsman that deals with complaints from EU citizens about Americans misusing or spying on their data.</p><p>A spokesman for the European Commission said: "This new framework for transatlantic data flows protects the fundamental rights of Europeans and ensures legal certainty for businesses."</p><p>Other existing key points of the EU-US Privacy Shield include promises that the US Office of the Director of National Intelligence will give written commitment that data collected from EU citizens will not be used in mass surveillance exercises and an annual review will be performed by both the EU and US to ensure the system is running correctly.</p><p>However, now the UK has voted to leave the EU, this means the UK would need to independently negotiate a similar law in line with the EU's regulations that protects the data of businesses should they choose to trade with the UK and vice versa.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European data protection supervisor says Privacy Shield not robust enough ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The European data protection supervisor has published a report, saying Privacy Shield is not robust enough to withstand sharing of data across the world.</p><p>Giovanni Buttarelli said a number of changes need to be made in order for data to be shared reliably between countries without it putting that data or others' privacy at risk.</p><p>He said any solution used to replace Safe Harbour must provide "adequate" protection against surveillance by authorities and should be transparent, allowing</p><p>Any new legislation should also take into account data protection rights already considered by both governments and private companies in Europe. This is particularly important as the new General Data Protection Regulation (GDPR) is set to come into force in May 2018.</p><p>The European Commission needs to ensure that anything introduced to replace Safe Harbour adheres to guidelines set out in the new European legislation so there is no confusion between parties sharing data.</p><p>"I appreciate the efforts made to develop a solution to replace Safe Harbour but the Privacy Shield as it stands is not robust enough to withstand future legal scrutiny before the Court," Buttarelli said in a statement.</p><p>"Significant improvements are needed should the European Commission wish to adopt an adequacy decision, to respect the essence of key data protection principles with particular regard to necessity, proportionality and redress mechanisms. Moreover, it's time to develop a longer term solution in the transatlantic dialogue."</p><p><strong>13/04/2016: Europe data watchdogs find flaws in Privacy Shield</strong></p><p>Europe's data protection authorities have called for urgent amendments to <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield</a>, the proposed agreement to safeguard EU data transferred to the US.</p><p>The watchdogs, who form the Article 29 Working Party, do not believe the legislation is up to scratch, identifying several changes they believe need to be made.</p><p>The group is still concerned about US agencies undertaking mass surveillance on European citizens' data, after Privacy Shield's predecessor, Safe Harbour, being scrapped because it was not deemed to protect personal data adequately.</p><p>Privacy Shield would rely on assurances from the US government that it would not spy indiscriminately on EU data, but the Article 29 Working Party does not think these are enough.</p><p>It also called into question the impartiality of Privacy Shield's proposed ombudsperson, a US position that would be responsible for tackling EU citizens' complaints about misuse of their data.</p><p>The group's chairwoman, Isabelle Falque-Pierrotin, said (via the <a href="http://www.bbc.co.uk/news/technology-36036531"><em>BBC</em></a>): "We believe that we don't have enough security [or] guarantees in the status of the ombudsperson and in their effective powers to be sure that this is really an independent authority."</p><p>However, it called the document a "great step forward" compared to Safe Harbour, reported <a href="http://arstechnica.co.uk/tech-policy/2016/04/privacy-shield-us-surveillance-eu-article-29-working-party"><em>Ars Technica</em></a>.</p><p>While the Working Party's conclusion does not mean the European Commission cannot approve Privacy Shield, its findings could become the basis of future legal challenges if the Commission decides not to address them.</p><p>It comes after <a href="http://www.cloudpro.co.uk/leadership/cloud-essentials/5931/box-explores-alternatives-to-privacy-shield-to-transfer-eu-data-to">both Microsoft and Box endorsed Privacy Shield</a>, though Box admitted it does not plan to rely on it, exploring alternatives like binding corporate rules as ways to transfer EU data outside of the US securely. </p><p>The watchdogs' conclusions should be published online later today.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26355/european-data-protection-supervisor-says-privacy-shield-not-robust-enough</link>
                                                                            <description>
                            <![CDATA[ Giovanni Buttarelli said the European Commission needs to develop a longer-term solution for sharing data across continents ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7X3PZqYnmPjie64B1MuEUu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jun 2016 11:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European data protection supervisor has published a report, saying Privacy Shield is not robust enough to withstand sharing of data across the world.</p><p>Giovanni Buttarelli said a number of changes need to be made in order for data to be shared reliably between countries without it putting that data or others' privacy at risk.</p><p>He said any solution used to replace Safe Harbour must provide "adequate" protection against surveillance by authorities and should be transparent, allowing</p><p>Any new legislation should also take into account data protection rights already considered by both governments and private companies in Europe. This is particularly important as the new General Data Protection Regulation (GDPR) is set to come into force in May 2018.</p><p>The European Commission needs to ensure that anything introduced to replace Safe Harbour adheres to guidelines set out in the new European legislation so there is no confusion between parties sharing data.</p><p>"I appreciate the efforts made to develop a solution to replace Safe Harbour but the Privacy Shield as it stands is not robust enough to withstand future legal scrutiny before the Court," Buttarelli said in a statement.</p><p>"Significant improvements are needed should the European Commission wish to adopt an adequacy decision, to respect the essence of key data protection principles with particular regard to necessity, proportionality and redress mechanisms. Moreover, it's time to develop a longer term solution in the transatlantic dialogue."</p><p><strong>13/04/2016: Europe data watchdogs find flaws in Privacy Shield</strong></p><p>Europe's data protection authorities have called for urgent amendments to <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield</a>, the proposed agreement to safeguard EU data transferred to the US.</p><p>The watchdogs, who form the Article 29 Working Party, do not believe the legislation is up to scratch, identifying several changes they believe need to be made.</p><p>The group is still concerned about US agencies undertaking mass surveillance on European citizens' data, after Privacy Shield's predecessor, Safe Harbour, being scrapped because it was not deemed to protect personal data adequately.</p><p>Privacy Shield would rely on assurances from the US government that it would not spy indiscriminately on EU data, but the Article 29 Working Party does not think these are enough.</p><p>It also called into question the impartiality of Privacy Shield's proposed ombudsperson, a US position that would be responsible for tackling EU citizens' complaints about misuse of their data.</p><p>The group's chairwoman, Isabelle Falque-Pierrotin, said (via the <a href="http://www.bbc.co.uk/news/technology-36036531"><em>BBC</em></a>): "We believe that we don't have enough security [or] guarantees in the status of the ombudsperson and in their effective powers to be sure that this is really an independent authority."</p><p>However, it called the document a "great step forward" compared to Safe Harbour, reported <a href="http://arstechnica.co.uk/tech-policy/2016/04/privacy-shield-us-surveillance-eu-article-29-working-party"><em>Ars Technica</em></a>.</p><p>While the Working Party's conclusion does not mean the European Commission cannot approve Privacy Shield, its findings could become the basis of future legal challenges if the Commission decides not to address them.</p><p>It comes after <a href="http://www.cloudpro.co.uk/leadership/cloud-essentials/5931/box-explores-alternatives-to-privacy-shield-to-transfer-eu-data-to">both Microsoft and Box endorsed Privacy Shield</a>, though Box admitted it does not plan to rely on it, exploring alternatives like binding corporate rules as ways to transfer EU data outside of the US securely. </p><p>The watchdogs' conclusions should be published online later today.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Has the US forced Reddit to secretly hand over user data? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Reddit users may no longer be safe from government spying.</p><p>The message forum site has removed a "warrant canary" from its latest transparency report, suggesting it has now received at least one classified request for user data.</p><p>National security letters and Foreign Intelligence Surveillance Act requests come to companies in secret requests for users' information, and the nature of these requests is such that companies are forbidden from even saying they have received them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7FeJLaUZ4CD9ZFfwgTaREo" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo-1920-80.png" mos="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The "warrant canary"</em></p><p>Reddit got around that last year by including a "warrant canary" for its <a href="https://www.reddit.com/wiki/transparency/2014" target="_blank">Transparency Report 2014</a>, that read: "As of January 29, 2015, reddit has never received a National Security Letter, an order under the Foreign Intelligence Surveillance Act, or any other classified request for user information. If we ever receive such a request, we would seek to let the public know it existed."</p><p>The idea works as a tacit admission, if the statement ever disappeared from future reports, that Reddit had received such a request.</p><p>After releasing its <a href="https://www.reddit.com/wiki/transparency/2015" target="_blank">Transparency Report 2015</a> yesterday, one user spotted that the statement was no longer included.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tY8Wunw3QX6qFfd656nD93" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93-1920-80.png" mos="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This led Reddit admin Spez <a href="https://www.reddit.com/r/announcements/comments/4cqyia/for_your_reading_pleasure_our_2015_transparency" target="_blank">to say</a>: "Even with the canaries, we're treading a fine line. The whole thing is icky, which is why we joined Twitter in pushing back."</p><p>Twitter is suing the US Department of Justice for a violation of free speech in an ongoing court case, after the department prevented the tech giant from revealing how many secret requests for user data it receives.</p><p>Reddit's apparent admission comes after <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">data protection campaigner Max Schrems sued Facebook</a> over allegedly transferring EU citizens' data to the NSA, something Facebook denied.</p><p>The court case eventually led to the European Court of Justice scrapping the Safe Harbour agreement in October 2015, saying it could not be relied upon to protect EU data transferred to the US. </p><p>A replacement agreement <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">dubbed Privacy Shield</a> is currently being considered by various parts of the EU.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26285/has-the-us-forced-reddit-to-secretly-hand-over-user-data</link>
                                                                            <description>
                            <![CDATA[ Disappearance of "warrant canary" seen as tacit admission of government data request ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rwMajcECkXVPVScd8ghEER</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6rkyQLvPU7LqhydJ5wUSfF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Apr 2016 13:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6rkyQLvPU7LqhydJ5wUSfF-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6rkyQLvPU7LqhydJ5wUSfF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Reddit users may no longer be safe from government spying.</p><p>The message forum site has removed a "warrant canary" from its latest transparency report, suggesting it has now received at least one classified request for user data.</p><p>National security letters and Foreign Intelligence Surveillance Act requests come to companies in secret requests for users' information, and the nature of these requests is such that companies are forbidden from even saying they have received them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7FeJLaUZ4CD9ZFfwgTaREo" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo-1920-80.png" mos="https://cdn.mos.cms.futurecdn.net/7FeJLaUZ4CD9ZFfwgTaREo.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The "warrant canary"</em></p><p>Reddit got around that last year by including a "warrant canary" for its <a href="https://www.reddit.com/wiki/transparency/2014" target="_blank">Transparency Report 2014</a>, that read: "As of January 29, 2015, reddit has never received a National Security Letter, an order under the Foreign Intelligence Surveillance Act, or any other classified request for user information. If we ever receive such a request, we would seek to let the public know it existed."</p><p>The idea works as a tacit admission, if the statement ever disappeared from future reports, that Reddit had received such a request.</p><p>After releasing its <a href="https://www.reddit.com/wiki/transparency/2015" target="_blank">Transparency Report 2015</a> yesterday, one user spotted that the statement was no longer included.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tY8Wunw3QX6qFfd656nD93" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93-1920-80.png" mos="https://cdn.mos.cms.futurecdn.net/tY8Wunw3QX6qFfd656nD93.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This led Reddit admin Spez <a href="https://www.reddit.com/r/announcements/comments/4cqyia/for_your_reading_pleasure_our_2015_transparency" target="_blank">to say</a>: "Even with the canaries, we're treading a fine line. The whole thing is icky, which is why we joined Twitter in pushing back."</p><p>Twitter is suing the US Department of Justice for a violation of free speech in an ongoing court case, after the department prevented the tech giant from revealing how many secret requests for user data it receives.</p><p>Reddit's apparent admission comes after <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">data protection campaigner Max Schrems sued Facebook</a> over allegedly transferring EU citizens' data to the NSA, something Facebook denied.</p><p>The court case eventually led to the European Court of Justice scrapping the Safe Harbour agreement in October 2015, saying it could not be relied upon to protect EU data transferred to the US. </p><p>A replacement agreement <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">dubbed Privacy Shield</a> is currently being considered by various parts of the EU.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Would a Brexit weaken data privacy in the UK? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>This week politicians blew lots of political FUD out of their collective nether regions around the EU 'Brexit' debate, but failed to consider how a stay' or leave' decision would affect data privacy.</p><p>All the wafty hot air from Iain Duncan Smith about staying in the EU making us more vulnerable to a Paris-style terror attack is, frankly, just that. I'd have been more impressed if he had taken the time out to examine how our EU status might impact data protection.</p><p>When industry trade body techUK asked its members <a href="https://www.techuk.org/member-eu-survey/eu_membership_survey" target="_blank">if they wanted in or out of the EU</a> last year, 71 per cent were in the stay camp, if the UK's agreement with the EU was reformed.</p><p>A total 78 per cent insisted that a UK outside the EU would have less influence on tech industry issues.</p><p>These issues include data protection, specifically <a href="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations" target="_blank" data-original-url="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations">the EU's General Data Protection Regulations (GDPR)</a>, which are set to come into force between now and 2018.</p><p>Only a complete fool would argue that leaving the EU would mean these rules no longer apply to us.</p><p>But what worries me is that if we do vote to leave the EU, then the UK will have to come up with a variant of <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">the new Privacy Shield data-transfer agreement</a> that replaced the defunct Safe Harbour deal, which ostensibly stopped the US spying on EU data.</p><p>I was no fan of the so-called Safe Harbour agreement. It was evident from the get-go that the USA was more interested in data snooping under the national security banner than any meaningful measure of privacy. What's more, it was also evident that the EU and the UK knew that and turned a blind eye to it.</p><p>Nothing will change under the Privacy Shield agreement, which requires the US to promise not to participate 'on its mum's life' in mass surveillance of EU citizens. Yeah right. I've called that <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">laudable in principle and laughable in practice</a>.</p><p>If I'm so against this, then surely I should support a Brexit in order to escape such regulation? Well, no, because the alternative is likely to be much worse.</p><p>Look at what Prime Minister David Cameron and Home Secretary Theresa May's Investigator Powers Bill. Earlier this month <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products"><em>IT Pro</em> reported</a> how this "risks destroying UK technology firms' reputations on cybersecurity and privacy, according to experts, civil liberties campaigners and industry trade bodies". This directly opposes the GDPR, which are designed to give citizens more control over who can see and access their data.</p><p>If we do leave the EU, we would have to obey the GDPR anyway if we want to continue doing trade with the rest of Europe, as well as demonstrate an adequate level of data protection.</p><p>But, depending on the nature of the government at the time, I suspect there will come a point where the 'all your data belongs to us' mentality that underpins the Investigatory Powers Bill shines through and trumps meaningful GDPR implementation.</p><p>That will leave the EU having to decide how it deals with a UK that resists GDPR when dealing with EU citizen data, and UK PLC suffering the consequences of the almost inevitable trading fallout.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/26119/would-a-brexit-weaken-data-privacy-in-the-uk</link>
                                                                            <description>
                            <![CDATA[ Data privacy should be a central issue in debate of EU referendum pros and cons ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ5Hn9oAdYKCn3M23QzWEj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Feb 2016 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This week politicians blew lots of political FUD out of their collective nether regions around the EU 'Brexit' debate, but failed to consider how a stay' or leave' decision would affect data privacy.</p><p>All the wafty hot air from Iain Duncan Smith about staying in the EU making us more vulnerable to a Paris-style terror attack is, frankly, just that. I'd have been more impressed if he had taken the time out to examine how our EU status might impact data protection.</p><p>When industry trade body techUK asked its members <a href="https://www.techuk.org/member-eu-survey/eu_membership_survey" target="_blank">if they wanted in or out of the EU</a> last year, 71 per cent were in the stay camp, if the UK's agreement with the EU was reformed.</p><p>A total 78 per cent insisted that a UK outside the EU would have less influence on tech industry issues.</p><p>These issues include data protection, specifically <a href="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations" target="_blank" data-original-url="https://www.itpro.com/it-legislation/25806/eu-finally-agrees-on-general-data-protection-regulations">the EU's General Data Protection Regulations (GDPR)</a>, which are set to come into force between now and 2018.</p><p>Only a complete fool would argue that leaving the EU would mean these rules no longer apply to us.</p><p>But what worries me is that if we do vote to leave the EU, then the UK will have to come up with a variant of <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">the new Privacy Shield data-transfer agreement</a> that replaced the defunct Safe Harbour deal, which ostensibly stopped the US spying on EU data.</p><p>I was no fan of the so-called Safe Harbour agreement. It was evident from the get-go that the USA was more interested in data snooping under the national security banner than any meaningful measure of privacy. What's more, it was also evident that the EU and the UK knew that and turned a blind eye to it.</p><p>Nothing will change under the Privacy Shield agreement, which requires the US to promise not to participate 'on its mum's life' in mass surveillance of EU citizens. Yeah right. I've called that <a href="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection" target="_blank" data-original-url="https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection">laudable in principle and laughable in practice</a>.</p><p>If I'm so against this, then surely I should support a Brexit in order to escape such regulation? Well, no, because the alternative is likely to be much worse.</p><p>Look at what Prime Minister David Cameron and Home Secretary Theresa May's Investigator Powers Bill. Earlier this month <a href="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products" target="_blank" data-original-url="https://www.itpro.com/data-protection/25968/snoopers-charter-could-destroy-customer-trust-in-uk-products"><em>IT Pro</em> reported</a> how this "risks destroying UK technology firms' reputations on cybersecurity and privacy, according to experts, civil liberties campaigners and industry trade bodies". This directly opposes the GDPR, which are designed to give citizens more control over who can see and access their data.</p><p>If we do leave the EU, we would have to obey the GDPR anyway if we want to continue doing trade with the rest of Europe, as well as demonstrate an adequate level of data protection.</p><p>But, depending on the nature of the government at the time, I suspect there will come a point where the 'all your data belongs to us' mentality that underpins the Investigatory Powers Bill shines through and trumps meaningful GDPR implementation.</p><p>That will leave the EU having to decide how it deals with a UK that resists GDPR when dealing with EU citizen data, and UK PLC suffering the consequences of the almost inevitable trading fallout.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy Shield hammers another nail in the coffin of data protection ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Safe Harbour is dead, long live the Privacy Shield. Although, to be honest, <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">the all-new US data transfer agreement</a> is already a dead man walking if you ask me. Indeed, a better name for it would be the Privacy Coffin.</p><p>Why the hostility? Consider this: <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">the European Court of Justice (ECJ) killed Safe Harbour in October</a> when it ruled that, essentially, the US was more interested in national security and law enforcement matters (also known as snooping the bejesus out of everyone) over and above any guarantees of meaningful privacy.</p><p>Since then, absolutely nothing has changed.</p><p>The Privacy Shield framework requires the US to give a written promise, on a yearly basis, that hand-on-heart it won't participate in mass surveillance of EU citizens.</p><p>This is laudable in principle and laughable in practice.</p><p>Any talk of 'clear limitations and safeguards', and most of all 'oversight mechanisms', in the context of the NSA is, frankly, a crock. Not least because the US explicitly allows mass surveillance of the very kind it's promising not to carry out.</p><p>The NSA doesn't consider it mass surveillance if they collect the data, only if they analyse it. But calling it something different does not mean it's not happening. </p><p>Seriously, replacing one fundamentally flawed framework with another and giving it a new X-Men movie name does not fix the problem. That problem being that neither the EU, UK nor the US actually gives a flying feck about your privacy.</p><p>At best, this optimistically-named Privacy Shield is nothing more than a stop-gap solution. It will enable the transatlantic data flow to, erm, flow once more. But not for long. I imagine the ECJ will take a long, hard look at the agreement and announce it, too, as invalid.</p><p>What really worries me, and should worry you as well, if this is a stop-gap, a temporary measure to ensure that data keeps flowing; is what comes next? </p><p>If, as I suspect, it will be more of the same political manoeuvring rather than something that really addresses the matter of data privacy in the post-Snowden era, then we are all screwed. Or, more accurately, we will continue to be screwed.</p><p>As long as we continue to take government agencies on both sides of the pond at their word when it comes to what they can and cannot spy upon, then nothing will change.</p><p>My advice, therefore, remains the same as it has always been: encrypt your data up the wazoo and manage your own keys to close the snooping opportunity window.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/26005/privacy-shield-hammers-another-nail-in-the-coffin-of-data-protection</link>
                                                                            <description>
                            <![CDATA[ Safe Harbour’s replacement is based entirely on trust - what a big mistake ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c8pr9DZBprbDK9UCtmferk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MG97BpWbwHcRm9oGh8g4b4-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Feb 2016 15:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MG97BpWbwHcRm9oGh8g4b4-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MG97BpWbwHcRm9oGh8g4b4-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Safe Harbour is dead, long live the Privacy Shield. Although, to be honest, <a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">the all-new US data transfer agreement</a> is already a dead man walking if you ask me. Indeed, a better name for it would be the Privacy Coffin.</p><p>Why the hostility? Consider this: <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">the European Court of Justice (ECJ) killed Safe Harbour in October</a> when it ruled that, essentially, the US was more interested in national security and law enforcement matters (also known as snooping the bejesus out of everyone) over and above any guarantees of meaningful privacy.</p><p>Since then, absolutely nothing has changed.</p><p>The Privacy Shield framework requires the US to give a written promise, on a yearly basis, that hand-on-heart it won't participate in mass surveillance of EU citizens.</p><p>This is laudable in principle and laughable in practice.</p><p>Any talk of 'clear limitations and safeguards', and most of all 'oversight mechanisms', in the context of the NSA is, frankly, a crock. Not least because the US explicitly allows mass surveillance of the very kind it's promising not to carry out.</p><p>The NSA doesn't consider it mass surveillance if they collect the data, only if they analyse it. But calling it something different does not mean it's not happening. </p><p>Seriously, replacing one fundamentally flawed framework with another and giving it a new X-Men movie name does not fix the problem. That problem being that neither the EU, UK nor the US actually gives a flying feck about your privacy.</p><p>At best, this optimistically-named Privacy Shield is nothing more than a stop-gap solution. It will enable the transatlantic data flow to, erm, flow once more. But not for long. I imagine the ECJ will take a long, hard look at the agreement and announce it, too, as invalid.</p><p>What really worries me, and should worry you as well, if this is a stop-gap, a temporary measure to ensure that data keeps flowing; is what comes next? </p><p>If, as I suspect, it will be more of the same political manoeuvring rather than something that really addresses the matter of data privacy in the post-Snowden era, then we are all screwed. Or, more accurately, we will continue to be screwed.</p><p>As long as we continue to take government agencies on both sides of the pond at their word when it comes to what they can and cannot spy upon, then nothing will change.</p><p>My advice, therefore, remains the same as it has always been: encrypt your data up the wazoo and manage your own keys to close the snooping opportunity window.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU throws US data transfers into doubt – again ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Companies that transfer European data to the US may be open to legal challenges after the EU refused to extend a grace period in the absence of any agreement guaranteeing that data's safety.</p><p>EU and US officials this week touted <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">Privacy Shield</a> as a successor to the now-defunct Safe Harbour deal, which had guaranteed adequate protection for European data transferred abroad.</p><p>But with months to go until Privacy Shield is officially approved, EU data regulators yesterday declined to extend a policy of no active enforcement against companies continuing to transfer data to the US without the protection of any valid deal.</p><p>Around 4,000 companies relied on the Safe Harbour agreement, and those who have not moved to an alternative data transfer mechanism are now at risk of enforcement actions.</p><p>Vinod Bange, head of UK data protection and privacy practice at law firm Taylor Wessing, told <em>IT Pro</em>: "UK PLC deserves better than this, Europe deserves better than this."</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid last October</a>, when the European Court of Justice decided that America valued anti-terrorist measures such as data surveillance above people's privacy.</p><p>While Europe and the US renegotiated the agreement, the EU announced a three-month grace period in which companies could carry on moving data to the US.</p><p>Some opted to use methods like model contract clauses and binding corporate rules, but others still worked under the umbrella of the invalid Safe Harbour agreement.</p><p>The Article 29 Working Party, a group of EU data protection regulators, <a href="http://united-kingdom.taylorwessing.com/en/article-29-working-party-cautious-about-eu-us-privacy-shield" target="_blank">said</a> those companies yet to adopt an alternative transfer mechanism could now be punished for transferring data to the US.</p><p>Head of the group, Isabelle Falque-Pierrotin, said in a press conference, quoted by <a href="http://www.out-law.com/en/articles/2016/february/deal-on-eu-us-privacy-shield-leads-eu-watchdogs-to-extend-moratorium-on-data-transfers-enforcement-action" target="_blank"><em>Out-Law.com</em></a>: "If companies are using the former Safe Harbour framework, it is illegal because this has clearly been invalidated by the judges."</p><p>Member states' own data watchdogs could now decide whether or not to take action against companies if they receive complaints.</p><p>But Bange said: "What happens to all those companies that were covered by Safe Harbour and have been left stranded in this abyss, and those who haven't found the right mechanism yet?</p><p>"There won't be an extended grace period. She said it would be up to individual states' regulators on how to respond to complaints."</p><p>While the Working Party claims many companies have shifted to using alternative data transfer methods, Bange said many have yet to migrate to a different mechanism, calling some of them unsuitable.</p><p>"Many are still grappling with this fundamental issue - how do they resolve their situation without using model clauses that were drafted a long time ago without considering the cloud scenario we are in now?" the lawyer said.</p><p>Whether they are suitable or not, the Working Party said these transfer mechanisms will remain valid until it has completed its assessment of Privacy Shield - likely by the middle of April.</p><p>It has asked the European Commission to provide all relevant Privacy Shield documents by the end of February.</p><p><a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield aims to offer stronger data protection to EU citizens</a>, with the US providing written assurances it will not undertake mass surveillance of European data.</p><p>It also plans to set up an Ombudsperson to investigate accusations of spying, and force companies to respond to data complaints by certain deadlines.</p><p>The agreement drew a mixed reaction from businesses and privacy campaigners, with the latter group saying the agreement is not backed up by US law, which does allow mass surveillance.</p><p>Jim Killock, executive director of Open Rights Group said: "The rights we have under data protection, such as the right to obtain and correct our personal data, need to be legally enforceable in the USA, for every EU citizen. There seems to be great reluctance to introduce these rights in full in the USA for Europeans.</p><p>"The EU Commission is making matters worse by failing to communicate how serious the EU Court of Justice's demands are. Unless both the EU and USA face up to the need to protect our individual data protection rights, it will end up back in court.</p><p>"That will be no good for citizens or industry."</p><p>UK cloud firm Skyhigh Networks welcomed the agreement, however.</p><p>Kamal Shah, senior VP of products, said: "We are thrilled with the news from Brussels. The data flows between the USA and EU are so important to global business that it could have been a disaster if the previous confused situation was extended. Here's hoping that the full text is acceptable to all sides and businesses can transfer data across the Atlantic without fear of legal challenge."</p><p>The EU is now drafting an "adequacy decision" for the coming weeks, which the European Commission could adopt after receiving the Working Party's advice, and after consulting all member states.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/25986/eu-throws-us-data-transfers-into-doubt-again</link>
                                                                            <description>
                            <![CDATA[ Europe’s data watchdog refuses to extend Safe Harbour grace period ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">scjeZvFXkXA8iwuwXBWzLD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Feb 2016 10:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies that transfer European data to the US may be open to legal challenges after the EU refused to extend a grace period in the absence of any agreement guaranteeing that data's safety.</p><p>EU and US officials this week touted <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">Privacy Shield</a> as a successor to the now-defunct Safe Harbour deal, which had guaranteed adequate protection for European data transferred abroad.</p><p>But with months to go until Privacy Shield is officially approved, EU data regulators yesterday declined to extend a policy of no active enforcement against companies continuing to transfer data to the US without the protection of any valid deal.</p><p>Around 4,000 companies relied on the Safe Harbour agreement, and those who have not moved to an alternative data transfer mechanism are now at risk of enforcement actions.</p><p>Vinod Bange, head of UK data protection and privacy practice at law firm Taylor Wessing, told <em>IT Pro</em>: "UK PLC deserves better than this, Europe deserves better than this."</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid last October</a>, when the European Court of Justice decided that America valued anti-terrorist measures such as data surveillance above people's privacy.</p><p>While Europe and the US renegotiated the agreement, the EU announced a three-month grace period in which companies could carry on moving data to the US.</p><p>Some opted to use methods like model contract clauses and binding corporate rules, but others still worked under the umbrella of the invalid Safe Harbour agreement.</p><p>The Article 29 Working Party, a group of EU data protection regulators, <a href="http://united-kingdom.taylorwessing.com/en/article-29-working-party-cautious-about-eu-us-privacy-shield" target="_blank">said</a> those companies yet to adopt an alternative transfer mechanism could now be punished for transferring data to the US.</p><p>Head of the group, Isabelle Falque-Pierrotin, said in a press conference, quoted by <a href="http://www.out-law.com/en/articles/2016/february/deal-on-eu-us-privacy-shield-leads-eu-watchdogs-to-extend-moratorium-on-data-transfers-enforcement-action" target="_blank"><em>Out-Law.com</em></a>: "If companies are using the former Safe Harbour framework, it is illegal because this has clearly been invalidated by the judges."</p><p>Member states' own data watchdogs could now decide whether or not to take action against companies if they receive complaints.</p><p>But Bange said: "What happens to all those companies that were covered by Safe Harbour and have been left stranded in this abyss, and those who haven't found the right mechanism yet?</p><p>"There won't be an extended grace period. She said it would be up to individual states' regulators on how to respond to complaints."</p><p>While the Working Party claims many companies have shifted to using alternative data transfer methods, Bange said many have yet to migrate to a different mechanism, calling some of them unsuitable.</p><p>"Many are still grappling with this fundamental issue - how do they resolve their situation without using model clauses that were drafted a long time ago without considering the cloud scenario we are in now?" the lawyer said.</p><p>Whether they are suitable or not, the Working Party said these transfer mechanisms will remain valid until it has completed its assessment of Privacy Shield - likely by the middle of April.</p><p>It has asked the European Commission to provide all relevant Privacy Shield documents by the end of February.</p><p><a href="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data" target="_blank" data-original-url="https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data">Privacy Shield aims to offer stronger data protection to EU citizens</a>, with the US providing written assurances it will not undertake mass surveillance of European data.</p><p>It also plans to set up an Ombudsperson to investigate accusations of spying, and force companies to respond to data complaints by certain deadlines.</p><p>The agreement drew a mixed reaction from businesses and privacy campaigners, with the latter group saying the agreement is not backed up by US law, which does allow mass surveillance.</p><p>Jim Killock, executive director of Open Rights Group said: "The rights we have under data protection, such as the right to obtain and correct our personal data, need to be legally enforceable in the USA, for every EU citizen. There seems to be great reluctance to introduce these rights in full in the USA for Europeans.</p><p>"The EU Commission is making matters worse by failing to communicate how serious the EU Court of Justice's demands are. Unless both the EU and USA face up to the need to protect our individual data protection rights, it will end up back in court.</p><p>"That will be no good for citizens or industry."</p><p>UK cloud firm Skyhigh Networks welcomed the agreement, however.</p><p>Kamal Shah, senior VP of products, said: "We are thrilled with the news from Brussels. The data flows between the USA and EU are so important to global business that it could have been a disaster if the previous confused situation was extended. Here's hoping that the full text is acceptable to all sides and businesses can transfer data across the Atlantic without fear of legal challenge."</p><p>The EU is now drafting an "adequacy decision" for the coming weeks, which the European Commission could adopt after receiving the Working Party's advice, and after consulting all member states.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Will the new Safe Harbour deal really protect your data? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The EU and US have reached a last-minute deal to ensure companies can transfer European data to American soil.</p><p>The new agreement provides guarantees that personal data from the EU will receive adequate protection when processed by US firms, and replaces a defunct deal that around 4,000 businesses relied on.</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid</a> by the EU last October when it decided the US valued national security and law enforcement over the guarantee of privacy.</p><p>Its replacement, <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">the EU-US Privacy Shield</a>, was hailed by the EU as a way of resolving the issue.</p><p>European Commission vice president Andrus Ansip said: "We have agreed with our US partners a new framework that will ensure the right checks and balances for our citizens.</p><p>"We have for the first time received detailed written assurances from the US on the safeguards and limitations applicable to US surveillance programmes."</p><p>In some ways it is stronger than Safe Harbour though. Where the former agreement did not check companies were meeting their obligations to protect data, the new deal forces companies to publish their commitments, making them enforceable under US law.</p><p>The US has also given the EU written assurances that it will not carry out "indiscriminate mass surveillance" on data transferred under the scheme.</p><p>Companies will have deadlines by which they must respond to complaints from people who feel their data has been misused, while data watchdogs can refer those complaints to US authorities.</p><p>Furthermore, any accusations of spies accessing people's data will be investigated by a new Ombudsperson.</p><p>However, the new agreement has been met with mixed reaction from businesses and data protection campaigners.</p><p>TechUK, an industry trade body representing more than 800 companies, welcomed Privacy Shield.</p><p>Deputy CEO Anthony Walker said: "Today's announcement of a new deal for EU - US data transfers is extremely important. The European Commission and US Administration must now show total commitment to implementing this and getting transatlantic data flows back onto a secure and stable legal footing.</p><p>"Businesses large and small across Europe need reliable and affordable legal mechanisms to enable the data transfers that underpin their operations and ability to serve customers."</p><p>The Information Technology and Innovation Foundation (ITIF), also welcomed the agreement, and criticised the decision to revoke Safe Harbour.</p><p>Vice president Daniel Castro said: "We commend US and European negotiators for completing an agreement that avoids disrupting the transatlantic digital economy in the near term by ensuring continuity for the thousands of US and European companies providing services across the two markets."</p><p>But others are more sceptical, with one lawyer claiming Privacy Shield's reputation is already "shot to pieces".</p><p>Phil Lee, data protection partner at European law firm Fieldfisher, said: "Keeping in mind that this new Safe Harbour will almost certainly be challenged by civil liberties groups (and possibly even some data protection authorities) pretty much immediately, only the foolhardy would place want to place their trust in a new Safe Harbour right now. Whether legal or not, its reputation is already shot to pieces."</p><p>Privacy campaigner Max Schrems, <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">whose lawsuit against Facebook</a> led to the original Safe Harbour being ruled invalid, also spoke out against the new agreement.</p><p>He claimed that despite the US' written assurances of not spying on EU data, there have thus far been no changes to its legal system to reflect this.</p><p>"A couple of letters by the outgoing Obama administration is by no means a legal basis to guarantee the fundamental rights of 500 million European users in the long run, when there is explicit US law allowing mass surveillance," <a href="http://europe-v-facebook.org/PS_update.pdf" target="_blank">he wrote</a>.</p><p>"I doubt that a European can walk to a US court and claim his fundamental rights based on a letter by someone. The Commission could to be en route to issuing a round-trip to the European Court in Luxembourg and back. This would also not provide any legal certainty for businesses - at the most it would provide a couple more months to adapt."</p><p>He ended his evaluation by warning that people will challenge the new agreement, adding that he may be among them.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-protection/25978/will-the-new-safe-harbour-deal-really-protect-your-data</link>
                                                                            <description>
                            <![CDATA[ Businesses and campaigners react to Privacy Shield, the new EU-US data transfer agreement ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jW8GRc32LkeDd4spmZRRur</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fS272S763cqVUYJ89d39RQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Feb 2016 18:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fS272S763cqVUYJ89d39RQ-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flag]]></media:description>                                                            <media:text><![CDATA[EU flag]]></media:text>
                                <media:title type="plain"><![CDATA[EU flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fS272S763cqVUYJ89d39RQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU and US have reached a last-minute deal to ensure companies can transfer European data to American soil.</p><p>The new agreement provides guarantees that personal data from the EU will receive adequate protection when processed by US firms, and replaces a defunct deal that around 4,000 businesses relied on.</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour was ruled invalid</a> by the EU last October when it decided the US valued national security and law enforcement over the guarantee of privacy.</p><p>Its replacement, <a href="http://europa.eu/rapid/press-release_IP-16-216_en.htm" target="_blank">the EU-US Privacy Shield</a>, was hailed by the EU as a way of resolving the issue.</p><p>European Commission vice president Andrus Ansip said: "We have agreed with our US partners a new framework that will ensure the right checks and balances for our citizens.</p><p>"We have for the first time received detailed written assurances from the US on the safeguards and limitations applicable to US surveillance programmes."</p><p>In some ways it is stronger than Safe Harbour though. Where the former agreement did not check companies were meeting their obligations to protect data, the new deal forces companies to publish their commitments, making them enforceable under US law.</p><p>The US has also given the EU written assurances that it will not carry out "indiscriminate mass surveillance" on data transferred under the scheme.</p><p>Companies will have deadlines by which they must respond to complaints from people who feel their data has been misused, while data watchdogs can refer those complaints to US authorities.</p><p>Furthermore, any accusations of spies accessing people's data will be investigated by a new Ombudsperson.</p><p>However, the new agreement has been met with mixed reaction from businesses and data protection campaigners.</p><p>TechUK, an industry trade body representing more than 800 companies, welcomed Privacy Shield.</p><p>Deputy CEO Anthony Walker said: "Today's announcement of a new deal for EU - US data transfers is extremely important. The European Commission and US Administration must now show total commitment to implementing this and getting transatlantic data flows back onto a secure and stable legal footing.</p><p>"Businesses large and small across Europe need reliable and affordable legal mechanisms to enable the data transfers that underpin their operations and ability to serve customers."</p><p>The Information Technology and Innovation Foundation (ITIF), also welcomed the agreement, and criticised the decision to revoke Safe Harbour.</p><p>Vice president Daniel Castro said: "We commend US and European negotiators for completing an agreement that avoids disrupting the transatlantic digital economy in the near term by ensuring continuity for the thousands of US and European companies providing services across the two markets."</p><p>But others are more sceptical, with one lawyer claiming Privacy Shield's reputation is already "shot to pieces".</p><p>Phil Lee, data protection partner at European law firm Fieldfisher, said: "Keeping in mind that this new Safe Harbour will almost certainly be challenged by civil liberties groups (and possibly even some data protection authorities) pretty much immediately, only the foolhardy would place want to place their trust in a new Safe Harbour right now. Whether legal or not, its reputation is already shot to pieces."</p><p>Privacy campaigner Max Schrems, <a href="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy" target="_blank" data-original-url="https://www.itpro.com/data-protection/24361/facebook-hit-by-class-action-lawsuit-focused-on-data-privacy">whose lawsuit against Facebook</a> led to the original Safe Harbour being ruled invalid, also spoke out against the new agreement.</p><p>He claimed that despite the US' written assurances of not spying on EU data, there have thus far been no changes to its legal system to reflect this.</p><p>"A couple of letters by the outgoing Obama administration is by no means a legal basis to guarantee the fundamental rights of 500 million European users in the long run, when there is explicit US law allowing mass surveillance," <a href="http://europe-v-facebook.org/PS_update.pdf" target="_blank">he wrote</a>.</p><p>"I doubt that a European can walk to a US court and claim his fundamental rights based on a letter by someone. The Commission could to be en route to issuing a round-trip to the European Court in Luxembourg and back. This would also not provide any legal certainty for businesses - at the most it would provide a couple more months to adapt."</p><p>He ended his evaluation by warning that people will challenge the new agreement, adding that he may be among them.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Firms will suffer if new Safe Harbour deal fails, Obama warned ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Thousands of businesses will lose out if the US and EU fail to renew the Safe Harbour agreement at the start of next month, trade groups have told US President Barack Obama.</p><p>The US Chamber of Commerce, BusinessEurope, DigitalEurope and the Information Technology Industry Council penned an open letter to US President Barack Obama and European Commission President Jean-Claude Juncker warning of the consequences if a new data protection deal is not forthcoming.</p><p>They wrote: "This issue must be resolved immediately or the consequences could be enormous for the thousands of businesses and millions of users impacted."</p><p>The Safe Harbour agreement, which protected EU data from government access when transferred to the US, <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">was ruled invalid last year</a> after the European Court of Justice decided America would value anti-terrorist measures above personal privacy.</p><p>Privacy regulators will meet in Brussels on 2 February to complete a renegotiation of the deal.</p><p>But the open letter also argued for a transition period to allow smaller businesses that rely on <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">Safe Harbour</a> to transfer to the new legislation in a longer timeframe without being punished. </p><p>However, EU Justice Commissioner Vera Jourova, who is in charge of the negotiations on behalf of the EU, explained at a conference that the issue is a lot more complicated than simply coming up with a quick-fire solution.</p><p>"Only a comprehensive arrangement with clear legal commitments can ensure the protection of personal data," she said. "When data travels, the protection has to travel with it."</p><p>Negotiations are set to continue this week at the World Economic Forum in Davos as European and US officials try to object to EU privacy regulators' ruling that Safe Harbour is invalid.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25885/firms-will-suffer-if-new-safe-harbour-deal-fails-obama-warned</link>
                                                                            <description>
                            <![CDATA[ Trade groups warn Obama and Juncker over consequences if no new data pact is agreed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xxV4qKnAPJAvZkch2u6ziL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Jan 2016 09:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Thousands of businesses will lose out if the US and EU fail to renew the Safe Harbour agreement at the start of next month, trade groups have told US President Barack Obama.</p><p>The US Chamber of Commerce, BusinessEurope, DigitalEurope and the Information Technology Industry Council penned an open letter to US President Barack Obama and European Commission President Jean-Claude Juncker warning of the consequences if a new data protection deal is not forthcoming.</p><p>They wrote: "This issue must be resolved immediately or the consequences could be enormous for the thousands of businesses and millions of users impacted."</p><p>The Safe Harbour agreement, which protected EU data from government access when transferred to the US, <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">was ruled invalid last year</a> after the European Court of Justice decided America would value anti-terrorist measures above personal privacy.</p><p>Privacy regulators will meet in Brussels on 2 February to complete a renegotiation of the deal.</p><p>But the open letter also argued for a transition period to allow smaller businesses that rely on <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">Safe Harbour</a> to transfer to the new legislation in a longer timeframe without being punished. </p><p>However, EU Justice Commissioner Vera Jourova, who is in charge of the negotiations on behalf of the EU, explained at a conference that the issue is a lot more complicated than simply coming up with a quick-fire solution.</p><p>"Only a comprehensive arrangement with clear legal commitments can ensure the protection of personal data," she said. "When data travels, the protection has to travel with it."</p><p>Negotiations are set to continue this week at the World Economic Forum in Davos as European and US officials try to object to EU privacy regulators' ruling that Safe Harbour is invalid.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Safe Harbour proposals 'must include suspension clause' ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The second iteration of the <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour</a> data sharing initiative between Europe and the US must be able to be suspended if the EU feels privacy concerns appear again.</p><p>The EU Justice Commissioner said following the suspension of the original Safe Harbour legislation in October, any new version of the agreement would be subject to a suspension clause.</p><p>"We have been negotiating a renewed, safer arrangement for transatlantic data transfers with our American partners since 2014," Commissioner Vera Jourova said.</p><p>"A renewed arrangement that will mean robust safeguards for citizens and legal certainty for businesses. I got the impression in Washington that the US side shares this aim and I hope they share our sense of urgency after the judgement."</p><p>"In the new Safe Harbour there will be a suspension clause, saying that under concrete conditions we are going to suspend (it)," Jourova said.</p><p>The understanding is meant to guarantee the same level of protection for EU data when it is transferred to the US.</p><p>However, the EU Court of Justice ruled the last Safe Harbour agreement invalid following many of NSA whistleblower Edward Snowden's revelations that led the court to decide the US would value anti-terrorism measures above personal privacy.</p><p>The agreement also relied on the self-certification of American businesses that they would protect data when transferred to a US-based datacentre, but Snowden revealed this data can still be snooped upon by authorities, meaning customer data was not safe from prying eyes at all.</p><p>Some of the companies using Safe Harbour as justification for transferring data between the EU and US could face legal action in January 2016 while the second iteration of the bill are discussed.</p><p>The parties <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" target="_blank" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">have until 31 January 2016</a> to reach a new agreement.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/strategy/25731/new-safe-harbour-proposals-must-include-suspension-clause</link>
                                                                            <description>
                            <![CDATA[ EU: We should instantly stop sharing data with US if privacy under threat ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h4Y96bLtJ7aJ7aBs3vKVeG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2B95cpsCBxVbuTGjPty6JK-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Dec 2015 09:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2B95cpsCBxVbuTGjPty6JK-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Europe and middle east map at night lit up with data lines]]></media:description>                                                            <media:text><![CDATA[Europe and middle east map at night lit up with data lines]]></media:text>
                                <media:title type="plain"><![CDATA[Europe and middle east map at night lit up with data lines]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2B95cpsCBxVbuTGjPty6JK-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The second iteration of the <a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked" target="_blank">Safe Harbour</a> data sharing initiative between Europe and the US must be able to be suspended if the EU feels privacy concerns appear again.</p><p>The EU Justice Commissioner said following the suspension of the original Safe Harbour legislation in October, any new version of the agreement would be subject to a suspension clause.</p><p>"We have been negotiating a renewed, safer arrangement for transatlantic data transfers with our American partners since 2014," Commissioner Vera Jourova said.</p><p>"A renewed arrangement that will mean robust safeguards for citizens and legal certainty for businesses. I got the impression in Washington that the US side shares this aim and I hope they share our sense of urgency after the judgement."</p><p>"In the new Safe Harbour there will be a suspension clause, saying that under concrete conditions we are going to suspend (it)," Jourova said.</p><p>The understanding is meant to guarantee the same level of protection for EU data when it is transferred to the US.</p><p>However, the EU Court of Justice ruled the last Safe Harbour agreement invalid following many of NSA whistleblower Edward Snowden's revelations that led the court to decide the US would value anti-terrorism measures above personal privacy.</p><p>The agreement also relied on the self-certification of American businesses that they would protect data when transferred to a US-based datacentre, but Snowden revealed this data can still be snooped upon by authorities, meaning customer data was not safe from prying eyes at all.</p><p>Some of the companies using Safe Harbour as justification for transferring data between the EU and US could face legal action in January 2016 while the second iteration of the bill are discussed.</p><p>The parties <a href="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016" target="_blank" data-original-url="https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016">have until 31 January 2016</a> to reach a new agreement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US and EU must reach new Safe Harbour deal by January 2016 ]]></title>
                                                                                                <dc:content><![CDATA[ <p><strong>20/10/2015: </strong>EU data protection regulators have set a deadline for a revised Safe Harbour agreement, after it was ruled invalid earlier this month.</p><p>The European Court of Justice decided that Safe Harbour did not give data tranfers between Europe and the US adequate protection at the start of October, declaring the agreement void, but the court has given the EU and US until 31 January 2016 to agree on a new deal.</p><p>If a solution is not found by that time, regulators will begin taking steps to enforce the ruling.</p><p>"EU data protection authorities are committed to take all necessary and appropriate actions, which may include coordinated enforcement actions", the court wrote in a <a href="http://ec.europa.eu/justice/data-protection/article-29/index_en.htm" target="_blank">statement</a>.</p><p>Elizabeth Maxwell, data regulation expert at Compuware, said the decision has "sent a ripple across the water".</p><p>"Around 4,500 US companies use the Safe Harbour agreement and related certification to allow them to do business with the European Economic Area. This judgement is providing a very definite message to the world that data privacy is a serious matter and there will be serious consequences for non-compliance," she added.</p><p><strong>12/10/2015: </strong>Dropbox is reviewing the ruling that declared the Safe Harbour agreement invalid and has not yet committed to building a European datacentre to overcome the issue.</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked">Safe Harbour</a> was a longstanding EU-US principle that guaranteed any EU data transferred to America would receive the same safeguards enjoyed within the EU.</p><p>But the European Court of Justice (ECJ) last week concluded that the agreement no longer affords EU citizens' data privacy and ruled the agreement to be invalid.</p><p>Its decision was based on evidence of US spy initiatives like PRISM, which Austrian privacy campaigner Max Schrems argued meant America could not guarantee European citizens' data would remain private.</p><p>The fallout from the ruling could provoke a scramble to build EU datacentres, with file-sharing firm Box already confirming that customers will be able to store data within the EU come a year's time.</p><p>But Dropbox has made no such commitment, responding to <em>IT Pro</em>'s questions to say only that it is reviewing the ECJ's decision.</p><p>A spokeswoman said: "Dropbox is committed to upholding the security and privacy of customer data. We are currently reviewing the court's decision in detail, and will continue partnering with our EU users and customers on their ongoing usage of our services."</p><p>In fact, the firm told <em>Cloud Pro</em> back in May that it <a href="http://www.cloudpro.co.uk/cloud-essentials/cloud-security/5088/dropbox-for-business-seeks-europe-data-transparency">had no plans at all to build an EU datacentre</a>.</p><p>UK chief Mark van der Linden said at the time: "That's completely not on the roadmap. Location in our opinion is only one piece of the puzzle. </p><p>In contrast, Box CEO Aaron Levie told <em><a href="http://www.telegraph.co.uk/finance/newsbysector/mediatechnologyandtelecoms/digital-media/11917628/Box-to-open-European-data-centres-after-ECJ-privacy-ruling.html">the Telegraph</a> </em>last week: "In a year from now I would absolutely expect we will have customers storing their data internationally. We're building towards it now."</p><p>It could leverage datacentres belonging to enterprise partner IBM to fulfill this aim.</p><p>Existing file-sharing competitors Google and Amazon Web Services have a number of European datacentres, while another rival, Egnyte, allows people to store their data in the cloud or on-premise, meaning they do not have to trust it to the public cloud.</p><p>However, there are a number of considerations for cloud service providers seeking to respond to the latest ruling, before they commit to building new data storage sites.</p><p><strong>Data transfers to the US are not actually illegal</strong></p><p>The first is that the Safe Harbour agreement was being reworked regardless of the ECJ's ruling a new and improved framework could be announced by the US and the European Commission as early as the end of 2015.</p><p>Secondly, as IDC's research director for European security, Duncan Brown, <a href="https://www.linkedin.com/pulse/impact-safe-harbor-judgement-data-transfers-cloud-duncan">pointed out</a>, the ruling does not render EU-US data transfers illegal.</p><p>"The judgement compels each EU nation's data protection authority (DPA) to investigate fully any complaint against a data processor transferring data to the US," he said.</p><p>"However, data processors may now be subject to multiple court cases that the DPAs are now obligated to investigate, and individual data transfers may be deemed to be non-compliant."</p><p><strong>EU datacentres may not be enough</strong></p><p>A wider issue that remains unresolved may explain Dropbox's non-committal response to the Safe Harbour ruling so far.</p><p>The issue in question is Microsoft's appeal against a court decision commanding it to <a href="https://www.itpro.com/it-legislation/25261/microsoft-heads-back-to-court-in-data-sovereignty-row" data-original-url="https://www.itpro.com/it-legislation/25261/microsoft-heads-back-to-court-in-data-sovereignty-row">hand over emails stored in its Dublin servers to the US government</a>.</p><p>Should that appeal fail it would effectively mean that the US government can demand data from any American company, regardless of where the data resides.</p><p><strong>Other ways to transfer data legally to the US</strong></p><p>While the invalidation of Safe Harbour means the easiest way for vendors to transfer EU data to the US is no longer possible, other methods still exist.</p><p>"Data protection law provides a number of other gateways to lawful export of personal data to a third country, such as data subject consent, standard form contracts and self-assessment," said Daniel Hedley, associate at national law firm Thomas Eggar LLP.</p><p>But he added that the judgement could affect those methods too in the longer term, and advised businesses who need to send their data outside of the EU to wait for the UK's data watchdog to issue advice.</p><p>The Information Commissioner's Office "has indicated that it is considering the judgment and will provide guidance for businesses in due course", Hedley explained.</p><p>"Reading between the lines, it seems to have little appetite for instant, rigorous enforcement against the new situation. Businesses would be well advised to start the dialog process with their US-based cloud providers and other data processors, and to keep an eye on the ICO for further guidance."</p><p><strong>06/10/2015:</strong> The European Court of Justice (ECJ) has ruled invalid the Safe Harbour data transfer agreement between the EU and US that has overseen data movements from European users of US cloud services to the US for processing. </p><p>The decision could lead to a disruption of services for firms such as Facebook, Google, Apple, Microsoft and others.</p><p>The ECJ made the same decision as the US Attorney General last month that data processing rules devised in 2000 do not give proper guarantees that EU citizens' data will stay safe once on US soil. The ruling originated in a case that Austrian resident Max Schrems brought against Facebook following revelations by Edward Snowden that showed how the NSA was able to snoop on data about EU citizens.</p><p>According to the court's Safe Harbour <a href="http://www.politico.eu/wp-content/uploads/2015/10/schrems-judgment.pdf">ruling</a>, tech companies could be forced to store data in the EU, rather than in the US. Otherwise, those companies could be forced to attain certification for more rigorous data transfer rules.</p><p>"The United States authorities were able to access the personal data transferred from the Member States to the United States and process it in a way incompatible, in particular, with the purposes for which it was transferred, beyond what was strictly necessary and proportionate to the protection of national security," said the ruling.</p><p>The court also said that EU citizens had no right of redress to stop the misuse of personal data. The rules were also found to have undermined national data protection authorities' ability to rule on data transfers.</p><p>"The court finds that the Safe Harbour decision denies the national supervisory authorities their powers where a person calls into question whether the decision is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals," it said. </p><p>It would seem that the ruling was on the horizon as talks are already taking place between the US and EU over the creation of a new framework to replace the current invalid one.</p><p>Ashley Winton, UK head of data protection and privacy at international law firm Paul Hastings, told <em>IT Pro</em> that the ruling has serious repercussions for multi-national companies with operations in Europe.</p><p>"Many European data protection regulators, particularly those in Germany, have long believed that the conditions of the safe harbour scheme are not substantial enough and the effect of today's ruling will empower them to investigate and check the acceptability of any data transfer themselves," he said. </p><p>He added that although the case today primarily concerns safe harbour the ruling will also apply to other European Commission approved methods of transferring personal data internationally.</p><p>"Crucially, this case cannot be considered alone. Following the landmark case of Weltimmo last week, multinational companies that have elected to create an establishment in a more business-friendly jurisdiction are now likely to have their data protection practices scrutinised by local regulators all across the EU," said Winton.</p><p>He added that there are currently no rules limiting individuals bringing complaints regarding data protection across multiple jurisdictions simultaneously, "so we may now see these complaints springing up from every direction, where data is being shared around the world."</p><p><em><strong>This article was originally published on 06/10/2015 but has been updated (most recently on 20/10/2015) to reflect the latest developments.</strong></em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/25393/us-and-eu-must-reach-new-safe-harbour-deal-by-january-2016</link>
                                                                            <description>
                            <![CDATA[ EU regulators committed to "coordinated enforcement actions" against violators ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tisbBsQnikVdLK3JG7M1fv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Oct 2015 14:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several EU flags hoisted outside a building]]></media:description>                                                            <media:text><![CDATA[Several EU flags hoisted outside a building]]></media:text>
                                <media:title type="plain"><![CDATA[Several EU flags hoisted outside a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wzM8kdNLDWwgPLxPShFPDG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>20/10/2015: </strong>EU data protection regulators have set a deadline for a revised Safe Harbour agreement, after it was ruled invalid earlier this month.</p><p>The European Court of Justice decided that Safe Harbour did not give data tranfers between Europe and the US adequate protection at the start of October, declaring the agreement void, but the court has given the EU and US until 31 January 2016 to agree on a new deal.</p><p>If a solution is not found by that time, regulators will begin taking steps to enforce the ruling.</p><p>"EU data protection authorities are committed to take all necessary and appropriate actions, which may include coordinated enforcement actions", the court wrote in a <a href="http://ec.europa.eu/justice/data-protection/article-29/index_en.htm" target="_blank">statement</a>.</p><p>Elizabeth Maxwell, data regulation expert at Compuware, said the decision has "sent a ripple across the water".</p><p>"Around 4,500 US companies use the Safe Harbour agreement and related certification to allow them to do business with the European Economic Area. This judgement is providing a very definite message to the world that data privacy is a serious matter and there will be serious consequences for non-compliance," she added.</p><p><strong>12/10/2015: </strong>Dropbox is reviewing the ruling that declared the Safe Harbour agreement invalid and has not yet committed to building a European datacentre to overcome the issue.</p><p><a href="http://www.cloudpro.co.uk/leadership/5415/what-is-safe-harbour-and-why-has-it-been-revoked">Safe Harbour</a> was a longstanding EU-US principle that guaranteed any EU data transferred to America would receive the same safeguards enjoyed within the EU.</p><p>But the European Court of Justice (ECJ) last week concluded that the agreement no longer affords EU citizens' data privacy and ruled the agreement to be invalid.</p><p>Its decision was based on evidence of US spy initiatives like PRISM, which Austrian privacy campaigner Max Schrems argued meant America could not guarantee European citizens' data would remain private.</p><p>The fallout from the ruling could provoke a scramble to build EU datacentres, with file-sharing firm Box already confirming that customers will be able to store data within the EU come a year's time.</p><p>But Dropbox has made no such commitment, responding to <em>IT Pro</em>'s questions to say only that it is reviewing the ECJ's decision.</p><p>A spokeswoman said: "Dropbox is committed to upholding the security and privacy of customer data. We are currently reviewing the court's decision in detail, and will continue partnering with our EU users and customers on their ongoing usage of our services."</p><p>In fact, the firm told <em>Cloud Pro</em> back in May that it <a href="http://www.cloudpro.co.uk/cloud-essentials/cloud-security/5088/dropbox-for-business-seeks-europe-data-transparency">had no plans at all to build an EU datacentre</a>.</p><p>UK chief Mark van der Linden said at the time: "That's completely not on the roadmap. Location in our opinion is only one piece of the puzzle. </p><p>In contrast, Box CEO Aaron Levie told <em><a href="http://www.telegraph.co.uk/finance/newsbysector/mediatechnologyandtelecoms/digital-media/11917628/Box-to-open-European-data-centres-after-ECJ-privacy-ruling.html">the Telegraph</a> </em>last week: "In a year from now I would absolutely expect we will have customers storing their data internationally. We're building towards it now."</p><p>It could leverage datacentres belonging to enterprise partner IBM to fulfill this aim.</p><p>Existing file-sharing competitors Google and Amazon Web Services have a number of European datacentres, while another rival, Egnyte, allows people to store their data in the cloud or on-premise, meaning they do not have to trust it to the public cloud.</p><p>However, there are a number of considerations for cloud service providers seeking to respond to the latest ruling, before they commit to building new data storage sites.</p><p><strong>Data transfers to the US are not actually illegal</strong></p><p>The first is that the Safe Harbour agreement was being reworked regardless of the ECJ's ruling a new and improved framework could be announced by the US and the European Commission as early as the end of 2015.</p><p>Secondly, as IDC's research director for European security, Duncan Brown, <a href="https://www.linkedin.com/pulse/impact-safe-harbor-judgement-data-transfers-cloud-duncan">pointed out</a>, the ruling does not render EU-US data transfers illegal.</p><p>"The judgement compels each EU nation's data protection authority (DPA) to investigate fully any complaint against a data processor transferring data to the US," he said.</p><p>"However, data processors may now be subject to multiple court cases that the DPAs are now obligated to investigate, and individual data transfers may be deemed to be non-compliant."</p><p><strong>EU datacentres may not be enough</strong></p><p>A wider issue that remains unresolved may explain Dropbox's non-committal response to the Safe Harbour ruling so far.</p><p>The issue in question is Microsoft's appeal against a court decision commanding it to <a href="https://www.itpro.com/it-legislation/25261/microsoft-heads-back-to-court-in-data-sovereignty-row" data-original-url="https://www.itpro.com/it-legislation/25261/microsoft-heads-back-to-court-in-data-sovereignty-row">hand over emails stored in its Dublin servers to the US government</a>.</p><p>Should that appeal fail it would effectively mean that the US government can demand data from any American company, regardless of where the data resides.</p><p><strong>Other ways to transfer data legally to the US</strong></p><p>While the invalidation of Safe Harbour means the easiest way for vendors to transfer EU data to the US is no longer possible, other methods still exist.</p><p>"Data protection law provides a number of other gateways to lawful export of personal data to a third country, such as data subject consent, standard form contracts and self-assessment," said Daniel Hedley, associate at national law firm Thomas Eggar LLP.</p><p>But he added that the judgement could affect those methods too in the longer term, and advised businesses who need to send their data outside of the EU to wait for the UK's data watchdog to issue advice.</p><p>The Information Commissioner's Office "has indicated that it is considering the judgment and will provide guidance for businesses in due course", Hedley explained.</p><p>"Reading between the lines, it seems to have little appetite for instant, rigorous enforcement against the new situation. Businesses would be well advised to start the dialog process with their US-based cloud providers and other data processors, and to keep an eye on the ICO for further guidance."</p><p><strong>06/10/2015:</strong> The European Court of Justice (ECJ) has ruled invalid the Safe Harbour data transfer agreement between the EU and US that has overseen data movements from European users of US cloud services to the US for processing. </p><p>The decision could lead to a disruption of services for firms such as Facebook, Google, Apple, Microsoft and others.</p><p>The ECJ made the same decision as the US Attorney General last month that data processing rules devised in 2000 do not give proper guarantees that EU citizens' data will stay safe once on US soil. The ruling originated in a case that Austrian resident Max Schrems brought against Facebook following revelations by Edward Snowden that showed how the NSA was able to snoop on data about EU citizens.</p><p>According to the court's Safe Harbour <a href="http://www.politico.eu/wp-content/uploads/2015/10/schrems-judgment.pdf">ruling</a>, tech companies could be forced to store data in the EU, rather than in the US. Otherwise, those companies could be forced to attain certification for more rigorous data transfer rules.</p><p>"The United States authorities were able to access the personal data transferred from the Member States to the United States and process it in a way incompatible, in particular, with the purposes for which it was transferred, beyond what was strictly necessary and proportionate to the protection of national security," said the ruling.</p><p>The court also said that EU citizens had no right of redress to stop the misuse of personal data. The rules were also found to have undermined national data protection authorities' ability to rule on data transfers.</p><p>"The court finds that the Safe Harbour decision denies the national supervisory authorities their powers where a person calls into question whether the decision is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals," it said. </p><p>It would seem that the ruling was on the horizon as talks are already taking place between the US and EU over the creation of a new framework to replace the current invalid one.</p><p>Ashley Winton, UK head of data protection and privacy at international law firm Paul Hastings, told <em>IT Pro</em> that the ruling has serious repercussions for multi-national companies with operations in Europe.</p><p>"Many European data protection regulators, particularly those in Germany, have long believed that the conditions of the safe harbour scheme are not substantial enough and the effect of today's ruling will empower them to investigate and check the acceptability of any data transfer themselves," he said. </p><p>He added that although the case today primarily concerns safe harbour the ruling will also apply to other European Commission approved methods of transferring personal data internationally.</p><p>"Crucially, this case cannot be considered alone. Following the landmark case of Weltimmo last week, multinational companies that have elected to create an establishment in a more business-friendly jurisdiction are now likely to have their data protection practices scrutinised by local regulators all across the EU," said Winton.</p><p>He added that there are currently no rules limiting individuals bringing complaints regarding data protection across multiple jurisdictions simultaneously, "so we may now see these complaints springing up from every direction, where data is being shared around the world."</p><p><em><strong>This article was originally published on 06/10/2015 but has been updated (most recently on 20/10/2015) to reflect the latest developments.</strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>