The European Court of Justice ruling in Schrems vs. Data Protection Commissioner seriously complicated operations for more than 4,400 American companies that had relied on the EU-U.S. Safe Harbor Agreement (“Safe Harbor”).[1] Safe Harbor had been the easiest way for U.S. companies to transfer personal data between the United States and Europe.[2] Finding Safe Harbor inadequate to protect the privacy of EU citizens,[3] the court’s October 6 decision stripped U.S. companies like Facebook, Google, Airbnb, LinkedIn,[4] Domino’s Pizza, and the women’s clothier Tory Burch, LLC,[5] of permission to transfer EU citizens’ personal data among EU member countries and the United States for commercial purposes.[6]

Fortunately for the affected companies, enforcement did not begin until the end of January 2016, leaving them a grace period to comply.[7] Many already had a “Plan B” for legal transfer of personal data.[8] Companies without such a plan were given the option to temporarily implement one of three other avenues—Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and Derogations.[9] These alternatives essentially allow legal transfer of personal data through forming “contract clauses or ad hoc agreements,” “establishing [certain] rules that permit transfers of personal data within a multinational corporation or international organization,” or “obtaining the ‘unambiguous consent’ of the data subject to the transfer of personal data.”[10] However, these alternative solutions require additional steps and expenses[11] that are prohibitive for many smaller companies.[12]

Penny Pritzker
U.S. Secretary of Commerce Penny Pritzker talks with German business 
officials in Munich in November 2013. Pritzker recently sent her EU counter-
parts a 132-page proposal to replace the longstanding Safe Harbor 
Agreement that facilitated U.S.-EU data transfer before the ECJ struck it
down in October.Photo via Wikimedia Commons.

Around the end of the Safe Harbor grace period, the European Commission and its U.S. counterpart announced an agreement of a revised Safe Harbor Agreement, the so-called EU-U.S. Privacy Shield.[13] On February 29, the U.S. Department of Commerce released a 132-page “package,” which included Privacy Shield Principles and a so-called "Arbitral Model".[14] The Privacy Shield Principles cover seven categories that provide guidance for companies in complying with European data protection laws:[15] “notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement, and liability.”[16]

The notice principle requires that organizations clearly provide individuals with “notice of the organization’s participation in the Privacy Shield, the type of data collected, . . . the purposes for which the data is collected . . . any third parties to whom their data will be transferred, their right to access their data, and the means for limiting the use and disclosure of their personal data.”[17] The individual must also be told about the avenues for redress and “the FTC’s . . . enforcement authority.”[18] The choice principle addresses information regarding how an individual can opt-out of having their personal information disclosed to a third party or collected for other reasons than originally designated.[19] As for disclosure and collection of particularly sensitive information, such as data regarding “health, racial or ethnic origin, political and religious opinions, trade union membership, or information revealing an individual’s sex life,” individuals must affirmatively consent.[20] Accountability for onward transfer lays out requirements for participating organizations in their transfer of personal data to third parties.[21] The principle broadens the participating organization’s responsibility beyond just their own organizations, to now include third parties when third parties act as agents.[22] The security principle requires that participating organizations “take reasonable and appropriate measures to protect [data] from loss, misuse and unauthorized access, disclosure, alteration and destruction,” while being particularly aware of the “risks involved and the nature of the personal data.”[23] The data integrity and purpose limitation principle requires that organizations maintain accurate and relevant data.[24] Access involves providing individuals with “access to their personal data as well as the opportunity to correct, amend, or delete information that is inaccurate or processed in violation of the Principles.”[25] This principle also provides organizations with guidelines on when access to data can be restricted.[26] Lastly, recourse, enforcement, and liability describe “detailed mechanisms for recourse and dispute resolution.”[27] In addition to these principles, there are supplemental principles informing businesses on how to handle “sensitive data, secondary liability, the role of data protection authorities, human resources data, pharmaceutical and medical products, and publicly available data.”[28]

Like the old Safe Harbor framework, the Privacy Shield is binding[29] on any organization that seeks the Privacy Shield certification.[30] The new Privacy Shield introduces a few revisions including choice and onward transfer, which are explained above.[31] Furthermore, the Privacy Shield improved “commercial oversight”[32] and now provides EU citizens with several new avenues for redress should they feel their privacy has been violated.[33] EU citizens can file complaints of non-compliance to the violating organization or to their national Data Protection Authority, with an expectation of a forty-five-day turn around for organizations that receive complaints.[34] If none of the other remedies right the alleged wrong, EU citizens can pursue a legal remedy through the Arbitral Model, which submits participating organizations to binding arbitration.[35] Organizations must provide this avenue for remedy, but a complaining individual has to exhaust all other options before seeking arbitration.[36]

The Privacy Shield package, not yet implemented, is subject to a final adequacy determination from the European Commission.[37] The determination will be made through a “comitology procedure, which involves insight from the Article 29 Working Party, a binding opinion from the EU Member State representatives, and a formal adoption of the adequacy decision by the EU College of Commissioners.”[38] Until the Privacy Shield’s implementation, the EU data protection supervisory authorities are allowing businesses to use one of the three aforementioned alternatives.[39] Businesses that did not want to turn to any of the three Safe Harbor alternatives will have to hold on for a little longer until the adequacy determination is approved, which is predicted for early summer.[40]

Posted by Sharon G. Lin on Thu. March 10, 2016 11:47 AM
Categories: Cyberlaw, European Union, Free Trade, United States

