Privacy Shield needs improvement, says EU privacy watchdog

The successor to Safe Harbor suffers from some of the same faults

Privacy Shield has a new detractor, and that spells bad news for businesses built on the transatlantic transfer of personal data.

The Privacy Shield agreement is intended to protect the privacy of European Union citizens when their personal information is processed in the U.S., but it has found few supporters since the European Commission unveiled an unfinished draft of the agreement in January.

Even after the Commission published further details, in April, the critics continued to pile on. Last month, national data protection authorities from across the EU said it still needed significant work, and last week the European Parliament said it too is unsatisfied.

Now it's the turn of the European data protection supervisor, appointed by the Commission to advise EU institutions on privacy and data protection matters.

EDPS Giovanni Buttarelli wants the Commission to negotiate improvements to Privacy Shield in three main areas: limiting exemptions to its provisions; improving its redress and oversight mechanisms, and integrating all the main EU data protection principles.

The Commission began negotiating Privacy Shield last October, when the Court of Justice of the EU struck down its predecessor, the Safe Harbor Agreement, saying it was inadequate.

Businesses that had previously relied on Safe Harbor were invited by the Commission to use other mechanisms provided for in the 1995 Data Protection Directive, such as standard contract clauses and binding corporate rules, to continue legally exporting data.

Many observers have said that those alternative mechanisms suffer from the same deficiencies as did Safe Harbor, particularly the protection of personal data from bulk surveillance by U.S. security services, but their adequacy has not yet been tested in court.

That may soon change, as the Irish data protection commissioner called last week for the CJEU to examine the legality of standard contract clauses. If the court decides they too are inadequate, then a swift conclusion to the Privacy Shield negotiations will be vital if the transatlantic flow of data is not to be interrupted.

The EDPS is concerned that Privacy Shield's provisions on surveillance are a step in the wrong direction.

"Whereas the 2000 Safe Harbour Decision formally treated access for national security as an exception, the attention devoted in the Privacy Shield draft decision to access, filtering and analysis by law enforcement and intelligence of personal data transferred for commercial purposes indicates that the exception may have become the rule," Buttarelli wrote in a report published late Monday.

"The purposes for which exceptions are allowed and the requirement of a legal basis should be more precise," he wrote.

Buttarelli's concerns echo those of the European Parliament, expressed in a resolution last Thursday.

They too warned of deficiencies in the arrangement, notably the possibility for U.S. authorities to collect bulk data in ways that do not meet the criteria of necessity and proportionality. They also criticized the complexity of the redress mechanism if data is mishandled, and the insufficient independence of the U.S. ombudsperson who will resolve data disputes.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Peter Sayer

Peter Sayer

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?