IAPP_StudyGuideAD
CS16_Web_300x250-wCopy

Privacy Shield details released

After two years of negotiations, and several major obstacles, including the invalidation of the Safe Harbor by a European court, the U.S. Department of Commerce released details today of the EU-U.S. Privacy Shield. The 132-page “package” includes the Privacy Shield Principles and an Arbitral Model, as well as letters from the DOC, U.S. Federal Trade Commission, Department of Transportation, Office of the Director of National Intelligence, Department of State, and the Justice Department.

“On behalf of the United States, I am pleased to transmit herewith a package of EU-U.S. Privacy Shield materials that is the product of two years of productive discussions among our teams,” DOC Secretary Penny Pritzker wrote in a letter to Vera Jourová, the European Commissioner for Justice, Consumers, and Gender Equality. “This package, along with other material available to the Commission from public sources, provides a very strong basis for a new adequacy finding by the European Commission.”

Jourová tweeted:

Notably, companies must self-certify they agree to and will comply with the Privacy Shield Principles.

The package names U.S. Under Secretary of State Catherine Novelli as the point of contact for the Ombudsman mechanism, a role “through which authorities in the EU will be able to submit requests on behalf of EU individuals regarding U.S. signals intelligence practices,” wrote U.S. Secretary of State John Kerry. An Annex includes more details of how the Ombudsperson mechanism will work.

Critics have pointed out that an Ombudsperson should be independent from the government to be truly effective. Kerry, however, wrote, “Under Secretary Novelli is independent from the U.S. intelligence community, and reports directly to me.”

In a separate letter, Office of the Director of National Intelligence General Counsel Robert Litt outlines steps taken by the U.S. to reform signals intelligence, provide oversight mechanisms and transparency, “and the overall protections for privacy and civil liberties, in order to assist the European Commission in making a determination about the adequacy of those protections as they relate to the national security exception to the Privacy Shield principles.”

Litt also noted, in what Reuters reported was a last-minute change, that “without confirming or denying media reports alleging that the U.S. Intelligence Community collects data from transatlantic cables while it is being transmitted to the United States, were the U.S. Intelligence Community to collect data from transatlantic cables, it would do so subject to the limitations and safeguards set out herein, including the requirements” of President Obama’s Presidential Policy Directive 28.

The Department of Justice included a section on how law enforcement agencies may acquire commercial data during a criminal investigation, noting that U.S. corporations can challenge orders in court.

The package also features the full set of Privacy Shield Principles, which entails seven distinct categories: notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement, and liability. There’s also a supplemental set of principles that includes provisions around sensitive data, secondary liability, the role of data protection authorities, human resources data, pharmaceutical and medical products, and publicly available data.

Additionally, the package contains an Arbitral Model to address a final means for redress. “The purpose of this option,” the package states, “is to provide a prompt, independent, and fair mechanism, at the option of individuals, for resolution of claimed violations of the Principles not resolved by any of the other Privacy Shield mechanisms, if any.”

FTC Chairwoman Edith Ramirez and DOT Secretary Anthony Foxx also reaffirmed each agency’s commitment to four areas: referral prioritization; false and deceptive Privacy Shield claims; continuous monitoring; and engagement with European data protection authorities.

The DOC’s Pritzker, in a separate release, praised the new agreement, calling it a “tremendous victory for privacy, individuals, and businesses on both sides of the Atlantic.”

But the Privacy Shield has many critics already.

The Greens in the European Parliament issued a statement calling it a “cosmetic change.” Green home affairs and data protection spokesman Jan Philipp Albrecht — who has also been instrumental in the region’s General Data Protection Regulation — said, “The new ‘Privacy Shield’ framework appears to amount to little more than a remarketed version of the pre-existing Safe Harbour decision.” Albrecht says the Commission should push for more improvements to protect the privacy of European citizens, and that since the GDPR is slated to come into force by 2018, “it is essential that ‘Privacy Shield’ is limited to two years and that a new framework is negotiated once the new EU rules on data protection come into force.”

Privacy advocate and lawyer Max Schrems — whose case against Facebook ultimately led to the invalidation of the Safe Harbor framework — also criticized the new agreement. Most notably, he stated that none of the new improvements “seems to address the core concerns and fundamental flaws of U.S. intelligence laws and the lack of privacy protections in U.S. law."

EDRi also did not pull any punches about their dislike of the agreement, arguing that the documents released today “confirm that no meaningful reforms have been made and that none are planned.”

Whether the Privacy Shield ends up going back to the European Court of Justice remains to be seen, but in the meantime, privacy pros are busy analyzing today’s package.

According to the Privacy Shield Principles, “The effective date of the Principles is the date of final approval of the European Commission’s adequacy determination.” The Commission also released a draft adequacy decision, a set of FAQs, a Communication to the European Parliament and the Council, and a Fact Sheet.

The draft adequacy decision now must be approved by comitology procedure, which involves insight from the Article 29 Working Party, a binding opinion from the EU Member State representatives, and a formal adoption of the adequacy decision by the EU College of Commissioners. According to a Covington & Burling post, the Commission aims for adoption by June or early summer. 

Top image courtesy of the European Commission

Written By

Jedidiah Bracy, CIPP/E, CIPP/US

0 Comments

If you want to comment on this post, you need to login.

Related

Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

The EU General Data Protection Regulation

Get the help you need from the people who know - all in one place.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

Be Part of Something Big: Join the Summit

Registration is open for the Global Privacy Summit 2016. Discounted early bird rates available for a short time, register today!

Symposium Registration Open!

Canada's leading privacy conference returns to Toronto! This event has sold-out three years in a row, so register early to guarantee your spot.

Data Protection Congress: Call for Speakers

The Congress returns! We're now seeking speakers to lead educational sessions for this year's program. Learn more and submit today.

Data Protection Intensive Returns to London

Registration is now open for the IAPP Europe Data Protection Intensive in London. Check out the program!

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

IAPP Privacy Bar Section Forum

Join us at the conclusion of the Global Privacy Summit 2016 for this inaugural event as we launch the new IAPP Privacy Bar Section. Register today!

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»