IAPP-GDPR Web Banners-300x250-FINAL

The European Union (EU) approved the U.S.-EU Safe-Harbor Agreement in 2000. Since that time, Safe Harbor has allowed companies to transfer personal data from the EU to the United States without violating EU data protection laws. EU data protection laws permit transfers of personal data to countries deemed to lack adequate protections for personal data only when those transfers are governed by certain legal mechanisms. One of those mechanisms is Safe Harbor, which was negotiated, with stakeholder input, between EU and U.S. officials who recognized the need for cross-border data transfers despite the EU’s position that the United States does not provide adequate protection for the personal data of EU data subjects.

Under Safe Harbor, U.S. organizations certify to the U.S. Department of Commerce that they provide certain protections for personal data. Those protections are designed to ensure that organizations meet EU data protection requirements. Safe Harbor certifications are enforced by the Federal Trade Commission or the Department of Transportation as appropriate. Over four thousand organizations are currently listed on the U.S.-EU Safe Harbor list. These organizations rely on Safe Harbor to authorize transfers of personal data from the EU to the U.S. Recent events, however, have created uncertainty for Safe Harbor and the organizations that depend on it.

Early this year, EU parliamentarian Jan-Phillip Albrecht, who is charged with steering the European Commission’s proposed data protection reform package through the EU Parliament, released a report in which he recommended 350 amendments to the Commission’s proposal. Albrecht surprised many by recommending that the EU discontinue the Safe Harbor framework two years after enactment of the data protection reform.

Further signs of EU discontent over Safe Harbor came to light after the announcement of the Transatlantic Trade and Investment Partnership (TTIP) negotiations. Those negotiations are aimed at establishing a free trade agreement between the U.S. and the EU. Because of the substantial contribution that data transfers make to international trade, senior U.S. officials wanted cross-border data transfers to be included in TTIP negotiations. The Coalition for Privacy and Free Trade, launched by Hogan Lovells in March of this year, stated in comments to the United States Trade Representative that TTIP offers a unique “opportunity to progress the interoperability of data privacy frameworks in a way that endures.” But not all stakeholders felt that TTIP was an appropriate forum for addressing cross-border data transfers. Germany’s data protection commissioner, for example, blogged that the United States data protection framework is lacking and that the Safe Harbor “cannot compensate for these deficits.” 

Recent attention to the National Security Agency’s (NSA’s) surveillance operations have made things even tougher for Safe Harbor. The European Parliament has called on the European Commission to conduct a full review of Safe Harbor. Parliament’s resolution notes that some companies involved in NSA’s PRISM surveillance program are certified under Safe Harbor. Parliament claims that PRISM surveillance may have involved a “serious violation” of EU data protection laws, and that the Commission may therefore be obliged to reverse or suspend Safe Harbor. Germany’s data protection commissioners wrote a letter asking German Chancellor Merkel to recommend that the EU suspend Safe Harbor. EU Vice President Viviane Reding announced the European Commission’s plan to conduct a full review of Safe Harbor by the end of this year. Reding, who drafted the Commission’s proposed data reform package, called PRISM a “wake-up call” and said that Safe Harbor “may not be so safe after all.” These claims come a little more than one year after Reding, in a joint release with then U.S. Commerce Secretary John Bryson, reaffirmed the EU’s commitment to Safe Harbor “as a tool to promote transatlantic trade and economic growth.”

Criticisms of Safe Harbor and other mechanisms that allow data to be transferred from the EU to the United States have, in many instances, been blind to the nature of government surveillance in EU countries. As Hogan Lovells privacy lead Chris Wolf wrote in a recent Privacy Perspectives blog post, “[I]t is naïve to think that intelligence agencies in European countries do not utilize information collected from phone and Internet companies in their investigations.” And those countries often lack the judicial and legislative oversight protections incorporated into U.S. surveillance laws. Regardless of the relative strengths and weaknesses of the privacy protections in EU and U.S. surveillance laws, however, the outcry over U.S. government surveillance has apparently reenergized EU data protection reform efforts. That could spell trouble for Safe Harbor even though Safe Harbor facilitates substantial and valuable data transfers that have been undisturbed by government access.

Moreover, there have been no allegations that the FTC has failed to adequately address EU complaints of perceived Safe Harbor violations. Although the FTC does not publicize filed complaints, complainants may disclose their complaint and whether they have been resolved satisfactorily. In addition, there have been no allegations that the certification/dispute resolution bodies—operated by organizations such as TRUSTe and the BBB—are not working.

In spite of Safe Harbor’s success at facilitating cross-border transfers, the mechanism does appear to be in danger. Organizations that have certified under Safe Harbor should closely monitor the EU’s legislative process and the TTIP for indications about Safe Harbor’s future. And they should give careful thought to contingency plans for handling the personal data of EU data subjects. 


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»