Certification_Ad_300x250final-01
Webcon_TE_300x250_ad_March1_2016-01
DPI16_Banner_300x250 WITH COPY
With Safe Harbor Invalid, What's Next for Privacy Pros?

Without doubt, Tuesday’s historic decision by the Court of Justice of the European Union (CJEU) invalidating the EU-U.S. Safe Harbor Agreement has ruffled a lot of feathers in the business community, while reenergizing privacy advocates in the EU and abroad. Now that the main agreement allowing the transfer of personal data between the two regions is essentially dead, what should privacy professionals be thinking and doing? Should privacy officers expect a knock on the door from a European data protection authority (DPA) tomorrow morning?

If you’re planning what to do now, then you’re too late, said Eduardo Ustaran, CIPP/E, of Hogan Lovells. “Many have already predicted this and the necessity for a plan B,” he added during an audio conference, "A World Without Safe Harbor?," hosted by the IAPP Tuesday afternoon. Though many businesses are in limbo, Ustaran said, moving forward, companies need to assess for their most critical data transfers and deal with those first and put alternative contracts in place as soon as possible.

Could a business rely on the principles of Safe Harbor, queried moderator Omer Tene, of the IAPP, and argue to DPAs that they’ve provided adequate data protection?

“You could argue that,” said Wilson Sonsini’s Christopher Kuner, “but it would be a crap shoot. The court clearly doesn’t find the Safe Harbor principles adequate.” Some DPAs might find the principles adequate, Kuner explained, while others would not, resulting in fragmentation and uncertainty in the region.

“I think it’s important to take a deep breath,” said Brian Hengesbaugh of Baker & McKenzie, and one of the lead negotiators while at the U.S. Department of Commerce when the Safe Harbor was originally put in place.

“This is not the end of the road. The European Commission is still working with the U.S. Department of Commerce to update a new Safe Harbor agreement, and, even today, the Commission said it was pleased with the process.” He added, “If tomorrow morning you receive an enforcement action from a DPA, I really think that would be a misuse of legal authority with good faith actors.” He noted that hundreds of businesses take the Safe Harbor Agreement seriously. Hengesbaugh also warned that small- and medium-sized businesses will really feel the weight of this decision, noting that many do not have the resources to commit to attaining a Binding Corporate Rules (BCRs) contract.

“These other mechanisms aren’t invalidated,” said Kuner. Standard contractual clauses and BCRs are still viable options for organizations, but looking forward logically, he explained, you could apply the same criticisms of Safe Harbor to these alternatives. “I doubt anyone will go against BCRs at the moment,” he said, “but there are bigger, longer-term implications” for them moving forward.

For instance, who’s to say that European citizens—what Tene referred to as the “500 million Max Schrems”—won’t file a similar complaint against a Facebook in Poland to challenge one of these alternative transfer mechanisms?

“Many people are focused on the power of the DPAs,” said Kuner, “but that’s not going to be the biggest risk of enforcement.” He said the court decision has empowered individuals, and that, now, DPAs have the obligation to investigate a citizen complaint. “I think some DPAs are uncomfortable about this judgment,” he said. Some DPAs will be thought of as being too lenient on a company, while others may be perceived as being too harsh under political pressure.

“Yesterday I was excited people were focused on privacy and surveillance laws globally, but, today, I felt very sad about this decision, which is surprising,” said Center for Democracy & Technology President and CEO Nuala O’Connor, CIPP/US, CIPP/G. She said she’s never really backed the Safe Harbor Agreement, referring to it as a “creaky political vehicle” that was “limited in scope and predicated on a thin legal basis.”

But O’Connor expressed a “profound sense of loss” after today’s decision.

“There’s a significant dysfunction in the EU and U.S. dialogue on privacy and surveillance,” she explained, adding, “I don’t think anybody’s privacy is better today than yesterday.” She said the bigger issue surrounding the Safe Harbor decision revolves around government surveillance and the transfer of personal data from companies to governments—the crux of the Snowden revelations, not just in the U.S. but the EU as well—and that issue ultimately needs to be dealt with. However, “That’s a government-to-government dialogue.”

Wilson Sonsini’s Kuner agreed, saying that government surveillance is not solvable via data protection law: “It has to be a government agreement.”

“From a practical perspective, forget about Safe Harbor,” said Ustaran. Organizations do have a range of options available to them. But first, he explained, “they need to differentiate between internal transfers and external ones with service providers.” For the former, organizations can use ad hoc contracts, intragroup agreements, standard contractual clauses and BCRS. “For those companies that have been taking Safe Harbor seriously, the obvious choice moving forward is to assess to what extent their Safe Harbor compliance program could be recycled into a BCR program.”

“In my experience, there’s not a big difference between the two,” he said. Yet, for the external transfer, customers are often at the mercy of what their vendors offer and that could be problematic.

“Good cross-border transfer solutions are not made over night,” said Baker & McKenzie’s Hengesbaugh. “Get it done in a strategic way and think about how you’ll approach it,” he said, “and give the political process time to work itself out.”

“If international data transfers have been a big issue,” said Ustaran, “as of today, they are going to become a number-one issue from a compliance standpoint," warning, “We’re going to be stuck for another 20 years on data transfer restrictions.”

In deciphering the long view, Kuner expressed pessimism, asking, “What is the endgame?” He said the “EU is getting parochial in data protection,” and that he's “worried about the inward-looking, narrow view of the EU regarding data transfers.”

And what about the new, ongoing Safe Harbor negotiations between the U.S. Department of Commerce and the European Commission, what some refer to as Safe Harbor 2.0?

Kuner expressed concern that even a new agreement may not hold sway based on today’s decision. “A Safe Harbor 2.0 might not even help right now. This would have to pass muster under legal standards and they’re being set quite high.”

The CDT’s O’Connor was a bit more optimistic about today’s decision. “I hope this will spur negotiations around Safe Harbor 2.0,” she said. “It’s possible this moment today will provide an impetus for negotiators,” O’Connor noted, citing recent changes in surveillance law in the U.S., notably the USA FREEDOM Act.

“If you care about privacy, you’ll want Safe Harbor 2.0 back,” Hengesbaugh said, explaining that doing so would bring the Federal Trade Commission (FTC) back into enforcement in the U.S.

It's true, today’s decision means the FTC has lost quite a bit of authority enforcing businesses that had self-certified under Safe Harbor, but at least one of its commissioners was optimistic as well. On Twitter, FTC Commissioner Julie Brill said:

Now, the questions remain, will more individuals take to legal action in the EU and will the DPAs have enough resources to deal with them?

Editor's Note:

A Brief History of Safe Harbor is available on the IAPP’s online Resource Center.

Written By

Jedidiah Bracy, CIPP/E, CIPP/US

0 Comments

If you want to comment on this post, you need to login.

Related

Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

The EU General Data Protection Regulation

Get the help you need from the people who know - all in one place.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

Be Part of Something Big: Join the Summit

Registration is open for the Global Privacy Summit 2016. Discounted early bird rates available for a short time, register today!

Symposium Registration Open!

Canada's leading privacy conference returns to Toronto! This event has sold-out three years in a row, so register early to guarantee your spot.

Data Protection Congress: Call for Speakers

The Congress returns! We're now seeking speakers to lead educational sessions for this year's program. Learn more and submit today.

Data Protection Intensive Returns to London

Registration is now open for the IAPP Europe Data Protection Intensive in London. Check out the program!

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

IAPP Privacy Bar Section Forum

Join us at the conclusion of the Global Privacy Summit 2016 for this inaugural event as we launch the new IAPP Privacy Bar Section. Register today!

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»