Safe Harbor may be dangerous to your business

What’s all the fuss about?

You might have heard about Safe Harbor recently and been wondering what it is and how it might affect your business. It concerns repeated, large-scale, international transfers of personal data.

What it doesn’t concern:

  • small-scale, one-off transfers of personal data
  • transfers of personal data (with consent) that are necessary to carry out a contract
  • international transfers of anonymised data

Current legal situation

So, if your business makes repeated transfers of large amounts of personal data, here’s the current situation under EU law:

  • International transfers of personal data from the European Economic Area must be covered by an adequate level of protection of the individual’s right to privacy.
  • The European Commission considers all territories within the European Economic Area, and certain other territories, to offer adequate protection.
  • The EU Commission requires transfers to any of the remaining territories (whose protection is not adequate) to be legitimised by, either:
    • the parties signing the lengthy EU Standard Contractual Clauses (SCC); or
    • if the transfer is within an international group of companies, use of the EU Binding Corporate Rules (BCR).
  • The European Commission has never considered the USA to offer adequate protection. To provide a more convenient alternative to the use of the SCC and BCR, the Safe Harbor arrangement was agreed between Washington and Brussels. Put very simply, Safe Harbor requires the US recipient to give certain assurances of the adequacy of its own data protection measures, and to be included in a US Department of Commerce approved list.

The scale of US state surveillance activities revealed by Edward Snowden prompted calls from various quarters of the EEA to revoke the Safe Harbor system.

It finally took a court case by an Austrian Facebook user (questioning the security of transfers of his personal data from Facebook Ireland to Facebook Inc.) to obtain the European Court of Justice’s decision that Safe Harbor was indeed invalid.

If Safe Harbor is invalid, what now?

That was in September 2015. The continuing advice from the Information Commissioner’s Office (ICO) since then is that international transfers from the EEA to the USA must now be protected by either the SCC or the BCR.

The EU-US Privacy Shield

In early February the European Commission announced the EU-US Privacy Shield, an agreement between Washington and Brussels to create a new framework for transatlantic data flows, to replace Safe Harbor. This is still at an early stage of development, so the ICO’s advice continues to apply until further notice.

Share this post
Posted in

Categories

Archives