What is the future of Privacy Shield?

First things first, let’s take a moment to look back before we look forward… What is Privacy Shield, and how did we get here?

Once upon a time, the EU and the United States had an agreement called “Safe Harbor” that allowed the transfer of data between the two territories without excessive need for legislative reform. This was a good thing, until it wasn’t.

We experienced a time of data-transfer uncertainty while the two governments negotiated a new data transfer agreement. This bad boy came to be known as “Privacy Shield.” As of July 12, 2016, once again all was good in the land of digital data transfers…or was it?

While both sides agreed Privacy Shield was better and more robust than Safe Harbor, Privacy Shield came under attack soon after it was launched. According to several privacy experts in the EU, it still lacked several things; data deletion standards, parameters around collection of “big data,” and clarifications of a privacy ombudsperson, or a government-appointed representative to speak for the general public, in the United States.

You likely know the story already. The government made promises to address and rectify these areas, and everyone felt good again. More than 3,000 companies registered to participate and agreed to meet the requirements and practices of the new Privacy Shield program. (Note: 250ok participates in Privacy Shield and will be actively monitoring this as it progresses to ensure ongoing compliance.)

However, in 2018 while the EU was preparing to go live with the General Data Protection Regulation (GDPR), the EU Parliament was still waiting for these promises to be fulfilled by their US counterparts. Foreseeing these may not ever come to fruition, a formal “Motion for a Resolution” for the future of Privacy Shield was put forth. That’s where we are today.

Within this motion are two key areas that could impact the future of Privacy Shield:

  1. It takes the view the current Privacy Shield arrangement does not provide an adequate level of protection required by the GDPR and EU Charter, as interpreted by the European Court of Justice.
  2. Unless the US is fully compliant by September 1, 2018, the Commission has failed to act in accordance with Article 45(5) GDPR. It therefore calls on the Commission to suspend Privacy Shield until the US authorities comply with its terms.

If the United States doesn’t implement any of the required changes, does this spell the end of Privacy Shield? There was some hope the California Consumer Privacy Act could save Privacy Shield, but it looks like it was too little, too late.

According to the IAPP, the EU commission voted on July 4th, 2018, 303 to 223 in favor of suspending Privacy Shield unless the US is fully compliant by September 1, 2018. Considering how changes have gone up to this point, this vote strongly signals Privacy Shield’s demise.

But wait! The decision to suspend Privacy Shield rests in the hands of the European Commission, which can choose to delay or ignore the result of this vote, and instead wait until after the second annual review of Privacy Shield, in October 2018.

We’ll stay plugged into the progress of all this as September and October draw near, so check back this autumn for the latest.

minute read

Popular stories

Products

BriteVerify

BriteVerify email verification ensures that an email address actually exists in real-time

DemandTools

The #1 global data quality tool used by thousands of Salesforce admins

Everest

Insights and deliverability guidance from the only all-in-one email marketing solution

GridBuddy Cloud

Transform how you interact with your data through the versatility of grids.

Return Path

World-class deliverability applications to optimize email marketing programs

Trust Assessments

A revolutionary new solution for assessing Salesforce data quality

Solutions

Validity for Email

Increase inbox placement and maximize subscriber reach with clean and actionable data

Validity for Data Management

Simplify data management with solutions that improve data quality and increase CRM adoption

Validity for Sales Productivity

Give your sales team back hours per day with tools designed to increase productivity and mitigate pipeline risks in real-time