SlideShare a Scribd company logo
1 of 2
Download to read offline
In July 2016, the European Commission adopted its highly anticipated EU-US “Privacy Shield,” setting up a
new data protection framework for organisations that transfer EU citizens’ personal data to the US. More
than 4,000 organisations are expected to have to adapt their privacy policies and practices accordingly, and
sign up to the new statutory requirements.
Key Elements of the Privacy-Shield
I. Enhanced Privacy Shield Principles
In compliance with the new Privacy-Shield Agreement,
organisations processing personal data from EU
countries will have to self-certify their adherence to the
following principles:
 The Notice principle - Companies will have to
inform European citizens about the type of data
they are collecting, including the purpose of their
processing. Companies will also provide the links to
the relevant data protection authorities and to the
provider of an appropriate alternative dispute
settlement on their website.
 The Choice principle - Individuals will have the
right to object to the disclosure of their personal
data to third parties and opt out, if desired. In the
case of more sensitive data, companies will have to
obtain express affirmative consent from individuals.
 The Security principle - The processing of
personal data will have to be guaranteed under
“reasonable and appropriate” security measures.
 The Purpose Limitation Principle - The
collection of data will be limited to the sole purpose
of its original intended use. The only exceptions are
archiving in the public interest, journalism, literature
and art, scientific and historical research and
statistical analysis.
 The Integrity Principle - The processing of
personal data will be limited to what is relevant for
its intended use. It will have to be accurate,
complete and current.
 The Access Principle - Individuals will be granted
the right to access the information collected about
them without need for justification and only against
a non-excessive fee. Individuals will have the right
to correct, amend or delete personal information
that is inaccurate or has been processed in
violation of the Privacy Shield Principles.
 The Accountability for Onward Transfer
Principle - Any onward transfer of personal data
from a company to controllers or processors will
only be possible for limited and specified purposes.
 The Recourse, Enforcement and Liability
Principle - Companies will have to provide robust
mechanisms to ensure compliance and effective
remedies.
II. Reinforced citizens’ rights
The US Department of Commerce will monitor and
verify that the affected companies apply policies in line
with the relevant Privacy Shield Principles. It will keep
up-to-date a list of organisations which have signed up
to the privacy shield and be responsible for removing
those organisations that have either left the
arrangement or failed to comply with the principles.
Under the new agreement, any individual who
considers that his or her data has been misused will
have the right to lodge a complaint either with:
 the company itself, which will have to reply within
45 days;
 its national Data Protection Authority, which will
refer the complaint to the US Department of
Commerce, who in turn will have to respond within
90 days, or;
 any Alternative Dispute Resolution Mechanism,
to which US companies will have to sign up at no
cost to the individual.
The whole functioning of the Privacy Shield in the US
will also be subject to an annual joint review to be
carried out by the European Commission and the US
Department of Commerce, bringing together national
intelligence experts from the US and the European
Data Protection Authorities.
III. Obligations of US public authorities
The Privacy-Shield also sets a certain number of
limitations and safeguard mechanisms in the case of
US intelligence services accessing EU citizens’
personal data for national security purposes. Most
notably, these include the following:
 The collection of personal data for intelligence
purposes will be authorised by statute or
Presidential approval and in accordance with the
US Constitution and Law.
 Individual data collection will be prioritised over bulk
data collection – i.e. data collection affecting all
individuals.
 Bulk collection will only be allowed where targeted
collection via the use of discriminants is not
possible and only in six very specific situations
(such as the fight against terrorism or opposition to
activities of foreign intelligence services which
could damage US interests).
 The treatment of personal data will have to take
into consideration the fundamental principles of
dignity and respect for legitimate privacy interests.
To complement these safeguards, the US authorities
will establish a specific redress path for EU citizens via
an Ombudsperson who will be independent from
national security services. The Ombudsperson will
follow up complaints and enquiries by EU individuals
with respect to national security access, and confirm to
the individual that the relevant laws have been
complied with or, in case of non-compliance, that any
non-compliance gap has been remedied.
Suggested Actions for Businesses
The principles-based statutory framework entails an
obligation of results in terms of compliance. It reduces
the uncertainty that has surrounded data-processing
between the EU and US since the abolition by the
European Court of Justice last October 2015 of the
previous legal framework known as the EU-US “safe
harbor” agreement, but does not immunize
organisations processing personal data across the
Atlantic against possible legal actions for alleged non-
compliance, with direct repercussions on company
reputation and the exposure vis-à-vis markets,
stakeholders and public opinion in general to negative
communication campaigns.
To reduce such risk, and given the high sensitivity of
the Europeans to data privacy, organisations wishing
to begin or start processing European citizens’
personal data in the US, should consider the following
actions with a view to assessing and adapting their
privacy policies and practices throughout the whole
organisation and in the context of third-party service
providers.
Action for Business
 Assess the adequacy of your current privacy
policies with the above-mentioned Privacy-Shield
Principles and adapt them accordingly.
 Assess and, if necessary, review external
contractual clauses with third parties that receive
personal data collected by your organisation to
ensure that they provide the same level of
protection as stipulated by the Privacy Shield
Principles.
 Review and set up the appropriate internal
governance to ensure that replies to potential
complaints from EU citizens are answered within
the time limit of 45 days, as well as inquiries and
requests by the US Department of Commerce.
 Identify and register with an Alternative Dispute
Resolution Provider which will have to be made
available to European citizens at no cost.
 Register your organisation to the Privacy Shield list
on the US Department of Commerce website,
providing a declaration of the organisation’s
commitment to comply with the Privacy Shield
Principles.
 Publicize on your own website the link to your
Alternative Dispute Resolution Provider, together
with a link to the US Department of Commerce’s
Privacy Shield website.
 Monitor implementation and renew the registration
every year.
Brussels, 20 July
For more specific advice on EU developments and on
possible actions to be taken within your organisation,
please contact
Leonardo Sforza
Managing Director and Head EU Affairs, Brussels
Leonardo.sforza@mslgroup.com
+32 (0)2 737 92 00

More Related Content

What's hot

Future of data - Insights from Discussions Building on an Initial Perspective...
Future of data - Insights from Discussions Building on an Initial Perspective...Future of data - Insights from Discussions Building on an Initial Perspective...
Future of data - Insights from Discussions Building on an Initial Perspective...Future Agenda
 
The future of work in europe
The future of work in europeThe future of work in europe
The future of work in europeFuture Agenda
 
The Three Pillars of Connected Insurance
The Three Pillars of Connected InsuranceThe Three Pillars of Connected Insurance
The Three Pillars of Connected InsuranceAndrea Silvello
 
Disruptive trends shaping the business landscape Singapore - 21 Aug 2019
Disruptive trends shaping the business landscape   Singapore - 21 Aug 2019Disruptive trends shaping the business landscape   Singapore - 21 Aug 2019
Disruptive trends shaping the business landscape Singapore - 21 Aug 2019Future Agenda
 
Design thinking: An approach to innovation that scales.
Design thinking:  An approach to innovation that scales. Design thinking:  An approach to innovation that scales.
Design thinking: An approach to innovation that scales. Infosys Consulting
 
Companies with social responsibility and services
Companies with social responsibility and servicesCompanies with social responsibility and services
Companies with social responsibility and servicesSharun Ichigo
 
What factors determine the success of market-leaders in the sharing economy? ...
What factors determine the success of market-leaders in the sharing economy? ...What factors determine the success of market-leaders in the sharing economy? ...
What factors determine the success of market-leaders in the sharing economy? ...Joe Bitter
 
Hyperconnected organisations: How businesses are adapting to the hyperconnect...
Hyperconnected organisations: How businesses are adapting to the hyperconnect...Hyperconnected organisations: How businesses are adapting to the hyperconnect...
Hyperconnected organisations: How businesses are adapting to the hyperconnect...The Economist Media Businesses
 
Share nl collaborative economy environmental impact and opportunities report
Share nl collaborative economy environmental impact and opportunities reportShare nl collaborative economy environmental impact and opportunities report
Share nl collaborative economy environmental impact and opportunities reportshareNL
 
Future Risk: 12 Key Issues for Insurance in the Next Decade
Future Risk: 12 Key Issues for Insurance in the Next DecadeFuture Risk: 12 Key Issues for Insurance in the Next Decade
Future Risk: 12 Key Issues for Insurance in the Next DecadeFuture Agenda
 
Be That Lawyer: Niche Practice for Lawyers
Be That Lawyer:  Niche Practice for LawyersBe That Lawyer:  Niche Practice for Lawyers
Be That Lawyer: Niche Practice for LawyersCarolyn Elefant
 
The evolution of client-agency relationships
The evolution of client-agency relationshipsThe evolution of client-agency relationships
The evolution of client-agency relationshipsMark Linder
 
Ten IT-enabled business trends for the decade ahead
Ten IT-enabled business trends for the decade aheadTen IT-enabled business trends for the decade ahead
Ten IT-enabled business trends for the decade aheadarms8586
 
Next Wave of Fintech: Redefining Financial Services through Technology
Next Wave of Fintech: Redefining Financial Services through TechnologyNext Wave of Fintech: Redefining Financial Services through Technology
Next Wave of Fintech: Redefining Financial Services through TechnologyRobin Teigland
 
E government a modern phenomenon
E government a modern phenomenon E government a modern phenomenon
E government a modern phenomenon LiveAdmins DMCC
 
Data Driven Marketing: the DNA of customer orientated companies
Data Driven Marketing: the DNA of customer orientated companiesData Driven Marketing: the DNA of customer orientated companies
Data Driven Marketing: the DNA of customer orientated companiesGood Rebels
 

What's hot (20)

legal-innovation(1)
legal-innovation(1)legal-innovation(1)
legal-innovation(1)
 
Future of data - Insights from Discussions Building on an Initial Perspective...
Future of data - Insights from Discussions Building on an Initial Perspective...Future of data - Insights from Discussions Building on an Initial Perspective...
Future of data - Insights from Discussions Building on an Initial Perspective...
 
The future of work in europe
The future of work in europeThe future of work in europe
The future of work in europe
 
The Three Pillars of Connected Insurance
The Three Pillars of Connected InsuranceThe Three Pillars of Connected Insurance
The Three Pillars of Connected Insurance
 
Disruptive trends shaping the business landscape Singapore - 21 Aug 2019
Disruptive trends shaping the business landscape   Singapore - 21 Aug 2019Disruptive trends shaping the business landscape   Singapore - 21 Aug 2019
Disruptive trends shaping the business landscape Singapore - 21 Aug 2019
 
Design thinking: An approach to innovation that scales.
Design thinking:  An approach to innovation that scales. Design thinking:  An approach to innovation that scales.
Design thinking: An approach to innovation that scales.
 
Companies with social responsibility and services
Companies with social responsibility and servicesCompanies with social responsibility and services
Companies with social responsibility and services
 
What factors determine the success of market-leaders in the sharing economy? ...
What factors determine the success of market-leaders in the sharing economy? ...What factors determine the success of market-leaders in the sharing economy? ...
What factors determine the success of market-leaders in the sharing economy? ...
 
Hyperconnected organisations: How businesses are adapting to the hyperconnect...
Hyperconnected organisations: How businesses are adapting to the hyperconnect...Hyperconnected organisations: How businesses are adapting to the hyperconnect...
Hyperconnected organisations: How businesses are adapting to the hyperconnect...
 
Share nl collaborative economy environmental impact and opportunities report
Share nl collaborative economy environmental impact and opportunities reportShare nl collaborative economy environmental impact and opportunities report
Share nl collaborative economy environmental impact and opportunities report
 
Online Comments Reports. BEO 2013
Online Comments Reports. BEO 2013Online Comments Reports. BEO 2013
Online Comments Reports. BEO 2013
 
Ftc privacy comments
Ftc privacy commentsFtc privacy comments
Ftc privacy comments
 
European Communication Monitor 2017
European Communication Monitor 2017European Communication Monitor 2017
European Communication Monitor 2017
 
Future Risk: 12 Key Issues for Insurance in the Next Decade
Future Risk: 12 Key Issues for Insurance in the Next DecadeFuture Risk: 12 Key Issues for Insurance in the Next Decade
Future Risk: 12 Key Issues for Insurance in the Next Decade
 
Be That Lawyer: Niche Practice for Lawyers
Be That Lawyer:  Niche Practice for LawyersBe That Lawyer:  Niche Practice for Lawyers
Be That Lawyer: Niche Practice for Lawyers
 
The evolution of client-agency relationships
The evolution of client-agency relationshipsThe evolution of client-agency relationships
The evolution of client-agency relationships
 
Ten IT-enabled business trends for the decade ahead
Ten IT-enabled business trends for the decade aheadTen IT-enabled business trends for the decade ahead
Ten IT-enabled business trends for the decade ahead
 
Next Wave of Fintech: Redefining Financial Services through Technology
Next Wave of Fintech: Redefining Financial Services through TechnologyNext Wave of Fintech: Redefining Financial Services through Technology
Next Wave of Fintech: Redefining Financial Services through Technology
 
E government a modern phenomenon
E government a modern phenomenon E government a modern phenomenon
E government a modern phenomenon
 
Data Driven Marketing: the DNA of customer orientated companies
Data Driven Marketing: the DNA of customer orientated companiesData Driven Marketing: the DNA of customer orientated companies
Data Driven Marketing: the DNA of customer orientated companies
 

Similar to Transatlantic Personal Data Processing: Complying with the new EU-US Privacy Shield

Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldParsons Behle & Latimer
 
Group 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptxGroup 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptxStephenQuijano3
 
香港六合彩 » SlideShare
香港六合彩 » SlideShare香港六合彩 » SlideShare
香港六合彩 » SlideShareyvtmnvul
 
香港六合彩 » SlideShare
香港六合彩 » SlideShare香港六合彩 » SlideShare
香港六合彩 » SlideSharepqkiykra
 
香港六合彩
香港六合彩香港六合彩
香港六合彩pchgmf
 
Regulatory compliance 2018
Regulatory compliance 2018Regulatory compliance 2018
Regulatory compliance 2018ProColombia
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborGayle Gorvett
 
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Dr. Oliver Massmann
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyKate Chan
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistChristina Gagnier
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
EU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeEU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeTrustArc
 
Aon GDPR white paper
Aon GDPR white paperAon GDPR white paper
Aon GDPR white paperGraeme Cross
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsUlf Mattsson
 
The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?TAG Alliances
 

Similar to Transatlantic Personal Data Processing: Complying with the new EU-US Privacy Shield (20)

Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy Shield
 
Group 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptxGroup 5 Banking Laws Semi Finals.pptx
Group 5 Banking Laws Semi Finals.pptx
 
香港六合彩 » SlideShare
香港六合彩 » SlideShare香港六合彩 » SlideShare
香港六合彩 » SlideShare
 
香港六合彩 » SlideShare
香港六合彩 » SlideShare香港六合彩 » SlideShare
香港六合彩 » SlideShare
 
香港六合彩
香港六合彩香港六合彩
香港六合彩
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Regulatory compliance 2018
Regulatory compliance 2018Regulatory compliance 2018
Regulatory compliance 2018
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe Harbor
 
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
Lawyer in Vietnam Dr. Oliver Massmann COMPLIANCE and CLEAR CONSENT - New EU G...
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation Checklist
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
EU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeEU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTe
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Aon GDPR white paper
Aon GDPR white paperAon GDPR white paper
Aon GDPR white paper
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?
 

More from MSL

The Disenchantment of Latin America: What to expect from the region in 2020?
The Disenchantment of Latin America: What to expect from the region in 2020?The Disenchantment of Latin America: What to expect from the region in 2020?
The Disenchantment of Latin America: What to expect from the region in 2020?MSL
 
Is Technology Removing the ‘Care’ from Healthcare?
Is Technology Removing the ‘Care’ from Healthcare?Is Technology Removing the ‘Care’ from Healthcare?
Is Technology Removing the ‘Care’ from Healthcare?MSL
 
Powered by AI - Country-wise Spotlight
Powered by AI - Country-wise SpotlightPowered by AI - Country-wise Spotlight
Powered by AI - Country-wise SpotlightMSL
 
Powered by AI: Communications and Marketing in the Algorithm Age
Powered by AI: Communications and Marketing in the Algorithm AgePowered by AI: Communications and Marketing in the Algorithm Age
Powered by AI: Communications and Marketing in the Algorithm AgeMSL
 
AT&T Dares to "Rethink Possible"
AT&T Dares to "Rethink Possible"AT&T Dares to "Rethink Possible"
AT&T Dares to "Rethink Possible"MSL
 
SCOTUS Launches New Economy with Legalized Sports Betting
SCOTUS Launches New Economy with Legalized Sports BettingSCOTUS Launches New Economy with Legalized Sports Betting
SCOTUS Launches New Economy with Legalized Sports BettingMSL
 
[Salterbaxter Directions] The Big Shift
[Salterbaxter Directions] The Big Shift[Salterbaxter Directions] The Big Shift
[Salterbaxter Directions] The Big ShiftMSL
 
[Salterbaxter Directions] Moving The Goal Posts
[Salterbaxter Directions] Moving The Goal Posts[Salterbaxter Directions] Moving The Goal Posts
[Salterbaxter Directions] Moving The Goal PostsMSL
 
MSL's 2018 Food Trends Presentation
MSL's 2018 Food Trends Presentation MSL's 2018 Food Trends Presentation
MSL's 2018 Food Trends Presentation MSL
 
MSL's 2018 Food Trends Forecast
MSL's 2018 Food Trends ForecastMSL's 2018 Food Trends Forecast
MSL's 2018 Food Trends ForecastMSL
 
The Second Technology Revolution: How the PR Business Needs To Change Once Again
The Second Technology Revolution: How the PR Business Needs To Change Once AgainThe Second Technology Revolution: How the PR Business Needs To Change Once Again
The Second Technology Revolution: How the PR Business Needs To Change Once AgainMSL
 
SDG Signals - SBTribe Research by Salterbaxter MSL
SDG Signals - SBTribe Research by Salterbaxter MSLSDG Signals - SBTribe Research by Salterbaxter MSL
SDG Signals - SBTribe Research by Salterbaxter MSLMSL
 
The Art and Science of Influence
The Art and Science of InfluenceThe Art and Science of Influence
The Art and Science of InfluenceMSL
 
News in the Times of Digital - Indian Media Trends
News in the Times of Digital - Indian Media TrendsNews in the Times of Digital - Indian Media Trends
News in the Times of Digital - Indian Media TrendsMSL
 
Trump Administration
Trump AdministrationTrump Administration
Trump AdministrationMSL
 
Governing a Divided Nation - Insights about the 2016 U.S. Presidential Election
Governing a Divided Nation - Insights about the 2016 U.S. Presidential ElectionGoverning a Divided Nation - Insights about the 2016 U.S. Presidential Election
Governing a Divided Nation - Insights about the 2016 U.S. Presidential ElectionMSL
 
Mind The Gap by Salterbaxter MSLGROUP
Mind The Gap by Salterbaxter MSLGROUPMind The Gap by Salterbaxter MSLGROUP
Mind The Gap by Salterbaxter MSLGROUPMSL
 
A Guide to the Trump Administration
A Guide to the Trump Administration A Guide to the Trump Administration
A Guide to the Trump Administration MSL
 
Brand Culture in the Conversation Age
Brand Culture in the Conversation AgeBrand Culture in the Conversation Age
Brand Culture in the Conversation AgeMSL
 
Role of Millennials and their Impact on Reputation Management
Role of Millennials and their Impact on Reputation ManagementRole of Millennials and their Impact on Reputation Management
Role of Millennials and their Impact on Reputation ManagementMSL
 

More from MSL (20)

The Disenchantment of Latin America: What to expect from the region in 2020?
The Disenchantment of Latin America: What to expect from the region in 2020?The Disenchantment of Latin America: What to expect from the region in 2020?
The Disenchantment of Latin America: What to expect from the region in 2020?
 
Is Technology Removing the ‘Care’ from Healthcare?
Is Technology Removing the ‘Care’ from Healthcare?Is Technology Removing the ‘Care’ from Healthcare?
Is Technology Removing the ‘Care’ from Healthcare?
 
Powered by AI - Country-wise Spotlight
Powered by AI - Country-wise SpotlightPowered by AI - Country-wise Spotlight
Powered by AI - Country-wise Spotlight
 
Powered by AI: Communications and Marketing in the Algorithm Age
Powered by AI: Communications and Marketing in the Algorithm AgePowered by AI: Communications and Marketing in the Algorithm Age
Powered by AI: Communications and Marketing in the Algorithm Age
 
AT&T Dares to "Rethink Possible"
AT&T Dares to "Rethink Possible"AT&T Dares to "Rethink Possible"
AT&T Dares to "Rethink Possible"
 
SCOTUS Launches New Economy with Legalized Sports Betting
SCOTUS Launches New Economy with Legalized Sports BettingSCOTUS Launches New Economy with Legalized Sports Betting
SCOTUS Launches New Economy with Legalized Sports Betting
 
[Salterbaxter Directions] The Big Shift
[Salterbaxter Directions] The Big Shift[Salterbaxter Directions] The Big Shift
[Salterbaxter Directions] The Big Shift
 
[Salterbaxter Directions] Moving The Goal Posts
[Salterbaxter Directions] Moving The Goal Posts[Salterbaxter Directions] Moving The Goal Posts
[Salterbaxter Directions] Moving The Goal Posts
 
MSL's 2018 Food Trends Presentation
MSL's 2018 Food Trends Presentation MSL's 2018 Food Trends Presentation
MSL's 2018 Food Trends Presentation
 
MSL's 2018 Food Trends Forecast
MSL's 2018 Food Trends ForecastMSL's 2018 Food Trends Forecast
MSL's 2018 Food Trends Forecast
 
The Second Technology Revolution: How the PR Business Needs To Change Once Again
The Second Technology Revolution: How the PR Business Needs To Change Once AgainThe Second Technology Revolution: How the PR Business Needs To Change Once Again
The Second Technology Revolution: How the PR Business Needs To Change Once Again
 
SDG Signals - SBTribe Research by Salterbaxter MSL
SDG Signals - SBTribe Research by Salterbaxter MSLSDG Signals - SBTribe Research by Salterbaxter MSL
SDG Signals - SBTribe Research by Salterbaxter MSL
 
The Art and Science of Influence
The Art and Science of InfluenceThe Art and Science of Influence
The Art and Science of Influence
 
News in the Times of Digital - Indian Media Trends
News in the Times of Digital - Indian Media TrendsNews in the Times of Digital - Indian Media Trends
News in the Times of Digital - Indian Media Trends
 
Trump Administration
Trump AdministrationTrump Administration
Trump Administration
 
Governing a Divided Nation - Insights about the 2016 U.S. Presidential Election
Governing a Divided Nation - Insights about the 2016 U.S. Presidential ElectionGoverning a Divided Nation - Insights about the 2016 U.S. Presidential Election
Governing a Divided Nation - Insights about the 2016 U.S. Presidential Election
 
Mind The Gap by Salterbaxter MSLGROUP
Mind The Gap by Salterbaxter MSLGROUPMind The Gap by Salterbaxter MSLGROUP
Mind The Gap by Salterbaxter MSLGROUP
 
A Guide to the Trump Administration
A Guide to the Trump Administration A Guide to the Trump Administration
A Guide to the Trump Administration
 
Brand Culture in the Conversation Age
Brand Culture in the Conversation AgeBrand Culture in the Conversation Age
Brand Culture in the Conversation Age
 
Role of Millennials and their Impact on Reputation Management
Role of Millennials and their Impact on Reputation ManagementRole of Millennials and their Impact on Reputation Management
Role of Millennials and their Impact on Reputation Management
 

Recently uploaded

Experience the Future of the Web3 Gaming Trend
Experience the Future of the Web3 Gaming TrendExperience the Future of the Web3 Gaming Trend
Experience the Future of the Web3 Gaming TrendFabwelt
 
57 Bidens Annihilation Nation Policy.pdf
57 Bidens Annihilation Nation Policy.pdf57 Bidens Annihilation Nation Policy.pdf
57 Bidens Annihilation Nation Policy.pdfGerald Furnkranz
 
Rohan Jaitley: Central Gov't Standing Counsel for Justice
Rohan Jaitley: Central Gov't Standing Counsel for JusticeRohan Jaitley: Central Gov't Standing Counsel for Justice
Rohan Jaitley: Central Gov't Standing Counsel for JusticeAbdulGhani778830
 
16042024_First India Newspaper Jaipur.pdf
16042024_First India Newspaper Jaipur.pdf16042024_First India Newspaper Jaipur.pdf
16042024_First India Newspaper Jaipur.pdfFIRST INDIA
 
IndiaWest: Your Trusted Source for Today's Global News
IndiaWest: Your Trusted Source for Today's Global NewsIndiaWest: Your Trusted Source for Today's Global News
IndiaWest: Your Trusted Source for Today's Global NewsIndiaWest2
 
Global Terrorism and its types and prevention ppt.
Global Terrorism and its types and prevention ppt.Global Terrorism and its types and prevention ppt.
Global Terrorism and its types and prevention ppt.NaveedKhaskheli1
 
15042024_First India Newspaper Jaipur.pdf
15042024_First India Newspaper Jaipur.pdf15042024_First India Newspaper Jaipur.pdf
15042024_First India Newspaper Jaipur.pdfFIRST INDIA
 
complaint-ECI-PM-media-1-Chandru.pdfra;;prfk
complaint-ECI-PM-media-1-Chandru.pdfra;;prfkcomplaint-ECI-PM-media-1-Chandru.pdfra;;prfk
complaint-ECI-PM-media-1-Chandru.pdfra;;prfkbhavenpr
 

Recently uploaded (8)

Experience the Future of the Web3 Gaming Trend
Experience the Future of the Web3 Gaming TrendExperience the Future of the Web3 Gaming Trend
Experience the Future of the Web3 Gaming Trend
 
57 Bidens Annihilation Nation Policy.pdf
57 Bidens Annihilation Nation Policy.pdf57 Bidens Annihilation Nation Policy.pdf
57 Bidens Annihilation Nation Policy.pdf
 
Rohan Jaitley: Central Gov't Standing Counsel for Justice
Rohan Jaitley: Central Gov't Standing Counsel for JusticeRohan Jaitley: Central Gov't Standing Counsel for Justice
Rohan Jaitley: Central Gov't Standing Counsel for Justice
 
16042024_First India Newspaper Jaipur.pdf
16042024_First India Newspaper Jaipur.pdf16042024_First India Newspaper Jaipur.pdf
16042024_First India Newspaper Jaipur.pdf
 
IndiaWest: Your Trusted Source for Today's Global News
IndiaWest: Your Trusted Source for Today's Global NewsIndiaWest: Your Trusted Source for Today's Global News
IndiaWest: Your Trusted Source for Today's Global News
 
Global Terrorism and its types and prevention ppt.
Global Terrorism and its types and prevention ppt.Global Terrorism and its types and prevention ppt.
Global Terrorism and its types and prevention ppt.
 
15042024_First India Newspaper Jaipur.pdf
15042024_First India Newspaper Jaipur.pdf15042024_First India Newspaper Jaipur.pdf
15042024_First India Newspaper Jaipur.pdf
 
complaint-ECI-PM-media-1-Chandru.pdfra;;prfk
complaint-ECI-PM-media-1-Chandru.pdfra;;prfkcomplaint-ECI-PM-media-1-Chandru.pdfra;;prfk
complaint-ECI-PM-media-1-Chandru.pdfra;;prfk
 

Transatlantic Personal Data Processing: Complying with the new EU-US Privacy Shield

  • 1. In July 2016, the European Commission adopted its highly anticipated EU-US “Privacy Shield,” setting up a new data protection framework for organisations that transfer EU citizens’ personal data to the US. More than 4,000 organisations are expected to have to adapt their privacy policies and practices accordingly, and sign up to the new statutory requirements. Key Elements of the Privacy-Shield I. Enhanced Privacy Shield Principles In compliance with the new Privacy-Shield Agreement, organisations processing personal data from EU countries will have to self-certify their adherence to the following principles:  The Notice principle - Companies will have to inform European citizens about the type of data they are collecting, including the purpose of their processing. Companies will also provide the links to the relevant data protection authorities and to the provider of an appropriate alternative dispute settlement on their website.  The Choice principle - Individuals will have the right to object to the disclosure of their personal data to third parties and opt out, if desired. In the case of more sensitive data, companies will have to obtain express affirmative consent from individuals.  The Security principle - The processing of personal data will have to be guaranteed under “reasonable and appropriate” security measures.  The Purpose Limitation Principle - The collection of data will be limited to the sole purpose of its original intended use. The only exceptions are archiving in the public interest, journalism, literature and art, scientific and historical research and statistical analysis.  The Integrity Principle - The processing of personal data will be limited to what is relevant for its intended use. It will have to be accurate, complete and current.  The Access Principle - Individuals will be granted the right to access the information collected about them without need for justification and only against a non-excessive fee. Individuals will have the right to correct, amend or delete personal information that is inaccurate or has been processed in violation of the Privacy Shield Principles.  The Accountability for Onward Transfer Principle - Any onward transfer of personal data from a company to controllers or processors will only be possible for limited and specified purposes.  The Recourse, Enforcement and Liability Principle - Companies will have to provide robust mechanisms to ensure compliance and effective remedies. II. Reinforced citizens’ rights The US Department of Commerce will monitor and verify that the affected companies apply policies in line with the relevant Privacy Shield Principles. It will keep up-to-date a list of organisations which have signed up to the privacy shield and be responsible for removing those organisations that have either left the arrangement or failed to comply with the principles. Under the new agreement, any individual who considers that his or her data has been misused will have the right to lodge a complaint either with:  the company itself, which will have to reply within 45 days;  its national Data Protection Authority, which will refer the complaint to the US Department of Commerce, who in turn will have to respond within 90 days, or;  any Alternative Dispute Resolution Mechanism, to which US companies will have to sign up at no cost to the individual. The whole functioning of the Privacy Shield in the US will also be subject to an annual joint review to be carried out by the European Commission and the US Department of Commerce, bringing together national intelligence experts from the US and the European Data Protection Authorities.
  • 2. III. Obligations of US public authorities The Privacy-Shield also sets a certain number of limitations and safeguard mechanisms in the case of US intelligence services accessing EU citizens’ personal data for national security purposes. Most notably, these include the following:  The collection of personal data for intelligence purposes will be authorised by statute or Presidential approval and in accordance with the US Constitution and Law.  Individual data collection will be prioritised over bulk data collection – i.e. data collection affecting all individuals.  Bulk collection will only be allowed where targeted collection via the use of discriminants is not possible and only in six very specific situations (such as the fight against terrorism or opposition to activities of foreign intelligence services which could damage US interests).  The treatment of personal data will have to take into consideration the fundamental principles of dignity and respect for legitimate privacy interests. To complement these safeguards, the US authorities will establish a specific redress path for EU citizens via an Ombudsperson who will be independent from national security services. The Ombudsperson will follow up complaints and enquiries by EU individuals with respect to national security access, and confirm to the individual that the relevant laws have been complied with or, in case of non-compliance, that any non-compliance gap has been remedied. Suggested Actions for Businesses The principles-based statutory framework entails an obligation of results in terms of compliance. It reduces the uncertainty that has surrounded data-processing between the EU and US since the abolition by the European Court of Justice last October 2015 of the previous legal framework known as the EU-US “safe harbor” agreement, but does not immunize organisations processing personal data across the Atlantic against possible legal actions for alleged non- compliance, with direct repercussions on company reputation and the exposure vis-à-vis markets, stakeholders and public opinion in general to negative communication campaigns. To reduce such risk, and given the high sensitivity of the Europeans to data privacy, organisations wishing to begin or start processing European citizens’ personal data in the US, should consider the following actions with a view to assessing and adapting their privacy policies and practices throughout the whole organisation and in the context of third-party service providers. Action for Business  Assess the adequacy of your current privacy policies with the above-mentioned Privacy-Shield Principles and adapt them accordingly.  Assess and, if necessary, review external contractual clauses with third parties that receive personal data collected by your organisation to ensure that they provide the same level of protection as stipulated by the Privacy Shield Principles.  Review and set up the appropriate internal governance to ensure that replies to potential complaints from EU citizens are answered within the time limit of 45 days, as well as inquiries and requests by the US Department of Commerce.  Identify and register with an Alternative Dispute Resolution Provider which will have to be made available to European citizens at no cost.  Register your organisation to the Privacy Shield list on the US Department of Commerce website, providing a declaration of the organisation’s commitment to comply with the Privacy Shield Principles.  Publicize on your own website the link to your Alternative Dispute Resolution Provider, together with a link to the US Department of Commerce’s Privacy Shield website.  Monitor implementation and renew the registration every year. Brussels, 20 July For more specific advice on EU developments and on possible actions to be taken within your organisation, please contact Leonardo Sforza Managing Director and Head EU Affairs, Brussels Leonardo.sforza@mslgroup.com +32 (0)2 737 92 00