EU Top Court Strikes Down Privacy Shield, CCIA Calls for Urgent Legal Certainty and Solutions

BY Heather Greenfield
July 16, 2020

Brussels, BELGIUM — The European Court of Justice (CJEU) issued a landmark ruling today that invalidates Privacy Shield, a key legal mechanism which thousands of companies use to transfer commercial data from the EU to the United States.

The CJEU ruled that the Privacy Shield decision does not comply with EU law. Among other things, the Court held U.S. law does not provide sufficient protection of EU personal data despite the public authorities access limitations provided in the Privacy Shield decision. The Court also takes issue with the Privacy Shield mechanism for EU individuals to seek judicial protection when their data is potentially accessed by U.S. public authorities.  

Over 5,000 companies have signed up to the Privacy Shield framework. 70% of them are small and medium-sized businesses. Many U.S. subsidiaries of European companies have also joined.

The CJEU did confirm that Standard Contractual Clauses (“SCCs”), another popular mechanism, remain valid to transfer data outside Europe. However, Data Protection Authorities must suspend or prohibit data transfers under SCCs if the laws of the country of destination are such that the contractual safeguards cannot be met by either one of the parties.

The following can be attributed to Alexandre Roure, CCIA Public Policy Senior Manager:

“This decision creates legal uncertainty for the thousands of large and small companies on both sides of the Atlantic that rely on Privacy Shield for their daily commercial data transfers. We trust that EU and U.S. decision-makers will swiftly develop a sustainable solution, in line with EU law, to ensure the continuation of data flows which underpins the transatlantic economy. We hope enforcement authorities will grant Privacy Shield signatories time to migrate to alternative legal mechanisms.”

For media inquiries, please contact Communications Director Heather Greenfield hgreenfield@ccianet.org

 

Related Articles

European Parliament Resolution Raises Doubt about EU-UK Data Flows

May 10, 2021

Brussels, BELGIUM — The European Parliament’s Civil Liberties, Justice and Home Affairs Committee (LIBE) today reportedly opined that the United Kingdom does not provide adequate privacy protection to allow the transfer of EU personal data. Under the terms of the EU-UK Trade and Cooperation Agreement, the UK is considered adequate until 30 June 2021. While…

CCIA Supports NIST’s Privacy Risk Management Framework

May 10, 2021

Washington — As the National Institute of Standards and Technology works to further develop its Privacy Risk Management Framework, CCIA offered a statement supporting this framework for risk-based mechanisms to improve privacy. The following can be attributed to CCIA Vice President of Public Policy Arthur Sidney:  “In the modern data-enabled economy, businesses work hard to…

CCIA Welcomes the EU’s Risk-Based AI Proposal, Urges Further Clarifications

Apr 21, 2021

Brussels, BELGIUM — The European Commission today presented its Artificial Intelligence (AI) framework which includes an AI-specific Regulation. The regulation prohibits certain practices and introduces comprehensive requirements for “high risk” systems before their introduction to the EU market. Other requirements include informing users when they are interacting with an AI system, e.g. via chatbots. Fines…