Is Privacy Shield Dead

As the GDPR was being published, the United States developed concepts known as Safe Harbor and the Privacy Shield, which were voluntary for U.S. organizations wishing to do business with EU persons or organizations. In essence it provided an early on-ramp for companies to achieve some degree of GDPR compatibility. Privacy Shield was implemented with a U.S.-EU agreement

2 slides · 1 min read · Domain 1

Slide 1

In July 2020, the European Court of Justice (ECJ) struck down the Privacy Shield agreement, siding with a plaintiff claiming that Privacy Shield did not protect EU persons from being exposed to U.S. national security surveillance activities. (Privacy Shield could not, for example, interfere with or block a National Security Letter's direction to a private business to establish surveillance or surrender data pursuant to the USA PATRIOT Act.)

The court did not strike down what is referred to as standard contract clauses (SCCs), which many major U.S. companies

(such as Microsoft) have been using in their contracts with EU customers and service providers. (SCCs hold these companies privately to obey the specifics of GDPR, in the absence of prevailing U.S. law.) The court did, however, admonish data surveillance and protection watchdogs to pay special attention to verify compliance with these SCCs.

Whether this is the first round in a "privacy trade war," as some analysts describe it, or a strong step toward exerting more control over the surveillance states is yet to be determined.

Test this domain