GDPR and Privacy Shield—Are They Compatible?

Moving and protecting sensitive data has faced a rocky road in the European Union. This is evidenced by the various schemes and regulations set up—and in some cases struck down—relating to rules and guidelines for data transfer and security.
On October 6, 2015, the European Court of Justice declared “invalid” the EC’s Decision 2000/520/EC of July 26, 2000 “on the adequacy of protection provided the safe harbour privacy principles and related frequently asked questions issued by the US Department of Commerce.” That decision meant that as of October 31, 2016, the Department of Commerce stopped accepting U.S.-EU Safe Harbor certifications, and companies could no longer turn to the U.S.-EU Safe Harbor Framework for compliance with EU data protection requirements when transmitting personal data from the EU to the United States. This outcome left both U.S. and EU companies dealing with a difficult reality: they had no legal process to transfer data out of the European Union to the United States.
So on July 12, 2016, the EU Commissioner and U.S. Secretary of Commerce jointly announced approval of the EU-U.S. Privacy Shield Framework. (The scheme was put forth in February 2016 and finally began accepting certifications on August 1, 2016.) Like the original Safe Harbor process that it replaced, Privacy Shield is a valid legal mechanism to comply with the European Union’s requirements regarding personal data transfer from the EU to the U.S.
The U.S. Department of Commerce’s International Trade Administration (ITA) administers the Privacy Shield program. The program enables U.S.-based companies to join one or both Privacy Shield Frameworks to benefit from the adequacy determinations. To join, organizations must self-certify to the Department of Commerce (via the Privacy Shield website) and commit to compliance with the Framework’s requirements. Joining the Privacy Shield is voluntary, but if an eligible organization commits to compliance, it becomes enforceable under U.S. law.
Despite the fact that the program is voluntary, 2,300 companies had joined the Privacy Shield as of November 2017. However, since not all European countries, localities, and courts have universally accepted Privacy Shield, it is expected to face similar challenges to the now-defunct Safe Harbor scheme.
Regulations, Directives, and Guidance—Oh My
There is another layer of legalese that EU-based companies must contend with as well in the growing attempts to protect EU citizens from data and privacy breaches. The EU is aiming to streamline data protection regulations while strengthening protection for all EU-affiliated individuals with the General Data Protection Regulation (GDPR). This new legal framework is set to come into effect in just a few months, on May 25, replacing the current EU Data Protection Directive. Compared with the 1995 directive, the GDPR has increased territorial scope—not only is every company in the EU going to be affected by GDPR, but companies outside of Europe including those based in the U.S. must follow the same rules if selling goods or services to Europeans. In terms of penalties, organizations found to be in breach of any of the conditions specified under GDPR (see below) may find themselves fined up to £20 million or 4 percent of their annual global turnover, whichever is greater. What’s more, GDPR strengthens the conditions for consent, and requests for consent must be given in an easily accessible form.
As companies attempt to sort out all of this new information, a logical question is, how do directives (which previously governed EU data privacy) differ from regulations, which will soon take affect via the GDPR? It’s important to note that directives are simply recommendations and are therefore not legally binding—but regulations like GDPR are laws, and therefore are legally binding. Therefore, the GDPR has huge liabilities for EU member states that don’t follow it, as well as for companies outside of the EU that hold any personal data of EU citizens.
With this in mind, let’s review 8 “rights” that data subjects are guaranteed under the pending GDPR legislation:
- Right to be informed. This provides transparency over how personal data is used. The GDPR also makes breach notification mandatory within 72 hours of becoming aware of a breach.
- Right to access. This ensures that you can obtain confirmation about whether your personal data is being processed, where it is being used, and for what purpose.
- Right to rectification. If your personal data is found to be incorrect or incomplete, you have the right to have it corrected.
- Right to be forgotten. Also known as “Data Erasure,” this gives you the right to have personal data removed when there is no compelling reason to store it, and to cease further dissemination of it.
- Right to restrict processing. You can opt to allow personal data to be stored without being processed—for example, you might summon this right if you feel that the data is inaccurate and have requested rectification.
- Right to data portability. The concept of data portability is being introduced for the first time with GDPR. This means that you can request copies of the personal information stored about you, and you can transmit it to use elsewhere.
- Right to object. You can object to the way that your data is processed, and the holder of that data must comply according to the regulation. For example, you might object to direct marketing organizations using your data.
- Rights to automated decision making and profiling. When decisions are made based on your data without human intervention, you have a right to object to them—for example, if your online shopping habits are determined based on your previous online behavior.
GDPR + Privacy Shield = ?
A fair question that many affected are now asking is whether the legal requirements under GDPR are compatible with the Privacy Shield Framework. The fact is, though, that the GDPR contains no mention of the Privacy Shield agreement. So what’s important to remember is that because the GDPR is a law and not a directive, it must take priority at all times, since there will be extremely high penalties if it is not followed.
Here are some key points to keep in mind when attempting to navigate the current data protection landscape:
- Privacy Shield allows EU companies and U.S. companies with an EU presence to meet specific GDPR data handling requirements.
- The GDPR features specific requirements applying to data transfer out of the EU—including that such transfer can only occur in countries that have been identified as having adequate data protection laws.
- Currently, the EU does not list the United States as a country that meets that requirement. That said, Privacy Shield is designed to designate member companies as meeting certain data protection requirements.
Considering the Cloud
All of this talk about data protection and safeguarding sensitive information naturally raises the subject of the cloud as a data repository. As companies attempt to wade through the new legislation and frameworks, some still fear moving their data into a cloud based on the erroneous belief the cloud is a huge, amorphous repository that stores data wherever there is available space. But in reality, keeping data in the cloud does not have to put your data at risk, particularly if you use the latest data protection platforms.
Microsoft Azure, for example, has a wide range of controls that allow users to designate how they collect, store, and use that stored data. Microsoft has installed data centers in 32 regions worldwide so that companies residing or doing business in the European Union have the ability to designate which regions to store their data assets. There’s even now a platform for native Azure cloud-managed archiving designed just for securely archiving and managing sensitive data. With the right technology tools, companies working with EU data can gain peace of mind that they will be fully compliant with EU laws and regulations—as well as the latest directives.


