Waselius & Wist Navigation
  • Our team
  • In Focus
    • Recent Work
    • News
    • Legal Updates
    • Publications
    • Rankings
    • Blog
    • Newsletter
  • About Us
    • Corporate Social Responsibility
  • Expertise
    • Banking and Finance
    • Capital Markets
    • Corporate and Commercial
    • Corporate governance and Investigations
    • Data Protection
    • Dispute Resolution
    • Employment and Incentives
    • Energy and Natural Resources
    • EU and Competition
    • Financial Regulatory and Compliance
    • Insurance
    • Intellectual Property and Technology
    • Marketing
    • Mergers and Acquisitions
    • Private Equity
    • Real Estate
    • Restructuring and Insolvency
    • Tax and Structuring
  • Careers
    • Lawyers
    • Law students
    • Support staff
    • Open Positions
    • Contact
  • Contact
  • Our team
  • In Focus
    • Recent Work
    • News
    • Legal Updates
    • Publications
    • Rankings
    • Blog
    • Newsletter
  • About Us
    • Corporate Social Responsibility
  • Expertise
    • Banking and Finance
    • Capital Markets
    • Corporate and Commercial
    • Corporate governance and Investigations
    • Data Protection
    • Dispute Resolution
    • Employment and Incentives
    • Energy and Natural Resources
    • EU and Competition
    • Financial Regulatory and Compliance
    • Insurance
    • Intellectual Property and Technology
    • Marketing
    • Mergers and Acquisitions
    • Private Equity
    • Real Estate
    • Restructuring and Insolvency
    • Tax and Structuring
  • Careers
    • Lawyers
    • Law students
    • Support staff
    • Open Positions
    • Contact
  • Contact
In Focus
Home In Focus The EU Commission introduces the EU-US Privacy Shield to restore the trust in transatlantic data flows

Legal Updates03.03.2016

The EU Commission introduces the EU-US Privacy Shield to restore the trust in transatlantic data flows

The EU Commission published on 29 February 2016 details of the EU-US Privacy Shield, the new framework for data exchange between the EU and the US. The EU-US Privacy Shield is intended to restore trust in transatlantic data flows since the Court of Justice of the European Union declared the previous Safe Harbour regime invalid on 6 October 2015.

The US government access to the data was a major factor contributing to the downfall of the Safe Harbour regime. The establishment of the new EU-US Privacy Shield was made possible by the written assurance given by the US government to the EU policymakers that the US government access to European data will be limited and subject to clear safeguards and oversight mechanisms, including a possibility for European individuals to file complaints through a specialized Ombudsperson mechanism.

Like its predecessor, the EU-US Privacy Shield will operate on an opt-in basis. The US companies participating in the new regime has to commit to comply with a set of privacy principles mirroring the obligations applicable to EU companies. To comply with the EU-US Privacy Shield US companies must, inter alia, adequately inform the data subjects of the processing of their personal data, set up necessary security measures to protect the data, provide effective remedies in case of non-compliance and ensure that the same level of protection is guaranteed if the personal data is transferred to a third party.

The US Federal Trade Commission will be authorized to enforce the commitments under US law, but the EU-US Privacy Shield will also empower EU citizens to look after their own rights. The citizens have an option to file a complaint directly with the respective company and the company is obliged to respond to a complaint within 45 days. Alternatively, EU citizens may go through their national Data Protection Authorities and have their complaints handled by the US Federal Trade Commission. The possibility for complaints is supported by an access to a free of charge alternative dispute resolution process or ultimately an arbitration mechanism providing for an enforceable remedy as a last resort.

The EU-US Privacy Shield will be subject to an annual joint review by the EU and the US authorities. Furthermore, the EU Commission reserves the right to suspend the EU-US Privacy Shield at any time if the EU Commission concludes that the required level of protection is no longer ensured in the US.

Before the EU-US Privacy Shield is adopted in its final form, the EU Commission will hear the EU Data Protection Authorities and the committee composed of the representatives of the Member States. At the same time the US authorities will start the steps to put in place the new structures required by the new framework.

There are strong indicators that the EU Commission will push through with the new framework and that the EU-US Privacy Shield will be adopted, but until then it would be prudent for transferors of data to the US to comply with other mechanisms set out in the European data protection legislation, such as model contractual clauses.

For details on the Commission’s announcement on the EU-US Privacy Shield, please click here.

For further information, please contact

Bernt Juthström

Partner

Jouni Kautto

Specialist Partner

Share:
Image

Contact info

Eteläesplanadi 24 A
00130 Helsinki, Finland

+358 9 668 9520
+358 9 668 95 222
ww@ww.fi

Quick links

  • Our Team
  • In Focus
  • About Us
  • Expertise
  • Careers

E-invoicing

E-address: 003710525214
Operator: Apix Messaging Oy
Service ID: 003723327487


BUSINESS ID 1052521-4
VAT ID FI10525214

Legal notice
Privacy notice
General Terms and Conditions

© 2022 Waselius & Wist

This website uses cookies to compile statistical data on the use of our website in order to enable us to evaluate and improve our site. OK Decline Cookie Policy
Manage Cookies

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT