What is Privacy Shield and how can organisations comply?

Post by LexisNexis Enterprise Solutions | February 18, 2016

The European Commission recently announced a new Safe Harbor deal - being called EU-US Privacy Shield, which it hopes to have in place within three months.

The European Commission recently announced a new Safe Harbor deal - being called EU-US Privacy Shield, which it hopes to have in place within three months. The Commission is proposing that the new Privacy Shield arrangement is based on a unilateral decision from the European Commission that US data protection laws are adequate when a company has signed up to the Privacy Shield Programme.

It remains to be seen if the new deal can be a lasting solution as it presently seems unlikely that Privacy Shield will be a complete answer to any organisation’s data transfer issues. With practical work on the deal still underway, it’s important that organisations act now to protect themselves. They must have plans in place to comply.

Here are some suggestions:

Even though Privacy Shield is still ‘work in progress’, questions remain about enforcement – will it be piecemeal and connected with other investigations or orchestrated and widespread? Initial signs from France and Germany especially suggest enforcement is starting but how much of an issue that becomes is yet to be seen.