On September 12, the North Rhine-Westphalia DPA published guidelines (source document in German) outlining responsibilities and requirements for transferring personal data from the EU to the United States under the new EU–US Privacy Shield. The guide, which is directed at data controllers, discusses due diligence requirements for transfers to Privacy Shield certified organizations, including certification verification and ensuring that the concrete data transfer is covered by the certification.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.