Third Time's A Charm - Adequacy Decision For EU-U.S. Data Privacy Framework Adopted By European Commission

GA
Global Advertising Lawyers Alliance (GALA)

Contributor

With firms representing more than 90 countries, each GALA member has the local expertise and experience in advertising, marketing and promotion law that will help your campaign achieve its objectives, and navigate the legal minefield successfully. GALA is a uniquely sensitive global resource whose members maintain frequent contact with each other to maximize the effectiveness of their collaborative efforts for their shared clients. GALA provides the premier worldwide resource to advertisers and agencies seeking solutions to problems involving the complex legal issues affecting today's marketplace.
Years of anticipation culminated on July 10, 2023, when the European Commission adopted an adequacy decision (the Adequacy Decision) on the EU-U.S. Data Privacy Framework (the Framework).
Worldwide Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Years of anticipation culminated on July 10, 2023, when the European Commission adopted an adequacy decision (the Adequacy Decision) on the EU-U.S. Data Privacy Framework (the Framework).

The Adequacy Decision is the result of a series of negotiations between the European Union and the United States to ensure that the United States provides a comparable level of protection to the EU with respect to cross-border transfers of personal data under Article 45(1) of the General Data Protection Regulation (GDPR). Following the 2020 decision by the Court of Justice of the European Union (CJEU) to invalidate the EU-U.S. Privacy Shield Framework in the Schrems IIcase, U.S. companies could no longer rely on their privacy shield certification as a lawful means to transfer EU personal data.

The Adequacy Decision provides an additional mechanism - instead of standard contractual clauses (SCCs) or binding corporate rules (BCRs) - to ensure the lawful transfer of data across the Atlantic. Importantly, U.S. companies that are certified under the Framework will no longer need to implement SCCs or BCRs as a data transfer mechanism, and such transfers will not require performing a Transfer Impact Assessment (TIA) (transfers based on SCCs will still need a TIA). Companies that retained their certification under the Privacy Shield will also have access to a simplified procedure to self-certify under the new Framework.

Key Components of the Adequacy Decision

A key aspect of the Adequacy Decision is that it limits access to European citizens' personal data by U.S. intelligence services to what is "necessary and proportionate", thereby addressing the CJEU's concerns surrounding surveillance that it raised in Schrems II. The Adequacy Decision also provides European citizens with the ability to lodge complaints (for free) with their national data protection authority, which will transmit the complaint to the United States for investigation by the "Civil Liberties Protection Officer" of the U.S. intelligence community. EU citizens may appeal a decision of the officer to the newly established Data Protection Review Court, which will have the power to obtain relevant information from intelligence agencies and enforce redress mechanisms.

Regulatory Oversight

According to the European Commission's press release, the Framework will be subject to periodic reviews by the European Commission, in collaboration with representatives of European data protection authorities and U.S. regulatory agencies. The first review will take place within a year of the Adequacy Decision taking effect and will verify that all relevant elements have been properly implemented under existing U.S. laws and regulations. Although the Adequacy Decision has been finalized and formally adopted, it still may be subject to an invalidation procedure before the CJEU, but EU officials have indicated that this would be highly unlikely.

For More Information

Almost immediately after issuing the Adequacy Decision, the European Commission issued FAQs. On the U.S. side, we expect that similar guidance from the U.S. Department of Commerce, which administers the Framework, and the Federal Trade Commission (FTC), which enforces it, is forthcoming. In the meantime, the Department of Commerce is launching a new website to provide information on participating organizations, how companies can self-certify under the Framework and other resources.

The Bottom Line

  • After both the U.S.-EU Safe Harbor Framework and EU-U.S. Privacy Shield Framework were invalidated by European courts, businesses are hopeful that the new Data Privacy Framework will be the one that finally survives legal scrutiny.
  • Businesses dealing with cross-border transfers of personal data from the EU to the United States should be ready to consider registering under the new framework.

https://www.dglaw.com/third-times-a-charm-adequacy-decision-for-eu-u-s-data-privacy-framework-adopted-by-european-com

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More