Sunday

22nd May 2022

Will US privacy-lite hollow out GDPR?

  • Despite their different approaches, the EU and the US have an agreement to share personal data for commercial purposes, known as 'Privacy Shield' (Photo: Josh Hallett)

Over 90 percent of the data on the internet has been created since 2016. Yet, the amount of personal information online is expected to grow exponentially in the next years.

As a result, data protection and privacy rules have either been introduced or are being considered in many countries across the world.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

The European Union's General Data Protection Regulation (GDPR), which entered into force in 2018, introduced pioneering legislation that set data privacy standards for millions of citizens in the EU and beyond.

Some say that GDPR is currently the most developed data protection law in the world, but the United States (US) has opted for a very different approach.

The American National Institute of Standards and Technology (NIST) recently released (16 January) the long-awaited Privacy Framework, which is not a law or regulation, but rather a "voluntary tool".

This framework aims to help organisations manage privacy risks and technical capabilities to comply with laws that may affect them, but also helps industries to communicate from the executive to the implementation level about privacy practices, aiming to increase consumers' trust.

"I think about it as building foundational blocks for privacy that anybody [small and big enterprises] can use to meet their obligations and manage their privacy risks," the senior policy adviser and leader for the Privacy Framework at NIST, Naomi Lefkovitz, told journalists in Brussels.

This model, basically focussed on privacy risk management, is "very flexible" so it could also be adopted in Europe complementing existing EU law, she said.

"We look at privacy risks from embarrassment to discrimination as a result of data processing, [and] these are the same issues that Europe is looking at," Lefkovitz said.

"But there is no one right answer when it comes to privacy," she added.

The European rules on data privacy have contributed to the development of the US Privacy Framework, according to Lefkovitz, who hopes that this voluntary tool "can return the favour" to achieve more effective solutions within the GDPR.

The EU-US Privacy Shield

Despite their different approaches, the EU and the US have an agreement to share personal data for commercial purposes, under certain conditions, since the EU-US 'privacy shield' framework was adopted in 2016.

But this deal has repeatedly received criticism from civil society and MEPs, who believe that European citizens' rights might be not fully protected.

In June 2018, the European Parliament's civil liberties committee (Libe) called on the European Commission to suspend the EU-US data transfer pact - something that might happen due to the "Schrems II" ongoing case before the European Court of Justice.

However, after the commission gave the green light to the agreement in its third annual review last October, some members of the committee remain sceptical.

"The EU-US 'privacy shield' is inadequate as a safeguard, badly implemented, hardly enforced and weakly scrutinised," Dutch liberal MEP Sophie in 't Veld said earlier this month.

"This is not the way that we can protect our citizens. This [agreement] does not even take the EU seriously. We make laws, then we negotiate with the US and we give it all away," she told MEPs from Libe.

According to the international NGO Access Now, "the EU does not only enable the continuous violation of fundamental rights under this arrangement, but it is also undermining its global leadership role on the protection of personal data".

MEPs from the Libe committee will be travelling to the US from 23 to 29 February to discuss EU-US justice and home affairs, including the privacy shield framework.

Privacy Shield less relevant given GDPR, says data chief

Giovanni Buttarelli, the European data protection supervisor, says the EU-US data sharing pact known as Privacy Shield will play an increasingly minor role given the general data protection regulation.

GDPR - a global 'gold standard'?

The new EU privacy rules are touted as a global 'gold standard' - but Mexico's former data commissioner warns some nations are far from ready.

Interview

2013: Snowden was 'wake-up call' for GDPR

The contentious negotiations on the EU's data protection rules (GDPR), very much influenced by intense lobbying from the US, radically changed after whistleblower Edward Snowden revealed in 2013 that US intelligence services were collecting worldwide user-data.

MEPs: 'Mass surveillance' still possible under US privacy deal

A delegation of MEPs from the civil liberties committee have warned of the remaining "deficiencies" of the EU-US 'privacy shield' framework, amid concerns over the efficiency of this mechanism to protect EU citizens' fundamental rights.

EU reaches deal on flagship cybersecurity law

The European Parliament and EU member states have reached an agreement over new rules intended to protect Europe's public and private critical entities from cyberattacks.

Stakeholder

The CPDP conference wants multidisciplinary digital future

During the Computers, Privacy and Data Protection (CPDP) conference, many high-level discussions will touch upon the dynamics of decision-making in the design of new technologies, including the importance of inclusion, diversity, and ethics perspectives within these processes.

EU Commission won't probe 'Pegasus' spyware abuse

The European Commission says people should file their complaints with national authorities in countries whose governments are suspected of using an Israeli-made Pegasus spyware against them.

News in Brief

  1. UK to send 'hundreds' of migrants to Rwanda each year
  2. Norwegian knife attacks were domestic dispute
  3. Sweden hits back at Turkey's 'disinformation' in Nato bid
  4. Germany's Schröder gives up one of two Russia jobs
  5. G7 countries pledge €18bn in financial aid for Ukraine
  6. Italian unions strike in protest over military aid for Ukraine
  7. Russia cuts gas supply to Finland
  8. Half of Gazprom's clients have opened rouble accounts

Stakeholders' Highlights

  1. Nordic Council of MinistersNordic delegation visits Nordic Bridges in Canada
  2. Nordic Council of MinistersClear to proceed - green shipping corridors in the Nordic Region
  3. Nordic Council of MinistersNordic ministers agree on international climate commitments
  4. UNESDA - SOFT DRINKS EUROPEEfficient waste collection schemes, closed-loop recycling and access to recycled content are crucial to transition to a circular economy in Europe
  5. UiPathNo digital future for the EU without Intelligent Automation? Online briefing Link

Latest News

  1. What Europe still needs to do to save its bees
  2. Remembering Falcone: How Italy almost became a narco-state
  3. Economic worries and Hungary on the spot Next WEEK
  4. MEPs urge sanctioning the likes of ex-chancellor Schröder
  5. MEPs call for a more forceful EU response to Kremlin gas cut
  6. Catalan leader slams Pegasus use: 'Perhaps I'm still spied on'
  7. More EU teams needed to prosecute Ukraine war crimes
  8. French EU presidency struggling on asylum reforms

Join EUobserver

Support quality EU news

Join us