Thursday

18th Oct 2018

Hundreds of US companies make false data protection claims

  • Data visualisation map for one client by internet firm LinkedIn (Photo: luc legay)

Hundreds of US-based companies handling EU citizens' data have lied about belonging to a data protection arrangement known as the Safe Harbour Framework.

Christopher Connolly, a director at Galexia, an Australian-based consulting company on internet law and privacy, told the European Parliament’s civil liberties committee on Monday (7 October) that “many claims of Safe Harbour membership are false.”

Read and decide

Join EUobserver today

Support quality EU news

Get instant access to all articles — and 18 year's of archives. 30 days free trial.

... or join as a group

He said around one out of every seven Safe Harbour claims of membership are bogus.

The Safe Harbour agreement, hammered out in 2000 between the European Commission and the US Department of Commerce, is supposed to ensure that firms follow EU data protection laws when processing the personal data of EU citizens.

Just under 3,000 companies have signed up to the self-certification scheme, which is only enforceable once the company makes a promise to adhere to a handful of privacy principles.

Companies are also entitled to limit the scope to cover only human resource data, or consumer data, or just offline data.

Galaxia research found over 200 false claims in 2008. This had increased to 427 in September 2013.

“In those 427 organisations, you will find large household names in Europe, with hundreds of millions of customers,” Connolly said.

He added that some of the companies place unauthorised Safe Harbour seals and logos on their website without ever having signed up to the framework in the first place.

The unauthorised visual symbols often have the word ‘EU’ or the European flag on the seal.

“These are simply very low quality and false representations of the actual membership of the Safe Harbour,” Connolly noted.

Over 10 percent of companies that make a false claim of Safe Harbour membership display the US department of commerce Safe Harbour logo on their website.

Privacy advocates have for years asked the Federal Trade Commission (FTC), which enforces Safe Harbour, to address the false claims but with little success.

The FTC has filed six cases of false claims against minor companies and did not sanction any of them.

Around 30 percent of all companies do not provide any information on dispute resolution options, contrary to the Safe Harbour rules. Others who display resolution options point to agencies that charge thousands of dollars to file a complaint.

Over 460 members cite the American Arbitration Association as their dispute resolution provider, which charges the person filing the complaint between $120 and $1,200 per hour with a four-hour minimum charge plus a $950 administration fee.

Meanwhile, Safe Harbour has no provisions to stop NSA-type activities from snooping on EU citizens.

Financial records, data records, travel records, and data and voice carried by US telecommunications providers are excluded from Safe Harbour jurisdiction.

“It would be dangerous to rely on Safe Harbour to manage any aspect of the specific national security issue we face now without first addressing the broader issue of false claims and non-compliance,” Connolly said.

The European Commission, for its part, said it is possible the agreement contains loopholes.

It noted, a few weeks after former NSA agent turned whistleblower Edward Snowden leaked secret documents to the Washington Post and the Guardian, that US data protection standards are lower than in the EU.

"The Safe Harbour agreement may not be so safe after all,” said EU commissioner for Justice Viviane Reding in July.

The commission is set to come out with an assessment report on Safe Harbour before the end of the year.

The FTC, for its part, says the agreement ensures the safe transfer of data of EU citizens.

“We think it is a great way for us to protect European citizens when we are doing a case involving a US company,” FTC commissioner Julie Brill told reports in Brussels in March.

EU privacy bill - one-stop shop

For her part, Reding also on Monday in Luxembourg said "an overwhelming majority" of EU justice ministers gave her "a very strong political endorsement" on a separate EU data privacy bill.

Under the draft law, EU citizens who want to complain about data-mishandling by internet firms, such as Facebook or Google, which have their EU seats in Ireland, can appeal to their national data chiefs instead of trying to reach the more remote Irish authorities.

On the other side, companies can tackle EU-wide data cases through the data chief in the EU country in which they have their HQ, instead of dealing with 28 different EU authorities.

Reding said her officials will draft a final version of the bill in December, with a view to adoption before EU elections in May 2014.

News in Brief

  1. Poland questions supremacy of EU court
  2. Medvedev to meet Juncker and Merkel in Brussels
  3. Italians and Czechs least favourable to remaining in EU
  4. Facebook hack set to be first major test of EU data rules
  5. Barnier open to extending Brexit transition period
  6. Juncker mulls rejection of Italy's 2019 budget
  7. German justice minister to lead SPD in European elections
  8. Tusk: May should come with new Brexit proposals

Opinion

Interpol, China and the EU

China joins a long list of countries - including Russia - accused of abusing Interpol's 'Red Notice' system to harras activists and dissidents.

Stakeholders' Highlights

  1. International Partnership for Human RightsOpen letter to Emmanuel Macron ahead of Uzbek president's visit
  2. International Partnership for Human RightsRaising key human rights concerns during visit of Turkmenistan's foreign minister
  3. NORDIC COUNCIL OF MINISTERSState of the Nordic Region presented in Brussels
  4. NORDIC COUNCIL OF MINISTERSThe vital bioeconomy. New issue of “Sustainable Growth the Nordic Way” out now
  5. NORDIC COUNCIL OF MINISTERSThe Nordic gender effect goes international
  6. NORDIC COUNCIL OF MINISTERSPaula Lehtomaki from Finland elected as the Council's first female Secretary General
  7. NORDIC COUNCIL OF MINISTERSNordic design sets the stage at COP24, running a competition for sustainable chairs.
  8. Counter BalanceIn Kenya, a motorway funded by the European Investment Bank runs over roadside dwellers
  9. ACCACompany Law Package: Making the Best of Digital and Cross Border Mobility,
  10. International Partnership for Human RightsCivil Society Worried About Shortcomings in EU-Kyrgyzstan Human Rights Dialogue
  11. UNESDAThe European Soft Drinks Industry Supports over 1.7 Million Jobs
  12. Mission of China to the EUJointly Building Belt and Road Initiative Leads to a Better Future for All

Latest News

  1. No progress at Brexit summit, talks continue
  2. May faces EU leaders head-to-head as Brexit deal falters
  3. Nordic region's top bank in new Russia funds complaint
  4. Why 'Spitzenkandidat' is probably here to stay
  5. EU ministers struggle to deal with Poland and Hungary
  6. Commission tried to hide details of 'WiFi4EU' glitch
  7. Brexit standoff continues before EU summit
  8. ASEM: Global Partners for Global Challenges

Stakeholders' Highlights

  1. International Partnership for Human RightsCivil society asks PACE to appoint Rapporteur to probe issue of political prisoners in Azerbaijan
  2. ACCASocial Mobility – How Can We Increase Opportunities Through Training and Education?
  3. Nordic Council of MinistersEnergy Solutions for a Greener Tomorrow
  4. UNICEFWhat Kind of Europe Do Children Want? Unicef & Eurochild Launch Survey on the Europe Kids Want
  5. Nordic Council of MinistersNordic Countries Take a Stand for Climate-Smart Energy Solutions
  6. Mission of China to the EUChina: Work Together for a Better Globalisation
  7. Nordic Council of MinistersNordics Could Be First Carbon-Negative Region in World
  8. European Federation of Allergy and AirwaysLife Is Possible for Patients with Severe Asthma
  9. PKEE - Polish Energy AssociationCommon-Sense Approach Needed for EU Energy Reform
  10. Nordic Council of MinistersNordic Region to Lead in Developing and Rolling Out 5G Network
  11. Mission of China to the EUChina-EU Economic and Trade Relations Enjoy a Bright Future
  12. ACCAEmpowering Businesses to Engage with Sustainable Finance and the SDGs

Join EUobserver

Support quality EU news

Join us