Thursday

19th Oct 2017

EU to adopt new US data rules in July

  • EU commission is set to roll out its updated draft version of Privacy Shield (Photo: Matthew Klein)

The European Commission is set to present a new draft of its data-exchange pact with the US, the Privacy Shield, in early July.

EU justice commissioner Vera Jourova told EUobserver in a recent interview that the most contentious issues had been agreed by Washington and Brussels.

Thank you for reading EUobserver!

Subscribe now for a 30 day free trial.

  1. €150 per year
  2. or €15 per month
  3. Cancel anytime

EUobserver is an independent, not-for-profit news organization that publishes daily news reports, analysis, and investigations from Brussels and the EU member states. We are an indispensable news source for anyone who wants to know what is going on in the EU.

We are mainly funded by advertising and subscription revenues. As advertising revenues are falling fast, we depend on subscription revenues to support our journalism.

For group, corporate or student subscriptions, please contact us. See also our full Terms of Use.

If you already have an account click here to login.

These concerned access to data by US security services, bulk collection of people’s personal information and independent oversight.

“We reached an accord on more precise listing of cases when bulk collection can occur and a better definition of how our American partners understand the difference between bulk collection which may be justified and mass surveillance without any purpose, which is not tolerable”, she said.

“These specific points have already been finished and put down in written form”.

The shield is to replace the 15 year-old Safe Harbour pact that failed to protect the privacy of EU nationals whose data was transferred to firms, such as Facebook, based in the US.

The EU Court of Justice (ECJ) invalidated the harbour treaty last year, due in part, to revelations by Edward Snowden, a former US intelligence contractor, of mass-scale US snooping on Europeans.

The EU commission and the US, after two years of talks, proposed the shield treaty as a replacement earlier this year.

But the EU's main regulatory body on privacy, the Article 29 Data Protection Working Party, criticised the initial draft in the strongest possible terms.

The body is composed of EU states’ national data supervisors and EU officials.

Isabelle Falque-Pierrotin, its chair, said in April that the shield would fail to protect people's data.

“The possibility that is left in the shield and its annexes for bulk collection … is not acceptable," she said.

She sent the draft back to the EU commission, which is now set to present its updated version.

Big money

The issue is important because big and small companies that use data on both sides of the Atlantic have had to use more costly and more complicated data exchange frameworks ever since Safe Harbour’s demise.

A lot of money is involved. The data flows are worth an estimated €230 billion a year.

Broader concerns on how well the new “shield” would stand up to ECJ scrutiny have also put companies on edge.

Giovanni Buttarelli, the European data protection supervisor (EDPS), told reporters in May he too had "serious concerns" with Privacy Shield.

But Jourova remained confident.

Aside from having narrowed down on US bulk collection, she said she had also tackled the problem of oversight.

The US has promised to set up a special ombudsman, embedded in the state department, to help deal with complaints from EU nationals.

But doubts emerged over the independence of the new office.

Jourova told this website that "a more precise definition of competencies, status, and functioning" of the ombudsman have since been agreed.

Not everything is ready, however.

Jourova said the EU and US still need to agree on how long firms can retain the data and for what purpose.

"We want to make sure that personal data will only be kept for that period which is necessary and to agree on exceptions which enable them to keep data for a longer time," she said.

Exceptions in the EU include retaining data for scientific research purposes or for healthcare needs.

“In the US they have a broader, a more benevolent system [on retention], and everything that we do on Privacy Shield is to make sure that there’ll be equivalent, not the same, but equivalent, protection [for EU and US nationals]”, she said.

EU data regulation

The EU commission said the Privacy Shield would become operational almost immediately after it is adopted by the college of EU commissioners in July, with no further input from the EU Council or MEPs.

Around a year later, the EU's reformed data protection regulation should also be implemented.

The regulation is much tougher when it comes to privacy controls and companies will have to comply with it or face big fines.

The difference between the two hinges on how a company uses data.

Data sent to a company in the US would fall under the Privacy Shield. But if the same company also offers goods and services in the EU and collects EU nationals’ data remotely, then it will have to comply with the EU regulation as well.

EU okays Privacy Shield's first year

Commission gives 'thumbs-up' to controversial Privacy Shield deal with US on data sharing after a year's operation - but notes room for improvement.

News in Brief

  1. EU summit moved to previous building after fumes scare
  2. Catalonia will 'not back down'
  3. New toxic incident in EU building ahead of summit
  4. Murdered Malta journalist's family invited to Parliament
  5. EU food safety chief denies keeping studies 'secret'
  6. EU states pledge 24,000 resettlement places so far
  7. US ready for arms sale to update Greece's F-16 fleet
  8. Austria's Green leaders step down following election failure

Stakeholders' Highlights

  1. EU2017EENorth Korea Leaves Europe No Choice, Says Estonian Foreign Minister Sven Mikser
  2. Mission of China to the EUZhang Ming Appointed New Ambassador of the Mission of China to the EU
  3. International Partnership for Human RightsEU Should Seek Concrete Commitments From Azerbaijan at Human Rights Dialogue
  4. European Jewish CongressEJC Calls for New Austrian Government to Exclude Extremist Freedom Party
  5. CES - Silicones EuropeIn Healthcare, Silicones Are the Frontrunner. And That's a Good Thing!
  6. EU2017EEEuropean Space Week 2017 in Tallinn from November 3-9. Register Now!
  7. European Entrepreneurs CEA-PMEMobiliseSME Exchange Programme Open Doors for 400 Companies Across Europe
  8. CECEE-Privacy Regulation – Hands off M2M Communication!
  9. ILGA-EuropeHealth4LGBTI: Reducing Health Inequalities Experienced by LGBTI People
  10. EU2017EEEHealth: A Tool for More Equal Health
  11. Mission of China to the EUChina-EU Tourism a Key Driver for Job Creation and Enhanced Competitiveness
  12. CECENon-Harmonised Homologation of Mobile Machinery Costs € 90 Million per Year

Latest News

  1. EU okays Privacy Shield's first year
  2. EU seeks to decrypt messages in new anti-terror plan
  3. EU agencies defend research ahead of glyphosate vote
  4. Spain points at elections as exit to Catalan crisis
  5. How EU can ensure Daphne Caruana Galizia's legacy survives
  6. Juncker dinner to warm up relations with eastern EU
  7. Court hearing in MEPs 'private' expenses battle
  8. The unbearable lightness of leadership