Wednesday

29th Jun 2022

EU to adopt new US data rules in July

  • EU commission is set to roll out its updated draft version of Privacy Shield (Photo: Matthew Klein)

The European Commission is set to present a new draft of its data-exchange pact with the US, the Privacy Shield, in early July.

EU justice commissioner Vera Jourova told EUobserver in a recent interview that the most contentious issues had been agreed by Washington and Brussels.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

These concerned access to data by US security services, bulk collection of people’s personal information and independent oversight.

“We reached an accord on more precise listing of cases when bulk collection can occur and a better definition of how our American partners understand the difference between bulk collection which may be justified and mass surveillance without any purpose, which is not tolerable”, she said.

“These specific points have already been finished and put down in written form”.

The shield is to replace the 15 year-old Safe Harbour pact that failed to protect the privacy of EU nationals whose data was transferred to firms, such as Facebook, based in the US.

The EU Court of Justice (ECJ) invalidated the harbour treaty last year, due in part, to revelations by Edward Snowden, a former US intelligence contractor, of mass-scale US snooping on Europeans.

The EU commission and the US, after two years of talks, proposed the shield treaty as a replacement earlier this year.

But the EU's main regulatory body on privacy, the Article 29 Data Protection Working Party, criticised the initial draft in the strongest possible terms.

The body is composed of EU states’ national data supervisors and EU officials.

Isabelle Falque-Pierrotin, its chair, said in April that the shield would fail to protect people's data.

“The possibility that is left in the shield and its annexes for bulk collection … is not acceptable," she said.

She sent the draft back to the EU commission, which is now set to present its updated version.

Big money

The issue is important because big and small companies that use data on both sides of the Atlantic have had to use more costly and more complicated data exchange frameworks ever since Safe Harbour’s demise.

A lot of money is involved. The data flows are worth an estimated €230 billion a year.

Broader concerns on how well the new “shield” would stand up to ECJ scrutiny have also put companies on edge.

Giovanni Buttarelli, the European data protection supervisor (EDPS), told reporters in May he too had "serious concerns" with Privacy Shield.

But Jourova remained confident.

Aside from having narrowed down on US bulk collection, she said she had also tackled the problem of oversight.

The US has promised to set up a special ombudsman, embedded in the state department, to help deal with complaints from EU nationals.

But doubts emerged over the independence of the new office.

Jourova told this website that "a more precise definition of competencies, status, and functioning" of the ombudsman have since been agreed.

Not everything is ready, however.

Jourova said the EU and US still need to agree on how long firms can retain the data and for what purpose.

"We want to make sure that personal data will only be kept for that period which is necessary and to agree on exceptions which enable them to keep data for a longer time," she said.

Exceptions in the EU include retaining data for scientific research purposes or for healthcare needs.

“In the US they have a broader, a more benevolent system [on retention], and everything that we do on Privacy Shield is to make sure that there’ll be equivalent, not the same, but equivalent, protection [for EU and US nationals]”, she said.

EU data regulation

The EU commission said the Privacy Shield would become operational almost immediately after it is adopted by the college of EU commissioners in July, with no further input from the EU Council or MEPs.

Around a year later, the EU's reformed data protection regulation should also be implemented.

The regulation is much tougher when it comes to privacy controls and companies will have to comply with it or face big fines.

The difference between the two hinges on how a company uses data.

Data sent to a company in the US would fall under the Privacy Shield. But if the same company also offers goods and services in the EU and collects EU nationals’ data remotely, then it will have to comply with the EU regulation as well.

Pegasus spyware makers grilled by MEPs

"We will not continue to work with a customer that is targeting a journalist illegally," Chaim Gelfand, chief compliance officer of NSO Group told MEPs — but shed little light on EU governments' use of its Pegasus spyware.

Opinion

Romania — latest EU hotspot in backlash against LGBT rights

Romania isn't the only country portraying lesbian, gay, bisexual, and transgender (LGBT) people as a threat to children. From Poland and Hungary in EU, to reactionary movements around the world are prohibiting portrayals of LGBT people and families in schools.

News in Brief

  1. Bulgaria expels 70 alleged Russian spies
  2. EU Commission told to improve CAP data analytics
  3. Scotland pushes for second independence vote in 2023
  4. Climate groups: G7 leaders 'backsliding' on climate
  5. Ukraine diplomat urges German MEPs to reject EU taxonomy
  6. EU asylum requests were climbing before Ukraine war
  7. Public sector journalists protest Macron tax plan
  8. EU engine ban splits Germany's coalition

Stakeholders' Highlights

  1. Nordic Council of MinistersEmerging journalists from the Nordics and Canada report the facts of the climate crisis
  2. Council of the EUEU: new rules on corporate sustainability reporting
  3. Nordic Council of MinistersNordic ministers for culture: Protect Ukraine’s cultural heritage!
  4. Reuters InstituteDigital News Report 2022
  5. EFBWW – EFBH – FETBBHow price increases affect construction workers
  6. Nordic Council of MinistersNew Nordic think tank examines influence of tech giants

Latest News

  1. EU ministers sign off on climate laws amid German infighting
  2. EU presidency still looking for asylum relocation pledges
  3. Finland and Sweden to join Nato, as Erdoğan drops veto
  4. The euro — who's next?
  5. One rubicon after another
  6. Green crime-fighting boss urgently required, key MEP says
  7. G7 leaders want price cap on Russian oil
  8. Western public has 'moral' duty to Ukraine, Nato chief says

Join EUobserver

Support quality EU news

Join us