Annual Review Confirms Validity of EU-US Privacy Shield
On 23 October 2019, the European Commission (Commission) published its report on the Third Annual Joint Review of the EU-US Privacy Shield. The Privacy Shield is a self-certification scheme whereby certified US organisations can more easily receive personal data transferred to them from the EU. Certification is granted when an organisation implements measures in order to protect personal data. At the time of the review, there were more than 5,000 participating companies.
In its report, the Commission confirms that the EU-US Privacy Shield continues to provide an adequate level of protection for transfers of personal data. It indicates that important improvements have been made to the framework, but also identifies some areas of concern. The European Data Protection Board (EDPB), which is invited to participate in the annual review process, published its own report on the Third Annual Joint Review on 12 November 2019, essentially confirming the findings of the Commission and making further recommendations on access by public authorities of data transferred to the US under the Privacy Shield. The annual review procedure is an important element in the construction of the Privacy Shield since its predecessor, the EU-US Safe Harbour scheme, was annulled by the Court of Justice of the European Union (CJEU) on 6 October 2015 (Case C-362/14). Whether the improvements suffice for the Privacy Shield to meet the EU requirements will be determined by the European Courts in the coming months.
Please click below for a short client memorandum on the Third Annual Review of the EU-US Privacy Shield.