The Cyber Security Review | Monday, December 19, 2022
The EU-US Data Privacy Framework drafted to allow the flow of data between the US and the European Union has cleared the first hurdle on its way to approval in the EU, but criticism of the pact makes it far from a done deal.
FREMONT, CA: After determining that the framework offers privacy safeguards comparable to those of the EU, the European Commission declared on Tuesday that the process of approving the EU-US Data Privacy Framework, which was crafted to permit the flow of data between the US and the European Union, has officially begun.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The Trans-Atlantic Data Policy Framework guidelines were enacted in the US when President Biden issued an executive order establishing them there in October, and the Commission evaluated the US legal system upon which the bill was based.
According to that assessment, the law provides a sufficient level of protection for personal data transmitted from the EU to US businesses. The European Data Protection Board (EDPB) has now received the draught adequacy decision for comment. Following EDPB approval, the Commission must request permission from a committee made up of EU member state representatives and the European Parliament, which has the right to review adequacy determinations. The Commission can then officially adopt the legislation after that.
If adopted, the framework would require US businesses to abide by a comprehensive set of privacy rules, including the need to delete personal information when it is no longer required for the purposes for which it was collected and to maintain security whenever personal information is shared with third parties. The rules effectively aim to guarantee that data transfer between the US and EU complies with EU GDPR privacy laws.
Additionally, EU citizens will have access to several avenues for redress if their data is handled inconsistently with the framework and will be able to seek redress for the collection and use of their data by US intelligence agencies in front of a newly established Data Protection Review Court, among other independent and impartial redress mechanisms.
The vice president of the Commission for values and transparency stated in remarks posted alongside the announcement that the proposed framework will further enhance the security of personal data transferred from Europe to the US, building on the positive progress the two parties have made over the years. The new framework would improve transatlantic cooperation and be excellent for businesses.
The Privacy Shield agreement, which the European Court of Justice terminated on the basis that the US does not adequately secure personal data, notably in connection to state surveillance, will be replaced by the new Trans-Atlantic Data Policy Framework. Critics of the new framework, however, claim that it does not guarantee that US security agencies will not access data on EU people once it has been transmitted to the US. Even if the EU does pass the framework despite the criticism, it is unlikely to happen until at least spring 2023.
More in News