![]()
When GDPR came into force in May 2018, many organisations found it challenging to approve Processors in third countries. However, the EU/US Privacy Shield enabled a simple way to approve US-based companies for the purposes of data protection. On the 16th July the European Court of Justice (EC) ruled that the EU/US Privacy Shield does not adequately protect EU data subjects when their data is stored in the US. This is partly due to the fact that it is does not prevent unwarranted snooping from their government.
Some will remember the US’s Safe Harbour Agreement which was an earlier attempt to reassure the EC that its data subjects’ data was safe when stored in the US. Its replacement, the Privacy Shield, was quickly implemented so that EC companies were not breaking the law when storing data in the US. However, the introduction of the Privacy Shield did not take away the fact that whilst US companies can implement strong safeguards on data which they process, the US authorities continue to have the ability to override them and conduct mass surveillance which the EC considers unjustified.
Now that the EC has confirmed that the Privacy Shield is not good enough, many will be wondering what it means for their compliance by continuing to process their data in the US. In theory, this now means that any EC data subject could take legal action on a business that stores their data in the US without appropriate controls.
As part of your GDPR compliance, the European Data Protection Board has advised that all organisations storing data in the US should perform a risk assessment as to whether the use of Standard Contractual Clauses provide enough protection within the local legal framework, whether the transfer is to the US or elsewhere.
If you need help understanding where you stand and your obligations for storing in the US, get in touch on 01782 512 127, or here.