Personal Data Transfers between US and Europe

The EU-US Data Privacy Framework introduces new binding safeguards to address the concerns raised by the CJEU.

Personal Data Transfers between US and Europe
Personal Data Transfers between US and Europe
Clive Mackintosh
November 10, 2023
International Data Transfers

In this blog Clive Mackintosh, Founder of GDPR Rep, experts in GDPR Representative services digs into the details of the EU-US Data Privacy Framework. The EU-US Data Privacy Framework is a new mechanism that allows for the transfer of personal data from the European Union to the United States. It was adopted by the European Commission on July 10, 2023, after the Court of Justice of the European Union (CJEU) invalidated the Privacy Shield Framework in 2020.

The EU-US Data Privacy Framework introduces new binding safeguards to address the concerns raised by the CJEU in its Schrems II decision. These safeguards include:

  • Limiting access to EU data by US intelligence services to what is necessary and proportionate.
  • Establishing a Data Protection Review Redress process to which EU individuals will have access.
  • Providing EU individuals with more enforceable  rights, such as the right to obtain access to their data, or obtain correction or deletion of incorrect or unlawfully handled data.

US companies can certify their participation in the EU-US Data Privacy Framework by committing to comply with a detailed set of privacy obligations. These obligations include:

  • Ensuring that personal data is collected and used only for legitimate purposes.
  • Providing individuals with access to their data and the right to correct or delete it.
  • Taking appropriate security measures to protect personal data.
  • Cooperating with EU data protection authorities.

The EU-US Data Privacy Framework is a significant improvement over the Privacy Shield Framework. It provides stronger safeguards for the protection of personal data, and it gives EU individuals more rights. The framework is expected to help to restore trust in the transatlantic data transfer relationship. But research suggests that the adequacy of the agreed arrangements may be challenged in the European Courts.

That said, here are some of the key benefits of the EU-US Data Privacy Framework:

  • It provides a secure and reliable mechanism for the transfer of personal data from the EU to the US.
  • It gives EU individuals more control over their personal data.
  • It helps to protect the privacy of individuals in both the EU and the US.

The EU-US Data Privacy Framework is suggested as a positive development for the transatlantic data transfer relationship. It is expected to help to restore trust and confidence in the ability of companies to transfer personal data across borders in a secure and compliant manner. Only time will tell if such expectation is correct.

GDPR Rep is on a mission to help every business achieve and maintain GPDR representation. If you are looking into how your organisation can fulfil its requirements why not schedule a no-commitment call with a GDPR representative expert today, or get a quote to understand how our value pricing makes compliance simple.

GDPR Representative
We use cookies on our site.
GDPREP.ORG would like to use performance and analytic cookies while you visit and browse our site to improve your experience. This means we may collect some of your data and you can read more about our use of cookies here. You can withdraw your consent at any time by emailing us at: clive@gdprep.org. View our Cookie Policy for more information.
Cookies