Article

William Yates
William Yates 9 October 2015
Categories Data & Analytics

Is Safe Harbor Sunk?

Safe Harbor agreement which has helped simplify legally compliant data transfer between EU and the United States has now been ruled invalid by the European Court of Justice (ECJ).

The fifteen year old Safe Harbor agreement which has helped simplify legally compliant data transfer between EU and the United States has now been ruled invalid by the European Court of Justice (ECJ).

 

In a ruling the ECJ has stated that the Safe Harbor agreement does not in itself eliminate the need for locally-based data privacy groups to ensure US enterprises are taking appropriate measures to protect imported EU data.

Cyber-Spy Concerns

This ruling initiated when Austrian privacy campaigner Max Schrems asked the Irish Data Protection Commission to audit what material Facebook might be transferring to the US and whether this data might find itself in the hands of those in the US involved with cyber-spying.


As an ISO 9001 and ISO 27001-certified agency, we at Novacom have a good understanding of data management, with inter-EU and international data security, and from our perspective, see significant and serious implications for all EU-based companies transfering data to the US.

‘Tick-Box’ Security

For the past fifteen years, EU businesses have relied on Safe Harbor as a tick-box exercise, because those signed up in the US were expected to have in place security measures to offer a level of protection similar to those present in the EU.

It was described as a ‘streamlined and cost-effective’ way to acquire EU data – through self certification – without transgressing EU data laws. But with this protocol abandoned, other, more focused transactional procedures will come into place.

Safe Harbor: What’s Changed?

From here on, personal data can no longer be transferred to US entities on the basis these entities have Safe Harbor certification. Now, the despatching and receiving parties will need to draw up and sign a document containing ‘model contract clauses.’


This agreement will comprise effectively standard clauses which will set out an agreement between the two parties on the way exported EU data is to be processed, handled and what data security measures are required in the US.

Shock Of The New

US data privacy laws are very different to those in the EU and are generally a lot less stringent in their protective power and the breadth of legal coverage. Similarly, data security laws are also less rigorous.

What this will mean is that when working with EU partners, these US entities will need to work to levels of security way above anything they have experience of to date.


So, the implementation and agreement of ‘model contract clauses’ will unlikely be ‘streamlined and cost-effective’ as Safe Harbor was described.

The Regulatory Minefield

These new EU-US data transfer laws, combined with the upcoming 2017 roll-out of the EU General Data Protection Regulation (GDPR) mean the data management and data security environment in the EU is changing significantly.

And with the huge financial penalties proposed for GDPR infringements, ever-more careful data management will be required to avoid the shifting sands of legal transgression and the financial consequences of non-compliance.

Negotiating The Legal Maze, Safely

EU-wide, marketers have enough work-time pressure dealing with gaining and maintaining completive advantage in crowded international marketplaces.

 

Therefore, unless these marketers can partner with digital agencies with the international legal knowledge required to avoid the ever-growing – but I think necessary – data security legislation, marketers are going to need to become lawyers to survive.

 

Original Article

 

Read More On Digital Doughnut

Please login or register to add a comment.

Contribute Now!

Loving our articles? Do you have an insightful post that you want to shout about? Well, you've come to the right place! We are always looking for fresh Doughnuts to be a part of our community.

Popular Articles

See all
Promote Your Blog On These 30 Places

Promote Your Blog On These 30 Places

Social Media channels are one of the best ways to promote your blog content, but you shouldn’t stop there. Besides Social Media, there are more available places on the web which can be a great marketing tool for your blog promotion. I’m bringing you 30 proven places where you can promote your blog content and get great results.

Aleksej Durdevic
Aleksej Durdevic 7 December 2016
Read more
Top 10 Digital Branding & Marketing Trends for 2017

Top 10 Digital Branding & Marketing Trends for 2017

It’s time to re-evaluate and rebalance the digital approach for your company. Here are the Top Digital Branding & Marketing Trends for 2017 to watch for. The probing minds at the Borenstein Group, a Top Washington DC Digital Marketing and Branding Agency, have done the homework for you. Use it or lose it.

Gal Borenstein
Gal Borenstein 7 December 2016
Read more
4 Important Digital Marketing Channels You Should Know About

4 Important Digital Marketing Channels You Should Know About

It goes without saying that a company can't do without digital marketing in today's world.

Digital Doughnut Contributor
Digital Doughnut Contributor 5 November 2014
Read more
What Mobile App Design Looks like in 2017

What Mobile App Design Looks like in 2017

They say ‘move with the time or the time will leave you behind’. Being a startup it is important for you that you understand the trends, and amalgamate them in your business in order to attain the targets.

Nasrullah Patel
Nasrullah Patel 6 December 2016
Read more
Digital Marketing Vs. Traditional Marketing: Which One Is Better?

Digital Marketing Vs. Traditional Marketing: Which One Is Better?

What's the difference between digital marketing and traditional marketing, and why does it matter? The answers may surprise you.

Julie Cave
Julie Cave 14 July 2016
Read more