What businesses need to know about standard contractual clauses, privacy shields, and legal workarounds.
Businesses with cross-border data transfers have had the rug pulled out from under them—again. Following the European Commission (EC)’s approval of the EU–US Privacy Shield (Shield) on July 12, 2016, many companies relied on standard contractual clauses to facilitate storage of European customers’ data in the United States. The Shield was created following Schrems I, a case brought by Austrian lawyer and activist Max Schrems, which invalidated the previous International Safe Harbor Privacy Principles.
Reliance on the Shield, however, proved short-lived. The Schrems II ruling invalidated the Shield, with the European Court of Justice finding that it failed to provide “an adequate level of data protection.” The fallout of the Schrems II ruling resulted in a series of trans-Atlantic negotiations, culminating in the EU–US Data Privacy Framework (DPF), which was agreed in 2022 and declared valid by the EC in 2023.
Here is a breakdown of the key differences between the Shield and the DPF and the main risk factors for companies. I also speculate a bit about what may change in light of ongoing negotiations between the US and EU.
Key Issues
The Framework differs from the Shield in several key ways:
- Certification:
- The Shield allowed U.S. companies to self-certify compliance. Some 3000 businesses, including many mom-and-pop ventures, came to rely on the Shield for cross-border data transfers and storage of user information in the United States.
- The DPF, by contrast, requires much more detailed corporate disclosures (subsidiaries, contact info, exit protocols)
- Intelligence surveillance
- The Shield’s intelligence surveillance was criticized as being inadequate by the European Union.
- Under the DPF, by contrast, there are now revised protections via Executive Order 14086, creation of a Data Protection Review Court (DPRC)
- Redress Rights
- The Privacy Shield included an ombudsman but lacked binding judicial recourse.
- The DPF, however, allows for judicial redress under the DPRC.
- Enforcement
- The Shield was managed by the FTC and allowed for annual recertification
- Commercial compliance under the DPF is managed by the FTC, whereas the DPRC is responsible for oversight of government surveillance.
What companies should know:
- Re-certify under the DPF. Companies should recertify under the DPF to resume compliant EU to US data transfers without extra mechanisms.
- Update policies and disclosures. Businesses must update DPF references, subsidiary info, and a data exit strategy in their contracts and privacy policies.
- Prepare for DPRC requests. U.S.-based firms should be prepared to comply with data requests from EU citizens.
- Plan data flows. Other jurisdictions still require standard contractual clauses (SCC) and binding corporate rules (BCR) to ensure adequate privacy protections. Businesses should keep using SCCs and BCRs as part of their standard practice.
- Monitor legal landscape: Activists like Max Schrems are likely to challenge the DPF’s adequacy. Companies should be aware that further changes may be possible.
Finally, there are signs that the DPF may be on shaky ground. TO date, no Executive Order during the Trump Administration has reaffirmed commitment to the DPF. While E.O. 14086 has not been revoked, President Trump has removed three of the five members of the U.S. Privacy & Civil Liberties Oversight Board. Executive Order 14215 (“Ensuring Accountability for All Agencies”) has also granted the President greater authority over administration agencies, including the Federal Trade Commission (FTC). Changes in executive oversight and FTC independence under Executive Order 14215 may impact the stability of the DPF framework going forward.
As of now, the DPF remains in full force and effect. To avoid fines and penalties for non-compliance, businesses must take their DPF-related certification and disclosure obligations seriously.
Disclaimer: This blog is for informational purposes only and does not constitute legal advice. Reading or interacting with this content does not create an attorney–client relationship. You should consult a qualified attorney for advice regarding your specific situation. Mehaffy, PLLC disclaims all liability for actions taken or not taken based on this blog.
