EU–US_Data_Privacy_Framework

EU–US Data Privacy Framework

EU–US Data Privacy Framework

Regulatory framework


The EU–US Data Privacy Framework is a European Union–United States data transfer framework that was agreed to in 2022[1][2] and declared adequate by the European Commission in 2023.[3] Previous such regimes—the EU–US Privacy Shield (2016–2020) and the International Safe Harbor Privacy Principles (2000–2015)—were declared invalid by the European Court of Justice in part due to concerns that personal data leaving EU borders is subject to sweeping US government surveillance. The EU-US Data Privacy Framework is intended to address these concerns.[4][5][6]

After the invalidation of the EU–US Privacy Shield in July 2020, companies wishing to transfer data between the EU and the US "have faced confusion, higher compliance costs, and challenges for EU–US business relationships".[6]

History

On March 25, 2022, it was announced that the European Commission and the United States had committed to a "Trans-Atlantic Data Privacy Framework" in reaction to the failure of the EU-US Privacy Shield.[1][7]

In October 2022, U.S. President Joe Biden signed an executive order to implement the framework.[4]

In May of 2023, the European Data Protection Board approved the Commission's adequacy decision draft that was published on December 13, 2022.[8]

Although not binding on the European Commission, on 11 May 2023 the European Parliament voted in favour of a resolution calling on the Commission to renegotiate the Framework[9] and not to adopt an adequacy finding on the basis that "the EU–U.S. Data Privacy Framework fails to create essential equivalence in the level of protection".[10]

On July 10 2023, the European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework, thereby allowing transfer of personal data from the EU to the U.S. on the basis of Article 45 of the GDPR.[3]

Data Protection Review Court

The Data Protection Review Court (DPRC) is a three-judge panel, established in Executive Order 14086 of 7 October 2022, which will deal with appeals made to the decisions of the Civil Liberties Protection Officer of the Office of the Director of National Intelligence as described by the EU-U.S. Privacy Framework.[11] The decisions made by the DPRC have binding authority.[12][13]

There has been criticism. [14]

See also


References

  1. McCabe, David; Stevis-Gridneff, Matina (25 March 2022). "U.S. and European leaders reach deal on trans-Atlantic data privacy". The New York Times. Retrieved 28 March 2022.
  2. "Data Protection: European Commission adopts new adequacy decision for safe and trusted EU-US data flows". European Commission - European Commission. 10 July 2023. Retrieved 2024-03-05.
  3. Shepardson, David; Blenkinsop, Philip (8 October 2022). "Biden signs order to implement EU-U.S. data privacy framework". Reuters. Retrieved 2022-11-01.
  4. "US expected to publish Privacy Shield executive order next week". Politico. 27 September 2022. Retrieved 2022-11-01.
  5. "Legal Questions Loom Over Latest Trans-Atlantic Data Flows Deal". news.bloomberglaw.com. Retrieved 2022-11-01.
  6. Silver, Andrew (2023-05-12). "Parliament calls on Commission not to adopt EU-US data deal". Research Professional News. Retrieved 2023-08-14.
  7. "Press corner". European Commission - European Commission. Retrieved 2023-01-30.

Share this article:

This article uses material from the Wikipedia article EU–US_Data_Privacy_Framework, and is written by contributors. Text is available under a CC BY-SA 4.0 International License; additional terms may apply. Images, videos and audio are available under their respective licenses.