SlideShare une entreprise Scribd logo
1  sur  17
Télécharger pour lire hors ligne
International Privacy: 

New Safe Harbor Requirements
Presented by
Kevin Haley
Brann & Isaacson
Outline
• Background on European Developments
• Recent changes
• The legal landscape
• Practical takeaways
Background: the EU process
• European Union Governance
▫ The EU issues “directives”
setting goals that all EU member
states must achieve
▫ However, individual nations
decide how to achieve them,
through their own legislative
process
▫ Thus, these goals can be
implemented very differently
from country to country – some
might fail to implement
altogether (“cookie directive”)
Background: EU privacy law
• EU Data Protection 

Directive (1998)
▫ Prohibits transfer of personal
data to non-EU countries
that do not meet EU
“adequacy” standards for
privacy protection
• US/EU “Safe Harbor
Framework”: standard
procedures whereby personal
data could be transferred to
the US
Background: safe harbor
Components of the Safe Harbor
Framework:

• Notice: must notify individuals about purpose
of data collection
• Choice: must give individuals the choice of
whether their personal information will be
disclosed
• Onward Transfer: if transferring information
to a third party, must follow the Notice and
Choice principles
• Access: individuals must have access to their
personal information, which can be amended,
corrected or deleted
• Security: must take reasonable precautions to
protect personal information
• Data Integrity: information collected must be
relevant for the purposes for which it is to be
used
• Enforcement: must be a readily available
independent mechanism for resolving disputes.
Source: http://www.export.gov/safeharbor/eu/eg_main_018476.asp
Background: safe harbor (cont.)
• The “Safe Harbor Decision” (2000)
▫ Decided that by meeting the
requirements of the Safe Harbor
Framework, US companies
adequately protected EU citizens’
data
▫ Allowed free flow of personal
information between all 28 EU
countries and US companies in
compliance with the Scheme
Recent Changes: Facebook lawsuit
• “Europe v. Facebook Lawsuit”
▫ Maximillian Schrems: Austrian
privacy activist
▫ Brought challenge to Safe Harbor
Decision in European court
▫ Based on US companies’ sharing
personal data with the US
government
VS.
Recent Changes: safe harbor invalid
• European Court of Justice declares Safe Harbor Decision
invalid (October 6, 2015)
• Cites Edward Snowden, finding that under the 

framework agreement, the

U.S. does not ensure

adequate protection of 

fundamental privacy

rights
• Companies can no longer

rely on the Safe Harbor

certification
Major Changes: uncertainty
• Extremely broad ruling:
▫ Unclear how US companies can meet EU privacy requirements
▫ Threatens suspending all transfer of data to non-EU countries that violate EU privacy
rights

• Uncertainty:
▫ Provides little to no guidance on compliance going forward

▫ Unclear what data transfer mechanisms are “adequate”
▫ Unclear what rules now apply to the ~4,400 companies operating under the Safe
Harbor framework standards
Continuing Developments
• German data privacy authority
(Schleswig-Holstein) issues position
paper (10/14):
▫ Argues that after this decision, there is
effectively no mechanism for lawful
transfer of data to the US
• EU working group issues statement
(10/19):
▫ “EU Model Contractual Clauses” and
“Binding Corporate Rules” can still be
used to lawfully transfer data from the
EU to the US
The Legal Landscape
• Now, EU countries’
national authorities
examine whether or not
US companies are in
compliance with EU
directives
• Some countries might
be friendlier than others
The Legal Landscape: reactions
Penny Pritzker, US Commerce
Secretary:


this ruling “puts at risk the
thriving trans-Atlantic digital
economy”
Facebook:


“Facebook, like many thousands
of European companies, relies on
a number of the methods
prescribed by EU law to legally
transfer data to the US from
Europe, aside from Safe Harbor”
Differing Reactions on Impact to US Business
The Legal Landscape: enforcement
• So, will the decision actually change much?

▫ What are most companies currently doing? (not much)

▫ What enforcement 

mechanisms exist?

▫ Who determines who is 

breaking the law? 

▫ What can they do about it?

Enforcement: Russia
• New Russian Law:
▫ Any data about Russians
must be stored in
Russia
▫ An attempt at actual
enforcement?
▫ How does this compare
to the EU approach?
Enforcement:
• Who is the target of this
decision?
• Does the EU’s concern with
NSA information collection
really have a connection to
most US business?
• Is it just Facebook, Google,
and Amazon?
Practical Steps: Options
• Wait and see
• If you have them, maintain Safe Harbor practices
• Review active contracts
• Update contracts/policies to comply with EU Model
Policies and Rules
• Consider using EU-based providers without affiliates in
the US
Questions?

Contenu connexe

Tendances

European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
David Erdos
 

Tendances (20)

EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and RequirementsPrivacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
 
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
 
The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?
 
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
 
Dataprotectionpackage 2015pptx
Dataprotectionpackage 2015pptxDataprotectionpackage 2015pptx
Dataprotectionpackage 2015pptx
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy Shield
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
 
Websites: do you tick all the boxes?
Websites: do you tick all the boxes?Websites: do you tick all the boxes?
Websites: do you tick all the boxes?
 
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTeEU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
 
Public Bill Seminar- Dorchester Presentations
Public Bill Seminar- Dorchester PresentationsPublic Bill Seminar- Dorchester Presentations
Public Bill Seminar- Dorchester Presentations
 
The Road to Schrems II
The Road to Schrems IIThe Road to Schrems II
The Road to Schrems II
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
 
Europeana Licensing Framework overview
Europeana Licensing Framework overviewEuropeana Licensing Framework overview
Europeana Licensing Framework overview
 
DPA and GDPR
DPA and GDPRDPA and GDPR
DPA and GDPR
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacy
 
Communications data retention in an evolving Internet
Communications data retention in an evolving InternetCommunications data retention in an evolving Internet
Communications data retention in an evolving Internet
 

En vedette

單車城市 BikeCity
單車城市 BikeCity單車城市 BikeCity
單車城市 BikeCity
hahalin
 
Informática básica introdução
Informática básica introduçãoInformática básica introdução
Informática básica introdução
rick-190
 

En vedette (14)

Ecologistas
EcologistasEcologistas
Ecologistas
 
Training plan
Training planTraining plan
Training plan
 
單車城市 BikeCity
單車城市 BikeCity單車城市 BikeCity
單車城市 BikeCity
 
Learning Through Video Games
Learning Through Video GamesLearning Through Video Games
Learning Through Video Games
 
GMDSS renewd
GMDSS renewdGMDSS renewd
GMDSS renewd
 
Анкета для обучающихся
Анкета для обучающихсяАнкета для обучающихся
Анкета для обучающихся
 
Tenemos conciencia
Tenemos concienciaTenemos conciencia
Tenemos conciencia
 
Introdução à programação para web com Java - Módulo 02: Conceitos básicos de...
Introdução à programação para web com Java -  Módulo 02: Conceitos básicos de...Introdução à programação para web com Java -  Módulo 02: Conceitos básicos de...
Introdução à programação para web com Java - Módulo 02: Conceitos básicos de...
 
Java básico - Módulo 09: Introdução a programação orientada à objetos
Java básico - Módulo 09: Introdução a programação orientada à objetosJava básico - Módulo 09: Introdução a programação orientada à objetos
Java básico - Módulo 09: Introdução a programação orientada à objetos
 
aBeansTalkSocial.com asks 5 key social media questions for business owners
aBeansTalkSocial.com asks 5 key social media questions for business ownersaBeansTalkSocial.com asks 5 key social media questions for business owners
aBeansTalkSocial.com asks 5 key social media questions for business owners
 
OPC TWS – MODULO 06
OPC TWS – MODULO 06OPC TWS – MODULO 06
OPC TWS – MODULO 06
 
Bioenergia en España. ¿Sostenible?
Bioenergia en España. ¿Sostenible?Bioenergia en España. ¿Sostenible?
Bioenergia en España. ¿Sostenible?
 
Informática básica introdução
Informática básica introduçãoInformática básica introdução
Informática básica introdução
 
Catalogs After Dark with Matt Fey
Catalogs After Dark with Matt FeyCatalogs After Dark with Matt Fey
Catalogs After Dark with Matt Fey
 

Similaire à International privacy with kevin haley

DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
Rachel Aldighieri
 
US eDiscovery v UK eDisclosure
US eDiscovery v UK eDisclosureUS eDiscovery v UK eDisclosure
US eDiscovery v UK eDisclosure
J. David Morris
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
Rachel Aldighieri
 
Presentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissiePresentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese Commissie
Europadialoog
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UK
Sally Hunt
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
Rachel Aldighieri
 

Similaire à International privacy with kevin haley (20)

Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe Harbor
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
DAY 1_ITEM 4_Privacy and personal data protection.ppt
DAY 1_ITEM 4_Privacy and personal data protection.pptDAY 1_ITEM 4_Privacy and personal data protection.ppt
DAY 1_ITEM 4_Privacy and personal data protection.ppt
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
What is the GDPR & What does it mean for YOUR business?
What is the GDPR & What does it mean for YOUR business?What is the GDPR & What does it mean for YOUR business?
What is the GDPR & What does it mean for YOUR business?
 
US eDiscovery v UK eDisclosure
US eDiscovery v UK eDisclosureUS eDiscovery v UK eDisclosure
US eDiscovery v UK eDisclosure
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
Presentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissiePresentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese Commissie
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UK
 
Safe Harbor Webinar
Safe Harbor WebinarSafe Harbor Webinar
Safe Harbor Webinar
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
Dai Davies - GDPR Presentation
Dai Davies - GDPR PresentationDai Davies - GDPR Presentation
Dai Davies - GDPR Presentation
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
 
1º Palestra sobre Proteção de Dados Pessoais
1º Palestra sobre Proteção de Dados Pessoais1º Palestra sobre Proteção de Dados Pessoais
1º Palestra sobre Proteção de Dados Pessoais
 
The Patriot Act and Cloud Security - Busting the European FUD
The Patriot Act and Cloud Security - Busting the European FUDThe Patriot Act and Cloud Security - Busting the European FUD
The Patriot Act and Cloud Security - Busting the European FUD
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 

Plus de Sarah Fletcher

Challah connection pub
Challah connection pub Challah connection pub
Challah connection pub
Sarah Fletcher
 
Catu critique mary maxim and revival animal health
Catu critique mary maxim and revival animal healthCatu critique mary maxim and revival animal health
Catu critique mary maxim and revival animal health
Sarah Fletcher
 
How to improve your customer's ux
How to improve your customer's uxHow to improve your customer's ux
How to improve your customer's ux
Sarah Fletcher
 
Pub web review 5-11-16 chris middings
Pub web review   5-11-16 chris middingsPub web review   5-11-16 chris middings
Pub web review 5-11-16 chris middings
Sarah Fletcher
 
Pub merchandising merchandising trends to prepare for holiday 2016
Pub merchandising   merchandising trends to prepare for holiday 2016Pub merchandising   merchandising trends to prepare for holiday 2016
Pub merchandising merchandising trends to prepare for holiday 2016
Sarah Fletcher
 
How to write great headlines
How to write great headlinesHow to write great headlines
How to write great headlines
Sarah Fletcher
 
Kevin hillstrom mine_thatdata_catalogu2015
Kevin hillstrom mine_thatdata_catalogu2015Kevin hillstrom mine_thatdata_catalogu2015
Kevin hillstrom mine_thatdata_catalogu2015
Sarah Fletcher
 
Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...
Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...
Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...
Sarah Fletcher
 
Physics of catalog design
Physics of catalog designPhysics of catalog design
Physics of catalog design
Sarah Fletcher
 

Plus de Sarah Fletcher (12)

Challah connection pub
Challah connection pub Challah connection pub
Challah connection pub
 
Catu critique mary maxim and revival animal health
Catu critique mary maxim and revival animal healthCatu critique mary maxim and revival animal health
Catu critique mary maxim and revival animal health
 
Holiday catalog testing with Christopher Werler
Holiday catalog testing with Christopher WerlerHoliday catalog testing with Christopher Werler
Holiday catalog testing with Christopher Werler
 
How to improve your customer's ux
How to improve your customer's uxHow to improve your customer's ux
How to improve your customer's ux
 
Pub web review 5-11-16 chris middings
Pub web review   5-11-16 chris middingsPub web review   5-11-16 chris middings
Pub web review 5-11-16 chris middings
 
Pub merchandising merchandising trends to prepare for holiday 2016
Pub merchandising   merchandising trends to prepare for holiday 2016Pub merchandising   merchandising trends to prepare for holiday 2016
Pub merchandising merchandising trends to prepare for holiday 2016
 
How to write great headlines
How to write great headlinesHow to write great headlines
How to write great headlines
 
Kevin hillstrom mine_thatdata_catalogu2015
Kevin hillstrom mine_thatdata_catalogu2015Kevin hillstrom mine_thatdata_catalogu2015
Kevin hillstrom mine_thatdata_catalogu2015
 
Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...
Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...
Catalog University Pub talk: Leveraging browsing behavior to improve catalog ...
 
Making Catalog Proofing Easier
Making Catalog Proofing EasierMaking Catalog Proofing Easier
Making Catalog Proofing Easier
 
Testing panel slides final
Testing panel slides   finalTesting panel slides   final
Testing panel slides final
 
Physics of catalog design
Physics of catalog designPhysics of catalog design
Physics of catalog design
 

Dernier

一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
Fir La
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
bd2c5966a56d
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
CssSpamx
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
bd2c5966a56d
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
e9733fc35af6
 
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
e9733fc35af6
 
一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书
一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书
一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书
F La
 

Dernier (20)

一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
 
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy NovicesIt’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
Career As Legal Reporters for Law Students
Career As Legal Reporters for Law StudentsCareer As Legal Reporters for Law Students
Career As Legal Reporters for Law Students
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentation
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
Navigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptxNavigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptx
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statute
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
Reason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaReason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in India
 
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
 
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
 
一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书
一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书
一比一原版(Essex毕业证书)埃塞克斯大学毕业证学位证书
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?
 

International privacy with kevin haley

  • 1. International Privacy: 
 New Safe Harbor Requirements Presented by Kevin Haley Brann & Isaacson
  • 2. Outline • Background on European Developments • Recent changes • The legal landscape • Practical takeaways
  • 3. Background: the EU process • European Union Governance ▫ The EU issues “directives” setting goals that all EU member states must achieve ▫ However, individual nations decide how to achieve them, through their own legislative process ▫ Thus, these goals can be implemented very differently from country to country – some might fail to implement altogether (“cookie directive”)
  • 4. Background: EU privacy law • EU Data Protection 
 Directive (1998) ▫ Prohibits transfer of personal data to non-EU countries that do not meet EU “adequacy” standards for privacy protection • US/EU “Safe Harbor Framework”: standard procedures whereby personal data could be transferred to the US
  • 5. Background: safe harbor Components of the Safe Harbor Framework:
 • Notice: must notify individuals about purpose of data collection • Choice: must give individuals the choice of whether their personal information will be disclosed • Onward Transfer: if transferring information to a third party, must follow the Notice and Choice principles • Access: individuals must have access to their personal information, which can be amended, corrected or deleted • Security: must take reasonable precautions to protect personal information • Data Integrity: information collected must be relevant for the purposes for which it is to be used • Enforcement: must be a readily available independent mechanism for resolving disputes. Source: http://www.export.gov/safeharbor/eu/eg_main_018476.asp
  • 6. Background: safe harbor (cont.) • The “Safe Harbor Decision” (2000) ▫ Decided that by meeting the requirements of the Safe Harbor Framework, US companies adequately protected EU citizens’ data ▫ Allowed free flow of personal information between all 28 EU countries and US companies in compliance with the Scheme
  • 7. Recent Changes: Facebook lawsuit • “Europe v. Facebook Lawsuit” ▫ Maximillian Schrems: Austrian privacy activist ▫ Brought challenge to Safe Harbor Decision in European court ▫ Based on US companies’ sharing personal data with the US government VS.
  • 8. Recent Changes: safe harbor invalid • European Court of Justice declares Safe Harbor Decision invalid (October 6, 2015) • Cites Edward Snowden, finding that under the 
 framework agreement, the
 U.S. does not ensure
 adequate protection of 
 fundamental privacy
 rights • Companies can no longer
 rely on the Safe Harbor
 certification
  • 9. Major Changes: uncertainty • Extremely broad ruling: ▫ Unclear how US companies can meet EU privacy requirements ▫ Threatens suspending all transfer of data to non-EU countries that violate EU privacy rights
 • Uncertainty: ▫ Provides little to no guidance on compliance going forward
 ▫ Unclear what data transfer mechanisms are “adequate” ▫ Unclear what rules now apply to the ~4,400 companies operating under the Safe Harbor framework standards
  • 10. Continuing Developments • German data privacy authority (Schleswig-Holstein) issues position paper (10/14): ▫ Argues that after this decision, there is effectively no mechanism for lawful transfer of data to the US • EU working group issues statement (10/19): ▫ “EU Model Contractual Clauses” and “Binding Corporate Rules” can still be used to lawfully transfer data from the EU to the US
  • 11. The Legal Landscape • Now, EU countries’ national authorities examine whether or not US companies are in compliance with EU directives • Some countries might be friendlier than others
  • 12. The Legal Landscape: reactions Penny Pritzker, US Commerce Secretary: 
 this ruling “puts at risk the thriving trans-Atlantic digital economy” Facebook: 
 “Facebook, like many thousands of European companies, relies on a number of the methods prescribed by EU law to legally transfer data to the US from Europe, aside from Safe Harbor” Differing Reactions on Impact to US Business
  • 13. The Legal Landscape: enforcement • So, will the decision actually change much?
 ▫ What are most companies currently doing? (not much)
 ▫ What enforcement 
 mechanisms exist?
 ▫ Who determines who is 
 breaking the law? 
 ▫ What can they do about it?

  • 14. Enforcement: Russia • New Russian Law: ▫ Any data about Russians must be stored in Russia ▫ An attempt at actual enforcement? ▫ How does this compare to the EU approach?
  • 15. Enforcement: • Who is the target of this decision? • Does the EU’s concern with NSA information collection really have a connection to most US business? • Is it just Facebook, Google, and Amazon?
  • 16. Practical Steps: Options • Wait and see • If you have them, maintain Safe Harbor practices • Review active contracts • Update contracts/policies to comply with EU Model Policies and Rules • Consider using EU-based providers without affiliates in the US