July 17, 2020

The EU-US Privacy Shield has collapsed: here's what you can do about it.

THE EU-US PRIVACY SHIELD, the principal agreement governing the transfer of personal data between the EU and the United States, has collapsed.

On Thursday morning the Court of Justice of the European Union delivered a fatal blow to the primary agreement relied upon by millions of businesses across the European Union to safely and legally transfer data between the EU and the United States.

The decision was handed down as a result of the Schrems II case against Facebook. However, it delivered an unexpected secondary effect which rocked the data protection world: it declared that US law does not provide adequate protection for the privacy and data protection rights of European citizens.

The results of this ruling are simple: you can no longer rely on the EU-US Privacy Shield for routine transfers of personal data. This includes third-party cloud services which base their data storage in the US.

There is a small silver lining: the same ruling also confirmed the validity of the EU Standard Contractual Clauses for transfers between the EU and the US. However, this is likely to result in a large amount of extra work for most businesses, especially smaller businesses who may not have easy access to legal help.

What to do about it

The simplest solution for most UK businesses is to make sure your vendors store data within the UK or Europe. This means:

  • Make a list of all the third-party services you use, especially cloud services such as OneDrive, mailing list providers like MailChimp, etc.
  • For each of these providers, look in the relevant settings and see if you can explicitly set the storage of your data to the UK or EU.
  • If you can't, contact their support email or open a ticket to ask the question.

It's possible that you may need to find alternatives for some services that store data in the US.

If a service is absolutely vital and processes data in the US, make sure it includes a Data Processing Agreement. This agreement needs to implement the EU Standard Contractual Clauses.

We can help

If you need any assistance moving your data to a compliant location, we can help. Contact us today for a no-obligation consultation.

Concerned about your cloud storage?

We can help. Contact us today for a no-obligation chat.

Contact us

Stay updated

Subscribe to our Newsletter to be the first to know about new products and solutions, and to qualify for exclusive early adopter discounts
Odoo & ERP
Copyright © 2020 Jötnar Systems. Jötnar Systems is a trading name of Jotnar Systems Ltd registered in England & Wales with company number 11982020.
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram