Finally, the European Commission has presented a proposal for the EU-US Privacy Shield conserning data protection, to replace the fallen “Safe Harbour” agreement. Sorry to say, it’s rather pointless.
The background is that the European Court of Justice invalidated the “Safe Harbour” agreement that was supposed to provide adequate data protection when Europeans personal data is being transfered to the US. The reason was that US companies didn’t really care about the agreement — and that US authorities (e.g. the NSA) in many cases had access to the data.
Then followed some confusion as the EU and the US tried to negotiate a new agreement, the EU-US Privacy Shield. Here are some previous blog posts:
• An EU-US Privacy Shield? »
• The EU-US Privacy Shield Illusion »
Now we have a proposal. Some EU links:
• European Commission presents EU-U.S. Privacy Shield »
• Restoring trust in transatlantic data flows through strong safeguards: European Commission presents EU-U.S. Privacy Shield »
• EU-U.S. Privacy Shield: Frequently Asked Questions »
This new proposal is rather similar to the old, fallen agreement. So much so, that it might very well be invalidated by the ECJ once again.
The main news seems to be “adequacy decisions”. In simple terms this means that things will be deemed OK if the European Commission says so. And that is hardly a solid judicial principle.
The Austrian student Max Schrems — who took the old agreement to the ECJ in the first place — says that he is considering taking the new agreement back to court, if adopted.
In a comment the NGO EDRi:s Executive Director Joe McNamee says..
The European Commission has given Europe a lesson on how not to negotiate. This isn’t a good deal, it hardly deserves to be called a ‘deal’ of any kind.
The EDRi press release also states that the documents published “confirm that no meaningful reforms have been made and that none are planned”.
EDRi Press Release: Privacy Shield is the same unsafe harbour »
The European Commission simply does not seems to be very concerned about protecting European personal data being transfered to the US.
/ HAX