Duyurular
European Commission Adopts New Adequacy Decision for Safe and Trusted EU-US Data Flows
On July 10, the European Commission (“Commission”) adopted an adequacy decision for the EU-U.S. Data Privacy Framework. The decision concludes that the United States ("US") guarantees an adequate level of protection for personal data transferred from the European Union ("EU") to US companies under the new framework.
The new framework includes binding safeguards to address concerns raised by the European Court of Justice, such as limitations on access to EU data by US intelligence services and the establishment of a Data Protection Review Court (“DPRC”).
The decision is based on the US' introduction of new safeguards in response to concerns raised by the Court of Justice of the European Union in its Schrems II decision.
US companies can join the framework by committing to privacy obligations, including the deletion of personal data when no longer necessary.
EU individuals will have redress mechanisms in case of mishandling of their data, including independent dispute resolution and an arbitration panel.
The safeguards also extend to other data transfer tools, like standard contractual clauses. The framework will undergo periodic reviews to ensure its effective implementation.
The US Department of Commerce will administer and monitor the framework, with enforcement by the US Federal Trade Commission.
- What are the key elements of the framework?
- The Executive Order signed by President Biden establishes binding safeguards to limit US intelligence authorities access to data, ensuring it is necessary and proportionate for national security protection.
- Enhanced oversight of US intelligence services is implemented to ensure compliance with surveillance limitations.
- An independent and impartial redress mechanism is established, including the creation of a DPRC, to investigate and resolve complaints regarding access to personal data by US national security authorities.
- The US Government has introduced a two-layer redress mechanism for complaints related to data transferred from the European Economic Area (EEA) to US companies, overseen by independent authorities. Complaints can be submitted to national data protection authorities, who will transmit them to the US through the European Data Protection Board.
- The "Civil Liberties Protection Officer" of the US intelligence community is responsible for investigating complaints. Individuals can appeal the officer's decision before the newly created DPRC, composed of members from outside the US Government. The DPRC has the power to obtain information from intelligence agencies and make binding decisions, such as ordering the deletion of data collected in violation of safeguards.
- The Court appoints a special advocate to represent the complainant's interests and ensure a fair trial and due process.
- Once the investigation is completed, the complainant is informed whether a violation of US law was identified and remedied.
- Confidentiality requirements may restrict the availability of information about the DPRC procedure but will be lifted at a later stage.
- When will the decision apply?
- The adequacy decision, which came into effect on July 10, establishes a framework for the transfer of personal data from the EU to the US. The decision does not have a time limitation, but the European Commission will continually monitor relevant developments in the US and conduct regular reviews to assess the adequacy decision.
- The first review will occur within one year after the decision's adoption to ensure that the US legal framework functions effectively in practice. Based on the review's outcome, the Commission, in consultation with EU Member States and data protection authorities, will determine the frequency of future reviews, which will take place at least every four years.
- If there are any developments that impact the level of data protection in the US, adequacy decisions can be adjusted or even revoked.
- What is the impact of the decision on the possibility to use other tools for data transfers to the United States?
- The safeguards established by the US Government in the area of national security, including the redress mechanism, apply to all data transfers under the General Data Protection Regulation (“GDPR”) to US companies, regardless of the transfer mechanisms used. These safeguards also facilitate the use of other data transfer tools, such as standard contractual clauses and binding corporate rules.
You can access the full text of the press release here.
Also, access the full Q&A here.
Kind regards,
Zumbul Attorneys-at-Law
Türkçe
English