On October 6, 2015, the European Union’s highest court (the “ECJ”) issued an order (the “Order”) invalidating the 15-year-old U.S.-EU Safe Harbor Program (the “Program”). Schrems v. Data Prot. Comm’r, E.C.J., No. C-362/14. The Program allowed U.S. companies to transfer EU citizens’ data to the U.S. by self-certifying to the U.S. Department of Commerce privacy principles similar to those contained in the EU Data Protection Directive (95/46/EC). The basis for the Order was that the Program didn’t safeguard personal data against surveillance by the U.S. government and didn’t allow sufficient redress to EU citizens whose privacy had been breached by such surveillance. The case was initiated by Austrian law student Max Schrems against Facebook in Ireland where Facebook’s European operations are headquartered. The case was referred to the ECJ by Ireland’s High Court after the Irish Office of the Data Protection Commissioner said it didn’t need to examine the complaint about data transfers made by Facebook Ireland Inc. because the transfers were done in accordance with the Program. The ECJ found that U.S. authorities could ignore the privacy protections of the Program and could “access the personal data transferred from the member states to the United States and process it in a way incompatible, in particular, with the purposes for which it was transferred, beyond what was strictly necessary and proportionate to the protection of national security.” The European Commission has stated publicly that any transfer of data from European Economic Area in the last 15 years that relied on the Safe Harbor Program may be subject to legal challenge. While approximately 4,400 U.S. companies are certified under the Program, the Order would not prevent the continued transfer of data by those with alternative means for data transfers in place, such as binding corporate rules or model contracts.
European Court of Justice Invalidates U.S.-E.U. Safe Harbor Program
European Court of Justice Invalidates U.S.-E.U. Safe Harbor Program
Related Posts
There are about twenty state privacy laws currently in effect or that will take effect by January 2026 that […]
These excerpts from Practical Guidance, a comprehensive resource providing insight from leading practitioners, are reproduced with the permission of LexisNexis. […]
This excerpt from Practical Guidance, a comprehensive resource providing insight from leading practitioners, is reproduced with the permission of LexisNexis. […]
Multiple state Privacy Acts take effect in 2023. Typically, these laws require website operators to implement certain compliance measures and […]
Kavon Adli, founder and managing attorney of The Internet Law Group, has been selected for inclusion in the Southern California […]
By Kavon Adli and Jason Civalleri * For informational purposes only; not intended as legal advice or as a recommendation/suggestion […]
After the Leys’ dog killed neighbor Jeppson’s cat, the Leys paid Jeppson $2,000 as part of a settlement agreement. After […]
On May 3, 2019, the United States District Court for the Northern District of California granted Defendant’s motion to compel […]
On March 4, 2019, Justice Ruth Bader Ginsburg, delivering a unanimous opinion of the Supreme Court of the United States, […]
We are pleased to announce that Kavon Adli, shareholder at The Internet Law Group, has been selected to the 2020 […]