{"id":6875,"date":"2020-12-07T09:00:59","date_gmt":"2020-12-07T09:00:59","guid":{"rendered":"https:\/\/letslaw.es\/?p=6875\/"},"modified":"2023-01-23T10:16:13","modified_gmt":"2023-01-23T10:16:13","slug":"privacy-shield-gdpr","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/privacy-shield-gdpr\/","title":{"rendered":"Fall of the privacy shield and its consequences"},"content":{"rendered":"<p>The Court of justice of the European Union (CJEU) issued on July 16, 2020 an important ruling with regard to the data transfer regime between the European Union (EU) and the United States of America (USA) in so-called case \u2018\u2019Facebook Ireland v Schrems\u2019\u2019, whereby the personal data stored and processed by the United States does not meet the level of security required by the GDPR.<\/p>\n<p>By this ruling, the CJEU invalidates Decision 2016\/1250 on the adequacy of the protection provided by so-called \u2018\u2019 Privacy Shield\u2019\u2019, which allowed the transference of data between the operators from the EU and the US abide by their data protection principles without further formalities.<\/p>\n<p>It declared that Commission Decision 2010\/87 regarding the standard contractual clauses for the transfer of personal data to processors, established in third countries is fully valid.<\/p>\n<p>&nbsp;<\/p>\n<h2>What is the privacy shield?<\/h2>\n<p>&nbsp;<\/p>\n<p>The Privacy Shield, also known as the \u2018\u2019EU-US Privacy Shield\u2019\u2019, is an agreement signed in 2016 between the US and the European Union which established a framework for data protection and replaces the old framework \u2018\u2019Safe Harbor\u2019\u2019, which had been in force until annulled by the Court of Justice of the European Union.<\/p>\n<p>The function of the Privacy Shield was based in accordance with European regulations on the protection of citizens\u2019 privacy in data exchanges with the US. In other words, its main purpose was to ensure that North America companies collect data from European users in compliance with European data protection regulations.<\/p>\n<p>&nbsp;<\/p>\n<h2>Why has this agreement been invalidated?<\/h2>\n<p>&nbsp;<\/p>\n<p>According to the CJEU, the invalidation of this agreement results on limitations of the protection of personal data issued from the internal regulations of the United States, with affects the access and use of data that is transferred from the EU by the American authorities.<\/p>\n<p>The limitations of the protection of personal data are not regulated in accordance with the requirements of European Union law, as they do not comply with the proportionality principle, unless the US surveillance programs are limited to the processing strictly necessary data.<\/p>\n<p>In other words, it refers to the fact that the Privacy Shield does not provide the affected persons with any guarantee that is sufficient and substantially equivalent to those existing in European Union Law to preserve data privacy and comply with the General Data Protection Regulation (GDPR).<\/p>\n<p>&nbsp;<\/p>\n<h2>How does the fall of Privacy Shield affect businesses?<\/h2>\n<p>&nbsp;<\/p>\n<p>The CJEU ruling implies that European companies must review their data transfer and processing to identify what international transfers they make to US. Many of these data transfer occur due to the fact that they have US technology service providers. The example is very common such as SaaS and Cloud services. They will have to verify whether these companies have their servers located in Europe or in the US.<\/p>\n<p>In case the servers are located in the US, it will be necessary to search for alternatives agreements that guarantee the legality of these transfers. Even though, there are the standard contractual clauses in Decision 2010\/87\/EU, it must be taken into account that these clauses will not be sufficient guarantees if they do not prevent of US organization from the intrusion on the data of European citizens for reason of national security or similar. Thus, it will be necessary to have additional guarantees.<\/p>\n<p>In case of multinational companies that are based in the United States and make international transfers between group of companies covered by Privacy Shield, they will have to amend these transfers in accordance with specific Binding Corporate Rules (BCR) that guarantee the appropriate security levels for transferred data.<\/p>\n<p>&nbsp;<\/p>\n<h2>What about users?<\/h2>\n<p>&nbsp;<\/p>\n<p>The Privacy Shield, although still in force, remains in the background of the GDPR, as the guarantees contained in European regulations are wider and more demanding in terms of the protection of users\u2019 personal data and international data transfers.<\/p>\n<p>Since the companies must seek other options to legitimize transfers, such as the mentioned above, standard contractual clauses. The consequences for users are that it can be envisaged that these data transfers are legal with users\u2019 consent as a way that guarantees to comply with GDPR.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/6875#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The Court of justice of the European Union (CJEU) issued on July 16, 2020 an important ruling with regard to the data transfer regime between the European Union (EU) and the United States of America&#8230;<\/p>\n","protected":false},"author":2,"featured_media":6876,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[],"class_list":["post-6875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/6875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=6875"}],"version-history":[{"count":2,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/6875\/revisions"}],"predecessor-version":[{"id":6884,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/6875\/revisions\/6884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/6876"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=6875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=6875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=6875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}