Financial Services: Dancing the legal limbo around US/EU data transfers

From: Data Guidance

Jana Fuchs, Associate/Bryan Cave LLP

Difficulties often manifest themselves in transferring data from the ‘safe’ EU to the ‘unsafe’ US. Difficulties also exist with US law enforcement authority requests for access to such data, which is often not permitted under EU law. Jana Fuchs, an Associate with Bryan Cave LLP, examines the problem and potential solutions.

When a Chief Privacy Officer (CPO) is finally able to check the box to ‘implement sufficient EU data protection adequacy measures for data transfers,’ nerves are often frayed and a level of frustration remains. For global companies, the path to centralise data management (e.g., allowing HR or customer data to be transferred and controlled in ‘unsafe’ countries such as the US) exists, but traversing it can be rocky.

EU originating personal data controlled abroad

The first thing that often comes to mind is the EU-US Safe Harbor framework. One of the first lessons that they learn is that the ‘Safe Harbor’ is not so safe at all. When they look to other commonly discussed routes to compliance, similar drawbacks start to emerge. Model Contracts have significant grey-zones, and the EU approved Binding Corporate Rules (BCR) can conflict with national compliance requirements applicable to US data importers.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *