If you currently rely on the Privacy Shield as a transfer mechanism and require advice on reviewing your data flows and implementing an alternative, legally compliant, transfer mechanism, please call us on 01332 226 130 or complete the form below.
Conveyancing
Explore All ConveyancingCriminal Defence
Explore All Criminal DefenceEstate Planning
Explore All Estate PlanningEstate Administraion
Explore All Estate AdministraionDispute Resolution
Explore All Dispute ResolutionFamily & Matrimonial
Explore All Family & MatrimonialMotoring & Driving Offences
Explore All Motoring & Driving OffencesResidential Property
Explore All Residential PropertyResidential Property Disputes
Explore All Residential Property DisputesWills, Trusts & Estate Disputes
Explore All Wills, Trusts & Estate DisputesAgriculture
Explore All AgricultureBusiness Recovery
Explore All Business RecoveryCharities & social enterprises
Explore All Charities & social enterprisesCommercial Disputes
Explore All Commercial DisputesCommercial Law & Contracts
Explore All Commercial Law & ContractsCommercial Property
Explore All Commercial PropertyCorporate & Finance
Explore All Corporate & FinanceData Protection
Explore All Data ProtectionDebt Services
Explore All Debt ServicesEcclesiastical Law
Explore All Ecclesiastical LawEducation Law
Explore All Education LawEmployment Law
Explore All Employment LawFamily Businesses
Explore All Family BusinessesFinance Dispute Resolution
Explore All Finance Dispute ResolutionFinancial & Business Crime
Explore All Financial & Business CrimeInsurance Litigation
Explore All Insurance LitigationIntellectual Property
Explore All Intellectual PropertyLicensing
Explore All LicensingRegulatory & Corporate Defence
Explore All Regulatory & Corporate Defence
Does the change in EU-US data protection law affect you?
Commercial|29 September 2020
Insight
The General Data Protection Regulation (GDPR) makes it unlawful to transfer personal data outside of the EU unless certain conditions are met.
Until very recently, organisations could rely on the EU-US Privacy Shield as a valid data protection mechanism for the transfer of personal data from the EU to the US. However, in a recent case, the Court of Justice of the European Court overturned this on the basis that the US laws do not offer adequate protection for EU personal data.
The EU-US Privacy Shield framework was introduced in 2016 as a mechanism to provide those organisations who have chosen to comply with it, adequate protection for any personal data transferred from the EU to the US. It imposes stronger obligations on members to protect Europeans’ personal data than US law imposes alone. It also requires the US to monitor and robustly enforce more data protection principles and cooperate with European data protection authorities.
The Privacy Shield is commonly used by cloud-based providers to store large volumes of data in the US.
If your business transfers personal data to the US using the Privacy Shield as the method for protecting that data, or, a contractor you are working with relies on this mechanism when processing your data, then you must find an alternative transfer mechanism.
There is no enforcement grace period allowing organizations to continue transferring data from the EU to the US without assessing their legal basis for doing so.
An alternative would be to use Standard Contractual Clauses (SCCs). These are a set of clauses that contain contractual obligations on both data exporters and importers in relation to the processing of personal data. SCCs are incorporated into contracts between parties and are the most commonly used mechanism for transfers of personal data outside of the EU.
The use of SCCs remains valid provided that your business verifies whether the overall context of the transfer (including the destination country) offers appropriate safeguards to the personal data. Where such appropriate safeguards cannot be provided, you must suspend or prohibit the transfer.
You may otherwise transfer personal data outside of the EU if the data subject gives you their explicit consent to do so. For consent to be deemed ‘explicit’ under the GDPR, it must be expressly confirmed in words, rather than by any other positive action, for example unticking a checked box.
Please note, the information included in this update is correct at the date of publishing.
If you currently rely on the Privacy Shield as a transfer mechanism and require advice on reviewing your data flows and implementing an alternative, legally compliant, transfer mechanism, please call us on 01332 226 130 or complete the form below.
Related Services


New legal duties require organisations to handle data protection complaints correctly. Learn what you need to do now.
Read More

How suppliers’ use of AI can create IP, data protection, and contractual risks, and how businesses can manage them.
Read More

Drop shipping is growing fast. Find out how the right contracts can protect your margins, brand and legal position.
Read More

Learn about fiduciary duties, commission disclosure, and legal compliance after the Expert Tooling v Engie ruling.
Read More

Learn how Rukhadze v Recovery Partners reinforces strict fiduciary duties and what it means for your business and governance.
Read More

The ICO and CMA's joint statement outlines new AI in finance regulations, focusing on data protection, competition, and consumer safeguards.
Read More

A decade of progress – but the fight against modern slavery isn’t over, we highlight how businesses can meet stricter transparency rules.
Read More

Navigate AI regulations in financial services. Key insights from the FCA & ICO on compliance, data protection, and innovation.
Read More

Explore how to create an AI usage policy that mitigates risks and ensures responsible adoption for your business.
Read More

Effective data safety and optimisation are key to business success, reducing risks and improving efficiency in a digital world.
Read More

Landmark EU court ruling awards damages for unlawful data transfer. Learn what this means for GDPR compliance and safeguarding your business.
Read More

Protect your SME from data breaches. Discover key tips for GDPR compliance and data security during Data Protection Week.
Read MoreScroll to next section
Scroll back to the top
