Welcome to our UK site – choose your Jurisdiction

Personal Data: US Privacy Shield

As we know, the US ‘Safe Harbor’ scheme was declared invalid by the European Court of Justice in October of last year – see Regulatory Roundup 70.

The issue at the time centred around Principle 8 of the Data Protection Act (Schedule 1) which prevents the transfer of personal data to a country outside the EEA unless that country has an adequate level of protection.

The Information Commissioner’s Office (“ICO”) website includes a list of non-EEA countries that the European Commission has determined have an adequate level of protection for personal data. The (short) list includes countries such as the Faroe Islands and Uruguay but the US is conspicuous by its absence.

As a reminder, based upon a previous European Commission Decision (2000/520), personal data sent to the US under the voluntary ‘Safe Harbor’ scheme was deemed adequately protected. To fall within this, US firms had to (a) sign up to the Safe Harbor arrangement under which they agree to follow the principles of data handling and (b) be held responsible for keeping those principles by the Federal Trade Commission (or other oversight scheme). Note that certain companies such as US financial institutions were not covered by the Safe Harbor scheme.

Since that time a new framework on transatlantic data flows has been under development: the EU-US Privacy Shield. The ‘Shield’ reflects the requirements set out by the European Court of Justice and will provide stronger obligations on companies in the US, which will be enforced by the US Department of Commerce and Federal Trade Commission.

There is no firm date for the Privacy Shield to come into force – the framework still has to go through due process, including the consent of the European Parliament – although consensus opinion is late Q2/early Q3 this year.

Why Choose Complyport?

Extensive Regulatory Expertise

With over 25 years of experience in the financial services industry, Complyport offers unparalleled expertise in regulatory compliance, ensuring your firm stays ahead of evolving regulations.

Comprehensive Service Offering

From AML audits to risk management and regulatory reporting, Complyport provides a full spectrum of compliance services, allowing you to streamline your compliance processes and focus on your core business activities.

Tailored Compliance Solutions

We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Client-Centric Approach

We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Senior-Level Guidance

Our team of seasoned professionals, including former regulators and industry experts, leads all engagements, offering deep insights and practical advice to help you manage compliance risks effectively.

Innovative Fintech, Regtech and AI Solutions

Leveraging cutting-edge fintech, regtech and AI tools, Complyport enhances your compliance processes with advanced technology, ensuring accuracy, efficiency, and real-time regulatory updates. Our innovative solutions empower your firm to stay compliant while maximising operational efficiency.

Key Figures

Over 25 Years

Providing Compliance Excellence

Over 1,500

Successful FCA and EU Authorisations

Over 1,000

Active Firms Receiving Regulatory Support

Get In Touch