Home News & Events News overview From Safe Harbor to Privacy Shield


February 29, 2016

From Safe Harbor to Privacy Shield

Since 2000, US companies were allowed to transfer data from the EU to the US, via the so-called “Safe Harbor”. However, we recently learned that it was justified to question whether this Safe Harbor was really as safe as the name implied.

Already in 2013 the European Commission identified shortcomings in this arrangement and set out 13 recommendations. While the Commission was assessing the Safe Harbor to ensure an adequate level of data protection, the Commission was overtaken by reality.

On October 6th 2015, the Court of Justice declared the Safe Harbor arrangement invalid, thereby fueling the need for a renewed and more robust regulatory framework for transatlantic data flows. Following this annulment, the EU data protection authorities, assembled in the Article 29 Working Party, discussed the first consequences at European and national level. On October 16th 2015, this Article 29 Working Party published a statement that if by the end of January 2016, no appropriate solution is found with the US authorities and depending on the assessment of the transfer tools by the Working Party, EU data protection authorities are committed to take all necessary and appropriate actions, which may include coordinated enforcement actions. It may be clear: Data Protection becomes serious business.

This statement worked out very well! On February 2nd 2016 a press release by the European Commission announced an agreement on a new regulatory framework to be developed for transatlantic data flows: Please welcome: The EU-US Privacy Shield. 

This new framework will include:

  • Strong obligations on companies handling Europeans’ personal data AND robust enforcement
  • Clear safeguards and transparency obligations on U.S. government access
  • Effective protection of EU citizens’ rights with several redress possibilities

Recommendation: Until this EU-Privacy Shield is formalized, please refer to this communication from the commission to the European parliament and the council on the Transfer of Personal Data from the EU to the United States of America under Directive 95/46/EC for future info.

By Alwin van den Broek

About the author


April 8, 2015

Strongman Run and Berlin Marathon 2015

September 2015, name it at Factory-CRO and most of the employees will tension their muscles in a reflex. Why? A group of 10 persons is currently training towards the Marathon of Berlin (27 September 2015) and the Fisherman’s Friend Strongmanrun...

April 6, 2017

Medical apps under the new European MDR

Worldwide 1 out of every 3 internet users currently monitors their health or fitness using an app. This was shown in a recent survey by market researcher GfK. Millions of health-related apps are downloaded every year, and this is expected...

Pre Market
December 30, 2016

Notified bodies under pressure

After our recent posts on the proposed Medical Device Regulation (MDR) and MEDDEV 2.7/1 rev. 4, it is interesting to shift our perspective, aiming to get a sense of the potential impact of the new regulatory framework for the medical...

Life Cycle