Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

EU Commission Recommends Suspension of Privacy Shield; Recent FTC Efforts May Be Too Little Too Late

By Dena M. Castricone on July 6, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

On July 5, 2018, the EU Parliament passed a non-binding resolution encouraging the European Commission to suspend the EU-US Privacy Shield Program unless the US is fully compliant by September 1, 2018.  The EU Parliament believes that the current Privacy Shield program does not provide an adequate level of protection required by European law.  This comes roughly two years after the European Commission deemed the EU-US Privacy Shield Framework adequate to enable data transfers under EU law.  But a lot has changed in two years. 

In its resolution (in draft form), the Parliament points to several concerns with the EU-US Privacy Shield program.  Notably, the Parliament uses the Facebook-Cambridge Analytica saga (both companies are Privacy Shield certified) as proof of the program’s inadequacy and the US’ failure to monitor the program sufficiently.  Further, the Parliament questions two recent US legislative actions as potentially being at odds with EU privacy principles:  the recent passage of the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) and the January 2018 reauthorization of warrantless searches under the Foreign Intelligence Surveillance Act (FISA).

Earlier this week, the Federal Trade Commission (FTC), one of the US agencies charged with enforcing Privacy Shield, announced a settlement with a California on-line training company that falsely claimed it was in the process of obtaining the EU-US Privacy Shield certification.  In its press release, the FTC boasts that this is the fourth case it has brought enforcing the Privacy Shield.  This obviously did not impress the Parliament.

The good news for the more than 3,100 organizations that voluntarily participate in Privacy Shield is that the Parliament does not have the authority to suspend the program.  Only the EU Commission or the Court of Justice of the European Union can do so and neither has taken action yet.  The EU Commission is slated to perform an annual review of the program in October.  We will continue to monitor any further developments.

Photo of Dena M. Castricone Dena M. Castricone

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro…

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro Bono Committee.  Prior to joining Murtha Cullina, Dena served as a law clerk to the Chief Justice of the Rhode Island Supreme Court, Frank J. Williams.

As the Chair of the Privacy and Cybersecurity group and a Certified Information Privacy Professional (CIPP/US), Dena provides the full complement of data breach coaching services to business and health care clients including breach notification to individuals and various government entities.  Related to data breaches, she also counsels clients on the creation of information security, incident response plans and other proactive measures.  Additionally, Dena advises clients on compliance with state, federal and international privacy laws including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) as well as many others. Dena has written extensively on privacy and cybersecurity issues and she is the Co-Editor of Privacy and Cybersecurity Perspectives.  Read More

Read more about Dena M. CastriconeEmailDena M.'s Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy and Cybersecurity Perspectives
  • Organization:
    Murtha Cullina LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo