Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Is a Privacy Shield Replacement on the Horizon?

By Sheila Millar, Tracy Marshall & Peter Craddock on March 30, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

After the EU-U.S. Privacy Shield was rendered invalid by the Court of Justice of the European Union (CJEU) in July 2020, and following a prior challenge to the U.S.-EU Safe Harbor, many businesses operating on both sides of the pond scrambled to find other ways to protect data flows between the EU and U.S. that meet the EU General Data Privacy Regulation (GDPR) adequacy standards. Now it appears that a replacement is finally on the horizon. On March 25, 2022, the White House announced that the U.S. and EU have committed to a new Trans-Atlantic Data Privacy Framework (Framework) to facilitate data flows from the EU to the United States and address concerns raised by the CJEU when it struck down the European Commission’s adequacy decision underlying the EU-U.S. Privacy Shield Framework in 2020.

Having worked through two prior frameworks that both governments previously supported, businesses are asking if the new Framework can solve the difficulties that undermined its predecessors. According to the White House press release, the Framework will address the CJEU’s concern in Schrems II, in which the court held that U.S. surveillance activities left EU citizens without a judicial remedy for potential privacy violations by the U.S. government. The new Framework pledges to “strengthen the privacy and civil liberties safeguards governing U.S. signals intelligence activities; establish a new redress mechanism with independent and binding authority; and enhance its existing rigorous and layered oversight of signals intelligence activities.”

The White House gives several examples of how the Framework will address the CJEU’s focus on “surveillance” by the U.S. government, namely:

  • Signals intelligence collection may be undertaken only where necessary to advance legitimate national security objectives and must not disproportionately impact the protection of individual privacy and civil liberties;
  • EU individuals may seek redress from a new multi-layer redress mechanism that includes an independent Data Protection Review Court that would consist of individuals chosen from outside the U.S. Government who would have full authority to adjudicate claims and direct remedial measures as needed; and
  • U.S. intelligence agencies will adopt procedures to ensure effective oversight of new privacy and civil liberties standards.

The Framework’s commitments appear to be a step towards addressing issues raised in the Schrems II decision, and the additional redress mechanisms outlined by the White House provide an independent means for EU residents to raise privacy concerns. However, because details are not yet available, businesses face uncertainty as to whether there will be challenges to the new Framework. To complicate matters, the recent Supreme Court case FBI v. Fazaga granted the U.S. government greater leeway in invoking the state secrets privilege, making it more difficult for both U.S. and EU citizens to challenge surveillance intrusions by the U.S. government in American courts. The interplay between the rights described in the White House press release about the new Framework and U.S. legal precedent requires further analysis.

For the time being, businesses that transfer data between the EU and U.S. can continue using the “adequacy” method they currently employ, provided they take into account the Schrems II judgment and the European Data Protection Board’s recommendations on supplementary measures. The Danish Data Protection Agency has already stressed that the new Framework is still just an agreement in principle and current transfer justification requirements still apply.

For assistance on options to transfer data between the EU and U.S., please contact our Privacy and Data Security team.

Photo of Sheila Millar Sheila Millar

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has…

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has been involved in a variety of audit and compliance projects, including, among other issues, privacy and data security audits, and is experienced in providing crisis management legal support to a variety of national and international companies and associations.

Ms. Millar is a frequent speaker on regulatory and public policy matters, and has authored many articles. Ms. Millar is one of the vice chairs of the International Chamber of Commerce (ICC) Marketing and Advertising Commission, and chair of its Working Group on Sustainability, where she spearheaded the development of the ICC Framework Guides on Environmental Marketing Claims.

Ms. Millar is AV® PreeminentTM Rated by Martindale-Hubbell and for the eigth consecutive year was selected by her peers for inclusion in The Best Lawyers in America® 2018 for her work in practicing Advertising Law. She has also received the distinguished honor of Advertising Law “Lawyer of the Year” 2014 in Washington, DC by Best Lawyers®, and was awarded Advertising and Marketing Lawyer of the Year USA by Finance Monthly for their Finance Monthly Global Awards 2017.

Read more about Sheila MillarEmailSheila's Linkedin Profile
Show more Show less
Photo of Tracy Marshall Tracy Marshall

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She …

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She is a Certified Information Privacy Professional (CIPP/US) through the International Association of Privacy Professionals (IAPP) and helps clients implement privacy, data security, and security breach response programs, develop internal and public-facing privacy policies to comply with applicable laws, respond to cyber and data security incidents, and manage relationships with service providers and third parties. Tracy advises on structuring and conducting email and text messaging campaigns, sweepstakes, contests, and other promotions, and she helps clients protect and enforce their intellectual property rights.

In addition, Tracy counsels clients on corporate matters and assists with structuring and negotiating a variety of transactions, including licensing, marketing, and outsourcing arrangements.

Tracy is frequently invited to speak at privacy, data security, telecommunications, and advertising conferences and is a contributor to Keller and Heckman’s Consumer Protection Connection blog and Beyond Telecom Law Blog.


To learn more about Tracy’s practice areas, click here.
Read more about Tracy MarshallEmailTracy's Linkedin Profile
Show more Show less
Photo of Peter Craddock Peter Craddock

Peter Craddock helps companies innovate and use data better in the European Union (EU) and worldwide by providing strategic advice and legal assistance in the areas of privacy, data protection, data governance, AI governance, cybersecurity, e-commerce, digitalization, and software contracting. Peter’s practice covers…

Peter Craddock helps companies innovate and use data better in the European Union (EU) and worldwide by providing strategic advice and legal assistance in the areas of privacy, data protection, data governance, AI governance, cybersecurity, e-commerce, digitalization, and software contracting. Peter’s practice covers advisory work, contract drafting, and negotiation, as well as representation of clients in litigation before data protection authorities or the courts.

He has recognized in-depth knowledge in complex matters such as online advertising and content personalization, data-intensive operations such as credit scoring and anti-fraud profiling, and digital marketing.

Peter’s legal experience and distinctive background as a software developer serve him well in advising global clients on new and existing technologies, from artificial intelligence (AI) to novel user identification techniques, and in analyzing data protection laws and regulations with a fresh perspective. He counsels clients through the intricacies of developing new initiatives in compliance with data protection and cybersecurity requirements and has developed smart compliance tools for clients to that end. Among the tools made available to a broader public, a data breach risk assessment tool that he built was awarded a “Highly Commended” label at the Financial Times Innovative Lawyers Awards 2019, and his General Data Protection Regulation (GDPR) fine calculation tool, DeFine, helps organizations better understand data protection financial risks.

Prior to joining Keller and Heckman, Peter was a partner at an international law firm in Brussels, where he focused on providing data protection advice under EU and local law.

Read more about Peter CraddockEmailPeter's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Consumer Protection Connection
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo