Victory for privacy campaigners as data-sharing deal ruled invalid
Victory for privacy campaigners as data-sharing deal ruled invalid
It could soon be a lot more difficult for the U.S. and European companies to share customer data. It comes after the EU court's main legal adviser ruled that transatlantic agreement known as Safe Harbour, which allows thousands of businesses operating in the EU to send the private data of Europeans to servers in the U.S., is "invalid." The ruling follows a complaint filed by Austrian activist Max Schrems, who argues that Safe Harbour, which largely depends on the goodwill of U.S. authorities, is too weak to guarantee the privacy of European residents.
Where systemic deficiencies are found in the third country to which the personal data is transferred, the Member States must be able to take the measures necessary to safeguard their fundamental rights.
Schrems' case stems from revelations brought to light in the Edward Snowden scandal. Snowden's data showed that the U.S. National Security Agency used Silicon Valley giants Apple, Google and Facebook to gather user data. Similar deals "that underpin data transfers to many third countries may also be impacted if the Court follows the Opinion of its Advocate General," a statement by DIGITALEUROPE said. In the wake of the scandal, the EU and Washington began talks to revamp Safe Harbour, and Wednesday's opinion will certainly complicate those talks.
[Safe Harbour] is used by about 4,500 companies to transfer a wide range of commercial data such as payroll and customer data.