No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Privacy Shield in Limbo

by Peter Merkulov
June 29, 2016
in Data Privacy, Featured
Data governance a challenge in the wake of Safe Harbor

At the turn of the 21st century, the internet grew to become a vital conduit for trade. International markets became accessible to any organization or entrepreneur with a modem, and consumer data, known as personally identifiable information (PII), emerged as an important component of commerce. However, U.S. and European laws do not cover the same digital privacy rules, therefore a trade agreement known as Safe Harbor was enacted to harmonize the differences and to make it easier for companies to comply with a single legal framework.

For a decade under Safe Harbor, the U.S. and EU engaged in a robust cross-border trade of private citizen data that U.S. Secretary of Commerce Penny Pritzker recently stated is worth $260 billion. Then, in 2013, a CIA employee by the name of Edward Snowden blew the whistle on what he regarded as unconstitutional domestic surveillance and intelligence gathering activities. Europeans and the rest of the global community were shocked, a lawsuit was filed and, in October of 2015, the Safe Harbor framework was invalidated by what is now known as the Schrems Decision—the culmination of an erosion of trust that seemed to take U.S. industry by surprise but, in hindsight, was not at all surprising. Safe Harbor’s foundation was a long-standing assumption of trust between trading partners and that trust was broken.

In an effort to restore simplified cross-border data exchange, a new proposal known as the EU-U.S. Privacy Shield was drafted and submitted to Europe’s privacy watchdog group, the Article 29 Working Party, for ratification earlier this year. The first draft was rejected over what the EU’s privacy chiefs deemed to be inadequate protections and redress. While Europe’s Article 29 Working Party waits for a revised draft of the EU-U.S. Privacy Shield agreement, American companies with overseas interests must continue to engage in trans-Atlantic data-sharing—and many are worried about what to do while diplomacy plays out.

Even with the likelihood that a rewritten Privacy Shield will be adopted by the EU, there remains uncertainty. What is a company to do while waiting for a Privacy Shield agreement that is acceptable to the EU privacy commissioners?

The first step is for companies to recognize that they remain responsible for the way PII is protected and respected. Privacy Shield will make things easier than they would be otherwise, but compliance and the ongoing maintenance of trust takes effort. That means investing in programs, training and tools required to protect data. In the U.S., companies are already compelled to invest in systems and practices that comply with privacy and data security laws in order to protect the public. According to research firm Gartner, total spending on information security products last year eclipsed $75 billion.

Security alone is not enough. Contractual obligations between companies that meet the standards prescribed by the various jurisdictions are necessary. Once such contracts are in place, the governance of data transfers—assurances that both data security and data management policies are adequate to current legal standards and are being followed—must be documented in order to demonstrate to regulating authorities that operations are compliant with the law and with binding contracts. It is one thing to say you know the rules and still another to verify compliance. This is vital for the company’s own protection should privacy violations be alleged. And, of course, this should all be done with the support of legal counsel.

Trans-Atlantic data transfer did not end abruptly when Safe Harbor was invalidated. U.S. and EU trading partners continue to do business and will do so with or without Privacy Shield, and forward-looking companies would do well to recognize that data security is a challenge that will grow more difficult no matter what trade agreements are in place. Compliance is a floor or a ceiling, and companies should therefore set their own high standards for protecting and managing data. That is how to build and maintain trust.


Tags: Board Risk OversightCommunications Management
Previous Post

Companies That Use Suppliers With Political ‘Connections’ May Damage Reputation

Next Post

Transparency International Condemns Prosecution and Sentencing of LuxLeaks Whistleblowers

Peter Merkulov

Peter Merkulov

Peter Merkulov serves as Chief Technology Officer at Globalscape. He is responsible for leading and overseeing the product strategy, product management, product marketing, technology alliances, engineering and quality assurance teams. Merkulov has more than 16 years of experience in the IT security industry, specifically in product strategy and management. Prior to joining Globalscape, Merkulov served as Executive Vice President at Kaspersky Lab North America, where he oversaw the expansion of the business within North America, and was second in command of their North American operations. He also served as their Chief Product Officer, where he drove the adoption, development and execution of long-term product strategy. Merkulov also served as the Vice President of Technology Alliances at Kaspersky Lab. Merkulov is a graduate of Moscow State Institute of International Relations and is fluent in English, Russian and Swedish.

Related Posts

signing deal signature

When the Ink Dries: 6 Critical Post-Transaction Areas That Make or Break M&A Success

by Jim DeLoach
April 14, 2025

Poor follow-up once the deal is closed can cause culture clashes & value erosion

news roundup new

Bang for the Buck: Regulators Pivot to Fewer But Higher-Value Enforcement Actions

by Staff and Wire Reports
April 11, 2025

CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your...

merger concept figurines

When Money Isn’t Cheap, M&A Due Diligence Must Go Deeper

by Jim DeLoach
March 17, 2025

Today's dealmakers must scrutinize targets through multiple lenses to avoid costly post-acquisition surprises

chess pieces

10 Questions That Separate Strategic Leaders From Spectators

by Jim DeLoach
February 19, 2025

From pattern recognition to emotional intelligence, key indicators reveal true boardroom influence

Next Post
Transparency International Condemns Prosecution and Sentencing of LuxLeaks Whistleblowers

Transparency International Condemns Prosecution and Sentencing of LuxLeaks Whistleblowers

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights