EU-U.S. Privacy Shield: Second review shows improvements but a permanent Ombudsperson should be nominated by 28 February 2019

Privacy Shield 2019

Dimitris Avramopoulos, Member of the EC in charge of Migration, Home Affairs and Citizenship, and Vĕra Jourová, Member of the EC in charge of Justice, Consumers and Gender Equality, give a press conference on the communication on Visa Reciprocity, the Second Report on the visa suspension mechanism and the Report on the second annual review of the EU-US Privacy Shield. © European Union , 2018 / Photo: Théodore Boermans

This article is brought to you in association with the European Commission.

Today the European Commission publishes its report on the second annual review of the functioning of the EU-U.S. Privacy Shield.

This year’s report shows thatthe U.S. continues to ensure an adequate level of protection for personal data transferred under the Privacy Shield from the EU to participating companies in the U.S. The steps taken by the U.S. authorities to implement the recommendations made by the Commission in last year’s report have improved the functioning of the framework.

However, the Commission does expect the US authorities to nominate a permanent Ombudsperson by 28 February 2019 to replace the one that is currently acting.  The Ombudsperson is an important mechanism that ensures complaints concerning access to personal data by U.S. authorities are addressed.

Andrus Ansip, Commission Vice-President for the Digital Single Market, said: “Today’s review shows that the Privacy Shield is generally a success. More than 3,850 companies have been certified, including companies like Google, Microsoft and IBM – along with many SMEs. This provides an operational ground to continuously improve and strengthen the way the Privacy Shield works. We now expect our American partners to nominate the Ombudsperson on a permanent basis, so we can make sure that our EU-US relations in data protection are fully trustworthy.”

Commissioner for Justice, Consumers and Gender Equality, Věra Jourová,stated: The EU and the U.S. are facing growing common challenges, when it comes to the protection of personal data, as shown by the Facebook / Cambridge Analytica scandal. The Privacy Shield is also a dialogue that in the long term should contribute to convergence of our systems, based on strong horizontal rights and independent, vigorous enforcement. Such convergence would ultimately strengthen the foundation on which the Privacy Shield is based. In the meantime, all elements of the Shield must be working at full speed, including the Ombudsperson.”

Improvements already made include the strengthening by the Department of Commerce of the certification process and of its proactive oversight over the framework. As recommended by the Commission’s first annual review, the Department of Commerce has set up several mechanisms, such as a system of checks (“spot checks”), which randomly selects companies to verify that they comply with the Privacy Shield principles. 100 companies have been checked: 21 had issues that have now been solved. Additional compliance review procedures also include the analysis of Privacy Shield participants’ websites to ensure that links to privacy policies are correct. The Department of Commerce put in place a system to identify false claims which prevents companies from claiming their compliance with the Privacy Shield, when they have not been certified.

The Federal Trade Commission has also demonstrated a more proactive approach to enforcement by monitoring the principles of the Privacy Shield, including by issuing subpoenas to request information from the participating companies.

As regards access to personal data by U.S. public authorities for national security purposes, new members of the Privacy and Civil Liberties Oversight Board (PCLOB) have been appointed which restores the Board’s quorum. The Board’s report on the implementation of Presidential Policy-Directive No. 28 (PPD-28, which provides for privacy protections for non-Americans) has been made publicly available. It confirms that these privacy protections for non-Americans are implemented across the U.S. intelligence community.

The second review took into account relevant developments in the U.S. legal system in the area of privacy. The Department of Commerce launched a consultation on a federal approach to data privacy to which the Commission contributed and the US Federal Trade Commission is reflecting on its current powers in this area. In the context of the Facebook/Cambridge Analytica scandal, the Commission noted the Federal Trade Commission’s confirmation that its investigation of this case is ongoing.

Next steps

The report will be sent to the European Parliament, the Council, the European Data Protection Board and to the U.S. authorities.

The European Commission expects the U.S. government to identify a nominee to fill the Ombudsperson position on a permanent basis by 28 February 2019 at the latest. If this does not take place by that date, the Commission will consider taking appropriate measures, in accordance with the General Data Protection Regulation.


The EU-U.S. Privacy Shield decision was adopted on 12 July 2016 and the Privacy Shield framework became operational on 1 August 2016. It protects the fundamental rights of anyone in the EU whose personal data is transferred to certified companies in the United States for commercial purposes and brings legal clarity for businesses relying on transatlantic data transfers.

The Commission committed to reviewing the arrangement on an annual basis, to assess if it continues to ensure an adequate level of protection for personal data. After the first annual review, which took place in 2017, the Commission made a number of recommendations to further improve the practical functioning of the Privacy Shield.

On 18 October 2018, Commissioner for Justice, Consumers and Gender Equality Věra Jourová, launched with the US Secretary of Commerce Wilbur Ross the discussions for the second review the EU-U.S. Privacy Shield (statement). The findings in this report are based on meetings with representatives of all US government departments in charge of running the Privacy Shield, including the Federal Trade Commission, the Office of the Director of National Intelligence (ODNI), the Department of Justice and the State Department, which took place in Brussels mid-October 2018, a study on automated decision-making commissioned by the Commission as well as on input from a wide range of stakeholders, including feedback from companies and privacy NGOs. Representatives of the EU’s independent data protection authorities also participated in the review.

the sting Milestone

Featured Stings

Can we feed everyone without unleashing disaster? Read on

These campaigners want to give a quarter of the UK back to nature

How to build a more resilient and inclusive global system

Stopping antimicrobial resistance would cost just USD 2 per person a year

Medical education during COVID-19 pandemic

Why enterprise risk management is the future for banks

The world needs carbon-neutral flying. Here’s how to bring it one step closer

Mergers: Commission opens in-depth investigation into joint ventures proposed by Boeing and Embraer

UN investigates systematic sexual violence across South Sudan

The power of trust and values in the Fourth Industrial Revolution

Investment Plan for Europe: European Investment Bank to provide BioNTech with up to €100 million in debt financing for COVID-19 vaccine development and manufacturing

FIAT Chrysler: from Geneva Motor show to the World, and back

Sweden must urgently implement reforms to boost fight against foreign bribery

The EU wants to create 10 million smart lampposts

The Peoples are missing from EU’s monetary union

Amid strong outlook for U.S. economy, risks abound

Refugee crisis update: EU lacks solidarity as migration figures drop

Bugged Europe accepts US demands and blocks Morales plane

Everything you need to know about the coronavirus

Islamophobia is driving more US Muslims to become politically engaged, suggests report

Elections results: Austerity’s black to prevail in the new multicolored German government

Traditional finance is failing millennials. Here’s how investing needs to change

UN condemns deadly attack one of its vehicles

‘Continuing absence’ of political solution to Israel-Palestine conflict ‘undermines and compounds’ UN efforts to end wholesale crisis

Migration: Better travel safe than sorry

UN study projects $32 billion loss for UK post no-deal Brexit

Eurozone: The crisis hit countries are again subsidizing the German and French banks

JADE Spring Meeting Live Coverage: Entrepreneurial skills in the digital markets

The Philippines is reopening a ‘cesspool’ island after a six month clean up

EU-UK: A deal synonymous to ‘remain’, England pays the Irish price

Governments must take further action to boost job opportunities at an older age

5 key concepts for blockchain newbies

Telemedicine and the Brazilian reality

Finnish Presidency outlines priorities to EP committees

‘Collective amnesia’ over causes of global financial crash – human rights expert

Europe again the black sheep at the G20 Finance Ministers and Central Bank Governors

Financial transactions tax gets go ahead

5 ways you can protect insects if you live in a city

Youth and Decent Work: A Review of Today’s Facts, Challenges and Possible Solutions

D-Day for Grexit is today and not Friday; Super Mario is likely to kill the Greek banks still today

3 reasons why most Africans aren’t on the internet – and how to connect them

Promoting Primary Health Care to the Young Health Workforce: a new approach

This city is planting a tree for every man, woman and child

Conquering COVID-19 through Collaboration

This is the biggest risk we face with AI, by Google CEO Sundar Pichai

UN-based World Summit Award (WSA) presents its master list on digital innovation with impact on society from 24 countries

Yemen war: UN-backed talks to silence the guns due to begin in Stockholm

Could implants treat people with brain disease? A young scientist explains

How to make your business thrive by doing good

Brexit may finally not really happen; The Brits have second thoughts

What is a CSO and does every company need one?

New York high school students are getting free water bottles to cut plastic waste

The European Sting’s 2018 in most critical review

Radio still a powerful worldwide tool for ‘dialogue, tolerance and peace’: Guterres

ECB’s unconventional monetary measures give first tangible results

Job vacancy data reveal better prospects for Britain, stagnation in Eurozone

Commission presents far-reaching anti-tax evasion measures

Coronavirus response: How the Capital Markets Union can support Europe’s recovery

How blockchain can cut the cost of new medicine

Civil society groups matter for Cambodia’s sustainable development: UN expert

The miserables and the untouchables of the economic crisis

Statement by the European Commission following the first meeting of the EU-UK Joint Committee

Boosting the EU’s Green Recovery: EU invests over €2 billion in 140 key transport projects to jump-start the economy

Eurozone at risk of home-made deflation and recession

More Stings?


Speak your Mind Here

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s