The European Court of Justice (ECJ) in Luxembourg has ruled that the current transatlantic data protection regulations do not sufficiently protect the data of European citizens.
The ‘Privacy Shield’ transatlantic agreement is used by thousands of companies to transfer data between the EU and the US. Previous to this, the ‘Safe Harbour’ agreement was in place, which itself was dismantled by European judges in 2015, due to similar complaints against the security, privacy and protection of personal data.
This new ruling comes about due to the discrepancy between data protection regulations in Europe and the US. The US affords far fewer rights to individuals over use of their personal data in comparison to EU countries, which are under the GDRP – for example which includes the right to make subject access requests to platforms/organisations to understand how they are using your data and to request that you be removed from their service(s) and ‘forgotten’. Vera Jourova, EU executive vice-president in charge of Values and Transparency said, “We would like to see on the American side a federal law that would be equivalent or similar to the General Data Protection Regulation”.
It has been stated that companies will still be able to move data under Standard Contractual Clauses (SCCs), which are legally binding agreements covering data protection, and are specific to each platform/company. But ‘Privacy Shield’ is no longer valid.
This is a major victory for privacy campaigners, and has immediate implications for Facebook and thousands of other companies that move personal data across the Atlantic.

