Alahmadi__SafeHarbor_PrivacyShield1.pdf

Running head: THE EU-US SAFE HARBOR LAWS 1

The EU-US Privacy Shield Program /Safe Harbor Vs. US privacy laws

Mohammed Alahmadi

CSUSB

10/13/2019

THE EU-US SAFE HARBOR LAWS 2

The EU-US Privacy Shield Program /Safe Harbor Vs. US privacy laws

The world of privacy and data protection rests on a paradox that pitches the pressing

issues that are fundamental to the fate of Privacy Shield. The onset and realignment of trade and

all business activities towards the internet marked the inception of the need to develop a

framework for steering the flow of data between the United States of America and the European

Union in a bid to enhance economic growth and development between the two regions. The

transformations in the data mining tactics and the existence of significant gaps in the protocols of

America and the EU called for the renegotiation of the Safe Harbor Agreement, which led to the

development of the new Privacy Shield (Weiss & Archick, 2016). While most arguments

associate the Safe Harbor Agreement/Privacy Shield with the provision of permission to

organizations and businesses to collect and use personal data, its prime role was to accord

maximum level of protection for the American and European citizen's information.

The EU-US Privacy Shield Program /Safe Harbor Laws

Developed in the year 2000 to aid the transactions by companies and organizations, the

Safe Harbor Agreement was an obligation towards safeguarding the privacy rights of people by

using their data within the realms of the guidelines. The European Union and the United States

established the framework as a collective understanding due to the differences in their data

confidentiality approaches and legal systems. While American laws allow for the gathering and

processing of personal data, except in situations expressly restricted by the regulations, the EU,

on the other hand, prohibits such activities and has a clear legal basis that permits the

dispensation of personal information. Moreover, in the EU, “protecting personal data is a

fundamental human right,” developed and published in a Charter binding all the member states.

The treaty of Lisbon reflected and incorporated the “Fundamental Rights of the EU in 2007.”

Consequently, the stringent data privacy demands of the Europeans emanate from the EU's

experience with the totalitarian and fascist systems (Weiss & Archick, 2016). Therefore, in the

drafting of the Safe Harbor Agreement, the EU had to front its concerns over the ideological

differences between the region and American attitudes towards data privacy.

Under Safe Harbor, American companies had to comply with a set of fundamental

principles depicting the requirements deemed essential for achieving the adequate data privacy

standards of the EU. For instance, a company must issue a notice that informs the target audience

about the reasons for collecting and using their information as well as providing a framework of

contacting the firm for inquiries and third-party information disclosure cases. An organization

must also grant users the choice to opt-in and out and determine whether they allow third parties

to access their information. In situations demanding highly private data, a person must explicitly

sign in to enable the transfer of data to a third party. Such info includes race, religion, ethnicity,

membership of trade unions, and sexuality of an individual. Under onward transfer, companies

must utilize the guidelines embedded in the issuance of a notice and the choices made by the

clients. Therefore, third parties must uphold the same integrity because they serve as agents that

enter a contract with an organization operating under Safe Harbor (Weiss & Archick, 2016). The

creation, maintenance, use, and dissemination of personal data must utilize legal precautionary

procedures that protect the information from loss, misuse, and any unapproved access.

THE EU-US SAFE HARBOR LAWS 3

Organizations must also ensure that information collected and held serves only the

relevant purposes, thereby upholding the integrity of the data by acquiring current and complete

information for use. In doing this, the clients must also have access to information about them

held by the organization. They have the liberty to amend the information. However, Safe Harbor

has limited authority in situations of national security, public interest, and law enforcement

demands.

The Privacy Shield Agreement, on the other hand, addressed the issues of data protection

emanating from contemporary data privacy and breaches across the EU nations and the USA

between 2005 to 2015. Therefore, American firms aiming to import personal data from countries

under the EU must commit to a wide range of obligations on how data security and protection is

guaranteed. For instance, such companies must issue a detailed notice obligation with limits on

data retention and descriptive rights of access to the information alongside transferability and

enhanced security demands. The new agreement also has clear transparency obligations in line

with written assurances from the United States Department of Justice on the limitations and

oversight mechanisms of data transfer and utilization. Every EU citizen has a right to seek

multiple redresses in a bid to enhance adequate data protection and development of systems that

impede the pilferage of information.

American Data Privacy Regulations

The United States of America does not have single legislation for individual principle

data protection initiatives. It has a collection of regulations that empowers the Federal Trade

Commission to protect American residents from deceptive activities. The federal laws are sector-

specific, and each State can impose restrictions on organizations on the collection, processing,

and the disclosure of information. The data protected by such regulations include biometric data,

health records, addresses, social security statistics, and education records. The American

constitution did not have the concept of privacy as its government utilizes the laissez-faire

system that grants people and businesses an autonomy in the markets (Movius & Krup, 2009).

The government only intervenes using sector-specific statutes to bail a failing industry because it

serves the role of a latent ruler. America understands the relevance of privacy protection in

steering e-commerce development but left it to self-regulate within businesses in different

industries.

The American approach differs from the EU's opinions on data privacy, where it is the

government's responsibility to protect the citizens as a fundamental human right. However, after

the 911 attack and the development of the U.S. Patriot Act, America ventured into investigative

activities that redefined the country's approach to personal data privacy rights (Movius & Krup,

2009). The Patriot Act only focuses on detecting and preventing terrorism as it grants law

enforcement officials the authority to monitor people's activity on the internet through advanced

technologies.

Nearly every data protection law in America is statute-specific, and the country does not

have any registration formalities and prior approval guidelines for businesses. It is also optional

to appoint a data protection officer in America unless demanded by specific statues in

compliance with the Health Insurance Portability and Accountability Act laws. The United States

of America does not have limitations on the transfer of its citizens' information to international

THE EU-US SAFE HARBOR LAWS 4

jurisdictions. Therefore, it is the responsibility of each company to determine the type of contract

or the nature of the activity to do with the data. However, institutions importing data from

countries under the EU block must adhere to the EU-US Data Privacy Shield Framework.

However, America treats the data security breach with the same level of seriousness as

the EU-US Data Privacy Shield Framework. It can enforce laws and sanctions against

organizations and companies exploiting its lenient laws for the advantage of other nations while

defrauding its economy.

The Importance of the Data Privacy Frameworks and their Impact on American

Companies Doing Business Abroad

America’s approach to data security gives firms the chance to invest in the country and

grow its economy without restrictions. Such autonomy makes it easier for organizations that

require personal data to enter the market and start their operations. At face value, it is a feasible

and well-structured approach. However, the laissez-faire approach of the government on data

privacy cannot allow firms to take advantage of the citizens. Entering the free market may be an

easy venture, but each industry has specific statutes that regulate the activities of businesses.

Consequently, each State in America functions as a separate entity guided by the federal

laws on data protection policies. Therefore, each state and a few protection and compliance

organizations set the guidelines for the self-regulating markets. Local companies also enjoy the

privilege of protection from unfair competition by international firms aiming to explore and

exploit the American industries. The United States of America’s hard stance on data breach also

mitigates the likelihood of data exploitation by international firms deeming the citizens as a

prospect market.

Complying with the EU-US Privacy Shield grants American firms the mark of integrity

as membership guarantees adequate data privacy protection. For instance, if a company faces

allegations of a data breach in the United States of America, the EU can verify the case and

reaffirm to the public, the safety of their data. The pre-approval and compliance requirements are

also clearly defined and cost-effective, thereby favoring both the small, medium and large-sized

multinational businesses. With the tremendous paradigm shift in privacy demands for businesses,

existing and relying on free markets, such as that of the United States of America, exposes a

company to numerous data breach risks. Enterprises opt for the EU-US trade relationships to

capture the attention of customers and create value for themselves, which brews trust and loyalty.

Having the EU-US Privacy Shield and the American privacy laws in place is of great

importance to the American companies. Within their homeland, these businesses enjoy the

loyalty and support of the citizens, and beyond the borders, they gain authenticity and integrity

from complying with the EU-US data policies. It can be challenging to outcompete the firms on

all grounds because America is an economic powerhouse with the business spillover effect that

labels its products trendy and the best in the market. Most consumers will prefer American goods

because of the history of the reviews available online or the celebrities associated with the brand,

which emanates from the country’s stringent regulations on quality. Therefore, most of the

American brands opt-in the EU-US Privacy Shield for integrity and to expand their customer

base, which translates to a double-gain for the firms.

THE EU-US SAFE HARBOR LAWS 5

References

Movius, L. B., & Krup, N. (2009). US and EU privacy policy: comparison of regulatory

approaches. International Journal of Communication, 3, 19. Retrieved 14 October 2019,

from https://ijoc.org/index.php/ijoc/article/viewFile/405/305.

Weiss, M. A., & Archick, K. (2016). US-EU data privacy: from safe harbor to privacy shield.

Retrieved 14 October 2019, from https://fas.org/sgp/crs/misc/R44257.pdf