Essay
Running head: THE EU-US SAFE HARBOR LAWS 1
The EU-US Privacy Shield Program /Safe Harbor Vs. US privacy laws
Mohammed Alahmadi
CSUSB
10/13/2019
THE EU-US SAFE HARBOR LAWS 2
The EU-US Privacy Shield Program /Safe Harbor Vs. US privacy laws
The world of privacy and data protection rests on a paradox that pitches the pressing
issues that are fundamental to the fate of Privacy Shield. The onset and realignment of trade and
all business activities towards the internet marked the inception of the need to develop a
framework for steering the flow of data between the United States of America and the European
Union in a bid to enhance economic growth and development between the two regions. The
transformations in the data mining tactics and the existence of significant gaps in the protocols of
America and the EU called for the renegotiation of the Safe Harbor Agreement, which led to the
development of the new Privacy Shield (Weiss & Archick, 2016). While most arguments
associate the Safe Harbor Agreement/Privacy Shield with the provision of permission to
organizations and businesses to collect and use personal data, its prime role was to accord
maximum level of protection for the American and European citizen's information.
The EU-US Privacy Shield Program /Safe Harbor Laws
Developed in the year 2000 to aid the transactions by companies and organizations, the
Safe Harbor Agreement was an obligation towards safeguarding the privacy rights of people by
using their data within the realms of the guidelines. The European Union and the United States
established the framework as a collective understanding due to the differences in their data
confidentiality approaches and legal systems. While American laws allow for the gathering and
processing of personal data, except in situations expressly restricted by the regulations, the EU,
on the other hand, prohibits such activities and has a clear legal basis that permits the
dispensation of personal information. Moreover, in the EU, “protecting personal data is a
fundamental human right,” developed and published in a Charter binding all the member states.
The treaty of Lisbon reflected and incorporated the “Fundamental Rights of the EU in 2007.”
Consequently, the stringent data privacy demands of the Europeans emanate from the EU's
experience with the totalitarian and fascist systems (Weiss & Archick, 2016). Therefore, in the
drafting of the Safe Harbor Agreement, the EU had to front its concerns over the ideological
differences between the region and American attitudes towards data privacy.
Under Safe Harbor, American companies had to comply with a set of fundamental
principles depicting the requirements deemed essential for achieving the adequate data privacy
standards of the EU. For instance, a company must issue a notice that informs the target audience
about the reasons for collecting and using their information as well as providing a framework of
contacting the firm for inquiries and third-party information disclosure cases. An organization
must also grant users the choice to opt-in and out and determine whether they allow third parties
to access their information. In situations demanding highly private data, a person must explicitly
sign in to enable the transfer of data to a third party. Such info includes race, religion, ethnicity,
membership of trade unions, and sexuality of an individual. Under onward transfer, companies
must utilize the guidelines embedded in the issuance of a notice and the choices made by the
clients. Therefore, third parties must uphold the same integrity because they serve as agents that
enter a contract with an organization operating under Safe Harbor (Weiss & Archick, 2016). The
creation, maintenance, use, and dissemination of personal data must utilize legal precautionary
procedures that protect the information from loss, misuse, and any unapproved access.
THE EU-US SAFE HARBOR LAWS 3
Organizations must also ensure that information collected and held serves only the
relevant purposes, thereby upholding the integrity of the data by acquiring current and complete
information for use. In doing this, the clients must also have access to information about them
held by the organization. They have the liberty to amend the information. However, Safe Harbor
has limited authority in situations of national security, public interest, and law enforcement
demands.
The Privacy Shield Agreement, on the other hand, addressed the issues of data protection
emanating from contemporary data privacy and breaches across the EU nations and the USA
between 2005 to 2015. Therefore, American firms aiming to import personal data from countries
under the EU must commit to a wide range of obligations on how data security and protection is
guaranteed. For instance, such companies must issue a detailed notice obligation with limits on
data retention and descriptive rights of access to the information alongside transferability and
enhanced security demands. The new agreement also has clear transparency obligations in line
with written assurances from the United States Department of Justice on the limitations and
oversight mechanisms of data transfer and utilization. Every EU citizen has a right to seek
multiple redresses in a bid to enhance adequate data protection and development of systems that
impede the pilferage of information.
American Data Privacy Regulations
The United States of America does not have single legislation for individual principle
data protection initiatives. It has a collection of regulations that empowers the Federal Trade
Commission to protect American residents from deceptive activities. The federal laws are sector-
specific, and each State can impose restrictions on organizations on the collection, processing,
and the disclosure of information. The data protected by such regulations include biometric data,
health records, addresses, social security statistics, and education records. The American
constitution did not have the concept of privacy as its government utilizes the laissez-faire
system that grants people and businesses an autonomy in the markets (Movius & Krup, 2009).
The government only intervenes using sector-specific statutes to bail a failing industry because it
serves the role of a latent ruler. America understands the relevance of privacy protection in
steering e-commerce development but left it to self-regulate within businesses in different
industries.
The American approach differs from the EU's opinions on data privacy, where it is the
government's responsibility to protect the citizens as a fundamental human right. However, after
the 911 attack and the development of the U.S. Patriot Act, America ventured into investigative
activities that redefined the country's approach to personal data privacy rights (Movius & Krup,
2009). The Patriot Act only focuses on detecting and preventing terrorism as it grants law
enforcement officials the authority to monitor people's activity on the internet through advanced
technologies.
Nearly every data protection law in America is statute-specific, and the country does not
have any registration formalities and prior approval guidelines for businesses. It is also optional
to appoint a data protection officer in America unless demanded by specific statues in
compliance with the Health Insurance Portability and Accountability Act laws. The United States
of America does not have limitations on the transfer of its citizens' information to international
THE EU-US SAFE HARBOR LAWS 4
jurisdictions. Therefore, it is the responsibility of each company to determine the type of contract
or the nature of the activity to do with the data. However, institutions importing data from
countries under the EU block must adhere to the EU-US Data Privacy Shield Framework.
However, America treats the data security breach with the same level of seriousness as
the EU-US Data Privacy Shield Framework. It can enforce laws and sanctions against
organizations and companies exploiting its lenient laws for the advantage of other nations while
defrauding its economy.
The Importance of the Data Privacy Frameworks and their Impact on American
Companies Doing Business Abroad
America’s approach to data security gives firms the chance to invest in the country and
grow its economy without restrictions. Such autonomy makes it easier for organizations that
require personal data to enter the market and start their operations. At face value, it is a feasible
and well-structured approach. However, the laissez-faire approach of the government on data
privacy cannot allow firms to take advantage of the citizens. Entering the free market may be an
easy venture, but each industry has specific statutes that regulate the activities of businesses.
Consequently, each State in America functions as a separate entity guided by the federal
laws on data protection policies. Therefore, each state and a few protection and compliance
organizations set the guidelines for the self-regulating markets. Local companies also enjoy the
privilege of protection from unfair competition by international firms aiming to explore and
exploit the American industries. The United States of America’s hard stance on data breach also
mitigates the likelihood of data exploitation by international firms deeming the citizens as a
prospect market.
Complying with the EU-US Privacy Shield grants American firms the mark of integrity
as membership guarantees adequate data privacy protection. For instance, if a company faces
allegations of a data breach in the United States of America, the EU can verify the case and
reaffirm to the public, the safety of their data. The pre-approval and compliance requirements are
also clearly defined and cost-effective, thereby favoring both the small, medium and large-sized
multinational businesses. With the tremendous paradigm shift in privacy demands for businesses,
existing and relying on free markets, such as that of the United States of America, exposes a
company to numerous data breach risks. Enterprises opt for the EU-US trade relationships to
capture the attention of customers and create value for themselves, which brews trust and loyalty.
Having the EU-US Privacy Shield and the American privacy laws in place is of great
importance to the American companies. Within their homeland, these businesses enjoy the
loyalty and support of the citizens, and beyond the borders, they gain authenticity and integrity
from complying with the EU-US data policies. It can be challenging to outcompete the firms on
all grounds because America is an economic powerhouse with the business spillover effect that
labels its products trendy and the best in the market. Most consumers will prefer American goods
because of the history of the reviews available online or the celebrities associated with the brand,
which emanates from the country’s stringent regulations on quality. Therefore, most of the
American brands opt-in the EU-US Privacy Shield for integrity and to expand their customer
base, which translates to a double-gain for the firms.
THE EU-US SAFE HARBOR LAWS 5
References
Movius, L. B., & Krup, N. (2009). US and EU privacy policy: comparison of regulatory
approaches. International Journal of Communication, 3, 19. Retrieved 14 October 2019,
from https://ijoc.org/index.php/ijoc/article/viewFile/405/305.
Weiss, M. A., & Archick, K. (2016). US-EU data privacy: from safe harbor to privacy shield.
Retrieved 14 October 2019, from https://fas.org/sgp/crs/misc/R44257.pdf