Export Compliance Daily is a Warren News publication.

Microsoft Backs Privacy Shield, but European Consumer Alliance Gives Thumbs Down

Privacy Shield is a "strong foundation" to build additional domestic legislation and modernize mutual legal assistance treaties, wrote Microsoft EU Government Affairs Vice President John Frank in a Monday blog post. The EU and U.S. are "better off" with the…

Sign up for a free preview to unlock the rest of this article

Export Compliance Daily combines U.S. export control news, foreign border import regulation and policy developments into a single daily information service that reliably informs its trade professional readers about important current issues affecting their operations.

proposed trans-Atlantic data transfer agreement to replace the old safe harbor framework (see 1602020040), he wrote, acknowledging its effectiveness rests on companies' "responsible steps" to comply. Microsoft, he said, will sign up for the voluntary framework and "put in place commitments to advance privacy as this instrument is implemented." When an eligible company publicly commits to comply with Privacy Shield requirements, its commitment is enforceable under U.S. law. However, an alliance of 41 independent national consumer groups from 31 European countries known as BEUC said the proposed framework doesn't adequately protect consumers' privacy and data and recommended it be jettisoned, in a letter to Isabelle Falque-Pierrotin, who chairs the European Commission's Article 29 Data Protection Working Party. That committee, comprised of the national data protection authorities from the 28 member states, is expected to offer a nonbinding opinion Wednesday. The EC is expected to adopt Privacy Shield this summer, but many have predicted the agreement would be immediately challenged in court like safe harbor, which the European Court of Justice invalidated in October (see 1510060001). Since the EU and U.S. privacy regimes "are oceans apart" in approach and substance, BEUC said it's "hard to grasp" that the U.S. regime can be considered "essentially equivalent" to the European level, which will be made stronger with the proposed general data protection regulation (see 1512160001). The European Parliament is expected to approve GDPR this week, though the new regulation won't be implemented for another two years.