Meanwhile, on the #GDPR front ...
After the invalidation of the second US-EU framework, known as #PrivacyShield was invalidated by the European court in the #SchremsII decision, the US and EU eventually signed an agreement in principle, and a good while later, the US President issued an Executive Order framing a new #DataPrivacyFramework this fall.
This week, the EU issued a draft #adequacy decision -- essentially, a recommendation that the new Framework be recognized as providing adequate protections for personal information of EU citizens if transmitted cross-border to the US. Many commentators have observed shortcomings of the Framework, and many businesses appear loath to plan for reliance on it. (Side note -- other jurisdictions around the world have data localization requirements without even the option to explore "adequacy" determinations. All in all, this approach leads to atomization of data; the pendulum has swung very far in one direction at the moment and I expect that over time things may settle down a bit.)
At every step along the way, Mr. Schrems has indicated his skepticism and his organization (#NOYB - "None of Your Business") is reviewing the draft and is likely to challenge any final adequacy finding in court. (The final adequacy decision is expected next Spring.)
An interesting development to close out this week is the announcement of a new #OECD agreement on safeguarding #privacy in #lawenforcement and #nationalsecurity data access. If this agreement comes close to the headline -- and means what it says, and says what it means, and member states (including the US) go home and fiddle with legislation (rather than Executive Orders -- some of which are not particularly long-lived), then maybe we have a fighting chance of working towards true "adequacy."
Links to all four of these gems below.
What do you think?
#data #business #dataprivacy #dataprivacylaw #digitalhealth #hcldr #HITsm #HarlowOnHC
Data Privacy Framework:
https://www.whitehouse.gov/briefing-room/statements-releases/2022/10/07/fact-sheet-president-biden-signs-executive-order-to-implement-the-european-union-u-s-data-privacy-framework/
Draft Adequacy Decision: https://ec.europa.eu/commission/presscorner/detail/en/ip_22_7631
NOYB statement on draft decision:
https://noyb.eu/en/statement-eu-comission-adequacy-decision-us
Statement on OECD agreement:
https://www.oecd.org/newsroom/landmark-agreement-adopted-on-safeguarding-privacy-in-law-enforcement-and-national-security-data-access.htm