A couple of years ago, there was a decision in the EU that dismantled the Privacy Shield program because of the lack of safeguards on the US government access to EU citizens’s data.
In July, the EU and the USA agreed to a whole new system called the EU-US Data Privacy Framework (DPF). Under this new agreement, there are privacy obligations that must apply to all US businesses that want to join the new framework.
The major requirements under the DPF are the following:
- Individuals must be informed about data processing.
- Free and accessible dispute resolution must be provided.
- Cooperation with the US Department of Commerce is a must.
- Limitations on purpose and data collected.
- Accountability for third-party data transfers.
- Enforcement Action transparency required.
If your business collects data from EU citizens, then your business probably needs to be compliant with the DPF.
Any questions? Contact me/Contácteme/Contactez-moi