Data Transfer to the US – a Change at Last?
Tuesday 10th July 2023 saw a significant change in European data protection law. Has the US finally ‘come in from the cold’? Or is there yet another legal challenge from the Austrian data rights campaigner, Max Schrems? The Data Privacy Framework (DPF) has arrived.
Will it survive until Christmas? Does it address the data security requirements the EU demands, or is this simply politics in play?

The European Commission has adopted its adequacy decision for the EU-U.S. Data Privacy Framework. It concluded that U.S. protection of personal data transferred between the countries is comparable to that offered in the EU. It is known as the Data Privacy Framework and will sit alongside the GDPR.
However, even as it was announced Monday, the new framework, which comes into force on 11th July 2023, may face a legal challenge. This will come from the privacy advocacy organisation NOYB. Its honorary chairman is Max Schrems.
A Welcome Decision
A press release published by the European Commission said the “EU-U.S. Data Privacy Framework introduces new binding safeguards to address all the concerns raised by the European Court of Justice. They include limiting access to EU data by U.S. intelligence services to what is necessary and proportionate. And establishing a Data Protection Review Court.”
Reynders said the framework “clearly” spells out necessity and proportionality requirements and “enforceable safeguards” with a “user friendly” redress mechanism. The new Data Protection Review Court will have the power to order deletion of data if it is found to be collected in violation of the new safeguards, he noted. And Europeans will be able to lodge complaints free of charge before their local data protection authority. This is without having to demonstrate that their data has been accessed by U.S. intelligence agencies. He called this improvement “important and crucial to ensure effective access to redress, which is sacred.”
European Commission President Ursula von der Leyen said the new Data Privacy Framework “will ensure safe data flows for Europeans and bring legal certainty to companies on both sides of the Atlantic.” The U.S., she said, “has implemented unprecedented commitments to establish the new framework.”
US Commitments
Under the U.S. commitments, EU member states, along with Iceland, Liechtenstein and Norway are “qualifying states,” and citizens will be able to file for redress through the Data Protection Review Court. They will continue to obtain enhanced U.S. privacy protections. There was no mention of the United Kingdom. This was as the US president took tea with the UK prime minister and later the King. Was this ‘drop in’ a distraction whilst the news was released?
The European Data Protection Board will be developing “an information note for stakeholders on the implications of the Data Privacy Framework” in the coming weeks, said Chair Anu Talus.
The EDPB “looks forward to the European Commission participation in its next plenary meeting. We hope it will shed light on the final text of the adequacy decision and on the changes following the EDPB opinion,” she said. So do we!
‘Schrems III’ is coming and soon.
The EU-U.S. Data Privacy Framework replaces the EU-U.S. Privacy Shield. This was invalidated by the European Court of Justice in July 2020. Since then, Reynders said, it’s been “a matter of top priority” for the commission to restore stable and continuous protection of European data crossing the Atlantic.
Reynders said the framework is “substantially different than the EU-U.S. Privacy Shield.” However, privacy advocacy organisation NOYB doesn’t agree. NOYB legally challenged the Privacy Shield and its predecessor the Safe Harbour Framework, stating that the new framework is a copy.
NOYB indicated it will appeal the framework. It noted that the “third attempt of the European Commission to get a stable agreement on EU-U.S. data transfers will likely be back at the Court of Justice (of the European Union) in a matter of months.” The organisation said the U.S. did not address “fundamental” surveillance issues.
“They [NOYB] claim that the definition of insanity is doing the same thing over and over again and expecting a different result. Just like ‘Privacy Shield’ the latest deal is not based on material changes. It is based on political interests. Once again, the current Commission seems to think that the mess will be the next Commission’s problem.” NOYB Honorary Chair Max Schrems stated, “We have had ‘Harbours,’ ‘Umbrellas,’ ‘Shields’ and ‘Frameworks’.
However, there has been no substantial change in US surveillance law. Simply announcing that something is ‘new,’ ‘robust’ or ‘effective’ is not likely to convince the European Court of Justice. We would need changes in U.S. surveillance law to make this work and we simply don’t have it.”
The Response
Reynders responded to NOYB’s announcement during Monday’s press conference. He said that the new system should be tested before announcing a legal challenge. No method of testing was offered, however. How will such a test be undertaken?
“I’m sure that we have very robust arguments to show that we now have a very different system than what we have had with Safe Harbour and also with the Privacy Shield,” he said. “We are very confident to not only implement such an agreement, but to defend such an agreement in all the different procedures that we will have to face. Again, it’s just a proposal. But why not test the new system before going too far in criticism of such a system.”
Joel said how well the framework will fare before the CJEU is “the big question.”
In the near term, the CJEU is likely to rule on whether the EU-U.S. Data Privacy Framework provides essentially equivalent safeguards to those required by EU law. In the meantime, the adequacy decision should enable data flows to continue. This includes current mechanisms such as (standard contractual clauses) and (binding corporate rules). The ICO in the UK has already opted for International Data Transfer Agreements (IDTA’s) as these provide better safeguards than SCC’s.
What if?
But what happens if U.S. protections within the new framework are not enough to stand up to legal challenges?
Lawyers like to say, it depends if the Court decides that is fundamentally inconsistent with the Supreme Court’s rulings on standing. This would require an amendment to the Constitution, and the EU will be faced with a potentially insoluble crisis. It seems that amending EU law, for example, The General Data Protection Regulation (GDPR) is not likely or politically possible. Therefore, trying to resolve these kinds of data flow challenges is a serious problem. Does this framework amend the GDPR? No. Or does it?
Fortis DPC
Fortis DPC help clients globally with their Data Protection challenges and has helped many US based businesses come to terms with and understand the EU and UK GDPR. Many such businesses believe they can ignore the GDPR, many to their peril! Those who see the potential of the European market call us and we help them succeed in Europe. If this sounds like you, get in touch.
Leave a Reply