[email protected]
  • Securities Law
  • Incorporations
  • Managed Legal
  • Capital Markets
Generis Global Legal Services
  • Services
    • Structured Finance
    • M&A
    • Electronic Discovery
    • Document Review
    • Legal Research
    • Funding
    • Incorporation
    • Consulting
    • Managed Legal Services & LPO
    • Agreements
  • Careers
  • About Us
  • Contact Us
  • Partner Program
  • Knowledge Base
  • Tools
    • Business Cost Calculator
    • Patent Cost Calculator
    • Trademark Cost Calculator
    • Settlement Letter Generator
    • Employee Contract Maker
    • Divorce Petition Drafter
    • Lease Agreement Generator
    • Discovery Request Builder
    • Will Creator
    • NDA Maker
    • Dissolution Fee Calculator
    • Bylaws Drafter
    • UCC Filing Fee Estimator
    • Franchise Fee Calculator
    • IP Assignment Tool
    • Merger Fee Estimator
    • Stock Grant Tool
    • Business License Lister
Select Page

Ensure GDPR Compliance for US Businesses Following the Expiration of the EU-US Privacy Shield

Apr 30, 2022

The EU-US Privacy Shield is most likely the most regularly utilised method for US enterprises to legitimately receive, handle, retain, and transmit personal information of EEA residents.

GDPR Compliance for US Businesses

On July 16, 2020, the EU Court of Justice (CJEU) declared that the EU-US Privacy Shield safeguards were unlawful because US law cannot effectively protect personal data of persons in the European Economic Area (EEA). Prior to this ruling, the EU-US Privacy Shield was most likely the most regularly utilised method for US enterprises to legitimately acquire, process, retain, and transmit personal information from EEA residents. The judgement was partly based on the conclusion that the US government does not restrict foreigner monitoring to what is absolutely required, and that both federal and state legislation in the US lack suitable remedies for people in the EEA.

Fortunately, there are still solutions recognised by the EU’s General Data Protection Regulation (GDPR) for enterprises in the US that handle personal data of EEA residents. Standard contractual clauses (SCCs) and binding company standards are two of these choices (BCRs). SSCs are provisions in data transfer or processing agreements that attempt to safeguard personal data in line with GDPR. BCRs are company-adopted policies relating to GDPR-compliant data transfer and processing procedures.

It is worth noting that the EU Commission is in the process of upgrading the approved SCCs. A previously ongoing procedure that has been halted awaiting the outcome of the CJEU judgement. Now that the work has been resurrected, it is critical that enterprises intending to handle personal data in the US monitor the issuing of any new SSCs and perhaps integrate the capacity to replace or alter such agreements when the new SSCs are published.

The US has been working to comply with the EU-US Privacy Shield framework, with officials from both the US and EU stating that “the US Department of Commerce and the European Commission have initiated discussions to evaluate the potential for an enhanced EU-US Privacy Shield framework to comply with the Court of Justice of the European Union’s July 16 judgement in the Schrems II case.” “The Department of Commerce will continue to manage the Privacy Shield programme, including processing submissions for self-certification and re-certification to the Privacy Shield Frameworks and maintaining the Privacy Shield List,” according to the Interim.

Despite the US Department of Commerce’s commitment to the programme, the European Data Protection Board (EDPB) has said that there is no grace period for firms who only operate under the EU-US Privacy Shield system. As a result, firms transferring and/or processing personal data of EEA citizens must immediately establish further protections to verify that they are in compliance with the GDPR standards.

Companies that are presently certified under the EU-US Privacy Shield system should consider continuing compliance in order to prevent any difficulties with the declarations made to those authorities, based on the statements made by the relevant US agencies. “[W]e will continue to hold firms responsible for their privacy obligations, including pledges made under the Privacy Shield,” stressed the FTC’s Chairman.

Even if a firm is not certified under the EU-US Privacy Shield, if it is transmitting or processing personal data of EEA citizens, the company should implement suitable safeguards, such as SSCs and/or BCRs, to be in compliance with GDPR. Companies may depend on particular exclusions known as “derogations for special circumstances.” The European Data Protection Board’s “Guidelines 2/2018 on derogations from Article 49 under Regulation 2016/679” go into great length on this. However, in order to avoid responsibility under GDPR, it is essential to verify that an applicable derogation exists, or that the relevant SCCs or BCRs are in place.

Table of Contents

      • Conclusion
  • Smart Legal Starts Here
  • Smart Legal Starts Here
  • Related Posts
Conclusion

If your organisation receives, transports, or processes personal data from the EEA, you must guarantee GDPR compliance, especially if you previously relied on the EU-US Privacy Shield to assure compliance. Following the July 16, 2020 judgement that invalidated the EU-US Privacy Shield provisions, it has been claimed that there is no safe harbour or grace time to come into compliance. As a result, confirming that one of the derogations applies to your company’s position, or adopting relevant SCCs or BCRs to enable GDPR compliance, is a need that should be handled as soon as possible.

Email This Share on X Share on LinkedIn
Citations
Embed This Article

Copy and paste this <iframe> into your site. It renders a lightweight card.

Preview loads from ?cta_embed=1 on this post.

NEW

Smart Legal Starts Here

✓Free walkthroughs for your legal situations
✓Track your legal request in your free dashboard
✓Draft and review your docs free
✓Only pay when you want action
+ Post a Legal Service Request

Smart Legal Starts Here

✓Free walkthroughs for your legal situations
✓Track your legal request in your free dashboard
✓Draft and review your docs free
✓Only pay when you want action
+ Post a Legal Service Request

Related Posts

  • The Implications of Patent Expiration for Industries in the UAE
  • Compliance with Data Privacy Regulations Is Critical In accordance with the GDPR
  • The Enduring Shield: How Trademarks Preserve a Brand’s Legacy Amidst Market Changes
  • The Impact of GDPR and Other Privacy Laws on Trademark Enforcement and Monitoring
  • AI and GDPR: Compliance Strategies for European Businesses
  • Five Examples of How GDPR Affects Small Businesses in the United States
  • A Document Review Services for Compliance with GDPR and Data Protection Laws
  • The Impact of GDPR on Contract Negotiation and Compliance
  • Ensuring GDPR Compliance in European Private Placements
  • How to Ensure Compliance with FINRA Rules in U.S. Private Placements
  • A Step-by-Step Guide to Starting a Business in Andorra
  • Navigating Andorra’s Tax Haven Status: Optimizing Business and Wealth
  • The Importance of Intellectual Property Rights in Andorra
  • A Guide to Andorra’s Corporate Law: Key Considerations for Foreign Investors
  • Key Considerations for Businesses Operating in Andorra: Employment Regulations
  • A Guide to Real Estate Acquisition in Andorra: Legal Procedures and Pitfalls to Avoid
  • A Comprehensive Guide to Setting up a Financial Services Company in Andorra
  • The Impact of Andorra’s EU Agreements on Local Businesses
  • Strengthening Anti-Money Laundering Measures in Andorra: Combating Financial Crime and Terrorism Financing
  • Andorra’s Commitment to Compliance and Anti-Money Laundering Measures
  • A Comprehensive Guide to Preparing for Your First Consultation on Civil or Criminal Judgment Appeals in Wyoming
  • Preparing for Your First Consultation on Appeals in Wisconsin
  • Preparation Guide for Your First Legal Consultation on Appeals in West Virginia
  • Preparing for Your Appeal Consultation in Washington: A Comprehensive Guide
  • First Consultation Preparation Guide for Appeal from a Civil or Criminal Judgment in Virginia
  • Refund Policy
  • Terms of Use
  • Privacy Policy
  • AI Agent Policy
  • Facebook
  • Twitter
  • Instagram
  • RSS
© 2025 Generis Global Legal Services. All rights reserved.

Quick Apply

Application submitted

Thanks for applying! Our team will review your application and get back to you within 15 days. If you don’t hear from the HR team within that time, your application may not have been successful.