Privacy Shield Compliance Tip #1: Navigating Your Annual Re-Certification

May 20, 2020 by BBB National Programs

In our Privacy Shield Compliance Tips series, the BBB EU Privacy Shield team shares insights into the ins and outs of complying with the Privacy Shield Frameworks—adequate mechanisms for transferring personal data from the European Union or Switzerland to the United States. Each tip is focused on an issue that we often encounter in our work with hundreds of companies that have self-certified under Privacy Shield.

One perennially complex issue for businesses that participate in Privacy Shield is the annual re-certification process. There are two separate steps that participating Privacy Shield businesses must take every year to maintain an active certification in the Privacy Shield Frameworks:

  1. Re-certify your Privacy Shield self-certification with the U.S. Department of Commerce (DOC).
  2. Renew your participation agreement with your Independent Recourse Mechanism (BBB EU Privacy Shield), ensuring that you continue to receive dispute resolution services—a core requirement of Privacy Shield. 

It is important to note that re-certification and IRM renewal are two separate and distinct steps. Depending on your history in Privacy Shield, the due date of your re-certification with DOC may differ from the due date of your renewal with BBB EUPS.

  • What is re-certification? Re-certification is the process by which you annually re-affirm to DOC your Privacy Shield self-certification. Your annual Privacy Shield re-certification is essentially a process of re-approval, much the same as the initial process of becoming approved under Privacy Shield. The required steps are almost identical to those you went through to secure initial approval of your Privacy Shield self-certification, including verifying that DOC has copies of your most up-to-date disclosures and policies. After submission, your account receives a thorough review by a Privacy Shield team member. Securing approval for your annual re-certification may take time, so we recommend that you file within 5 days of your due date.

    If you allow your account to lapse, this could trigger a series of processes that make regaining compliance extremely difficult! The Privacy Shield site has full instructions for completing your re-certification.
  • What is IRM renewal? Renewal is the process of re-registering with BBB EU Privacy Shield, renewing your contract so that we may continue to serve as your IRM. When you renew with BBB EUPS, you pay your annual dues and our staff reviews your Privacy Shield disclosures to ensure ongoing compliance with our program.

In addition to our compliance tracking services provided throughout the year, BBB EUPS notifies each of our participating businesses when its DOC re-certification date is coming up, as well as when it is time to renew enrollment in our program. If you are a BBB EU Privacy Shield participant, please look out for these messages and follow the instructions in themIf you are interested in our services, click here to learn more about signing up for Privacy Shield

Suggested Articles


Defining The 'S' In ESG And Navigating Disclosures

For businesses interested in making robust ESG disclosures, not only can the sheer number of frameworks and standards make ESG performance reporting seem overwhelming, the frameworks themselves can be a bit fuzzy on how they define and measure the "S" of ESG.
Read more

BBB AUTO LINE Marks a Milestone: 40 Years of Lemon Law Dispute Resolution

As the largest and longest-running vehicle dispute resolution program in the United States, BBB AUTO LINE’s 40 years of experience will drive its future course. Together, automakers and BBB AUTO LINE will keep paving the way to make neutral, mutually trusted, out-of-court resolution solutions accessible to consumers.
Read more

The Next Phase of Privacy Shield

A new Trans-Atlantic Data Privacy Framework (TADPF) is on its way, lifting a cloud of uncertainty that has been hanging over Privacy Shield. TADPF serves as a foundation for a US adequacy decision reinstituting trans-Atlantic data flow. Here our Global Privacy Division highlights several key details regarding the substance of TADPF and the EU’s adequacy decision process.
Read more

Protecting Consumer Health Data Privacy Beyond HIPAA

Many are taking advantage of apps and other technologies to keep better track of our health in some shape or form, but it is not always clear how the personal information we input is collected, safeguarded, and shared online.
Read more