Data Privacy Framework (DPF) is Here – Now What?

July 27, 2023

Data Privacy Framework Special Episode

The Data Privacy Framework (DPF) program is now in effect, replacing Privacy Shield as the mechanism to allow the safe, seamless transfer of personal data from the EU to the U.S in compliance with EU law. In this special edition episode of Privacy Abbreviated, host Dona Fraser is joined by IAPP’s Cobun Zweifel-Keegan to explain the current landscape of cross-border data transfer privacy, to break down the launch of the DPF program including what it means for U.S. businesses, and make some predictions about what the road ahead looks like.

 

_______________________________________________

Related Resources


Data Privacy Framework Timeline

Data Privacy Framework Services

Two Peas in a Privacy Pod: Global CBPR and the DPF

_______________________________________________

Show Notes

Dona Fraser, host and Senior Vice President of Privacy Initiatives at BBB National Program is joined by former colleague and friend Cobun Zweifel-Keegan who is now Managing Director of IAPP, the International Association of Privacy Professionals, to present a special edition of the Privacy Abbreviated podcast. On July 10th, the European Commission deemed the EU-U.S. Data Privacy Framework (DPF) adequate. This episode addresses what adequacy means and the assurances that DPF brings for U.S. businesses that can once again do business with the EU in compliance with GDPR.

3:12 - Cobun begins by defining the GDPR, the General Data Protection Regulation, a comprehensive data protection law across the European Union that has within it a restriction on transferring personal information from the EU to other countries. The purpose is to ensure the data isn't placed where it's not subject to the same privacy and data protection rules that govern the EU.

Cobun explains that there are several ways that businesses can legally export data from the EU. "The gold standard is an adequacy decision," Cobun explains. The process of coming to an adequacy decision begins with a review of the practices of the receiving country by the European Commission. They are the deciding body that allows any company operating within the receiving jurisdiction to legally receive data if found that practices meet the scope of the law.

Dona stresses to listeners the importance of using the DPF. She expresses her concerns regarding small to medium size companies that may not have in-house counsel to support and guide them through the vitality of compliance. Both hosts walk listeners through the consequences of non-compliance. Cobun points out that these companies "could be subject to fines and other penalties, but the fines usually grab people's attention." Cobun warns that the fines are tremendously significant for any size company, so those not taking the extra steps to ensure compliance are already behind.

15:01 - Upon tackling self-certification, Dona shifts the conversation toward Binding Corporate Rules (BCR). The two agree that BCRs are inappropriate for small to medium-sized companies that aren't engaging with highly sensitive data.

What Cobun does suggest for smaller businesses is signing standard contractual clause agreements with the entities they are conducting business with. These clauses have become stronger due to the surveillance adjustments made by the U.S., along with additional commitments from the intelligence community. By implementing these measures, businesses can ensure compliance while maintaining their operations.

22:00 - As a final discussion point, Dona highlights that there were separate frameworks for EU-U.S. and Swiss-U.S. agreements under Privacy Shield. However, with the UK's exit from the EU, and the establishment of the DPF, there are now distinct frameworks for the EU and U.S. Dona asks Cobun to provide additional clarification regarding this matter.

According to Cobun, there is a UK extension to the EU-U.S. DPF, and companies can self-certify for that extension. Even existing DPF companies must take the affirmative step of applying for the UK-U.S. extension. While it is a separate entity, businesses must already be part of the EU-U.S. DPF to be eligible for the UK extension.

Cobun also mentions that we are still awaiting approval from the UK for what they will refer to as a UK-U.S. data bridge, which is essentially equivalent to adequacy. He adds that once this data bridge is established, it will acknowledge the adequacy and validity of self-certifications to the UK extension while adhering to the same rules as the EU-U.S. DPF.

He further emphasizes, "It's good that this extension is going to be in place, but it will require that extra step for everybody to take to ensure that those commitments are extended."

Signing off, Dona encourages listeners to sign up for the Privacy Initiatives Newsletter and listen to previous episodes of Privacy Abbreviated to learn more about the current privacy landscape. To do so, you can visit BBB National Programs' Accountability Studios website or subscribe to Privacy Abbreviated on Apple Podcast, Google Podcast, Spotify, or where you access your favorite podcast.

Latest News

Press Release

BBB National Programs Appoints Amy Steacy as General Counsel, Promotes New Leaders in Children’s Food and Beverage Advertising and Global Privacy

McLean, VA – June 4, 2024 – BBB National Programs announced the appointment of Amy Steacy as General Counsel. Additional leadership promotions include Daniel Range as Vice President of the Children's Food and Beverage Advertising Initiative (CFBAI) and Dr. Divya Sridhar as Vice President, Global...

Read the Press Release
Press Release

Companies Agree to Expand School Coverage under the Children’s Food and Beverage Advertising Initiative Core Principles

McLean, VA – May 2, 2024 – Twenty-one of the nation’s leading food, beverage, and quick serve restaurant companies have agreed to strengthen their voluntary commitments for responsible food advertising to children under the Children’s Food and Beverage Advertising Initiative (CFBAI) Core Principles.

Read the Press Release
Press Release

BBB National Programs Issues Compliance Warning for Use of AI in Child-Directed Advertising and Data Collection

McLean, VA – May 1, 2024 – BBB National Programs’ Children’s Advertising Review Unit (CARU) today issued a new compliance warning on the application of CARU’s Advertising and Privacy Guidelines to the use of Artificial Intelligence (AI), putting advertisers, brands, endorsers, developers, toy manufacturers, and others on...

Read the Press Release
Press Release

BBB National Programs Applauds Today’s Launch of the Global CBPR Forum, Strengthening Commitments to International Data Privacy

McLean, VA – April 30, 2024 – BBB National Programs applauds the work of the Global CBPR Forum members, including the U.S. Department of Commerce, to launch the Global Cross Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) certification systems, a key development in...

Read the Press Release