Privacy Shield Compliance Tip #1: Navigating Your Annual Re-Certification

May 20, 2020 by BBB National Programs

In our Privacy Shield Compliance Tips series, the BBB EU Privacy Shield team shares insights into the ins and outs of complying with the Privacy Shield Frameworks—adequate mechanisms for transferring personal data from the European Union or Switzerland to the United States. Each tip is focused on an issue that we often encounter in our work with hundreds of companies that have self-certified under Privacy Shield.

One perennially complex issue for businesses that participate in Privacy Shield is the annual re-certification process. There are two separate steps that participating Privacy Shield businesses must take every year to maintain an active certification in the Privacy Shield Frameworks:

  1. Re-certify your Privacy Shield self-certification with the U.S. Department of Commerce (DOC).
  2. Renew your participation agreement with your Independent Recourse Mechanism (BBB EU Privacy Shield), ensuring that you continue to receive dispute resolution services—a core requirement of Privacy Shield. 

It is important to note that re-certification and IRM renewal are two separate and distinct steps. Depending on your history in Privacy Shield, the due date of your re-certification with DOC may differ from the due date of your renewal with BBB EUPS.

  • What is re-certification? Re-certification is the process by which you annually re-affirm to DOC your Privacy Shield self-certification. Your annual Privacy Shield re-certification is essentially a process of re-approval, much the same as the initial process of becoming approved under Privacy Shield. The required steps are almost identical to those you went through to secure initial approval of your Privacy Shield self-certification, including verifying that DOC has copies of your most up-to-date disclosures and policies. After submission, your account receives a thorough review by a Privacy Shield team member. Securing approval for your annual re-certification may take time, so we recommend that you file within 5 days of your due date.

    If you allow your account to lapse, this could trigger a series of processes that make regaining compliance extremely difficult! The Privacy Shield site has full instructions for completing your re-certification.
  • What is IRM renewal? Renewal is the process of re-registering with BBB EU Privacy Shield, renewing your contract so that we may continue to serve as your IRM. When you renew with BBB EUPS, you pay your annual dues and our staff reviews your Privacy Shield disclosures to ensure ongoing compliance with our program.

In addition to our compliance tracking services provided throughout the year, BBB EUPS notifies each of our participating businesses when its DOC re-certification date is coming up, as well as when it is time to renew enrollment in our program. If you are a BBB EU Privacy Shield participant, please look out for these messages and follow the instructions in themIf you are interested in our services, click here to learn more about signing up for Privacy Shield

Suggested Articles


Case Study: Getting to Compliance with CARU and COPPA

In a recent case, CARU worked with TickTalk to help them achieve compliance with CARU’s Privacy Guidelines and the Children’s Online Privacy Protection Act (COPPA). CARU sat down with TickTalk once the case had closed to discuss their experience as well as some of the privacy challenges many companies face in the children’s space.
Read more

What to Know About the Georgia Lemon Law

BBB AUTO LINE provides an overview of each state’s lemon laws. In our ongoing blog series, we offer further insights on the laws for select states, and how BBB AUTO LINE can support consumers with lemon law disputes. Florida, California, and Texas have been covered. This post reviews the nuances of the lemon law in the Peachtree State – Georgia.
Read more

The TAPP Roadmap: Helping U.S. Companies Responsibly Collect and Manage Teenager Data

Even as data privacy and safety practices that work for adult consumers provide a firm foundation for teens, they simultaneously run the risk of being insufficient to respond to the unique needs of teens. The TeenAge Privacy Program (TAPP) Roadmap was designed to assist any business that wishes to engage proactively with teen consumers, providing an operational framework to map the broad spectrum of potential harms impacting teens onto a concrete set of operational considerations.
Read more

Pursuing Best Practices For Representation In Advertising

As advertising volume increases, so too do people’s expectations of representation in advertising. Unfortunately, advertising collectively is still falling short, and consumer perceptions reflect that. Why answer this call from consumers? And what is being done about it?
Read more