Home » News » What are the consequences for European companies?

What are the consequences for European companies?

An adequacy decision is a decision adopted by the European Commission under Article 45 of the GDPR that certifies that a country outside the European Union ensures an adequate level of protection of personal data. Such a decision takes into account the country’s domestic legislation, its supervisory authorities and its international commitments.

For the United States, the adequacy decision involved an in-depth analysis of the. EU-US Data Privacy Framework (“DPF”) by the European Commission. This DPF is based, like the ! Privacy Shield, on a certification system by which American ! organizations commit to respecting a set of principles relating to the protection of privacy.

Such a Decision Allows

European companies to transfer personal data to companies germany phone number library located in the United States without requiring the implementation of additional guarantees.

This new framework will notably allow European companies to use solutions ! published by certified American law companies (such as Google Analytics, the use of which was called into !  question by the CNIL in February 2022 due to Google’s submission to American intelligence laws and insufficiently regulated transfers to the United States).

What are the consequences for American companies?

Companies established in the United States will thus be able to receive and process ! personal data of Europeans provided that they are certified. To obtain certification, they will have to provide certain information !  to the American Department of Commerce (“DoC”), such as the description of their processing purposes and the data processed as well as the independent appeal mechanism.

US organizations certified under Privacy Shield must ! update their speaking of blogs privacy policies by October 10, 2023, but do not need to self-certify again to participate in the. DPF and can receive personal data from the EU immediately.

Additionally, certified organizations must be subject to the investigatory !  and bfb directory enforcement powers of the Federal Trade Commission (“FTC”) or the U.S. Department of Transportation (“DoT”) and will be required to renew their certification annually to maintain their adherence to established principles.

Scroll to Top