Privacy Shield Research: were Privacy Shield participants compliant with GDPR?

A shield with the eu and u s flags on it.

When the European Court of Justice handed down its judgement in the Schrems II case, it came as little surprise to anyone familiar with the first Schrems case, where the same court’s decision struck down Safe Harbour (a previous mechanism for the cross-border transfer of EU personal data to the US).

While the companies which relied on Privacy Shield move to alternate methods, and the EU and US continue to discuss how to replace Privacy Shield with a process which (hopefully) won’t be invalidated by the EU courts, one question occurred to us: To what extent did Privacy Shield participation by a US company give an EU company reassurance of that participant’s GDPR compliance?

The immediate logical inference seemed to be that a company which has been certified by Privacy Shield as safe to be a recipient of EU personal data, would be processing EU personal data in a manner consistent with GDPR. If they weren’t processing the data in a manner compliant with GDPR, how could the transfer of that EU personal data to them be compliant? We should be clear that the link between GDPR compliance and Privacy Shield certification has never been expressly stated by Privacy Shield, but it appears – to us – unavoidable.

To answer the question, we undertook the research which resulted in the report which is available here.

Of course, it isn’t possible to confirm a company’s GDPR compliance externally, because most of the processing activities take place behind the scenes. Nor would it be fair to expect the administrators of Privacy Shield to undertake an in-depth investigation of every participants’ data processing activities.

However, some aspects of GDPR compliance are apparent from the outside, and we identified the following as being measurable from an external desktop review:

  • The existence of a privacy notice (in line with GDPR Article 13),
  • The manner in which consent for the use of cookies is sought (Article 6), and
  • If the company had no apparent EU/EEA establishment (so they are brought under the obligations of GDPR as a result of Article 3(2) and not 3(1)) – whether they have appointed an EU/EEA Representative (Article 27)

When we checked a sample of Privacy Shield participants’ compliance with these elements, the results varied – we found that almost all of them did have a privacy notice easily available on their website, but the results for cookie consents (around 21% were compliant) and appointment of an EU Representative (of the companies which appeared to need this appointment, fewer than 8% had done so) were much less reassuring.

The detailed results of the research, along with our conclusions and recommendations, are available here.

The dpr logo on a white background.
Datarep logo with an orange and blue background.

Thank you for visiting DPR Group’s website!

We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

If you have any questions about the change, please don’t hesitate to contact us here!

We see you’re leaving our site

Can we help you further?

 If you have a question or you’d like more information, please leave your email address and someone will contact you: