The Blog Lawyer

  • About
  • Contact
  • Podcast
  • Legal

GDPR – Oh Yes, There’s More……….

May 11, 2018 by Mark 11 Comments

My last blog post provided an overview of the new General Data Protection Regulation (“GDPR”) rules for the protection of personal data when capturing, storing, or processing personal data originating from individuals in the European Union (“EU”).

If you missed that post, you can read it by clicking here.

In addition to the GDPR, it’s also important for U.S. businesses to be aware of the EU Privacy Shield requirements. The GDPR is a comprehensive law designed to control the transfer and use of personally identifiable information in general. The Privacy Shield is concerned with only one specific aspect of data protection; namely the transfer of personal data from the EU to the U.S.

The privacy laws in Europe are much more protective of personal data than the laws of the U.S. and the Privacy Shield is an agreement that binds participants to specific rules and procedures that must be followed in order to lawfully transfer personal data from the EU to the US.

Before you dive into the details below, remember that many of your service providers are likely well aware of the Privacy Shield requirements and can help you successfully reach compliance so be sure and talk to your account representative to get details on what they are doing.

What are the requirements for Privacy Shield?

The Privacy Shield framework has seven points, all of which are shown below. This is going to be a lot to take in, but it’s not as daunting as it seems if you just take it one step at a time.

1. Notice

You are responsible to notify individuals about:

  • Your participation in the Privacy Shield framework;
  • The type of personal data being collected;
  • How you will use the personal data collected;
  • Third parties that you may share their personal data with;
  • Their rights to access their personal data;
  • Ways they can limit the use and disclosure of their personal data; and
  • Ways they can resolve problems with the collection, use, or processing of their personal data.

2. Choice

You must provide “clear, conspicuous, and readily available mechanisms” for individual to opt out of the disclosure of their personal data to third parties, or use of the data for a purpose other than what it was collected for.

3. Accountability

You are required to ensure that all third-party contracts state that personal data “may only be processed for limited and specified purposes consistent with” the consent of the individual.  Should anything happen to the personal data you collected, you are on the hook, even if the problem is the fault of your service providers.

4. Security

You are expected to “take reasonable and appropriate measures” to secure personal data against “loss, misuse and unauthorized access, disclosure, alteration and destruction.” If you follow industry best practices, you should be fine.

5. Integrity

The Privacy Shield requires that you must limit collection of personal data to only relevant information and ensure that personal data on file is “reliable for its intended use, accurate, complete and current.”

6. Access

The Privacy Shield requires that individuals have the ability to access their personal data, along with the ability to correct it, amend it or even delete it.

7. Enforcement

Under the Privacy Shield, you must provide detailed procedures for recourse and dispute resolution. These procedures need to be implemented thoroughly and you will need to have an verifiable process for handling complaints.

You can read more about the Privacy Shield framework at the Commerce Department Website.

Remember – Be Smart. Be Legal.

 Disclaimer – Yes, I’m a lawyer, but I’m not your lawyer. All information in this post is provided for educational purposes only and should not be considered legal advice for any specific person or any specific situation.

Filed Under: Business, Compliance, Website

Comments

  1. Monica Ashton says

    May 16, 2018 at 10:37 pm

    I am currently getting my business law degree, and I have been learning so much! I wasn’t aware of the Privacy Shield requirements. It’s important to make sure individuals have access to their personal data, and I didn’t know they were allowed to change it as well. Thank you for these helpful tips!

    Reply
    • Mark says

      May 16, 2018 at 11:24 pm

      Thank you for reading the blog. I hope that you can learn more from the other posts as well.

      Reply
  2. Michael says

    August 31, 2018 at 10:27 pm

    Thank you for the info. Have talked with some fellow attorneys about this but really did not know what was going on till I found this info. Thank you

    Reply
  3. Scott Cummings says

    October 18, 2018 at 4:36 am

    Thanks for this wonderful post. I found it very informative and knowledgeable and also I am waiting for your next post.

    Reply
  4. Brain Keller says

    January 28, 2019 at 6:31 am

    thanks for the valuable information through the post.

    Reply
  5. ahmad shoman says

    March 5, 2019 at 6:51 pm

    good post l hope to see more !

    Reply
  6. Colin Maher says

    March 18, 2019 at 2:48 pm

    Thanks for sharing the great article.

    Reply
  7. Susanna says

    March 20, 2019 at 4:52 am

    Very nice….I really like your post

    Reply
  8. Jarvis says

    March 29, 2019 at 8:32 am

    Thanks for sharing this great information.

    Reply
  9. Lee Franck says

    April 6, 2019 at 5:58 am

    The blog is really helpful for someone who wants to understand about GDPR. I must say it is wonderful

    Reply
  10. shanmugam associate says

    May 21, 2021 at 6:43 am

    nice thanks for sharing information

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe For Free Email Updates

Stay Connected

  • Email
  • Facebook
  • Instagram
  • LinkedIn
  • Twitter

© Copyright 2014-2025 The Blog Lawyer · All Rights Reserved

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT