The European Commission has decided that it is safe for personal data to be transferred from the European Union to American big tech companies such as Facebook and Google, despite many advocates protesting against this decision due to concerns over U.S. government surveillance.
The Commission announced that it has ‘adopted a decision on the adequacy of the EU-U.S. data privacy framework‘, concluding that ‘the United States provides an adequate level of protection—comparable to that in the European Union, for personal data transferred from the EU to U.S. companies under the new framework. Based on the new adequacy decision, personal data can flow safely from the EU to U.S. companies participating in the Framework, without the need for additional data protection measures.’
In May of this year, Facebook’s owner, Meta, was fined €1.2 billion for violating the General Data Protection Regulation (GDPR) by transferring personal data to the United States and was ordered to stop storing data of users from the European Union in the U.S. within six months. At that time, Meta threatened to withdraw its business from the EU and that users from the Union would not have access to Meta’s applications such as Facebook, but that, of course, did not happen.
Legal Challenges
The data transfer agreement is expected to ‘face a legal challenge from European privacy advocates, who have long argued that the U.S. needs to make significant changes to its surveillance laws.’ Data transfers from Europe to the U.S. were called into question when the EU court ruled in 2020 that the previous agreement, which allowed transatlantic data flows, was illegal because the U.S. did not provide EU individuals with an effective way to challenge surveillance over their data.
In a statement, the EC noted that the new framework includes ‘binding safeguards to address all concerns raised by the European Court of Justice, including limiting U.S. intelligence agencies’ access to EU data to what is necessary and proportionate, and establishing a Data Protection Review Court (DPRC), which EU individuals will have access to.’ The new court will ‘be able to order the deletion’ of data found to have been collected in violation of the new rules.
