The uncertainty is being fuelled by a double whammy of scepticism about how robust Privacy Shield is and fears that the alternative method, used by 80% of companies – the so-called standard contractual clauses (SCCs) – could be soon be rendered illegal.
According to a survey of 600 data professionals in the US and EU, only 40 US firms have so far adopted Privacy Shield, with just 34% intending to use the new data privacy framework, compared with 50% which used its Safe Harbour forerunner.
The situation is not being helped by EU data regulators sitting on the Article 29 Working Party (WP29). Although they approved the framework in late July, they have set off alarm bells by pledging to keep a close eye on how Privacy Shield develops.
Data privacy Shield assessment
At the time, they released a statement which said: “The first joint annual review will be a key moment for the robustness and efficiency of the Privacy Shield mechanism to be further assessed.”
US think tank the Brookings Institution has estimated that “digitally delivered services” between the EU and the US – including customer data storage – were worth nearly $250bn (£188bn) in 2015.
IAPP president and chief executive Trevor Hughes commented: “The legal uncertainty of standard contractual clauses and the scepticism about Privacy Shield may be a hangover effect from the Max Schrems case that invalidated Safe Harbour in the European courts. Clearly, organisations face an extremely complex regulatory landscape as they look to build their businesses for the digital future.
“It will be vital for them to employ privacy professionals at the highest levels of management to help navigate that landscape and capitalise on opportunity.”

The study suggests there are at least 100,000 copies of each individual’s personal data being held on physical devices and cloud storage platforms.
The firm said the new recruits will be join its UK Risk Assurance team within the next four years and cover all industry sectors across the country. As well as cybersecurity and privacy threats, the beefed up team will cover data management, business systems and IT risks.
Charities that ignore the 
In what will also make interesting reading for those following the row over the new transatlantic
Robert Arandjelovic (pictured), director of product marketing EMEA at Blue Coat Systems, said: “The EU regulatory landscape is set to radically change with the introduction of the GDPR legislation and this research highlights the level of distrust in countries outside the EU.
Although the data protection reforms have already been passed, the date has only just been released following the GDPR’s publication in the EU Official Journal.
Working alongside the