
According to a survey of 600 data professionals in the US and EU, only 40 US firms have so far adopted Privacy Shield, with just 34% intending to use the new data privacy framework, compared with 50% which used its Safe Harbour forerunner.
The situation is not being helped by EU data regulators sitting on the Article 29 Working Party (WP29). Although they approved the framework in late July, they have set off alarm bells by pledging to keep a close eye on how Privacy Shield develops.
Data privacy Shield assessment
At the time, they released a statement which said: “The first joint annual review will be a key moment for the robustness and efficiency of the Privacy Shield mechanism to be further assessed.”
US think tank the Brookings Institution has estimated that “digitally delivered services” between the EU and the US – including customer data storage – were worth nearly $250bn (£188bn) in 2015.
IAPP president and chief executive Trevor Hughes commented: “The legal uncertainty of standard contractual clauses and the scepticism about Privacy Shield may be a hangover effect from the Max Schrems case that invalidated Safe Harbour in the European courts. Clearly, organisations face an extremely complex regulatory landscape as they look to build their businesses for the digital future.
“It will be vital for them to employ privacy professionals at the highest levels of management to help navigate that landscape and capitalise on opportunity.”
