Irony Alert: US Could Block Personal Data Transfers To Ireland, European Home Of Digital Giants, Because GDPR Is Not Being Enforced Properly

from the biter-bit dept

Last year, the EU’s top court threw out the Privacy Shield framework for transferring personal data between the EU and US. The court decided that the NSA’s surveillance practices meant that the personal data of EU citizens was not protected to the degree required by the GDPR when it was sent to the US. This was the second time that such an agreement had been struck down: before, there was Safe Harbor, which failed for similar reasons. The absence of a simple procedure for sending EU personal data to the US is bad news for companies that need to do this on a regular basis. No wonder, then, that the US and EU are trying to come up with a new legal framework to allow it, as this CNBC story notes:

Officials from the EU and U.S. are “intensifying negotiations” on a new pact for transatlantic data transfers, trying to solve the messy issue of personal information that is transferred between the two regions.

Even if they manage to come up with one, there’s no guarantee that it won’t be shot down yet again by the courts, unless the underlying issues of NSA surveillance are addressed in some way — no easy task. Meanwhile, there’s been a fascinating development on the US side, reported here by The Irish Times:

The US Senate is to debate a proposal to limit foreign countries’ access to US citizens’ personal data and to introduce a licence requirement for foreign companies that trade in this information.

The draft “Protecting Americans’ Data From Foreign Surveillance Act”, presented on Thursday by Democratic Senator Ron Wyden of Oregon, is aimed primarily at curbing the sale and theft of data by “shady data brokers” to “hostile” foreign governments such as China.

The law may be aimed primarily at China, but its reach is wide, and it could hit an unlikely target. As the Irish Council for Civil Liberties (ICCL) explains, the new Bill (pdf) aims to stop the personal data of US citizens being transferred to locations with inadequate data protection — just as the EU’s GDPR does. But according to the ICCL, one country that may fall into this category of dodgy data handling is Ireland:

ICCL understands from those who wrote the draft Bill that Ireland’s failure to enforce the GDPR is of particular concern. The Bill intentionally uses language from the GDPR, and targets this enforcement failure. The draft Bill makes clear that merely enacting strong data protection law such as the GDPR is not enough. That law must be enforced.

Most digital giants have their European headquarters in Ireland. Under the GDPR, it is Ireland’s Data Protection Commission (DPC) that must investigate and ultimately fine these companies for their GDPR infringements anywhere in the EU. The DPC has opened many data privacy inquiries (pdf), but has so far failed to impose serious fines. Without strict enforcement by the Irish authorities, there is a growing feeling that the GDPR could be fatally undermined. Hence the risk that the US might not allow personal data to be transferred to Ireland, if the new “Protecting Americans’ Data From Foreign Surveillance Act” becomes law. Given the long-standing concerns over the protection of personal data flows from the EU to the US, that would be a rather ironic turn of events.

Follow me @glynmoody on Twitter, Diaspora, or Mastodon.

Filed Under: , , , , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Irony Alert: US Could Block Personal Data Transfers To Ireland, European Home Of Digital Giants, Because GDPR Is Not Being Enforced Properly”

Subscribe: RSS Leave a comment
13 Comments

This comment has been flagged by the community. Click here to show it.

This comment has been flagged by the community. Click here to show it.

This comment has been flagged by the community. Click here to show it.

Anonymous Coward says:

Re: profit harboring corporate criminals, get sanctioned

and now that I’m in, works for a while, so I’ll add this to point up is NOT "spam", that is, commercial, but only my ordinary opinion, not out of the ordinary on OTHER sites, that is, just that Techdirt has to discriminate against ordinary viewpoints or its corporatist advocacy falls apart

This comment has been deemed insightful by the community.
Anonymous Coward says:

Re: Re: profit harboring corporate criminals, get sanctioned

That’s for making it clear that you are writting stupid-pointless-annoying-message.

(HINT: a message that is comprised of "this is not spam" and basically nothing else… is spam)

Scary Devil Monastery (profile) says:

Re: Re: Re:3 Re:

"but I don’t have proof yet that they can grok one written idea"

Pretty sure by now that Baghdad Bob’s actually managed the trick of learning to write without learning to read. Nine times out of ten his "contribution" on this forum is a recounting on how many times he spammed the thread for that one comment to get in.

And the tenth is always an implied complaint about being silenced by Mike Masnick for, apparently, being a threat to the CIA’s agenda of corporate overlordship or some deranged and gleeful rant about how pirates and corporatists will all end up punished.

Never any indication he’s actually read the OP.

This comment has been deemed insightful by the community.
PaulT (profile) says:

Re: Re: profit harboring corporate criminals, get sanctioned

"I’ll add this to point up is NOT "spam", that is, commercial"

Whenever you get around to looking at how spam filters work (hint: it’s not a person clicking on your emails to spite you), you might also want to check the definition of the word – spam need not be commercial by nature.

You’re also not "ordinary" by any stretch of the imagination. You’re a rather unique moron.

Scary Devil Monastery (profile) says:

Re: Re: Re: profit harboring corporate criminals, get sanctioned

"You’re also not "ordinary" by any stretch of the imagination. You’re a rather unique moron."

No he’s not? There are plenty of homeless, drunk, and/or insane people who act just like him. It’s just that where the average village idiot on a bad trip rants about the gubmint being in cahoots with dem aliens who probed his ass, Baghdad Bob does the equivalent online.

This comment has been deemed insightful by the community.
That One Guy (profile) says:

'How dare you ignore the law we're ignoring ourselves?!'

Privacy Shield gets tossed because an EU court doesn’t trust the NSA to exercise self-control and not violate the GDPR, and now turnabout risks being applied thanks to Ireland not actually enforcing the GDPR and only paying lipservice to it. Both sides may have valid points but they are really shooting their own feet here and undermining their credibility by their actions and inactions respectively.

As a side-note the fact that the NSA’s penchant for snooping and grabbing everything it can tanked the previous two data-transfer agreements and is still apparently a sticking point is rather damning of the US here, as if that is the point of contention the fix would be to simply force the NSA to stop doing that, yet apparently that’s seen as unacceptable.

Anonymous Coward says:

The data regulator in ireland is investigating facebook for the massive data leak of 500 million accounts,
under gdpr it should inform users of any data breach but its claiming its just a case of data scraping not a hack.
of course nsa wants to grab everything but at this point almost every adult who uses the web in america must have had personal user data hacked and this info is still out there .
there seem to be companys hacked with millions of user accounts almost every week.
the usa has a point in that when theres fines for tech companys
it always seems to be from the usa regulator.

Leave a Reply to cattress Cancel reply

Your email address will not be published.

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...