Topic: Schrems 2, Privacy Shield, and data sharing
Hosts:
Larry Garfield, Director of Developer Experience at Platform.sh: / crell
Joey Stanford, CISO at Platform.sh: / rinchen
Guests:
Caroline McCaffery, CEO, co-Founder, General Counsel of Clearops.IO: / carolinemccaffery
Brandi Bennett, Data Privacy Attorney: / brandibennett
Adding more complexity to international privacy law:
A recent ruling from the Court of Justice of the European Union invalidates the US EU Privacy Shield, which has many implications for data rules around the GDPR. More than 5,000 U.S. companies rely on Privacy Shield to conduct trans-Atlantic trade in compliance with the GDPR. We talk with a team of legal experts to clarify what this means for you and your international business.
Comprehensive data protection for European residents:
GDPR stands for “General Data Protection Regulation,” which governs how businesses that interact with and collect data of European residents can be managed. It regulates everything from:
Why an organization collects data
How much data organizations should collect when building platforms
How long organizations can store your data
How organizations handle international transfers
What happens in cases of misuse of data or privacy breach
Privacy Shield allowed for data flow between the EU and the US:
Under the GDPR, for you to transfer the data, there’s a determination of whether a particular country is “adequate” in terms of data protection.
Brandi Bennet, one of our guests, helps us define adequacy. “Europe has high standards for data protection: your data protection rights are considered a human right. What adequacy really means is, when they transfer the data to another country, are those country’s laws as good as our laws? Do they treat and protect data as robustly and as strong as we do?”
The United States does not meet The EU’s adequacy requirements. The Privacy Shield treaty provides a framework to nonetheless allow for data flow between the EU and the US. With the ruling, we’re no longer legally allowed to use Privacy Shield, which leaves businesses wondering what practical measures can they take to protect their data? Some suggestions from our guests are:
Data encryption and minimization
Storage minimization
Risk assessment of your vendors
Pseudo-anonymization, where you’re masking the identity of your users behind other identifiers
Giving customers access, notice, and choice
You can read more about international privacy law on the International Association of Privacy Professionals website.
Resources:
Caroline on Medium: / clearops.io
Brandi on Medium: / bbennettesq
International Association of Privacy Professionals: https://iapp.org/
Information Commissioner's Office (ICO): https://ico.org.uk/
Lexology: https://www.lexology.com/
Hunton: https://www.huntonak.com/en/
Future of Privacy Forum: https://fpf.org/
Electronic Frontier Foundation: https://www.eff.org/
Please share your feedback with us: https://platform-sh.typeform.com/to/g...
Platform.sh on social media
Twitter @platformsh
Twitter (France): @platformsh_fr
LinkedIn: Platform.sh
LinkedIn (France): Platform.sh
Facebook: Platform.sh
About Platform.sh
Platform.sh combines a robust, highly reliable hosting platform and modern tools that enable development teams to build, evolve, and scale applications faster and more efficiently—contributing to achieving departmental and organizational goals.
Whether your organization has one website or 1,000, Platform.sh lets your dev team focus on creating innovative, sticky features and apps with their favorite tools, languages, and frameworks—instead of managing infrastructure and process.