Fear not, Europe`s Privacy Shield is Trumpproof – exFTC bigwig

2/20/2017
Fear not, Europe's Privacy Shield is Trump-proof – ex-FTC bigwig • The Register
Log in Sign up Forums
DATA CENTER
M³ CLL Events Whitepapers The Next Platform
SOFTWARE
SECURITY
TRANSFORMATION
DEVOPS
BUSINESS
PERSONAL TECH
Security
Fear not, Europe's Privacy Shield is Trump­proof
– ex­FTC bigwig
SCIENCE
EMERGENT TECH
BOOTNOTES
More like this
Trump
Privacy Shield
President's executive order causes jitters, but data agreement
became law today
'13 Cadillac SRX
$21,999
View Details
'16 Lexus IS 300
$35,394
View Details
'13 Volkswagen Jetta
Sedan
$11,960
View Details
Former FTC Commissioner Julie Brill
'16 Lexus IS 300
1 Feb 2017 at 20:29, Kieren McCarthy
$36,690
View Details
The transatlantic Privacy Shield data transfer agreement is not at risk from Trump's
executive actions, former FTC Commissioner Julie Brill has promised.
'15 Lexus RX 350
$36,899
In an article on her law firm's blog, Brill notes that the recent executive order (EO) from the
Oval Office, which expressly limited privacy rights to US citizens only, does not impact the
critical agreement between the European Union and the United States.
How come? Three reasons:
1. The Privacy Act applies only to government databases, whereas the Privacy Shield
covers corporate databases.
2. No presidential Executive Order can override existing laws written by Congress – and
Congress has already approved the Judicial Redress Act that grants EU citizens the
right to use the US courts in the case of misuse of data.
3. The other mechanism set up to make the Privacy Shield work legally – an Ombudsman
that will look into any requests from Europe about access to data by the US government
– remains in place.
https://www.theregister.co.uk/2017/02/01/former_ftc_com_brill_says_privacy_shield_not_impacted/
View Details
Most read
Oh happy day! Linus
Torvalds has given the
world Linux 4.10
'At least I can walk away
with my dignity' –
Streetmap founder after
Google lawsuit loss
Google bellows bug news
after Microsoft sails past
fix deadline
1/4
2/20/2017
Fear not, Europe's Privacy Shield is Trump-proof – ex-FTC bigwig • The Register
Brill played an active role in developing the Privacy Shield with other US government
Connected car in the
second­hand lot? Don't
buy it if you're not hack­
savvy
agencies and their counterparts in the European Union, and so has as good an
understanding of the law as anyone. The FTC is expected to act as a key enforcer of the
agreement.
In colossal shock, Uber
alleged to be wretched
hive of sexism, craven
managerial ass­covering
In arguing why the agreement still holds, despite's Trump's actions, Brill and her coauthor
Bret Cohen also give mention to another key component – the Attorney General's
designation of specific countries that are covered by the Judicial Redress Act.
That Act and the accompanying Attorney General list officially become law today,
Wednesday February 1, 2017 – and the Trump Administration has done nothing to prevent
or stymie what is now a legal reality.
And so the Privacy Shield is up and running, despite President Trump's isolationist
approach. And a good job it is too, since every large internet company, including Facebook
and Google, are heavily reliant on it to provide them with a legal foundation on which to
offer their services outside the United States.
'16 Porsche Macan $52,577
$52,577 CarGurus Great Deal.
Not so fast
Shop now!
All that said, Brill and Cohen feel obliged to include some caveats – just as European Union
officials did last week when they saw the text included in Trump's Enhancing Public Safety
in the Interior of the United States order.
"Going forward, it will be important to pay attention to European officials' reaction to the
EO," they wrote. "It will also be important to watch how the EO may impact the Attorney
General's designations of countries covered under the Judicial Redress Act or countries
that could receive such designation in the future."
The EU made a similar statement: "We will continue to monitor the implementation of both
instruments and are following closely any changes in the US that might have an effect on
Europeans' data protection rights."
In other words, it is possible that President Trump's pick for Attorney General, Jeff
Sessions, could decide at a later date to revoke some countries' – or the EU's –
designations under the Judicial Redress Act: a decision that would wreak immediate havoc
to Privacy Shield.
'16 Porsche Macan $52,577
$52,577 CarGurus Great Deal.
Shop now!
Spotlight
While Sessions appears to be more of a racist than a xenophobe, he has also proven to be
fiercely loyal to Trump. The president has already made it plain that he is prepared to fire
any Attorney General who does not agree to his executive orders, even if they doubt those
orders' legality.
To that end, government officials in both the US and Europe – as well as the management
teams at every major online corporation – will be hoping that Donald Trump never hears
about the Privacy Shield.
The Register's guide to protecting
your data when visiting the US
Not so fast a second time
That may still only be half the problem, however, as Lawfare's Adam Klein and Carrie
Cordero point out on another post here on The Register.
The combination of the very old Privacy Act (written in 1974, since which time Europe has
rewritten its privacy rules three times) and Trump's wide executive order could see
government agencies insist on access to European citizens' personal data, having met a
very low threshold of proof – a mere "risk to public safety" would be enough, and some
agencies are likely to view that very broadly.
https://www.theregister.co.uk/2017/02/01/former_ftc_com_brill_says_privacy_shield_not_impacted/
Despite the spiel, we're still some
decades from true anti­malware AI
2/4
2/20/2017
Fear not, Europe's Privacy Shield is Trump-proof – ex-FTC bigwig • The Register
Trump's order actively exhorts government agencies to share such information between
themselves – and that could mean an individual's personal details made available to huge
numbers of government officials without any concern given to privacy laws.
One of the key aspects of the Privacy Act is that an individual's consent has to be sought
before personally identifiable material can be shared (subject to a few important
exceptions). But if someone is deemed to be outside of that Act, their personal information
can not only be readily shared, but the individual in question would not know about it.
In that sense, the value of an Ombudsman is questionable: if someone doesn't know their
personal data is being shared, how are they supposed to question it?
Honeypots: Free psy­ops weapons
that can protect your network before
defences fail
It is possible that the data protection authorities in Europe will take issue with this catch­22
situation when they carry out an annual audit of the new system in just under six months'
time.
Hopefully by then the Trump Administration will have been sufficiently persuaded not to
write and sign executive orders without first running them through the machinery of
government. ®
23 Comments
Tips and corrections
Cyber­spying, leaking to meddle in
foreign politics is the New Normal
More from The Register
God save the Queen...
from Donald Trump. So
say 1 million Britons
China to Donald Trump:
Twitter diplomacy
'undesirable'
Tech titans tentatively
trot toward Trump Tower
to talk turkey today
Parliament receives petition to
prevent President's state visit
Old­school PRC response to
the 140­character kid
The Schmidt meets the Man
256 Comments
Security hardened, pah! Expert
doubts Kaymera's mighty Google's
Pixel
13 Comments
46 Comments
How to secure MongoDB – because it
isn't by default and thousands of
DBs are being hacked
Trump may stump
Australian techies
heading for the US
President Trump tweets
from insecure Android,
security boffins roll eyes
Preferential E­3 visa deal likely
to come under scrutiny for labor
and free trade reasons
To be fair, you might too. But
you're not the most powerful
man in the world
9 Comments
AT&T CEO clambers up
Trump's tower, explains
why he should shower
gold for Time Warner
Randall Stephenson makes
case for yuuuge merger
99 Comments
9 Comments
Whitepapers
Proven HFA Vendor Nimble Storage Achieving Rapid Success in the
AFA Market
Because I'm bad, I'm bad, Shamoon:
PC wiper tried to shut down Saudi
snapshot defences
A helpful summary of the evolving AFA Market as well as the Nimble technology, business
value, customers, and go­to­market strategies.
Make a smart investment in Office 365 smarter with Box
https://www.theregister.co.uk/2017/02/01/former_ftc_com_brill_says_privacy_shield_not_impacted/
3/4
2/20/2017
Fear not, Europe's Privacy Shield is Trump-proof – ex-FTC bigwig • The Register
Office 365 marks an important change for both the IT groups that administer Microsofts core
toolset and the end users that interact with those tools.
Your top 5 cloud Data challenges solved
The cloud s changing everything, Its transforming IT orgnisations with agility and efficiency
like never before, enabling them to realise new IT as a service delivery models.
Swisscom builds OpenStack cloud possibilities with Red Hat
As a result, Swisscom can meet customer needs more effectively, embrace open source
innovation and DevOps.
Top cop: Strap Wi­Fi jammers to teen
web crims as punishment
Sponsored links
All­Flash Arrays ­ A flash of brilliance or just a
flash in the pan? Have your say in our reader
survey
Sign up to The Register to receive newsletters
and alerts
About us
More content
Privacy
Subscribe to newsletter
Company info
Top 20 stories
Advertise with us
Week’s headlines
Syndication
Archive
Send us news tips
Webcasts
Follow us
Mobile
website
The Register
Biting the hand that feeds IT © 1998–2017
Independent news, views, opinions and
reviews on the latest in the IT industry.
Offices in London, San Francisco and
Sydney.
https://www.theregister.co.uk/2017/02/01/former_ftc_com_brill_says_privacy_shield_not_impacted/
4/4