Privacy Ref Blog

Safe Harbor Found “Invalid”, Now What?

Transferring personal information from the EU to the US has been a challenge. Today it may have become more difficult with the EU Court of Justice finding that Safe Harbor is invalid. For those 4,000 or so businesses that use Safe Harbor for data transfers the question  is how to go ahead.

This is actually a question not only for businesses, but for DPAs as well. The ruling had more to do with the practices of US surveillance as disclosed by Snowden than the construct of the Safe Harbor program itself. This places not only transfers via Safe Harbor in questions, but may have an equally impactful impact of transfers based on contracts, binding corporate rules, and consent. In each case, surveillance is equally possible so the DPAs, along with the Article 29 Working Party, will need to offer some guidance. .

What to do next is murky at best. In the coming weeks the DPAs should begin to give some direction. As I believe in contingency planning, it is not a bad time to begun to understand model contracts and BCRs just to get the lay of the land. Then, when the DPAs weigh in, you will have a foundation to make proper decisions.

Privacy Ref provides consulting and assessment services to build and improve organizational privacy programs. For more information call Privacy Ref at (888) 470-1528 or email us at

Posted on October 6, 2015 by Bob Siegel

« »

No Responses

Comments are closed.

« »

Subscribe to our mailing list

Please fill out the form below.


Want to find out more?

Simply go to the contact page, fill out the form, and someone from Privacy Ref will be in touch with you. You can also send an email to or call (888) 470-1528.


May 10, 2017

Predictive Breach Cost Model
Download our predictive breach cost modelhere.

Latest Blog Posts

October 30, 2017

PSR 2017 in Review
After a long trip from the northeast to San Diego, I finally made it to another exciting Privacy, Security, and Risk Conference from the IAPP. With GDPR on the horizon, the air was thick with discussion of this regulation in effect in May of next year. Even more so, a lot of questions received at the Privacy Ref booth were focused on this law, or preparing a privacy program through assessments data mapping. Overall, a great show with a few major themes. Continue reading this post...

The key to effective privacy training
I spend a lot of time facilitating privacy training. Whether it is directly for our clients or on behalf of the IAPP or their training partners, there are common elements to a successful educational event. Continue reading this post...

Other Recent Posts