Privacy Shield First Annual Joint Review to Take Place in September 2017
Time 2 Minute Read

On May 29, 2017, a high-level EU Commission official and Politico reported that the primary objective of the first annual joint review of the EU-U.S. Privacy Shield (“Privacy Shield”) is not to obtain more concessions from the U.S. regarding Europeans’ privacy safeguards, but rather to monitor the current U.S. administration’s work and steer U.S. privacy debates to prevent privacy safeguards from deteriorating. On March 31, 2017, the EU Commissioner for Justice, Věra Jourová, announced that the joint review will take place in September 2017.

The review will focus on two important points:

  • The EU Commission will verify that the key foundations of the Privacy Shield remain in place, in particular with respect to government access for national security reasons. The Commissioner recalled the importance of maintaining the protections provided under Presidential Policy Directive 28, as well as the Ombudsperson mechanism. In addition, the EU Commission will follow closely the debates around the reform of section 702 of FISA and the potential impact on Europeans’ personal data.
  • The EU Commission will also focus on day-to-day implementation and robust follow-up of the Privacy Shield by companies that have self-certified. In this context, the Department of Commerce will monitor the compliance of companies with the Privacy Shield principles on an ongoing basis, including through detailed questionnaires that companies will have to complete to identify issues that may require further follow‐up action.

Most recently, the European Parliament passed a Resolution on the adequacy of the protection afforded by the Privacy Shield, pointing out several weaknesses to be fixed in the upcoming review of the framework, including the lack of specific rules on automated decisions, the lack of a general right to object, the need for stricter guarantees on the independence and powers of the Ombudsperson mechanism, and the lack of concrete assurances with respect to bulk collection of data.

On the basis of the annual review, the EU Commission will issue a public report to the European Parliament and the Council.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On March 3, 2026, the European Commission published draft guidelines intended to clarify the application of the Cyber Resilience Act and opened a public consultation to gather feedback from stakeholders.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page