Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - All Ashore in 2016 As EU’s Rejects Safe Harbor Protocols
Articles

All Ashore in 2016 As EU’s Rejects Safe Harbor Protocols

ISBuzz TeamBy ISBuzz TeamJanuary 25, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
All Ashore in 2016 As EU’s Rejects Safe Harbor Protocols
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The highest European Union court has declared Safe Harbor invalid. Companies around the world  must undertake an immediate reassessment of IT, data storage and eDiscovery policies

At the end of last year, businesses that relied on the Safe Harbor protocol to transfer data method between the EU and the US had to conduct a major review and policy shift following a landmark decision by the Court of Justice of the European Union (CJEU). It came about because, in the last quarter of 2015 the court invalidated the EU-US Safe Harbor agreement, stating that the agreement failed to provide adequate protections for EU citizens’ private data located in, or transferred to, the United States. In December the stakes were raised further when EU officials reached an agreement on a stringent new data protection regulation that will subject multinational companies to fines of up to four percent of their annual global revenue. For a company like Facebook, for example, this could mean a potential fine of somewhere close to $500 million.

The new law also requires companies to clearly explain what customer and/or HR data is being used for. For the first time, it also offers a “right to be forgotten” provided there are no legitimate grounds for retaining the data and a right to know when your data been hacked. In this instance, companies would need to notify the relevant supervisory authority of serious breaches as soon as possible so that customers and staff can take appropriate protective measures. Assuming that the law is approved by the European Parliament and each of the member countries next year, companies would have until 2018 to comply fully.

In the meantime, companies will have to move quickly to ensure they still comply with local country data protection and may need to make significant changes to the way data is collected, where it is processed, hosted, searched and reviewed.  The CJEU ruling requires companies that did rely on Safe Harbor to obtain each EU citizen’s explicit consent before moving their personal data to the US. In practical terms, this has implications across Europe for the way in which businesses in the sector store customer data and archive HR information – as well as the way in which subsidiaries share internal and external data with their US-based parent organisations. Explicit customer and/or employee consent is now required for transferring name, email or home address, employee’s HR data and health-related information or any documents containing such details.

In a world without Safe Harbor, financial sector companies need to be particularly careful when data transfer is required as part a criminal investigation, particularly if it is an eDiscovery request pertaining to a US fraud or bribery investigation. If they have not already done so, businesses will need to undertake thorough reassessments of their eDiscovery practices and consider how the data relating to the investigation is collected and where it is processed, hosted, searched and reviewed. This could cover anything from emails, documents, presentations, databases, voicemail, audio and video files, through to social media and websites.

Even when Safe Harbor was in place, FRA has always recommend that all the data collection, hosting, review and analysis needed for an eDiscovery request is performed within the relevant country using tools that allow local review and segregation of data.  Now, however, it is absolutely essential.

All of this means that, without Safe Harbor in place, US-based financial sector companies will have to be up-to-speed on the individual data protection policies in individual European countries – particularly Germany, France and Switzerland, which have the most stringent rules – especially in the context of civil and criminal investigation and litigation.

Once the new EU legislation is in place, the EU Council and EU Parliament will be able to enforce proposed, new potentially crippling fines. It is therefore vital for companies to conduct self-assessments and ensure compliance with interim data protection legislation with individual EU countries and, longer term, make sure that they have the procedures and infrastructure in place to comply with possible forthcoming EU legislation. It is, therefore, critical that financial sector companies act now and keep on the right side of Europe’s new data protection laws.

[su_box title=”About Toby Duthie” style=”noise” box_color=”#336588″]Toby DuthieToby Duthie, a co-founder of FRA and head of its London office, has more than 20 years’ experience in financial analysis, complex financial modeling, investigations and compliance reviews. Fluent in English and German, Toby has particular expertise in multi-jurisdictional investigations, anti-bribery and corruption compliance testing, and specializes in matters of government enforcement in the UK and US. As one of FRA’s founders, Toby was instrumental in developing the firm’s white-collar and regulatory defense services across Europe and has been integral in resolving such high-profile FCPA enforcement cases as Panalpina, Bonny Island LNG, and Oil-for-Food. He has worked on matters involving UK, Swiss, Dutch, and French regulators and has extensive experience calculating damages in FCPA enforcement actions.  He has worked on three of the ten largest FCPA settlements.

Toby has worked on a number of complex financial frauds which have involved damages analysis and modeling in a variety of jurisdictions, including the US, Japan, Austria, and the UK. He also set up the UK’s first third party litigation funding company in 2002 (IM Litigation Management Limited) which pursued over 50 claims with over a 70% success rate. A graduate with honors from University College London, Toby worked as a steel trader in Hong Kong and in the investment banking division of Deutsche Bank/Morgan Grenfell.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}