1. Home
  2. Marketing Glossary

Safe Harbor

What is the Safe Harbor agreement?

Safe Harbor was an agreement between the European Union and the United States that allowed the transfer of personal data from entities located in the EU to companies in the United States.

The aim of the agreement was to protect the privacy and security rights of EU citizens while allowing the transmission of personal data across international borders.

Safe Harbor was based on the idea that US companies would voluntarily adhere to a set of privacy principles regarding the processing of personal data received from the EU.

These principles included aspects such as notice, choice, onward transfer, security, data integrity, access and enforcement.

However, in 2015, the Court of Justice of the European Union invalidated the Safe Harbor agreement in the case of Schrems v. Data Protection Commissioner.

The court held that Safe Harbor did not provide sufficient protection to the personal data of EU citizens in the United States.

As a result of that decision, the European Commission and the United States negotiated a new data protection agreement known as the Privacy Shield between the EU and the US. (EU-US Privacy Shield), which was designed to provide greater privacy protections for EU citizens.

However, this new agreement was also invalidated by the Court of Justice of the EU in July 2020, which calls into question the future of transatlantic transfers of personal data.

How does the cancellation of these agreements affect European companies using US tools?

The annulment of both the Safe Harbor agreement and the EU-US Privacy Shield has posed significant challenges for European companies wishing to use services established in the United States such as Mailchimp, which store or process personal data.

When the Court of Justice of the European Union invalidated these agreements, it declared that companies cannot rely on them to justify the transfer of personal data to the United States.

This means that European companies wishing to use these services must find other legal bases for doing so.

Some of the alternatives companies can consider include:

  • Standard Contractual Clauses (SCCs): These are contractual provisions that companies can include in their contracts with US service providers, which require those providers to comply with certain data protection standards. However, in some cases, data protection authorities may require additional safeguards.
  • Explicit consent: In some cases, companies may be able to transfer data to the US with the explicit consent of the person the data refers to. However, this approach may not be practical in all cases, and consent can be withdrawn at any time.
  • Legal exceptions: There are certain exceptions in EU regulations that allow data transfers in specific circumstances. However, these exceptions are usually limited and may not apply to all companies.

Therefore, it is advisable for companies wishing to use these tools to consult a lawyer or a data protection expert to ensure they are complying with EU data protection laws.

Another less complex alternative would be to use services established in the European Union, such as Mailrelay.

Related entries