Privacy

Trump order strips privacy rights from non-U.S. citizens, could nix EU-US data flows

Comment

Image Credits: Chip Somodevilla / Getty Images

An Executive Order signed by U.S. President Donald Trump in his first few days in office could jeopardize a six-month-old data transfer framework that enables EU citizens’ personal data to flow to the U.S. for processing — with the promise of ‘essentially equivalent’ privacy protection once it gets there.

Close to 1,500 companies have signed up to the framework so far, which only got up and running in August, following a multi-year negotiation process.

MEP Jan Philipp Albrecht, the European Parliament’s rapporteur on data protection regulation, tweeted earlier today suggesting that Trump’s presidential order, signed yesterday, might invalidate Privacy Shield.

JPA

Section 14 of the Executive Order signed by Trump — ostensibly aimed at enhancing domestic enforcement of U.S. immigration laws — reads:

Privacy Act.  Agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information.

Earlier this month European Commissioner Vera Jourova said she would be traveling to the U.S. this spring to meet with the Trump administration to assess its commitment to the EU-US Privacy Shield.

The data transfer framework is also be due for its first annual review this summer.

Talks to agree the Privacy Shield stepped up urgently in October 2015 after the prior Safe Harbor arrangement was struck down by Europe’s top court, following a legal challenge related to U.S. Government mass surveillance programs. That self-certification regime had been operational for fifteen years.

The question now is whether the replacement EU-US data flow mechanism is about to come unstuck far more quickly — helped on its way by the Trump administration’s privacy-related policy choices.

According to Albrecht’s analysis, there could also be ramifications for another EU-US umbrella agreement, which covers data-sharing between law enforcement agencies in the two regions — with the MEP suggesting sanctioning the administration for making this executive order.

At the time of writing the MEP could not be reached for comment.

It’s not clear at this point exactly how damaging the policy change might be to the continued functioning of Privacy Shield — that depends on how important the extensibility of the U.S. Privacy Act to non-U.S. citizens was during the EU Privacy Shield negotiations, and whether another relevant piece of U.S. legislation (the Judicial Redress Act) is also affected by Trump’s executive order.

But the order on “Enhancing Public Safety in the Interior of the United States” certainly looks likely to deepen concerns about the legal robustness of the EU-US data transfer mechanism, given it’s explicitly seeking to strip away privacy protections from non-U.S. citizens. Aka the opposite of what the European Commission was intent on achieving during negotiations.

A spokeswoman for the Commission told TechCrunch it does not have a statement on the implications of Trump’s executive order at present — but did confirm: “We’re looking at it at the moment.” Update: The spokeswoman has now sent us a statement in which the EC asserts that Privacy Shield “does not rely on the protections under the U.S. Privacy Act”.

On the Umbrella Agreement the spokeswoman said this relies on the Judicial Redress Act which she said “extends the benefits of the U.S. Privacy Act to Europeans and gives them access to U.S. courts”.

“We will continue to monitor the implementation of both instruments and are following closely any changes in the U.S. that might have an effect on European’s data protection rights,” she added.

The Commission does look to have fired a warning shot across the U.S. administration’s bows at a privacy conference taking place in Brussels this week, by reiterating that if adequate protection for EU citizen’s personal data under U.S. law can no longer be guaranteed then the framework would indeed have to be suspended.

https://twitter.com/LauKaya/status/824278088397766656

Any suspension of Privacy Shield would mean a return to legal uncertainty for the 1,500+ businesses currently processing EU data in the U.S. via this authorization framework — which includes the likes of Facebook, Twitter, Google and Microsoft. (You can find a full list of sign-ups here.)

A key sticking point in the lengthy EU-US Privacy Shield negotiations was the need for the arrangement to ensure essential equivalence of privacy protections for European citizens’ data in the U.S. — so there really can be little doubt that a presidential order seeking to strip privacy protections from Europeans (regardless of the stated intent) will be viewed very dimly by EU officials.

Compare and contrast Trump’s order with a policy directive signed by President Obama at the start of 2014 — which imposed limits on U.S. agencies’ use of signals intelligence collected in bulk with the stated aim of protecting “the privacy and civil liberties of all persons, whatever their nationality and regardless of where they might reside” [emphasis mine].

Obama’s extension of privacy protections to non-U.S. citizens was lauded as a very positive step by EU officials during the Privacy Shield negotiations. So it’s hard not to conclude the trajectory of the new U.S. administration vis-a-vis privacy and foreigners does not bode well for easy data flows between the two regions.

Earlier this month, as the inauguration of President Trump loomed, the Commission was already signalling public concern about the U.S.’ response to questions it sent following the Yahoo email scanning scandal — after news broke last fall the company had built a custom scanning tool at the behest of U.S. intelligence agencies to enable real-time keyword scanning of the incoming email of all Yahoo users.

On that issue Jourova complained the U.S. response had been tardy and lacking in detail. “This is not how we understand good, quick and full exchange of information,” she told Reuters in an interview earlier this month.

Critics of Privacy Shield –– including the lawyer who brought the original challenge against Safe Harbor — have consistently argued the arrangement contains the same fundamental flaws as its invalidated predecessor, given ongoing U.S. government agency surveillance programs accessing European citizens’ data.

And even before President Trump’s signing-in the Privacy Shield had attracted its first legal challenge. (Which might well find fresh fuel for its fight in Trump’s executive order.)

But the European Commission has previously rejected these structural criticisms of the framework — professing itself satisfied with “assurances” secured from the Obama administration that any access to personal data for law enforcement or national security would be “limited to what is necessary and proportionate”, and arguing the mechanism strengthens privacy protections via new components such as an ombudsperson to handle complaints, and an annual review of how Privacy Shield is operating.

However the arrival of Trump could really put the cat among the Commission’s pigeons.

Its overarching aim for Privacy Shield has been to grease the wheels of digital commerce by providing a streamlined mechanism for authorizing EU-US personal data transfers, while achieving an adequate level of compliance with European privacy law. But the new U.S. administration’s priorities on immigration and on business suggest Trump’s America is intent on pulling in a very different direction.

Other data transfer mechanisms for enabling the processing of EU personal data in the U.S. do exist but are generally more complex for businesses to comply with. And their legality has also been called into question.

More TechCrunch

Some Indian government websites have allowed scammers to plant advertisements capable of redirecting visitors to online betting platforms. TechCrunch discovered around four dozen “gov.in” website links associated with Indian states,…

Scammers found planting online betting ads on Indian government websites

Around 550 employees across autonomous vehicle company Motional have been laid off, according to information taken from WARN notice filings and sources at the company.  Earlier this week, TechCrunch reported…

Motional cut about 550 employees, around 40%, in recent restructuring, sources say

The deck included some redacted numbers, but there was still enough data to get a good picture.

Pitch Deck Teardown: Cloudsmith’s $15M Series A deck

The company is describing the event as “a chance to demo some ChatGPT and GPT-4 updates.”

OpenAI’s ChatGPT announcement: What we know so far

Unlike ChatGPT, Claude did not become a new App Store hit.

Anthropic’s Claude sees tepid reception on iOS compared with ChatGPT’s debut

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Look,…

Startups Weekly: Trouble in EV land and Peloton is circling the drain

Scarcely five months after its founding, hard tech startup Layup Parts has landed a $9 million round of financing led by Founders Fund to transform composites manufacturing. Lux Capital and Haystack…

Founders Fund leads financing of composites startup Layup Parts

AI startup Anthropic is changing its policies to allow minors to use its generative AI systems — in certain circumstances, at least.  Announced in a post on the company’s official…

Anthropic now lets kids use its AI tech — within limits

Zeekr’s market hype is noteworthy and may indicate that investors see value in the high-quality, low-price offerings of Chinese automakers.

The buzziest EV IPO of the year is a Chinese automaker

Venture capital has been hit hard by souring macroeconomic conditions over the past few years and it’s not yet clear how the market downturn affected VC fund performance. But recent…

VC fund performance is down sharply — but it may have already hit its lowest point

The person who claims to have 49 million Dell customer records told TechCrunch that he brute-forced an online company portal and scraped customer data, including physical addresses, directly from Dell’s…

Threat actor says he scraped 49M Dell customer addresses before the company found out

The social network has announced an updated version of its app that lets you offer feedback about its algorithmic feed so you can better customize it.

Bluesky now lets you personalize main Discover feed using new controls

Microsoft will launch its own mobile game store in July, the company announced at the Bloomberg Technology Summit on Thursday. Xbox president Sarah Bond shared that the company plans to…

Microsoft is launching its mobile game store in July

Smart ring maker Oura is launching two new features focused on heart health, the company announced on Friday. The first claims to help users get an idea of their cardiovascular…

Oura launches two new heart health features

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI considers allowing AI porn

Garena is quietly developing new India-themed games even though Free Fire, its biggest title, has still not made a comeback to the country.

Garena is quietly making India-themed games even as Free Fire’s relaunch remains doubtful

The U.S.’ NHTSA has opened a fourth investigation into the Fisker Ocean SUV, spurred by multiple claims of “inadvertent Automatic Emergency Braking.”

Fisker Ocean faces fourth federal safety probe

CoreWeave has formally opened an office in London that will serve as its European headquarters and home to two new data centers.

CoreWeave, a $19B AI compute provider, opens European HQ in London with plans for 2 UK data centers

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason