Security

Trump order strips privacy rights from non-U.S. citizens, could nix EU-US data flows

Comment

Image Credits: Chip Somodevilla / Getty Images

An Executive Order signed by U.S. President Donald Trump in his first few days in office could jeopardize a six-month-old data transfer framework that enables EU citizens’ personal data to flow to the U.S. for processing — with the promise of ‘essentially equivalent’ privacy protection once it gets there.

Close to 1,500 companies have signed up to the framework so far, which only got up and running in August, following a multi-year negotiation process.

MEP Jan Philipp Albrecht, the European Parliament’s rapporteur on data protection regulation, tweeted earlier today suggesting that Trump’s presidential order, signed yesterday, might invalidate Privacy Shield.

JPA

Section 14 of the Executive Order signed by Trump — ostensibly aimed at enhancing domestic enforcement of U.S. immigration laws — reads:

Privacy Act.  Agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information.

Earlier this month European Commissioner Vera Jourova said she would be traveling to the U.S. this spring to meet with the Trump administration to assess its commitment to the EU-US Privacy Shield.

The data transfer framework is also be due for its first annual review this summer.

Talks to agree the Privacy Shield stepped up urgently in October 2015 after the prior Safe Harbor arrangement was struck down by Europe’s top court, following a legal challenge related to U.S. Government mass surveillance programs. That self-certification regime had been operational for fifteen years.

The question now is whether the replacement EU-US data flow mechanism is about to come unstuck far more quickly — helped on its way by the Trump administration’s privacy-related policy choices.

According to Albrecht’s analysis, there could also be ramifications for another EU-US umbrella agreement, which covers data-sharing between law enforcement agencies in the two regions — with the MEP suggesting sanctioning the administration for making this executive order.

At the time of writing the MEP could not be reached for comment.

It’s not clear at this point exactly how damaging the policy change might be to the continued functioning of Privacy Shield — that depends on how important the extensibility of the U.S. Privacy Act to non-U.S. citizens was during the EU Privacy Shield negotiations, and whether another relevant piece of U.S. legislation (the Judicial Redress Act) is also affected by Trump’s executive order.

But the order on “Enhancing Public Safety in the Interior of the United States” certainly looks likely to deepen concerns about the legal robustness of the EU-US data transfer mechanism, given it’s explicitly seeking to strip away privacy protections from non-U.S. citizens. Aka the opposite of what the European Commission was intent on achieving during negotiations.

A spokeswoman for the Commission told TechCrunch it does not have a statement on the implications of Trump’s executive order at present — but did confirm: “We’re looking at it at the moment.” Update: The spokeswoman has now sent us a statement in which the EC asserts that Privacy Shield “does not rely on the protections under the U.S. Privacy Act”.

On the Umbrella Agreement the spokeswoman said this relies on the Judicial Redress Act which she said “extends the benefits of the U.S. Privacy Act to Europeans and gives them access to U.S. courts”.

“We will continue to monitor the implementation of both instruments and are following closely any changes in the U.S. that might have an effect on European’s data protection rights,” she added.

The Commission does look to have fired a warning shot across the U.S. administration’s bows at a privacy conference taking place in Brussels this week, by reiterating that if adequate protection for EU citizen’s personal data under U.S. law can no longer be guaranteed then the framework would indeed have to be suspended.

https://twitter.com/LauKaya/status/824278088397766656

Any suspension of Privacy Shield would mean a return to legal uncertainty for the 1,500+ businesses currently processing EU data in the U.S. via this authorization framework — which includes the likes of Facebook, Twitter, Google and Microsoft. (You can find a full list of sign-ups here.)

A key sticking point in the lengthy EU-US Privacy Shield negotiations was the need for the arrangement to ensure essential equivalence of privacy protections for European citizens’ data in the U.S. — so there really can be little doubt that a presidential order seeking to strip privacy protections from Europeans (regardless of the stated intent) will be viewed very dimly by EU officials.

Compare and contrast Trump’s order with a policy directive signed by President Obama at the start of 2014 — which imposed limits on U.S. agencies’ use of signals intelligence collected in bulk with the stated aim of protecting “the privacy and civil liberties of all persons, whatever their nationality and regardless of where they might reside” [emphasis mine].

Obama’s extension of privacy protections to non-U.S. citizens was lauded as a very positive step by EU officials during the Privacy Shield negotiations. So it’s hard not to conclude the trajectory of the new U.S. administration vis-a-vis privacy and foreigners does not bode well for easy data flows between the two regions.

Earlier this month, as the inauguration of President Trump loomed, the Commission was already signalling public concern about the U.S.’ response to questions it sent following the Yahoo email scanning scandal — after news broke last fall the company had built a custom scanning tool at the behest of U.S. intelligence agencies to enable real-time keyword scanning of the incoming email of all Yahoo users.

On that issue Jourova complained the U.S. response had been tardy and lacking in detail. “This is not how we understand good, quick and full exchange of information,” she told Reuters in an interview earlier this month.

Critics of Privacy Shield –– including the lawyer who brought the original challenge against Safe Harbor — have consistently argued the arrangement contains the same fundamental flaws as its invalidated predecessor, given ongoing U.S. government agency surveillance programs accessing European citizens’ data.

And even before President Trump’s signing-in the Privacy Shield had attracted its first legal challenge. (Which might well find fresh fuel for its fight in Trump’s executive order.)

But the European Commission has previously rejected these structural criticisms of the framework — professing itself satisfied with “assurances” secured from the Obama administration that any access to personal data for law enforcement or national security would be “limited to what is necessary and proportionate”, and arguing the mechanism strengthens privacy protections via new components such as an ombudsperson to handle complaints, and an annual review of how Privacy Shield is operating.

However the arrival of Trump could really put the cat among the Commission’s pigeons.

Its overarching aim for Privacy Shield has been to grease the wheels of digital commerce by providing a streamlined mechanism for authorizing EU-US personal data transfers, while achieving an adequate level of compliance with European privacy law. But the new U.S. administration’s priorities on immigration and on business suggest Trump’s America is intent on pulling in a very different direction.

Other data transfer mechanisms for enabling the processing of EU personal data in the U.S. do exist but are generally more complex for businesses to comply with. And their legality has also been called into question.

More TechCrunch

Like its rival, Google, Amazon has launched an AI-powered video generator — but it’s only for advertisers at the moment, and somewhat limited in what it can do. Today at…

Amazon releases a video generator — but only for ads

The startup, previously known as GreenBlu, was working on desalination when it realized there was more value in the minerals that were left behind.

Tidal Metals sees seawater as the solution to a critical mineral shortage

Amazon sellers now have access to an AI assistant designed to help them grow their business by answering questions about their metrics, and later, may be able to help them…

Amazon debuts an AI assistant for sellers, Project Amelia

The startup has been methodically exploring how batteries might transform life in emerging markets

Zeno emerges from stealth to crib Tesla’s master plan for Africa and beyond

In many meetings today, it sometimes feels like there are more AI notetaking and transcription bots than people. There are seemingly dozens of options to choose from these days, but…

Like most good startup stories, Harbor began life as a product of disappointment. Kevin Lavelle, the co-founder and CEO of innovative clothing company Mizzen and Main, couldn’t find a baby…

Harbor is building a better baby monitor and an army of night nannies

There’s ample opportunity in the form of a mobile billboard. Kiwibot is so convinced of this fact that it plunked down $25 million to purchase Nickelytics.

Kiwibot acquires an ad startup to turn its delivery robots into mobile billboards

The startup will use turbomachinery to develop a heat pump capable of generating industrial-grade heat.

Karman Industries hopes its SpaceX-inspired heat pumps will replace industrial boilers

The European Union has opened two “specification proceedings” on Apple under the bloc’s Digital Markets Act (DMA) that will see it instructing the iPhone maker on how to comply with…

EU to tell Apple how to do interoperability, DMA style

Growing up in the Hunter Valley, a region of Australia renowned for its fine wine production, Mitchel Fowler never realized he might one day think of an idea that could…

This founder grew up in wine country — now he’s built a platform for wine makers

Picus Security, which runs continuous validation processes to root out and fix inconsistencies in code, has raised $45 million in a Series C round.

Picus Security, founded by 3 Turkish mathematicians, raises $45M after simulating 1B cyber attacks

With an explosion of weather and climate data that the last generation of tools can’t handle, is AI the future of forecasting? Research certainly suggests so, and a newly funded…

Brightband sees a bright (and open-source) future for AI-powered weather forecasting

A final report by the UN’s high level advisory body on artificial intelligence makes for, at times, a surreal read. Named ‘Governing AI for Humanity’, the document underlines the contradictory…

AI governance can’t be left to the vested interests

The startup is taking a different approach to removing carbon dioxide from the air than most of its competitors.

Phlair’s carbon sucking technology could lower direct air capture’s costs

The governing body overseeing India’s popular UPI payments rail is considering increasing its proposed market share cap for operators like Google Pay, PhonePe and Paytm.

India weighs easing market share limits for UPI payment operators

Palmer Luckey, the Hawaiian-shirt wearing founder who sold Oculus VR for $2 billion before co-founding the military tech company Anduril, is back in the headset business — in a sense.…

Palmer Luckey returns to headsets as Anduril partners with Microsoft on U.S. military tech

Motional, the autonomous vehicle startup backed by Hyundai, is shaking up its leadership ranks. Karl Iagnemma, an early pioneer in the autonomous vehicle industry whose startup Nutonomy lies at the…

CEO of self-driving startup Motional is stepping down

Craig Newmark plans to donate $100 million to further strengthen U.S. cybersecurity. The Craigslist founder tells The Wall Street Journal he is addressing what he sees as a growing threat…

Craig Newmark pledges $100M to fight hacking by foreign governments

The company is in various stages of developing and piloting a range of initiatives focused on dealing with bad actors, harassment, spam, fake accounts, video safety, and more.

Bluesky addresses trust and safety concerns around abuse, spam, and more

Fal.ai, a dev-focused platform for AI-generated audio, video, and images, today revealed that it’s raised $23 million in funding from investors including Andreessen Horowitz (a16z), Black Forest Labs co-founder Robin…

Fal.ai, which hosts media-generating AI models, raises $23M from a16z and others

A House committee overwhelmingly voted to approve a bill that would require new cars to be built with AM radio at no additional cost to the owner. The AM for…

Bill requiring AM radio in new cars gets closer to law

The Vive Focus Vision has enough firepower under the hood to appeal to PC gamers tethered via the DisplayPort.

HTC takes on Apple’s Vision Pro and PC Gaming with $1,000 Vive Focus Vision

The reversal comes as EV startup Fisker prepares to enter the fourth month of its Chapter 11 bankruptcy process.

Fisker reverses course on making Ocean owners pay for recall repairs

iOS 18 offers the most control over the look and feel of your iPhone’s user interface than any other version of Apple’s mobile operating system to date.

Three new ways to personalize your iPhone’s Home Screen in iOS 18

LinkedIn may have trained AI models on user data without updating its terms. LinkedIn users in the U.S. — but not the EU, EEA, or Switzerland, likely due to those…

LinkedIn scraped user data for training before updating its terms of service

Hiya, folks, welcome to TechCrunch’s regular AI newsletter. If you want this in your inbox every Wednesday, sign up here. It’s been just a few days since OpenAI revealed its latest…

This Week in AI: Why OpenAI’s o1 changes the AI regulation game

The FBI, NSA and other U.S. government agencies detailed a Chinese-government operation that used 260,000 of internet-connected devices to launch cyberattacks.

US government ‘took control’ of a botnet run by Chinese government hackers, says FBI director

The pitch sounds a bit sci-fi: a helmet called Lily that people undergoing chemotherapy wear to prevent hair loss, which is a common side effect of the treatment.

Luminate’s hair-saving chemo helmet nears release, as new funding goes toward home cancer care

At its Made On YouTube event on Wednesday, the company announced a new dedicated space for creators to interact with their fans and viewers. The space, called “Communities,” is kind…

YouTube launches Communities, a Discord-like space for creators and fans to interact with each other

Amazon’s Buy with Prime program, which lets shoppers with a Prime membership purchase items from third-party stores and check out using their Amazon account, is getting a new payment option:…

Amazon adds PayPal as a payment option to Buy with Prime