Last Updated: August 2020
In light of the recent decision by the Court of Justice of the European Union (CJEU) invalidating the EU-U.S. Privacy Shield agreement as a lawful basis for transferring data from the European Union to the United States, we are taking several steps to ensure that the European personal data we receive will remain protected and can continue to be lawfully exported from Europe.
First, for data transferred from the EEA or the UK, we will no longer rely on EU-U.S. Privacy Shield. Instead, we ask that our customers that have not yet signed our General Data Protection Regulation Addendum (DPA) to do so. The DPA sets out our commitments to protect customer personal data. It also includes the Standard Contractual Clauses (SCCs) adopted by the European Commission as a lawful means of transferring data from Europe.
Second, we will update the DPA to add additional safeguards designed to protect customer data in response to the concerns raised in the CJEU decision. In particular, we are adding a new commitment regarding requests for personal data from law enforcement or other government agencies. If we receive such a request, we will (1) oppose it unless legally compelled to comply, (2) attempt to redirect the agency to request that data directly from Customer, and (3) promptly notify Customer and provide a copy of the request unless legally prohibited from doing so. Given our past experience, we believe it is unlikely we will receive such requests. Nevertheless, these additional safeguards will provide assurances that we will do everything we can to protect our customers’ personal data in such a case.
Third, as European data protection authorities are likely to provide further guidance in the coming weeks and months, we will take the steps necessary to ensure that European customer data is transferred and processed in accordance with all necessary protections and applicable legal requirements.
If you have any questions about our approach to data transfers or our commitments to protect the privacy and security of the data we process for our customers, please feel free to contact us.