Privacy Shield hammers another nail in the coffin of data protection
Safe Harbour’s replacement is based entirely on trust - what a big mistake


Safe Harbour is dead, long live the Privacy Shield. Although, to be honest, the all-new US data transfer agreement is already a dead man walking if you ask me. Indeed, a better name for it would be the Privacy Coffin.
Why the hostility? Consider this: the European Court of Justice (ECJ) killed Safe Harbour in October when it ruled that, essentially, the US was more interested in national security and law enforcement matters (also known as snooping the bejesus out of everyone) over and above any guarantees of meaningful privacy.
Since then, absolutely nothing has changed.
The Privacy Shield framework requires the US to give a written promise, on a yearly basis, that hand-on-heart it won't participate in mass surveillance of EU citizens.
This is laudable in principle and laughable in practice.
Any talk of 'clear limitations and safeguards', and most of all 'oversight mechanisms', in the context of the NSA is, frankly, a crock. Not least because the US explicitly allows mass surveillance of the very kind it's promising not to carry out.
The NSA doesn't consider it mass surveillance if they collect the data, only if they analyse it. But calling it something different does not mean it's not happening.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Seriously, replacing one fundamentally flawed framework with another and giving it a new X-Men movie name does not fix the problem. That problem being that neither the EU, UK nor the US actually gives a flying feck about your privacy.
At best, this optimistically-named Privacy Shield is nothing more than a stop-gap solution. It will enable the transatlantic data flow to, erm, flow once more. But not for long. I imagine the ECJ will take a long, hard look at the agreement and announce it, too, as invalid.
What really worries me, and should worry you as well, if this is a stop-gap, a temporary measure to ensure that data keeps flowing; is what comes next?
If, as I suspect, it will be more of the same political manoeuvring rather than something that really addresses the matter of data privacy in the post-Snowden era, then we are all screwed. Or, more accurately, we will continue to be screwed.
As long as we continue to take government agencies on both sides of the pond at their word when it comes to what they can and cannot spy upon, then nothing will change.
My advice, therefore, remains the same as it has always been: encrypt your data up the wazoo and manage your own keys to close the snooping opportunity window.
Davey is a three-decade veteran technology journalist specialising in cybersecurity and privacy matters and has been a Contributing Editor at PC Pro magazine since the first issue was published in 1994. He's also a Senior Contributor at Forbes, and co-founder of the Forbes Straight Talking Cyber video project that won the ‘Most Educational Content’ category at the 2021 European Cybersecurity Blogger Awards.
Davey has also picked up many other awards over the years, including the Security Serious ‘Cyber Writer of the Year’ title in 2020. As well as being the only three-time winner of the BT Security Journalist of the Year award (2006, 2008, 2010) Davey was also named BT Technology Journalist of the Year in 1996 for a forward-looking feature in PC Pro Magazine called ‘Threats to the Internet.’ In 2011 he was honoured with the Enigma Award for a lifetime contribution to IT security journalism which, thankfully, didn’t end his ongoing contributions - or his life for that matter.
You can follow Davey on Twitter @happygeek, or email him at davey@happygeek.com.
-
UK businesses patchy at complying with data privacy rules
News Companies need clear and well-defined data privacy strategies
By Emma Woollacott
-
Data privacy professionals are severely underfunded – and it’s only going to get worse
News European data privacy professionals say they're short of cash, short of skilled staff, and stressed
By Emma Woollacott
-
Four years on, how's UK GDPR holding up?
News While some SMBs are struggling, most have stepped up to the mark in terms of data governance policies
By Emma Woollacott
-
Multicloud data protection and recovery
whitepaper Data is the lifeblood of every modern business, but what happens when your data is gone?
By ITPro
-
Intelligent data security and management
whitepaper What will you do when ransomware hits you?
By ITPro
-
How to extend zero trust to your cloud workloads
Whitepaper Implement zero trust-based security across your entire ecosystem
By ITPro
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro
-
Why The Matrix offers valuable lessons on data sovereignty for channel partners
Industry Insight Two decades on, there's much that the Matrix series can teach channel partners about data sovereignty
By David Devine