What happens in Europe, doesn't stay in Europe: US giants accused of breaking EU privacy pact

Campaigners file complaint with watchdog FTC

Intelligent flash storage arrays

More than 30 big US tech firms are breaking international agreed-upon US-EU Safe Harbor commitments to safeguard Europeans’ data, according to a complaint filed with the US Federal Trade Commission (FTC) on Thursday.

The Washington-based Center for Digital Democracy (CDD) claims tech giants such as AOL, Adobe, Salesforce, Datalogix, Marketo, BlueKai, Criteo, Merkle and others are ignoring their promise to keep EU citizens’ data private – as opposed to sharing it with other organisations.

None of these companies have responded to requests for comment, but we'll update when we hear more. The CDD claims "these companies are compiling, using, and sharing EU consumers’ personal information without their awareness and meaningful consent, in violation the Safe Harbor framework."

The Safe Harbor agreement is a legally enforceable but voluntary "code of conduct" for US businesses that process European citizens’ data. The bilateral deal was reached in 2000 and is supposed to guarantee Europeans data privacy in line with the 1995 EU Data Protection Directive, but following the Snowden revelations last year, many don’t believe it is worth the paper it’s printed on.

The deal let the US off the hook of having to comply with data privacy adequacy requirements for transferring data outside the EU and instead allowed companies to sign up to the agreement on a case-by-case basis. Currently 4,767 companies have so far signed up.

These companies are then authorised to display a logo showing that they are part of the scheme and the rules can be legally enforced. But last year Galexia, an Australian-based consulting company on internet law and privacy, carried out research into the Safe Harbor membership scheme and claimed it had found that around one in every seven claims is false.

According to the CDD, the 30-odd companies in the complaint are actively involved in “data profiling”.

“Our investigation found that many of the companies are involved with a web of powerful multiple data broker partners who, unknown to the EU public, pool their data on them so they can be profiled and targeted online," said CDD executive director, Jeff Chester.

The group has also claimed that the FTC is failing to enforce the Safe Harbor rules. Compiling, using and sharing EU consumers' personal information without their awareness, consent, or ability to opt out is in violation the Safe Harbor framework. In such cases the FTC could enforce sanctions.

Representatives of the EU and US are currently in negotiations to create a new, so-called data privacy “umbrella agreement” which would – possibly – give Europeans the same rights of redress as American citizens if their data is used inappropriately.

In the meantime, many in the European Parliament have called for the Safe Harbor agreement to be suspended. Following an investigation into the NSA spying revelations last year, the parliament voted to suspend the deal, but the European Commission, which would have to act on such a vote, has not done so, preferring instead to continue the “umbrella” negotiations.

Claude Moraes, Labour MEP for London, and now head of the European Parliament’s civil liberties committee, said that Safe Harbor was very far from safe and should be thrown out.

The CDD added:

Among the companies covered are data broker companies with reams of for-sale sensitive information on individual consumers, data management platforms that allow customers to rapidly analyse their own consumer information and combine it with outside data sources to produce marketing insights, and mobile marketers that track devices and tie them to user profiles so as to sell customers the most profitable consumers’ attention.


Internet Security Threat Report 2014

More from The Register

next story
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Lords take revenge on REVENGE PORN publishers
Jilted Johns and Jennies with busy fingers face two years inside
Yes, yes, Steve Jobs. Look what I'VE done for you lately – Tim Cook
New iPhone biz baron points to Apple's (his) greatest successes
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
prev story


Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.