Privacy Shield hammers another nail in the coffin of data protection

Safe Harbour’s replacement is based entirely on trust - what a big mistake

Safe Harbour is dead, long live the Privacy Shield. Although, to be honest, the all-new US data transfer agreement is already a dead man walking if you ask me. Indeed, a better name for it would be the Privacy Coffin.

Why the hostility? Consider this: the European Court of Justice (ECJ) killed Safe Harbour in October when it ruled that, essentially, the US was more interested in national security and law enforcement matters (also known as snooping the bejesus out of everyone) over and above any guarantees of meaningful privacy.

Since then, absolutely nothing has changed.

The Privacy Shield framework requires the US to give a written promise, on a yearly basis, that hand-on-heart it won't participate in mass surveillance of EU citizens.

This is laudable in principle and laughable in practice.

Any talk of 'clear limitations and safeguards', and most of all 'oversight mechanisms', in the context of the NSA is, frankly, a crock. Not least because the US explicitly allows mass surveillance of the very kind it's promising not to carry out.

The NSA doesn't consider it mass surveillance if they collect the data, only if they analyse it. But calling it something different does not mean it's not happening. 

Seriously, replacing one fundamentally flawed framework with another and giving it a new X-Men movie name does not fix the problem. That problem being that neither the EU, UK nor the US actually gives a flying feck about your privacy.

At best, this optimistically-named Privacy Shield is nothing more than a stop-gap solution. It will enable the transatlantic data flow to, erm, flow once more. But not for long. I imagine the ECJ will take a long, hard look at the agreement and announce it, too, as invalid.

What really worries me, and should worry you as well, if this is a stop-gap, a temporary measure to ensure that data keeps flowing; is what comes next? 

If, as I suspect, it will be more of the same political manoeuvring rather than something that really addresses the matter of data privacy in the post-Snowden era, then we are all screwed. Or, more accurately, we will continue to be screwed.

As long as we continue to take government agencies on both sides of the pond at their word when it comes to what they can and cannot spy upon, then nothing will change.

My advice, therefore, remains the same as it has always been: encrypt your data up the wazoo and manage your own keys to close the snooping opportunity window.

Featured Resources

The ultimate law enforcement agency guide to going mobile

Best practices for implementing a mobile device program

Free download

The business value of Red Hat OpenShift

Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShift

Free download

Managing security and risk across the IT supply chain: A practical approach

Best practices for IT supply chain security

Free download

Digital remote monitoring and dispatch services’ impact on edge computing and data centres

Seven trends redefining remote monitoring and field service dispatch service requirements

Free download

Recommended

Senators urge FTC to enforce child privacy laws
privacy

Senators urge FTC to enforce child privacy laws

8 Oct 2021
Are you over-sharing online?
social media

Are you over-sharing online?

1 Sep 2021
What is customer identity and access management? 
identity and access management (IAM)

What is customer identity and access management? 

19 Aug 2021
Pearson fined $1 million for downplaying severity of 2018 breach
data breaches

Pearson fined $1 million for downplaying severity of 2018 breach

17 Aug 2021

Most Popular

Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
HPE wins networking contract with Birmingham 2022 Commonwealth Games
Network & Internet

HPE wins networking contract with Birmingham 2022 Commonwealth Games

15 Oct 2021
What is cyber warfare?
Security

What is cyber warfare?

15 Oct 2021