home.social

#dataprivacyframework — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dataprivacyframework, aggregated by home.social.

  1. 🗽 Gestern fand unser #DatenschutzDiskurs zu EU-US-Datentransfers beim Bitkom statt.

    Prof. Dr. Lothar Determann erklärte, inwiefern Unternehmen in Europa nunmehr auch Datentransferbeschränkungen nach US-Bundesrecht einhalten müssen.

    Hier geht es zur Aufzeichnung: stiftungdatenschutz.org/verans

    #TeamDatenschutz #DSDiskurs #DataPrivacyFramework

  2. Ultim'ora (pessima): La 2a corte suprema d'Europa si è espressa positivamente sul #DataPrivacyFramework stipulato tra UE e USA

    "Così facendo, si conferma che, alla data di adozione della decisione impugnata, gli Stati Uniti d'America garantivano un livello adeguato di protezione dei dati personali trasferiti dall'Unione europea alle organizzazioni di tale paese", ha aggiunto il Tribunale con sede in Lussemburgo.

    #SchremsII #DPF #privacy

    reuters.com/sustainability/boa

    @privacypride

  3. Die Bundesdatenschutzbeauftragte (@bfdi) Louisa Specht-Riemenschneider im Spiegel-Interview mit @publictorsten und Marcel Rosenbach u. a. zu digitaler Souveränität:

    > Ich verstehe ehrlicherweise nicht, warum wir uns überhaupt in diese Abhängigkeit begeben haben (…) Ich würde mich aktuell nicht darauf verlassen, dass das bisherige #DataPrivacyFramework für immer hält.

    (€) spiegel.de/netzwelt/netzpoliti (18.04.2025)

    #Datenschutz #privacy #DPF #TADPF #DigitaleSouveranitat #TeamDatenschutz

  4. Jede Wette, dass das „EU-US Data Privacy Framework“ – das Datenschutzabkommen zwischen EU und USA – noch dieses Jahr kippt. Ein Feigenblatt, das nie echten Datenschutz geboten hat. 🍃

    #dataprivacy #datenschutz #privacy #DataPrivacyFramework #dsgvo #fail

  5. Euractiv berichtet über mögliches Ende legaler Datentransfers in die USA. 🔗 euractiv.com/section/tech/news

    @privacyDE:

    „Organisationen, die sich auf das #DataPrivacyFramework (DPF) stützen, sollten rechtzeitig Standardvertragsklauseln für Datentransfers in die USA vorbereiten. Eine Annullierung des #DPF sollte sie nicht unvorbereitet treffen.

    Auch bei SCC ist fraglich, ob Maßnahmen hinreichenden Schutz der Grundrechte und -freiheiten betroffener Personen gewährleisten können.“

    #TeamDatenschutz

  6. Ujawniony list do Komisji Europejskiej sugeruje niepewną przyszłość umowy dotyczącej przekazywania danych między UE a USA

    Istnieje niepotwierdzone jeszcze ryzyko, że usługi mające swój zarząd w Stanach Zjednoczonych mogą zostać zamknięte w krajach Unii Europejskiej, gdyby Data Privacy Framework w obecnej postaci upadł.

    kontrabanda.net/r/ujawniony-li

    #DataPrivacyFramework #Facebook #Instagram #KomisjaEuropejska #MetaPlatforms #Signal #StanyZjednoczone #WikimediaFoundation #Wikipedia #YouTube

  7. So weit so unschön. Seit Montag ist #trump im Amt. Der hat ein (bis dahin) unabhängiges Kontrollgremium welches für das #dataprivacyframework essentiell ist zum Rücktritt aufgefordert: noyb.eu/en/us-cloud-soon-illeg

    Wir wissen: die wütende Orange macht ernst. Und zerstört gern Dinge, auch wenn sie zum Vorteil der USA waren. Das Abkommen war fragwürdig, aber für beide Seiten praktisch.

    2/3 Auswirkungen ⤵️

  8. 🇪🇺↔️🇺🇸 🕵🏽‍♀️

    #PCLOB is also instrumental in implementing an agreement between the U.S. and European Union that allows businesses to transfer Europeans' data to the United States.”

    The White House has requested that the three Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB) resign by end of day Thursday or face termination, a source close to the agency confirmed.

    axios.com/2025/01/22/white-hou

    #privacy #datatransfer #edpb #dataprivacyframework

  9. Sedan 2023 har vi kunnat luta oss mot EU-US Data Privacy Framework för att överföra personuppgifter till amerikanska företag. Avtalet har varit tveksamt och Max Schrems (som fick avtalets två föregångare ogiltigförklarade) har varit minst sagt skeptisk till det. Nu verkar det tyvärr som att USA själva äventyrar avtalets giltighet.

    noyb.eu/en/us-cloud-soon-illeg

    #Noyb #Schrems #DataPrivacyFramework #GDPR

  10. Är vi redo att Trump river upp Executive Order 14086 och gör Data Privacy Framework ogiltigt?

    Kanske är detta en bloggpost som målar fan på väggen, men DPF står inte på en särskilt stabil grund.
    #DPF #DataPrivacyFramework #GDPR

    webperf.se/articles/trump-2025

  11. Finally exchange data securely and efficiently between the USA and Switzerland – the new Swiss-US Data Privacy Framework makes it possible. 🔐✅

    Companies in this country can now be sure that the exchange of data with America is legally secure and less costly. ⚖️🇨🇭

    In addition, compliance requirements are simplified and competitiveness is strengthened through the simplified and more efficient exchange of data. 📈🇺🇸

    #dataprivacyframework #swissus #dataexchange #dataprotection #nine

  12. @br_data @netzpolitik_feed @cutterkom @rebeccacie @roofjoke @sebmeineck @robsh

    Soso, europäische Gesetze gelten also nicht für außereuropäische Konzerne? 🤔

    Das würde ja bedeuten, dass #SafeHarbor #PrivacyShield und #DataPrivacyFramework auf Treibsand gebaut sind und ein politisch motivierter #Angemessenheitsbeschluss maximal unangemessen ist, ... 🤷‍♂️

    Und was war noch gleich mit den betriebssystemeigenen #Telemetriedaten bei #iOS #Android #Windows #MS365, die die Anbieter "zu eigenen Zwecken" missbrauchen ... ?

    Die #NationaleSicherheit ist bedroht, aber #Lobbyisten und #Geheimdienste haben durch den Status quo mehr Vorteile, als die Sicherheit der Bürger, Beamten und Mitarbeiter rechtfertigen könnte.

    Ich erwarte also leider, dass nach dieser Recherche / Veröffentlichung politisch exakt gar nichts geschieht. 🤷‍♂️
    So, wie bei Snowden.
    Außer natürlich: Die Bundesregierung verklagt den BfDI und die Europäische Kommission den EDSB.

    Europa ist eine unmündige digitale Kolonie.

  13. Is anyone familiar with #GloFox / #Zappy app, and its #DataProtection practices?

    They appear to be based in Texas, and neither GloFox nor Zappy are listed on the #DataPrivacyFramework participant search, and standard contractual clauses only get a brief passing mention on their Privacy Statement page.

    A Dublin gym is asking me to use the GloFox app for payments and appointment scheduling.

    #MastoDaoine #GDPR

  14. @DerKurhesse Ja, da ändert sich nichts.

    Selbst für #ZoomX steht in den Ergänzenden Bestimmungen Auftragsverarbeitung, dass #Zoom Video Communications Inc. aus San Jose, Kalifornien, USA ein "vom Kunde genehmigter Unterauftragsverarbeiter" für "Hosting & Betrieb" ist, allerdings fehlt dafür die #DataPrivacyFramework-Zertifizierung.

    Ein bisschen Firefox-Network-Debugger offenbart, dass Nutzername und Mail an app.zoom.us gesendet werden, dahinter steckt zoom und nicht die #Telekom

    #BBA #BBA23

  15. @DerKurhesse Ja, da ändert sich nichts.

    Selbst für #ZoomX steht in den Ergänzenden Bestimmungen Auftragsverarbeitung, dass #Zoom Video Communications Inc. aus San Jose, Kalifornien, USA ein "vom Kunde genehmigter Unterauftragsverarbeiter" für "Hosting & Betrieb" ist, allerdings fehlt dafür die #DataPrivacyFramework-Zertifizierung.

    Ein bisschen Firefox-Network-Debugger offenbart, dass Nutzername und Mail an app.zoom.us gesendet werden, dahinter steckt zoom und nicht die #Telekom

    #BBA #BBA23

  16. @DerKurhesse Ja, da ändert sich nichts.

    Selbst für #ZoomX steht in den Ergänzenden Bestimmungen Auftragsverarbeitung, dass #Zoom Video Communications Inc. aus San Jose, Kalifornien, USA ein "vom Kunde genehmigter Unterauftragsverarbeiter" für "Hosting & Betrieb" ist, allerdings fehlt dafür die #DataPrivacyFramework-Zertifizierung.

    Ein bisschen Firefox-Network-Debugger offenbart, dass Nutzername und Mail an app.zoom.us gesendet werden, dahinter steckt zoom und nicht die #Telekom

    #BBA #BBA23

  17. @DerKurhesse Ja, da ändert sich nichts.

    Selbst für #ZoomX steht in den Ergänzenden Bestimmungen Auftragsverarbeitung, dass #Zoom Video Communications Inc. aus San Jose, Kalifornien, USA ein "vom Kunde genehmigter Unterauftragsverarbeiter" für "Hosting & Betrieb" ist, allerdings fehlt dafür die #DataPrivacyFramework-Zertifizierung.

    Ein bisschen Firefox-Network-Debugger offenbart, dass Nutzername und Mail an app.zoom.us gesendet werden, dahinter steckt zoom und nicht die #Telekom

    #BBA #BBA23

  18. @DerKurhesse Ja, da ändert sich nichts.

    Selbst für #ZoomX steht in den Ergänzenden Bestimmungen Auftragsverarbeitung, dass #Zoom Video Communications Inc. aus San Jose, Kalifornien, USA ein "vom Kunde genehmigter Unterauftragsverarbeiter" für "Hosting & Betrieb" ist, allerdings fehlt dafür die #DataPrivacyFramework-Zertifizierung.

    Ein bisschen Firefox-Network-Debugger offenbart, dass Nutzername und Mail an app.zoom.us gesendet werden, dahinter steckt zoom und nicht die #Telekom

    #BBA #BBA23

  19. #Daten sind schnell um den Globus geschickt. Doch wann ist das erlaubt? Dürfen dafür #Dienstleistungen von US-Unternehmen in Anspruch genommen werden? Und was ändert sich mit dem #Angemessenheitsbeschluss zum #DataPrivacyFramework? Dies erfahren Sie in unserer Start-up-Schule:

    Donnerstag, 5. Oktober 2023, 11-13 Uhr
    "#Datenexporte: Geht's noch?"

    Anmeldung und weitere Informationen: 👉 datenschutz-berlin.de/themen/u

    #Datenschutz #Schulung #Startups #Vereine

  20. [de] Data Privacy. Von „Sicheren Häfen“, Schutz­schilden und Rahmenwerken

    "Dieser lücken­hafte Daten­schutz, der weit­ge­hend unre­gu­lierte Privat­sektor und eine schwache Aufsicht sind mithin Ursa­chen für die heutigen Probleme im Austausch mit der EU."

    geschichtedergegenwart.ch/data

    #dataprivacyframework #privacy #privatsphaere #datenschutz #dsg #datenschutzgesetz #gdpr #dsgvo #datasovereignty #datensouveraenitaet

  21. In unserer heutigen #DatenschutzWoche geht es u.a. um:

    ▫️ #EDPB: zum geplanten #DataPrivacyFramework, nächster Halt: @europarl_en
    ▫️ LfDI Sachsen-Anhalt abwägend zu #MS365#Microsoft
    ▫️ Norwegen: #GoogleAnalytics verstößt gegen #DSGVO
    ▫️ LG Mannheim zur Löschung aus System d. dt. #Versicherungswirtschaft
    ▫️ @bfdi veröffentlicht FAQ zu #TrustPID

    Alle #Datenschutz-News von @stefan_hessel lesen:
    sds-links.de/DSW79

    📨 Als Newsletter per E-Mail-bestellen:
    sds-links.de/Anmeldung-Datensc

  22. Meanwhile, on the #GDPR front ...

    After the invalidation of the second US-EU framework, known as #PrivacyShield was invalidated by the European court in the #SchremsII decision, the US and EU eventually signed an agreement in principle, and a good while later, the US President issued an Executive Order framing a new #DataPrivacyFramework this fall.

    This week, the EU issued a draft #adequacy decision -- essentially, a recommendation that the new Framework be recognized as providing adequate protections for personal information of EU citizens if transmitted cross-border to the US. Many commentators have observed shortcomings of the Framework, and many businesses appear loath to plan for reliance on it. (Side note -- other jurisdictions around the world have data localization requirements without even the option to explore "adequacy" determinations. All in all, this approach leads to atomization of data; the pendulum has swung very far in one direction at the moment and I expect that over time things may settle down a bit.)

    At every step along the way, Mr. Schrems has indicated his skepticism and his organization (#NOYB - "None of Your Business") is reviewing the draft and is likely to challenge any final adequacy finding in court. (The final adequacy decision is expected next Spring.)

    An interesting development to close out this week is the announcement of a new #OECD agreement on safeguarding #privacy in #lawenforcement and #nationalsecurity data access. If this agreement comes close to the headline -- and means what it says, and says what it means, and member states (including the US) go home and fiddle with legislation (rather than Executive Orders -- some of which are not particularly long-lived), then maybe we have a fighting chance of working towards true "adequacy."

    Links to all four of these gems below.

    What do you think?

    #data #business #dataprivacy #dataprivacylaw #digitalhealth #hcldr #HITsm #HarlowOnHC

    Data Privacy Framework:
    whitehouse.gov/briefing-room/s

    Draft Adequacy Decision: ec.europa.eu/commission/pressc

    NOYB statement on draft decision:
    noyb.eu/en/statement-eu-comiss

    Statement on OECD agreement:
    oecd.org/newsroom/landmark-agr

  23. Meanwhile, on the #GDPR front ...

    After the invalidation of the second US-EU framework, known as #PrivacyShield was invalidated by the European court in the #SchremsII decision, the US and EU eventually signed an agreement in principle, and a good while later, the US President issued an Executive Order framing a new #DataPrivacyFramework this fall.

    This week, the EU issued a draft #adequacy decision -- essentially, a recommendation that the new Framework be recognized as providing adequate protections for personal information of EU citizens if transmitted cross-border to the US. Many commentators have observed shortcomings of the Framework, and many businesses appear loath to plan for reliance on it. (Side note -- other jurisdictions around the world have data localization requirements without even the option to explore "adequacy" determinations. All in all, this approach leads to atomization of data; the pendulum has swung very far in one direction at the moment and I expect that over time things may settle down a bit.)

    At every step along the way, Mr. Schrems has indicated his skepticism and his organization (#NOYB - "None of Your Business") is reviewing the draft and is likely to challenge any final adequacy finding in court. (The final adequacy decision is expected next Spring.)

    An interesting development to close out this week is the announcement of a new #OECD agreement on safeguarding #privacy in #lawenforcement and #nationalsecurity data access. If this agreement comes close to the headline -- and means what it says, and says what it means, and member states (including the US) go home and fiddle with legislation (rather than Executive Orders -- some of which are not particularly long-lived), then maybe we have a fighting chance of working towards true "adequacy."

    Links to all four of these gems below.

    What do you think?

    #data #business #dataprivacy #dataprivacylaw #digitalhealth #hcldr #HITsm #HarlowOnHC

    Data Privacy Framework:
    whitehouse.gov/briefing-room/s

    Draft Adequacy Decision: ec.europa.eu/commission/pressc

    NOYB statement on draft decision:
    noyb.eu/en/statement-eu-comiss

    Statement on OECD agreement:
    oecd.org/newsroom/landmark-agr

  24. Meanwhile, on the #GDPR front ...

    After the invalidation of the second US-EU framework, known as #PrivacyShield was invalidated by the European court in the #SchremsII decision, the US and EU eventually signed an agreement in principle, and a good while later, the US President issued an Executive Order framing a new #DataPrivacyFramework this fall.

    This week, the EU issued a draft #adequacy decision -- essentially, a recommendation that the new Framework be recognized as providing adequate protections for personal information of EU citizens if transmitted cross-border to the US. Many commentators have observed shortcomings of the Framework, and many businesses appear loath to plan for reliance on it. (Side note -- other jurisdictions around the world have data localization requirements without even the option to explore "adequacy" determinations. All in all, this approach leads to atomization of data; the pendulum has swung very far in one direction at the moment and I expect that over time things may settle down a bit.)

    At every step along the way, Mr. Schrems has indicated his skepticism and his organization (#NOYB - "None of Your Business") is reviewing the draft and is likely to challenge any final adequacy finding in court. (The final adequacy decision is expected next Spring.)

    An interesting development to close out this week is the announcement of a new #OECD agreement on safeguarding #privacy in #lawenforcement and #nationalsecurity data access. If this agreement comes close to the headline -- and means what it says, and says what it means, and member states (including the US) go home and fiddle with legislation (rather than Executive Orders -- some of which are not particularly long-lived), then maybe we have a fighting chance of working towards true "adequacy."

    Links to all four of these gems below.

    What do you think?

    #data #business #dataprivacy #dataprivacylaw #digitalhealth #hcldr #HITsm #HarlowOnHC

    Data Privacy Framework:
    whitehouse.gov/briefing-room/s

    Draft Adequacy Decision: ec.europa.eu/commission/pressc

    NOYB statement on draft decision:
    noyb.eu/en/statement-eu-comiss

    Statement on OECD agreement:
    oecd.org/newsroom/landmark-agr

  25. Meanwhile, on the #GDPR front ...

    After the invalidation of the second US-EU framework, known as #PrivacyShield was invalidated by the European court in the #SchremsII decision, the US and EU eventually signed an agreement in principle, and a good while later, the US President issued an Executive Order framing a new #DataPrivacyFramework this fall.

    This week, the EU issued a draft #adequacy decision -- essentially, a recommendation that the new Framework be recognized as providing adequate protections for personal information of EU citizens if transmitted cross-border to the US. Many commentators have observed shortcomings of the Framework, and many businesses appear loath to plan for reliance on it. (Side note -- other jurisdictions around the world have data localization requirements without even the option to explore "adequacy" determinations. All in all, this approach leads to atomization of data; the pendulum has swung very far in one direction at the moment and I expect that over time things may settle down a bit.)

    At every step along the way, Mr. Schrems has indicated his skepticism and his organization (#NOYB - "None of Your Business") is reviewing the draft and is likely to challenge any final adequacy finding in court. (The final adequacy decision is expected next Spring.)

    An interesting development to close out this week is the announcement of a new #OECD agreement on safeguarding #privacy in #lawenforcement and #nationalsecurity data access. If this agreement comes close to the headline -- and means what it says, and says what it means, and member states (including the US) go home and fiddle with legislation (rather than Executive Orders -- some of which are not particularly long-lived), then maybe we have a fighting chance of working towards true "adequacy."

    Links to all four of these gems below.

    What do you think?

    #data #business #dataprivacy #dataprivacylaw #digitalhealth #hcldr #HITsm #HarlowOnHC

    Data Privacy Framework:
    whitehouse.gov/briefing-room/s

    Draft Adequacy Decision: ec.europa.eu/commission/pressc

    NOYB statement on draft decision:
    noyb.eu/en/statement-eu-comiss

    Statement on OECD agreement:
    oecd.org/newsroom/landmark-agr

  26. Meanwhile, on the #GDPR front ...

    After the invalidation of the second US-EU framework, known as #PrivacyShield was invalidated by the European court in the #SchremsII decision, the US and EU eventually signed an agreement in principle, and a good while later, the US President issued an Executive Order framing a new #DataPrivacyFramework this fall.

    This week, the EU issued a draft #adequacy decision -- essentially, a recommendation that the new Framework be recognized as providing adequate protections for personal information of EU citizens if transmitted cross-border to the US. Many commentators have observed shortcomings of the Framework, and many businesses appear loath to plan for reliance on it. (Side note -- other jurisdictions around the world have data localization requirements without even the option to explore "adequacy" determinations. All in all, this approach leads to atomization of data; the pendulum has swung very far in one direction at the moment and I expect that over time things may settle down a bit.)

    At every step along the way, Mr. Schrems has indicated his skepticism and his organization (#NOYB - "None of Your Business") is reviewing the draft and is likely to challenge any final adequacy finding in court. (The final adequacy decision is expected next Spring.)

    An interesting development to close out this week is the announcement of a new #OECD agreement on safeguarding #privacy in #lawenforcement and #nationalsecurity data access. If this agreement comes close to the headline -- and means what it says, and says what it means, and member states (including the US) go home and fiddle with legislation (rather than Executive Orders -- some of which are not particularly long-lived), then maybe we have a fighting chance of working towards true "adequacy."

    Links to all four of these gems below.

    What do you think?

    #data #business #dataprivacy #dataprivacylaw #digitalhealth #hcldr #HITsm #HarlowOnHC

    Data Privacy Framework:
    whitehouse.gov/briefing-room/s

    Draft Adequacy Decision: ec.europa.eu/commission/pressc

    NOYB statement on draft decision:
    noyb.eu/en/statement-eu-comiss

    Statement on OECD agreement:
    oecd.org/newsroom/landmark-agr

  27. The European Parliament's Committee on Civil Liberties, Justice and Home Affairs ("LIBE") released a draft resolution that does not look very kindly on the US attempt to support an adequacy determination under GDPR through an Executive Order. (It points out all the things it finds lacking in the US attempt at creating a new data privacy framework - no surprises here.) If this is indicative of the final outcome at the Commission (please, no wagering ;) ), Mr Schrems will be happy... and many of us will continue to work under the assumption that this is all going nowhere fast. Among the many failings noted: The US does not have a federal privacy law. #ADPPA was on the table in the last Congress. Are nudges from #POTUS at the #SOTU and from the #EU going to be sufficient to get the ball rolling again? Would any such law comprehensively address the outstanding concerns re: adequacy? Does failure to adopt such a law harm the global economic position of the US in the near term or in the long term? What other issues are raised by this development or by an eventual negative finding re: adequacy? #GDPR #adequacy #LIBE #DPF #dataprivacyframework #dataprivacy #privacy #data #personaldata #personaldataprotection #dataprotection #schremsii #schremsiii #EU #IAPP europarl.europa.eu/doceo/docum

  28. Noch sind ein paar Plätze frei bei unserem Webinar #DatenschutzAmMittag am Dienstag, 14. März 2023, 15:00 Uhr.

    Diesmal informieren Barbara Schmitz und Dr. Axel Spies über den Stand der Dinge beim #Datentransfer in die USA und den California Consumer #Privacy Act (#CCPA).
    Wie schnell wird das #DataPrivacyFramework nutzbar sein? Warten oder Contractual Clauses (#SCC) nutzen? #Datenschutz #TeamDatenschutz

    Gern Fragen mitbringen.

    Wie immer: kostenfrei und online. Anmelden:
    sds-links.de/we4

  29. @lrhodes
    In order for the #adequacydecision to to be effective, #EO14086 needs to be respected and implemented by the US intelligence agencies.

    However, the relevant “procedures” for NSA (No. 4), CIA (Sec. II, G) and FBI (Sec. IV) contain the avenue to generally “depart” from the safeguards provided for in #EO14086.

    A clear assessment on what US intelligence agencies are allowed to do under the #DataPrivacyFramework would – again – not be possible anymore.

    #DPF

    intel.gov/ic-on-the-record-dat

  30. @heiseonline
    Vor dem Beschluss muss Executive Order #EO14086 bei den US-Sicherheitsbehörden umgesetzt werden. Die entsprechenden “Procedures” enthalten für NSA (Nr. 4), CIA (Sec. II, G) und FBI (Sec. IV) jedoch die Möglichkeit,  eigenständig von den Vorgaben und dem Schutz der EO14086 abzuweichen.

    Eine wirklich verlässliche Aussage, welche Vorgaben für US-Behörden unter dem #DPF nun gelten, ist dadurch (wieder) nicht möglich.
    #DataPrivacyFramework #adequacy #ECJ #DSGVO

    intel.gov/ic-on-the-record-dat

  31. 🎙️In der neuen Folge #Weggeforscht diskutieren Ole-Christian Tech & Klaus Palenberg, Forschungsstelle #RechtimDFN⚖️an der #WWUMünster, über den Angemessenheitsbeschluss zum neuen Datenschutzrahmen zwischen @EU_Commission & USA #DataPrivacyFramework👉podcasters.spotify.com/pod/sho