• Login· Join/Renew
  • Legal Resources
  • Education
  • Community
  • About ACC
  • Careers
  • ACC Value Challenge
  • Chapters
  • Committees
  • Advocacy

Legal Resources

QuickCounsel


Data Privacy and Protection: EU as Compared with U.S.

Overview
EU Directive
Personal Data
Employee Data
Compliance
Additional Resources

Rate this QuickCounsel

Overview

Data Protection laws in the European Union, Canada, and other countries, require companies to ensure they take appropriate steps to safeguard personal information both in their possession and being processed on their behalf. While in the U.S. the approach towards data privacy tends to deal with industry-wide legislation and regulation, or even self-regulation, outside of the U.S., there are often specific laws which govern the control and processing of any personal information.

Back to top

EU Directive

Laws in other jurisdictions are often more stringent than in the U.S. An example of a data protection law that differs from the U.S. approach is the European Union Directive 95/46/EC ("EU Directive"). Among the basic principles of the EU Directive are:

  • For all data collected there should be a stated purpose and such information cannot be disclosed unless authorized by law or by consent of the individual.
  • Records kept on an individual should be accurate and up-to-date and mechanisms should be provided to allow individuals to review data about them, to ensure accuracy.
  • Data should be deleted when it is no longer needed for the stated purpose.
  • Transmission of personal data to locations where "equivalent" personal data protection cannot be assured is prohibited.
  • Some data is too sensitive to be collected (e.g., sexual orientation, religion), unless there are extreme circumstances.

Back to top

“Personal Data”

“Personal data” is data about a living individual from which an individual can be identified and is genuinely viewed more broadly in the EU than in the U.S. Two separate pieces of information (things such as an address on a Christmas card list, a photo i.d., work telephone numbers or expense reimbursement data), which if put together can be used to identify a particular individual, can constitute “personal data” under the EU Directive.

Under the EU Directive, the prohibited transfer of personal data to countries which do not have in place adequate protection for personal information means transfer to the U.S. is prohibited, unless other mechanisms are put in place to ensure the EU-required level of protection. Consent of the individual may be one such mechanism, but some EU members deem consent from an employee not to be freely given and therefore not valid. Voluntary compliance with certain Safe Harbor principles is another mechanism. Model contract clauses and approved binding Intra-Group Rules are other mechanisms which might be employed.

Back to top

Employee Data

Employees have certain rights and must be informed of the information being collected, the purposes for which it is being used, and any information transferred outside of the EU. The EU Directive (as individually implemented by the member states of the EU) will apply to companies on various occasions, in particular when information is being processed on equipment located in Europe, if a company has an office located within the EU or if the company has customers in the EU.

The EU Directive applies to both electronically stored and manually stored information and it applies to potential employees, existing employees, customers, suppliers and any individuals the company may come in contact with.

Back to top

Compliance

Failure to comply with the EU Directive can result in investigation by the local data protection agency and the levying of fines. Employee relations can suffer and leave the company in a weak position in negotiating with Works Councils or trade unions. Potential criminal sanctions for a company and possibly for individual officers are other good reasons to ensure compliance.

Noncompliance can also result in bad publicity, which can even damage share prices. And regarding customer information, it is important to be data protection compliant for many reasons, not the least of which is in preparation for a possible sale of the company. If the database of the company is not lawful, the price can be negatively impacted.

Sample data protection policies of multinational companies reflect certain considerations that are personal to the company, but most include an assessment of the company’s personal information practices, the implementation of detailed internal policies and the establishment of clear lines of responsibility for privacy. Contracts with service providers need to be evaluated and address privacy issues. Regular assessments to verify compliance are recommended.

Back to top

Additional Resources

ACC Resources


  • ACC InfoPAK:
  • Data Protection – A Practical Guide to Personal Data Transfer Laws in the Asia/Pacific Region, Canada, Europe and the United States(2006)
  • ACC Annual Meeting Programs:
  • International Privacy Law (2004)
  • Pitfalls & Landmines in Privacy & the Collection, Use, & Security of Personal Information (2005)
  • ACC Program Material:
  • Privacy Law: Tips for Keeping Your Company out of the Headlines (2008)
  • ACC Docket:
  • Keeping Secrets, the Growing Challenge of Protecting Data in Outsourcing and Service Provider Arrangements (Nov/Dec 2004)
  • Clash of the Titans, Complying with US Whistle-blowing Requirements while Respecting EU Privacy Rights (April 2006)
  • The Nuts and Bolts of the EU Safe Harbor (Nov.2009)
  • ACC Webcast Transcript:
  • Data Privacy in Europe – the Essentials (June 15, 2006)
  • ACC Sample Form and Policy:
  • EU Employee Data Privacy Policy, (Dec.2007)
  • Safe Harbor Employee Privacy Policy (Oct. 2007)
  • Data Protection Policy (2007)
  • ACC Leading Practice Profiles:
  • Privacy and Data Protection: What Companies are Doing (Jan. 2006)
  • ACC Survey:
  • Global Privacy Law, A Survey of 15 Major Jurisdictions, (April 2003)

Have an idea for a quickcounsel or interested in writing one?

  • Submit your ideas by filling out our online topic proposal form.
The information in this QuickCounsel should not be construed as legal advice or legal opinion on specific facts and should not be considered representative of the views of its authors, its sponsors, and/or the ACC. This QuickCounsel is not intended as a definitive statement on the subject addressed. Rather, it is intended to serve as a tool providing practical advice and references for the busy in-house practitioner and other readers.


Back to top

Published April 14, 2010

Download PDF

Login to rate this document

Download PDF

 

Share  

Questions?

Contact legalresources@acc.com
phone:01- 202-293-4103
ext. 456

additional tools

International Legal Affairs Committee

Get the latest information on international business affairs and legal resources from your professional peers. Once you're a member of the committee you're eligible to join the eGroup where you can pose your questions to hundreds of your colleagues and get the assistance you need.

IT, Privacy & eCommerce Committee

Covers information technology, privacy, data protection, ecommerce, outsourcing, the Internet and related areas.

Join the committee
Join the eGroup

ACC Newsstand

Sign up for the ACC Newsstand, a daily newsfeed, tailored to your chosen practice areas, providing you with a depth of free practical know-how. Look for news items and stories related to the topic discussed in this QuickCounsel.

Find a Member

Search by expertise and find an ACC Member with in-depth knowledge of the topic discussed in this QuickCounsel who is willing to help.

Browse ACC Resources By
Practice Area
  • Commercial
  • Compliance & Ethics
  • Corporate, Securities & Governance
  • Employment & Labor
  • Energy/Public Utility
  • Environmental
  • Financial Services
  • Government
  • Insurance
  • Intellectual Property
  • International
  • Law Department Management
  • Litigation
  • Media/Publishing
  • Real Estate
  • Technology
Region
  • Africa
  • Asia
  • Australia/Pacific
  • Caribbean/Central America
  • Europe
  • Middle East
  • North America
  • South America
Resource Type
  • Amicus Briefs
  • Forms & Policies
  • Online Education
  • Policy Statements
  • Practice Examples
  • Presentations
  • Primers
  • Publications
  • Quick References
  • Surveys
Advocacy Key Issues
  • Disparate Treatment
  • Gatekeeping/Liability
  • Legal Ethics
  • Multijurisdictional Practice
  • Privilege Protection





  • Home
  • Legal
  • About ACC
  • FAQs
  • Advertising & Sponsorships
  • Site Map
  • Contact Us

©Copyright 1998–2012 All rights reserved.     Reprint Request