03/02/2020
CURIA - Documents
3.
The Member States and the Commission shall also inform each other of cases where the action of bodies
responsible for ensuring compliance with the Principles implemented in accordance with the FAQs in the United
States fails to secure such compliance.
4.
If the information collected under paragraphs 1, 2 and 3 provides evidence that any body responsible for
ensuring compliance with the Principles implemented in accordance with the FAQs in the United States is not
effectively fulfilling its role, the Commission shall inform the US Department of Commerce and, if necessary,
present draft measures in accordance with the procedure referred to in Article 31 of Directive 95/46/EC with a view
to reversing or suspending the present Decision or limiting its scope.
Article 4
1.
This Decision may be adapted at any time in the light of experience with its implementation and/or if the
level of protection provided by the Principles and the FAQs is overtaken by the requirements of US legislation.
The Commission shall in any case evaluate the implementation of the present Decision on the basis of available
information three years after its notification to the Member States and report any pertinent findings to the
Committee established under Article 31 of Directive 95/46/EC, including any evidence that could affect the
evaluation that the provisions set out in Article 1 of this Decision provide adequate protection within the meaning of
Article 25 of Directive 95/46/EC and any evidence that the present Decision is being implemented in a
discriminatory way.
2.
The Commission shall, if necessary, present draft measures in accordance with the procedure referred to in
Article 31 of Directive 95/46/EC.’
Annex I to Decision 2000/520 is worded as follows:
‘Safe Harbour Privacy Principles
issued by the US Department of Commerce on 21 July 2000
... the Department of Commerce is issuing this document and Frequently Asked Questions (“the Principles”) under
its statutory authority to foster, promote, and develop international commerce. The Principles were developed in
consultation with industry and the general public to facilitate trade and commerce between the United States and
European Union. They are intended for use solely by US organisations receiving personal data from the European
Union for the purpose of qualifying for the safe harbour and the presumption of “adequacy” it creates. Because the
Principles were solely designed to serve this specific purpose, their adoption for other purposes may be
inappropriate. …
Decisions by organisations to qualify for the safe harbour are entirely voluntary, and organisations may qualify for
the safe harbour in different ways. ...
Adherence to these Principles may be limited: (a) to the extent necessary to meet national security, public interest,
or law enforcement requirements; (b) by statute, government regulation, or case-law that create conflicting
obligations or explicit authorisations, provided that, in exercising any such authorisation, an organisation can
demonstrate that its non-compliance with the Principles is limited to the extent necessary to meet the overriding
legitimate interests furthered by such authorisation; or (c) if the effect of the Directive [or] Member State law is to
allow exceptions or derogations, provided such exceptions or derogations are applied in comparable contexts.
Consistent with the goal of enhancing privacy protection, organisations should strive to implement these Principles
fully and transparently, including indicating in their privacy policies where exceptions to the Principles permitted by
(b) above will apply on a regular basis. For the same reason, where the option is allowable under the Principles
and/or US law, organisations are expected to opt for the higher protection where possible.
...’
Annex II to Decision 2000/520 reads as follows:
‘Frequently Asked Questions (FAQs)
...
FAQ 6 — Self-Certification
How does an organisation self-certify that it adheres to the Safe Harbour Principles?
Safe harbour benefits are assured from the date on which an organisation self-certifies to the Department of
Commerce (or its designee) its adherence to the Principles in accordance with the guidance set forth below.
To self-certify for the safe harbour, organisations can provide to the Department of Commerce (or its designee) a
letter, signed by a corporate officer on behalf of the organisation that is joining the safe harbour, that contains at
least the following information:
name of organisation, mailing address, e-mail address, telephone and fax numbers;
description of the activities of the organisation with respect to personal information received from the [European
Union]; and
description of the organisation’s privacy policy for such personal information, including: (a) where the privacy policy
is available for viewing by the public, (b) its effective date of implementation, (c) a contact office for the handling of
complaints, access requests, and any other issues arising under the safe harbour, (d) the specific statutory body
that has jurisdiction to hear any claims against the organisation regarding possible unfair or deceptive practices and
violations of laws or regulations governing privacy (and that is listed in the annex to the Principles), (e) name of
any privacy programmes in which the organisation is a member, (f) method of verification (e.g. in-house, third
party) …, and (g) the independent recourse mechanism that is available to investigate unresolved complaints.
Where the organisation wishes its safe harbour benefits to cover human resources information transferred from the
[European Union] for use in the context of the employment relationship, it may do so where there is a statutory
body with jurisdiction to hear claims against the organisation arising out of human resources information that is
listed in the annex to the Principles. ...
The Department (or its designee) will maintain a list of all organisations that file such letters, thereby assuring the
availability of safe harbour benefits, and will update such list on the basis of annual letters and notifications
received pursuant to FAQ 11. ...
curia.europa.eu/juris/document/document.jsf;jsessionid=9ea7d2dc30dd5b610279af57461688cfc1d680446584.e34KaxiLc3qMb40Rch0SaxuRbN90?text=&doc…
5/14