The EU-US Data Privacy Framework: Is the Dragon Eating its Own Tail?
Marcelo Corrales Compagnucci

TL;DR
The paper analyzes the EU-US Data Privacy Framework's recent adoption, highlighting its potential to enhance transatlantic data exchange while discussing legal challenges and implications for health data transfers.
Contribution
It provides a comprehensive analysis of the framework's main features, legal context, and practical implications, especially for healthcare organizations navigating cross-border data transfers.
Findings
Framework extends data transfer rights and oversight mechanisms.
Legal uncertainties threaten the framework's long-term viability.
Health data transfer complexities remain significant.
Abstract
The European Commission adequacy decision on the EU US Data Privacy Framework, adopted on July 10th, 2023, marks a crucial moment in transatlantic data protection. Following an Executive Order issued by President Biden in October 2022, this decision confirms that the United States meets European Union standards for personal data protection. The decision extends to all transfers from the European Economic Area to US entities participating in the framework, promoting privacy rights while facilitating data exchange. Key aspects include oversight of US public authorities access to transferred data, the introduction of a dual tier redress mechanism, and granting new rights to EU individuals, encompassing data access and rectification. However, the framework presents both promise and challenges in health data transfers. While streamlining exchange and aligning legal standards, it grapples…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
