New Data Privacy Framework: Meta gets a lifeline

The European Commission has now adopted an adequacy decision for an EU-US Data Privacy Framework, adding a new twist to an ongoing tale.

New Data Privacy Framework: Meta gets a lifelineNew Data Privacy Framework: Meta gets a lifeline
Category
Insight | Tech
Insight
|
Tech
Published Date
1
September 2023
Reading Time

In a recent Insight we discussed the record €1.2 billion fine imposed on Meta Platforms Ireland Limited by the Irish Data Protection Commission (DPC) for unlawfully transferring the personal data of Facebook users from Europe to the US.

Shortly following the DPC’s decision, the European Commission announced that it had adopted an adequacy decision for an EU-US Data Privacy Framework, adding a new twist to an ongoing tale.

A quick recap

Meta was handed a record fine by the DPC after relying on Standard Contractual Clauses (SCCs) to provide the safeguards required by GDPR to transfer data outside of the European Union. Central to the DPC’s decision was that the European Commission did not consider that US law provided equivalent levels of protection for personal data compared to the EU. A key reason for this conclusion was that US surveillance agencies can collect electronic communications of non-US persons stored by US internet service providers. Therefore, the DPC determined that entities transferring data to the US needed to take additional measures to compensate for the lack of equivalence. The DPC found that the SCCs used by Meta (and of course many others) were not a sufficient measure to address this gap in protection under US law.

Introducing the EU-US Data Privacy Framework

On 10 July the European Commission announced it had adopted an adequacy decision for the EU-US Data Privacy Framework.

The new Framework is a set of privacy principles and safeguards developed by the US Department of Commerce and the European Commission to provide a mechanism for personal data transfers from the European Union to the US. It allows US entities to self-certify compliance with the Framework. EU data can then be transferred to these self-certified US entities without the need for any additional measures.  Unsurprisingly, Meta Platforms, Inc. (Meta’s US entity) has already self-certified under the new Framework.    

Key aspects of the new Framework include limiting US surveillance access to EU data to what is necessary and proportionate, and the establishment of a Data Protection Review Court to which EU individuals will have access. It is these features in particular which the European Commission relied on to issue its adequacy decision, resolving that US data protection law is essentially equivalent to that of the EU.  

Because the Framework relies on self-certification, the US Department of Commerce has said that they will monitor compliance by participating organisations on an ongoing basis. Non-compliance can then ultimately be enforced by the Federal Trade Commission (FTC) (or another statutory body that can ensure compliance). For example, the FTC can prosecute non-compliance as “unfair or deceptive acts in or affecting commerce” under section 5 of the US’s FTC Act. So, it will be important for participating organisations to take care in their compliance assessments with the Framework.

Will the new Framework hold up?

The question of whether the US has adequate data protection laws when compared to the European Union has some history:

• In 2000 the European Commission issued a “Safe Harbour” decision allowing data transfers from the EU to the US. This was invalidated by the European Court of Justice (ECJ) in 2015 following legal action from privacy campaigner Max Schrems (this decision is known as Schrems I); and

• In 2016 the European Commission approved a different EU-US data transfer regime known as the “Privacy Shield”. However, the Privacy Shield was also invalidated by the ECJ in 2019 (in a decision known as Schrems II).

The new EU-US Data Privacy Framework is touted as addressing concerns previously raised by the ECJ. However, critics argue that the new Framework changes little in practice so expect to see the issue before the ECJ once again. For example, Max Schrems – the man behind much of the previous litigation in this area – reacted to the announcement of the Framework by stating:

"We have now had 'Harbors', 'Umbrellas', 'Shields' and 'Frameworks' - but no substantial change in US surveillance law. The press statements of today are almost a literal copy of the ones from the past 23 years. Just announcing that something is 'new', 'robust' or 'effective' does not cut it before the Court of Justice. We would need changes in US surveillance law to make this work - and we simply don't have it."

What happens next?

For now, organisations who have self-certified to the Framework can receive EU data without having to put in place additional safeguards.

An interesting footnote – the Meta decision included a suspension order requiring it to cease personal data transfers to the US, and a compliance order requiring it to bring its processing obligations into compliance with GDPR and to cease unlawful processing. However, the DPC stated at the time of its decision that these orders would not be effective if the gap in protection between EU and US laws was resolved by a future adequacy decision. So, while the fine will stand (at least at this stage), these other orders have for now been superseded by the new Framework, which has provided Meta with a much-needed lifeline.

Max Schrems has indicated that he expects the issue of EU-US data transfers to be back before the ECJ by the beginning of next year, with his privacy advocacy and enforcement organisation NOYB eyeing up various options for a challenge.  

So, it will pay for businesses operating in the EU and US to continue to keep tabs on how this long-running saga (and compliance nightmare) progresses.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore.

There are no services for this current insight. Take a look at our services page for more information on our different offerings.
Previous Article
Next Article

From Hertzian waves to hyperlinks – What the BSA’s online decision means for your business

Space Law in New Zealand — Signals from the ground

Cyber security changes flagged for New Zealand

The four Cs of successful fintech partnerships

New rule 3A introduced to the Biometric Processing Privacy Code

IPP3A is nearly in force – What agencies need to know

OPC shifts public enquiries online – What agencies should do now

AI as a confidante? Legal privilege and the ever-increasing use of AI

New Therapeutic and Health Advertising Code – What you need to know

Building blocks of trade mark law: New Zealand approach to "use as a trade mark" now compatible with Australia

Consumer law update 2025

Open banking launches in New Zealand

Is fair something to fear? The Government announces beefed-up Fair Trading Act

Is it fair? Lessons from Bartz v Anthropic and Kadrey v Meta

Open banking almost live

Why New Zealand businesses should care about the EU Data Act

Product labelling changes flagged for New Zealand

Biometric Processing Privacy Code 2025 introduced to New Zealand

Open banking regulations released for consultation

Ten tips for buy-side M&A success

A recipe for disaster – Is caramel a copyright work?

Becoming a Globally Renowned Fintech Nation (and how regulation can light the path)

Important changes made to the Privacy Act

New Zealand may ban social media for young users

Customer and Product Data Act update – Open banking officially on the way

Tips from the trenches – Your AI policy cheat sheet

Significant regulatory reform proposed for New Zealand media

Security guidance released for emerging tech companies

Customer and Product Data Bill – Select Committee reports back

Consumer law update 2024

New Zealand’s Artist Resale Royalty is ready to go

The shape of coffee – “Moccona” vs “Vittoria”

New Zealand’s Copyright Act gets a sense of humour

WIPO’s traditional knowledge treaty is adopted

Doing business in the Middle East

AI and advertising – What producers need to know

Seven contract clauses every freelancer needs

Baby Reindeer – When truth is stranger than fiction?

Our comments on the Biometric Processing Privacy Code

Therapeutic Products Act to be repealed this year

Is End-to-End to end?

Geographical indications – Changes uncorked by the EU-NZ Fair Trade Agreement

Lawyers and Generative AI – New NZ Law Society guidance released

Facing the future – A biometrics code of practice for New Zealand?

Deepfakes and style mimicking – Should New Zealand adopt a right of publicity?

Five Eyes release the Five Principles to Secure Innovation

The copyright conundrum with generative AI

Innovate at the speed of trust – Privacy Commissioner releases new guidance on artificial intelligence tools

Political advertising on social media: sludge or copyright quagmire?

Privacy Amendment Bill introduced to Parliament

New Data Privacy Framework: Meta gets a lifeline

The long and winding road to royalties

Implications of the Supreme Court’s “new debt” approach in Mainzeal

EU gets closer to AI laws

UK Supreme Court puts Quincecare ‘duty’ back in its box

A Deep Dive into The Customer and Product Data Bill

Searching for a shield: Meta’s €1.2 billion fine and international transfers in the age of Big Data

New NZ-UK Free Trade Agreement signals tech, media and IP law changes

Ditch the fax! Tips for building a tech-savvy law firm

The Incorporated Societies Act 2022 – what you need to know for your society

Common myths about copyright online

Artificial artist, or artificial plagiarist?

Big boost to gaming

Is your product “AI powered”?

The latest on New Zealand’s Consumer Data Right

Space Law in New Zealand

You Cannot Defame the Dead or Can You? Tikanga Māori and NZ Defamation Law

Open Banking is coming – through the Consumer Data Right

Massive SEC Fines for Companies Using Text and Instant Messaging

One Act to Rule Them All

A Legal Guide to Kicking SaaS

Potential changes to the Privacy Act 2020

NZ's Social Media "Code of Practice" Launched

Are you being unfair?

A new Companies Office levy is one step closer

Has Paramount Pictures gone maverick?

From Russia with love: The ‘other’ Russian conflict targeting intellectual property owners

Retail Payment System Act 2022 now in force

Paying the price for getting privacy wrong

Can AI be an inventor?

Finfluencer Crackdown

TIN Fintech Insights Report Launch

Britain seeks to regulate 'Big Tech'

Disclosure of personal information - how to, not don't do

The Spice May Flow, But The Copyright Doesn’t

Sound Recording Ownership (Taylor's Version)

The Lowdown (and Lockdown) on Summer Clerkships

Building Blocks of Trust

Firm News | Legal Rankings

Buy Now, Regulate Soon

Ten simple things

Funding the Future

Cyber Security for Start-ups

Fit for purchase

The Screen Industry Workers Bill

UK/New Zealand Trade Deal Takes Flight

Palmer v Alalääkkölä

Other articles you
might like

The four Cs of successful fintech partnerships
2
April 2026

Negotiating a fintech partnership agreement is not a zero sum game.

Andrew Dentice

Partner

New rule 3A introduced to the Biometric Processing Privacy Code
1
April 2026

New rule 3A means individuals must be notified about indirect collection under the Biometric Processing Privacy Code 2025.

Kyra Vince

Special Counsel – Knowledge

Anchali Anandanayagam

Partner

Open banking launches in New Zealand
2
December 2025

The official commencement of open banking in New Zealand is a significant milestone for the local industry.

Andrew Dentice

Partner

Kyra Vince

Special Counsel – Knowledge