1. Home
  2. |Insights
  3. |U.S.-EU Safe Harbor Renegotiation Deadline Passes: What Now?

U.S.-EU Safe Harbor Renegotiation Deadline Passes: What Now?

Client Alert | 1 min read | 02.01.16

Despite intensive last-minute talks over the weekend, U.S. and European Union (EU) negotiators have yet to reach a new agreement for the legitimization of data transfers from Europe to the United States to replace the invalidated U.S.-EU Safe Harbor Framework (Safe Harbor). On February 1, EU Commissioner Věra Jourová provided a status update at a plenary meeting of the European Parliament's Committee on Civil Liberties, Justice and Home Affairs (LIBE) in Brussels. Jourová told the Parliament committee, "I believe the close relationship between the United States and European Union deserves these special efforts. We are close but an additional effort is needed." Negotiators on both sides still hope to find an agreement this week.

In the meantime, the EU Member States' Data Protection authorities (Article 29 Working Party) will meet on February 2 to discuss how to proceed. The meeting will include discussions about investigations and possible suspensions of data transfers which continue based solely on the former Safe Harbor. The authorities will also assess other transfer mechanisms such as EU Standard Contractual Clauses and Binding Corporate Rules, which also have been criticized based on the same concerns relating to U.S. government surveillance.

We will provide additional guidance as it becomes available.

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....