{"id":6885,"date":"2022-01-17T13:55:06","date_gmt":"2022-01-17T11:55:06","guid":{"rendered":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems%e2%80%99-advice-for-worried-companies"},"modified":"2024-05-07T19:19:17","modified_gmt":"2024-05-07T17:19:17","slug":"privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies","status":"publish","type":"post","link":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/","title":{"rendered":"Privacy Shield, Standard Contractual Clauses, CLOUD Act: Privacy activist Max Schrems\u2019 advice for worried companies"},"content":{"rendered":"\n

Ever since the European Court of Justice declared the bilateral treaties on the transatlantic exchange of data (Safe Harbor and later Privacy Shield) invalid at the instigation of Austrian data privacy activist Max Schrems<\/a>, a growing number of US cloud providers have resorted to using standard contractual clauses (SCC). In our customer projects, we are asked time and again to give our opinion on this approach. Adding to the uncertainty are laws such as the US CLOUD Act, which governs the provision of data to authorities by US providers \u2013 even if the data in question is not stored in the USA, but for instance on servers within the European Union.<\/p>\n\n\n\n

Schrems also skeptical of revised standard contractual clauses<\/h2>\n\n\n\n

While a blog post could certainly never take the place of proper legal counsel, we would nevertheless like to take this opportunity to refer you once again to our virtual Fire Side Chat [available in German only]<\/a> with the man himself \u2013 Max Schrems which took place last year. In the course of the event, Schrems explicitly expands on what he sees as the \u201ccircumvention\u201d of the issue by way of SCCs. He especially takes aim at the revised version<\/a> commonly used since June 2021, which is significantly more complicated to put into practice as each case in principle requires its own individual assessment.<\/p>\n\n\n\n

Video: “Privacy Provided” webinar co-hosted by Retarus [available in German only]<\/figcaption><\/figure>\n\n\n\n

European data centers of US providers not safe from access by authorities<\/h2>\n\n\n\n

The scenario of US providers using geographically distributed processing of data, common in the provision of email, security and content delivery services, remains particularly difficult to assess. According to Schrems, at least one thing is perfectly clear: Even if US cloud providers are running their own data centers in Europe, the data stored there is not protected from access under the the Foreign Intelligence Surveillance Act (FISA), as the law does not stipulate any geographic limitation.  <\/p>\n\n\n\n

Impacted parties not informed of access due to secrecy requirements<\/h2>\n\n\n\n

Considered especially problematic in this regard are the secrecy requirements imposed by the National Security Letters (NSL) and FISA, which explicitly prohibit providers from informing those involved about the authorities\u2019 requests for data \u2013 much to the displeasure of large US providers<\/a> such as Microsoft, by the way.<\/p>\n\n\n\n

Schrems advises: Question providers directly and place them under scrutiny<\/h2>\n\n\n\n

Getting back to the question posed at the beginning of this blog post: What does Max Schrems advise for companies which are apprehensive following the demise of Privacy Shield? In our Fire Side Chat he was also crystal clear on this point: Rather than pouring their money into the legal counselling industry, companies would be better advised to approach their providers, question them directly and scrutinize their processes. To assist you in this regard, we have compiled a list of the essential aspects to consider on our website<\/a>. There you will also find a questionnaire to forward to your IT service providers.<\/p>\n","protected":false},"excerpt":{"rendered":"

Even if US cloud providers are running their own data centers in Europe, the data stored there is not protected from access under the FISA Act, according to Schrems. Also, new SCC versions will be much more complicated to apply, says Europe’s most well-known data protection activist.<\/p>\n","protected":false},"author":12,"featured_media":10071,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_s2mail":"yes","footnotes":""},"categories":[78,8,15],"tags":[946,3678,102,3679,286,3680],"dipi_cpt_category":[],"class_list":["post-6885","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry","category-news","category-security","tag-cloud-act","tag-dsgvo","tag-email-security","tag-max-schrems","tag-privacy-shield","tag-scc"],"acf":[],"yoast_head":"\nPrivacy Shield, SCCs, CLOUD Act: Was Datensch\u00fctzer Schrems nun r\u00e4t<\/title>\n<meta name=\"description\" content=\"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctzt das laut Schrems die dort gespeicherten Daten nicht vor Zugriffen durch US-Beh\u00f6rden. In 2021 aktualisierte SCC-Fassungen seien noch deutlich komplizierter anzuwenden.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy Shield, Standard Contractual Clauses, CLOUD Act: Privacy activist Max Schrems\u2019 advice for worried companies\" \/>\n<meta property=\"og:description\" content=\"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctzt das laut Schrems die dort gespeicherten Daten nicht vor Zugriffen durch US-Beh\u00f6rden. In 2021 aktualisierte SCC-Fassungen seien noch deutlich komplizierter anzuwenden.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/\" \/>\n<meta property=\"og:site_name\" content=\"Retarus Corporate Blog - EN\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-17T11:55:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-07T17:19:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"562\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"S\u00f6ren Schulte\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Standardvertragsklauseln und CLOUD Act: Was Max Schrems nun r\u00e4t\" \/>\n<meta name=\"twitter:description\" content=\"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctze das laut Schrems nicht vor Zugriff durch US-Beh\u00f6rden.\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"S\u00f6ren Schulte\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/\",\"name\":\"Privacy Shield, SCCs, CLOUD Act: Was Datensch\u00fctzer Schrems nun r\u00e4t\",\"isPartOf\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg\",\"datePublished\":\"2022-01-17T11:55:06+00:00\",\"dateModified\":\"2024-05-07T17:19:17+00:00\",\"author\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d\"},\"description\":\"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctzt das laut Schrems die dort gespeicherten Daten nicht vor Zugriffen durch US-Beh\u00f6rden. In 2021 aktualisierte SCC-Fassungen seien noch deutlich komplizierter anzuwenden.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#primaryimage\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg\",\"contentUrl\":\"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg\",\"width\":1000,\"height\":562},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.retarus.com\/blog\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Privacy Shield, Standard Contractual Clauses, CLOUD Act: Privacy activist Max Schrems\u2019 advice for worried companies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#website\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/\",\"name\":\"Retarus Corporate Blog - EN\",\"description\":\"Always up to date\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.retarus.com\/blog\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d\",\"name\":\"S\u00f6ren Schulte\",\"url\":\"https:\/\/www.retarus.com\/blog\/en\/author\/sschulte\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Privacy Shield, SCCs, CLOUD Act: Was Datensch\u00fctzer Schrems nun r\u00e4t","description":"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctzt das laut Schrems die dort gespeicherten Daten nicht vor Zugriffen durch US-Beh\u00f6rden. In 2021 aktualisierte SCC-Fassungen seien noch deutlich komplizierter anzuwenden.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/","og_locale":"en_US","og_type":"article","og_title":"Privacy Shield, Standard Contractual Clauses, CLOUD Act: Privacy activist Max Schrems\u2019 advice for worried companies","og_description":"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctzt das laut Schrems die dort gespeicherten Daten nicht vor Zugriffen durch US-Beh\u00f6rden. In 2021 aktualisierte SCC-Fassungen seien noch deutlich komplizierter anzuwenden.","og_url":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/","og_site_name":"Retarus Corporate Blog - EN","article_published_time":"2022-01-17T11:55:06+00:00","article_modified_time":"2024-05-07T17:19:17+00:00","og_image":[{"width":1000,"height":562,"url":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg","type":"image\/jpeg"}],"author":"S\u00f6ren Schulte","twitter_card":"summary_large_image","twitter_title":"Standardvertragsklauseln und CLOUD Act: Was Max Schrems nun r\u00e4t","twitter_description":"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctze das laut Schrems nicht vor Zugriff durch US-Beh\u00f6rden.","twitter_misc":{"Written by":"S\u00f6ren Schulte","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/","url":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/","name":"Privacy Shield, SCCs, CLOUD Act: Was Datensch\u00fctzer Schrems nun r\u00e4t","isPartOf":{"@id":"https:\/\/www.retarus.com\/blog\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#primaryimage"},"image":{"@id":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg","datePublished":"2022-01-17T11:55:06+00:00","dateModified":"2024-05-07T17:19:17+00:00","author":{"@id":"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d"},"description":"Selbst wenn US-Cloud-Anbieter eigene Data Center in Europa betreiben, sch\u00fctzt das laut Schrems die dort gespeicherten Daten nicht vor Zugriffen durch US-Beh\u00f6rden. In 2021 aktualisierte SCC-Fassungen seien noch deutlich komplizierter anzuwenden.","breadcrumb":{"@id":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#primaryimage","url":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg","contentUrl":"https:\/\/www.retarus.com\/blog\/en\/wp-content\/uploads\/sites\/22\/2024\/05\/surveillance.jpg","width":1000,"height":562},{"@type":"BreadcrumbList","@id":"https:\/\/www.retarus.com\/blog\/en\/privacy-shield-standard-contractual-clauses-cloud-act-privacy-activist-max-schrems-advice-for-worried-companies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.retarus.com\/blog\/en\/"},{"@type":"ListItem","position":2,"name":"Privacy Shield, Standard Contractual Clauses, CLOUD Act: Privacy activist Max Schrems\u2019 advice for worried companies"}]},{"@type":"WebSite","@id":"https:\/\/www.retarus.com\/blog\/en\/#website","url":"https:\/\/www.retarus.com\/blog\/en\/","name":"Retarus Corporate Blog - EN","description":"Always up to date","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.retarus.com\/blog\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.retarus.com\/blog\/en\/#\/schema\/person\/da5eb37e5936738ea4e12be8b429433d","name":"S\u00f6ren Schulte","url":"https:\/\/www.retarus.com\/blog\/en\/author\/sschulte\/"}]}},"_links":{"self":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts\/6885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/comments?post=6885"}],"version-history":[{"count":22,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts\/6885\/revisions"}],"predecessor-version":[{"id":10456,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/posts\/6885\/revisions\/10456"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/media\/10071"}],"wp:attachment":[{"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/media?parent=6885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/categories?post=6885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/tags?post=6885"},{"taxonomy":"dipi_cpt_category","embeddable":true,"href":"https:\/\/www.retarus.com\/blog\/en\/wp-json\/wp\/v2\/dipi_cpt_category?post=6885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}