Search
Contact
28.03.2022 | KPMG Law Insights

Trans-Atlantic Data Privacy Frame-work: Old wine in new bottles?

On March 25, EU Commission President Ursula von der Leyen and U.S. President Joe Biden officially announced that the EU and the U.S. want to facilitate transatlantic data exchange and are working on drafting a successor agreement to the “EU-US Privacy Shield.” The Commission has now published an information paper with the first details of the content of the “Trans-Atlantic Data Privacy Framework”.

 

  • The U.S. holds out the prospect of creating a new set of rules and binding safeguards to limit U.S. intelligence agencies’ access to data to what is necessary and proportionate to protect national security. Specifically, U.S. intelligence agencies are to implement procedures to ensure effective oversight of the new privacy and liberty standards.

 

  • A new, two-tiered redress system to investigate and remedy complaints by EU citizens regarding data access by U.S. authorities is to be introduced. An independent “Data Protection Review Court” is to be established for this purpose.

 

  • The Trans-Atlantic Data Privacy Framework will – again – be based on a system of self-certification by U.S. companies under the supervision of the U.S. Department of Commerce.

 

Next steps

Concrete legal obligations must now be formulated from the agreed principles. These are then to be issued within the framework of an “Executive Order”, which obliges the US authorities to implement them. The Executive Order is intended to form the basis for the Commission’s draft adequacy decision. With each of these steps potentially taking months, it is still entirely unclear when (if ever) an adequacy decision can be expected. However, a short-term solution to the problem of transatlantic data traffic seems impossible. Last but not least, Max Schrems – lawyer and data protection activist – has already announced that, as in the “Safe Harbour” and “Privacy Shield” cases, he will also take timely action against future adequacy decisions if they do not comply with European Union law.

 

Doubts about compliance with European data protection standards

The news about a planned successor agreement to the “Privacy Shield” is encouraging due to the increasing relevance of transatlantic data exchange. However, not too many hopes should be placed in the “Trans-Atlantic Data Privacy Framework” just yet. Under no circumstances should processes already initiated to secure U.S. transfers be stopped.

The principles proposed by the EU and the U.S. do take up specific points of the ECJ’s Schrems II decision, in that legal protection options are to be improved and complaints by those affected are to be decided by an independent body.

However, crucial questions remain unanswered. For example, whether there will be any obligation at all on the part of U.S. authorities to inform EU citizens about data access. Furthermore, it remains to be seen whether the powers of the Data Protection Review Court vis-à-vis U.S. authorities will also be sufficient to enforce compliance vis-à-vis U.S. authorities.

Another major criticism of the ECJ with respect to the predecessors of the proposed Trans-Atlantic Data Privacy Framework was that Section 702 of the Foreign Intelligence Surveillance Act (FISA) did not impose restrictions on surveillance activities or provide other safeguards for non-U.S. citizens. In response to this, surveillance measures are to be carried out in the future only if this is necessary to protect national security and appropriate with regard to the intrusion into privacy. However, past experience has shown that there are sometimes different understandings in the EU and the U.S. regarding the value of privacy rights and national security, and balancing the positions involves some challenges. The introduction of an adequacy test on the U.S. side is an essential and important step, although the actual implementation will only show whether sufficient account is taken of the restriction on the access rights of the U.S. authorities previously demanded by the EU.

 

Keep calm and stay on course

Efforts to officially regulate transatlantic data sharing on the basis of an adequacy decision could mean major benefits for all stakeholders, as this would allow data to be transferred without the need to enter into standard contractual clauses, which have since become complex, and to conduct time-consuming and costly transfer impact assessments. However, a “Privacy Shield 2.0” and the associated uncertainties must be prevented, because what companies need above all else is legal certainty; and they need it in the long term. In this regard, it remains to be seen how the U.S. will implement the announced measures and how the EU courts will assess this. It therefore remains essential for European companies to take individual measures to comply with data protection requirements when using U.S. providers and to work overall on maintaining their compliance with regard to data transfers to the United States.

 

Explore #more

02.04.2026 | KPMG Law Insights

Building Modernization Act (GMG): What is now important for companies

The planned Building Modernization Act (GMG) is set to replace significant parts of the previous Building Energy Act (GEG). Companies in the real estate industry,…

01.04.2026 | In the media

Manager Magazin: KPMG Law in first place for legal advice

Every two years, Manager Magazin, together with the Wissenschaftliche Gesellschaft für Management und Beratung (WGMB), awards Germany’s best auditors with a “Best-in-Class” seal and evaluates

27.03.2026 | KPMG Law Insights

Special Infrastructure Fund and State Aid Law: Orientation for Funding Practice and Planning

The special fund “Infrastructure and Climate Neutrality” (SVIK) also entails considerable responsibility under state aid law for federal states, municipalities and recipients of funds. Anyone

23.03.2026 | Deal Notifications

KPMG Law, KPMG Law AT as well as KPMG in Germany and KPMG in Austria advise GOLDBECK GmbH on the acquisition of 50 percent of the shares in ZAUNERGROUP Holding GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and Buchberger Ettmayer Rechtsanwälte GmbH (KPMG Law AT) as well as KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG in Germany) and KPMG…

19.03.2026 | KPMG Law Insights

Business Judgement Rule in the use of AI: how governing bodies are liable for decisions

If an AI provides the basis for business decisions, the people responsible are liable, not the machine. This makes the use of artificial intelligence risky…

16.03.2026 | KPMG Law Insights

KPIs in the legal department: How legal becomes strategically effective through control, transparency and data analysis

Today, legal departments are facing a strategic turning point: they must reliably hedge risks, but at the same time enable speed, control costs and make…

13.03.2026 | KPMG Law Insights

Commercial courts: when they are worthwhile for companies – and when they are not

Large commercial disputes are given courts specially tailored to their needs: the Commercial Courts. The German legislator introduced it with the Act to Strengthen the

10.03.2026 | Deal Notifications

KPMG Law advises on the sale of Krasemann Hausverwaltung to Buena

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) provided legal advice to the KRASEMANN family on the sale of KRASEMANN Immobilien- & Gebäudeservice GmbH (KIGS) and KRASEMANN…

09.03.2026 | KPMG Law Insights

MiCAR and whitepaper obligations – what the transitional regulations mean

The Markets in Crypto-Assets Regulation (MiCAR) has been in force for just over a year. Among other things, MiCAR obliges issuers and providers of crypto…

09.03.2026 | In the media

Guest article in Private Banking Magazine: What tokenized banknotes mean in day-to-day treasury operations

The future of payment transactions will be shaped not by new currencies, but by new processing models. A practical report by Marc Pussar (KPMG Law),…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll