If you are a United States-based company that collects personal or personally identifiable information from residents of the European Union, maintains an office in the European Union, or processes data on servers in the European Union, then it is time to take data privacy compliance seriously. Though the United States has limited laws concerning data privacy, the EU has adopted the Data Protection Directive to standardize the data privacy regulations applicable to EU member states. While the US is an opt-out society, the EU is, in all means, an opt-in society.
In Europe, data protection is a fundamental human right. The EU Data Protection Directive requires that personal data be collected only for specified, explicit, and legitimate purposes. A company’s collection of data from a EU resident can only be maintained to the extent that the collected data is relevant to the purpose for which it was collected. If the data is no longer relevant, it must be purged. And all data must be maintained in an accurate and up to date form.
To consent to the collection of data, a EU resident must “opt-in,” meaning, he or she must provide unambiguous consent to the collection and use of personal information. Further, the Data Protection Directive restricts the circumstances under which personal information can be transferred outside of the European Union. Transfers of personal or personally identifiable information outside of the European Union may take place only if the target country ensures an “adequate” level of protection. The local, state-level, implementation of the Directive often requires companies to deposit a copy of the data transfer contact with local authorities to ensure that an adequate level of protection is maintained.
Since the United States is an opt-in society and does not recognize data protection as a fundamental human right, the United States initially declined to participate in the Data Protection Directive’s standards. To accommodate the US’s vision of data protection, the EU Data Protection Directive provides a means by which a company in the United States can self-certify that its procedures for handling the personal or personally identifiable information of persons located in the European Union conforms to the practices outlined in the safe-harbor agreement, which is in turn based on the Data Protection Directive. Where a US company has certified that it complies with the safe harbor agreement through the US Department of Commerce, state and federal regulators can take enforcement action against the company for its failure to maintain the Data Protection Directive standards.
If you are a United States-based company that collects information from EU residents, processes data on servers in the EU, or otherwise transfers data to or from the EU, you should seek an evaluation of your data protection practices to ensure that you avoid potential liability for non-compliance with the EU Data Protection Directive. Doing so could save you time, money, and a substantial headache in the future.
In May 2025, as part of a settlement of litigation involving college football, a new entity was created called the College Sports Commission (“CSC” or “Commission”). See news media reports here and here. Among many other purposes, the CSC will monitor and approve name, image, and likeness (“NIL”) agreements for college athletes. As the term […]
Trademarks are words, designs, symbols, logos, and other things that are used/associated with goods or services that identify the specific commercial source of the goods/services. COCA-COLA, APPLE, and GUCCI are just a few famous examples. If COCA-COLA is on the bottle, consumers know what to expect from the beverage in the bottle. The same for […]
Getting an endorsement deal as a social media influencer may be a seminal event financially and for the progress of your career. However, the question always has to be asked whether your endorsement deal is fair. In other words, are you getting paid what you are worth? There are a number of factors that can […]