If you are a United States-based company that collects personal or personally identifiable information from residents of the European Union, maintains an office in the European Union, or processes data on servers in the European Union, then it is time to take data privacy compliance seriously. Though the United States has limited laws concerning data privacy, the EU has adopted the Data Protection Directive to standardize the data privacy regulations applicable to EU member states. While the US is an opt-out society, the EU is, in all means, an opt-in society.
In Europe, data protection is a fundamental human right. The EU Data Protection Directive requires that personal data be collected only for specified, explicit, and legitimate purposes. A company’s collection of data from a EU resident can only be maintained to the extent that the collected data is relevant to the purpose for which it was collected. If the data is no longer relevant, it must be purged. And all data must be maintained in an accurate and up to date form.
To consent to the collection of data, a EU resident must “opt-in,” meaning, he or she must provide unambiguous consent to the collection and use of personal information. Further, the Data Protection Directive restricts the circumstances under which personal information can be transferred outside of the European Union. Transfers of personal or personally identifiable information outside of the European Union may take place only if the target country ensures an “adequate” level of protection. The local, state-level, implementation of the Directive often requires companies to deposit a copy of the data transfer contact with local authorities to ensure that an adequate level of protection is maintained.
Since the United States is an opt-in society and does not recognize data protection as a fundamental human right, the United States initially declined to participate in the Data Protection Directive’s standards. To accommodate the US’s vision of data protection, the EU Data Protection Directive provides a means by which a company in the United States can self-certify that its procedures for handling the personal or personally identifiable information of persons located in the European Union conforms to the practices outlined in the safe-harbor agreement, which is in turn based on the Data Protection Directive. Where a US company has certified that it complies with the safe harbor agreement through the US Department of Commerce, state and federal regulators can take enforcement action against the company for its failure to maintain the Data Protection Directive standards.
If you are a United States-based company that collects information from EU residents, processes data on servers in the EU, or otherwise transfers data to or from the EU, you should seek an evaluation of your data protection practices to ensure that you avoid potential liability for non-compliance with the EU Data Protection Directive. Doing so could save you time, money, and a substantial headache in the future.
The answer is legally complicated since the Food and Drug Administration (“FDA”) has defined the term “healthy” to apply to foods, not dietary supplements. On the other hand, in some circumstances, certain types of oils — like olive oil — are now eligible to use the “healthy” label. Thus, if your supplement is an oil […]
If nurtured properly, trademarks can continue to function indefinitely, bringing continued and increasing value to the owners. There are, however, ways that trademarks can be “lost.” As an example, a trademark can be abandoned through lack of use or can be lost to the general public through the process of genericide. That happens when the […]
Social media influencing has become a big business. As such, influencers need experienced internet lawyers to help with their contracts and other legal needs. In early October 2025, there was a bit of a stir on the internet concerning claims that the Government of Israel, through its Ministry of Foreign Affairs, was paying social media […]