{"id":1861,"date":"2020-08-17T09:50:11","date_gmt":"2020-08-17T09:50:11","guid":{"rendered":"https:\/\/eventscase.com\/blog\/?p=1861"},"modified":"2022-07-05T10:59:35","modified_gmt":"2022-07-05T08:59:35","slug":"privacy-shield-is-your-event-data-at-risk","status":"publish","type":"post","link":"https:\/\/eventscase.com\/blog\/privacy-shield-is-your-event-data-at-risk","title":{"rendered":"EU-US Privacy Shield Collapses \u2013 Is Your Event Data at Risk of Snooping?"},"content":{"rendered":"<p>Perhaps a story involving a privacy trade war, metaphorical \u2018shields\u2019 and Donald Trump doesn\u2019t naturally shift your attention to the European events industry. Let\u2019s face it, 2020 is giving us plenty of other matters to worry about.<\/p>\n<p>Still, it\u2019s not every day that a<a href=\"https:\/\/www.bbc.co.uk\/news\/technology-53418898\" target=\"_blank\" rel=\"noopener\"> \u201cbold move\u201d <\/a>from the EU\u2019s top court has a direct impact on attendees and their personal data.<\/p>\n<p>On July 16, the European Court of Justice (ECJ) moved to invalidate the EU-US Privacy Shield:\u00a0 an agreement allowing US companies to transfer and store information from countries belonging to the European Union.<\/p>\n<p>The action has wide-ranging implications, but EventsCase is particularly interested in what it says about the safety of your event data. Without an agreement to protect what you gather, you could be at a greater risk of <strong>data breaches,<\/strong> leading to<strong> fines<\/strong>, a <strong>loss of information,<\/strong> and <strong>huge reputational damage<\/strong>. Allow us to explain in more detail.<\/p>\n<h2><strong>What is the EU-US Privacy Shield?<\/strong><\/h2>\n<p>The EU-US Privacy Shield system underpins transatlantic digital trade for thousands of companies. It\u2019s one of the major agreements that sit outside of the General Data Protection Regulation (GDPR), ensuring the safe flow of data from the EU to non-EU countries.<\/p>\n<p>Any US company signing up to the Shield must cooperate with data protection regulators due to certain assurances given by the framework regarding the safety of information. Until recently, it\u2019s provided peace of mind to European-based companies that host data in the US.<\/p>\n<p><img decoding=\"async\" class=\"wp-image-1871 aligncenter\" src=\"https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg-876x630.jpg\" alt=\"Event Data - Privacy shield\" width=\"700\" height=\"503\" title=\"-\" srcset=\"https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg-876x630.jpg 876w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg-300x216.jpg 300w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg-110x80.jpg 110w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg-768x552.jpg 768w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg-83x60.jpg 83w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/what-is.jpeg.jpg 1000w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/p>\n<p>Some have no idea their information travels this far. Indeed, the most common scenario in an events context would be the use of technology to manage registrations, check-in and create mobile apps, with all data making its way across to a US server.<\/p>\n<p>Don\u2019t forget, the platform itself could be \u2018global\u2019, and not all organisers realise where their attendee information ends up. Judging by our investigations and knowledge of the event tech market, this is fairly common.<\/p>\n<p>\u2018Privacy Shields\u2019 play a key role in policing the use of your data, until they themselves are brought to question.<\/p>\n<p>Enter Max Schrems, an Austrian privacy advocate, who in 2018 <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-53418898\" target=\"_blank\" rel=\"noopener noreferrer\">challenged the agreement<\/a> in the ECJ. He argued that US national security laws failed to adequately protect EU citizens from acts of \u201csnooping\u201d. After two years of deliberation, he won.<\/p>\n<p>The court ruled in favour of Schrems and his case, therefore making the Shield invalid.<\/p>\n<h2><strong>How does this affect my event?<\/strong><\/h2>\n<p>Further invalidation of mechanisms like the Privacy Shield could see the end of a truly borderless internet. More pertinently, though, the ECJ has essentially spelt out the risk associated with housing information in the US.<\/p>\n<p>It\u2019s official: <em>you cannot guarantee that someone isn\u2019t trawling through your attendee data.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1870\" src=\"https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg.jpg\" alt=\"Privacy Shield - Data protection GDPR\" width=\"680\" height=\"489\" title=\"-\" srcset=\"https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg.jpg 1000w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg-300x216.jpg 300w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg-876x630.jpg 876w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg-110x80.jpg 110w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg-768x552.jpg 768w, https:\/\/eventscase.com\/blog\/wp-content\/uploads\/2020\/08\/data-breaching-hacker-decoding-information-from-futuristic-network-technology-with-white-symbols.jpeg-83x60.jpg 83w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.politico.com\/news\/2020\/08\/04\/privacy-shield-data-transfers-391650\" target=\"_blank\" rel=\"noopener noreferrer\">Politico<\/a> reports that some companies have already ceased the movement of their information and are now keeping it within the EU. Others are seeking Standard Contractual Clauses (SCCs), which are individual and made between two organisations. However, it\u2019s now thought that last week&#8217;s decision may see the end of these as well.<\/p>\n<p>All signs point towards a reform of US surveillance practices to fit in line with EU laws. Analysts have long complained about the lack of protection being offered to companies that pass data into the States. Yet, considering <a href=\"https:\/\/www.politico.com\/news\/2020\/06\/29\/trump-administration-gdpr-345254\" target=\"_blank\" rel=\"noopener noreferrer\">President Trump\u2019s previous conflicts with GDPR<\/a> and his frosty relationship with the EU, we\u2019d be surprised if this were made a priority.<\/p>\n<h2><strong>What should I do about it?<\/strong><\/h2>\n<p>Anyone using a technology for their registration, check-in and event management should now be asking where their data is positioned. Our investigations show several big names in the event tech landscape housing information on US servers, which could leave it vulnerable to surveillance.<\/p>\n<p>One safeguarding measure would be to seek a clause in your contract that specifies where your data is stored. If your provider does not wish to include this, you could be risking a financial penalty from watchdogs like the Information Commissioner\u2019s Office and a severe blow to your reputation.<\/p>\n<p>These issues aside, there is definitely something to be taken from the sheer confusion surrounding the next possible steps.<\/p>\n<p>Companies applying SCCs as a short-term measure have no idea if they will soon be deemed unfit for purpose. Transfers of data between the EU and US are not expected to stop, chiefly because companies are awaiting a more detailed response from the European Commission and UK Information Commissioner.<\/p>\n<p>Our advice would be to err on the side of caution and keep your data away from the US, at least until you can be sure of its protection.<\/p>\n<p>Attendees impart a wealth of personally identifiable information from the moment they register for a ticket. Companies like <a href=\"https:\/\/mackeeper.com\/blog\/post\/599-biggest-data-breaches-five-years\/\" target=\"_blank\" rel=\"noopener noreferrer\">Yahoo and Equifax<\/a> are still recovering from their respective customer data breaches, where millions of records found their way into the wrong hands. In a world where <a href=\"https:\/\/www.pewresearch.org\/internet\/2019\/11\/15\/americans-and-privacy-concerned-confused-and-feeling-lack-of-control-over-their-personal-information\/\" target=\"_blank\" rel=\"noopener noreferrer\">online privacy is at the top of consumer consciousness<\/a>, you want to avoid being implicated in any potential leak.<\/p>\n<p>News of the Shield\u2019s collapse might seem like the last thing our industry needs right now. But as data becomes all the more vital to our operations, allowing for the creation of personalised experiences, the current period of downtime could be ideal for patching some of the chinks in our armour.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>If you\u2019d like to discuss how we\u2019re supporting our customers with advanced data protection, feel free to <\/em><\/strong><a href=\"mailto:enquiries@eventscase.com\"><strong><em>get in touch<\/em><\/strong><\/a><strong><em>.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Perhaps a story involving a privacy trade war, metaphorical \u2018shields\u2019 and Donald Trump doesn\u2019t naturally shift your attention to the European events industry. Let\u2019s face &hellip; <\/p>\n","protected":false},"author":3,"featured_media":1865,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pgc_meta":"","footnotes":""},"categories":[1],"tags":[355,356,354],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/posts\/1861"}],"collection":[{"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/comments?post=1861"}],"version-history":[{"count":5,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/posts\/1861\/revisions"}],"predecessor-version":[{"id":1872,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/posts\/1861\/revisions\/1872"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/media\/1865"}],"wp:attachment":[{"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/media?parent=1861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/categories?post=1861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventscase.com\/blog\/wp-json\/wp\/v2\/tags?post=1861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}