COMMISSION IMPLEMENTING DECISION (EU) 2016/1250 | 32016D1250 — European Union law | Esheria

COMMISSION IMPLEMENTING DECISION (EU) 2016/1250

U.S. organisations that self-certify under the Privacy Shield must follow the Principles, and EU-to-U.S. transfers are allowed only for organisations that have self-certified and committed to comply.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Decision
Citation
32016D1250
Version
Undated source snapshot
Language
en
Official source
View official record ↗
children's online privacy complaints complaints handling compliance consumer redress cross-border data transfer cross-border data transfers cross-border privacy compliance data access data governance dispute resolution government access to data government oversight government surveillance human resources data judicial redress personal data handling privacy compliance privacy shield enforcement self-certification subpoenas surveillance third-party transfers verification and recordkeeping

Statute overview

About this statute

U.S. organisations that self-certify under the Privacy Shield must follow the Principles, and EU-to-U.S. transfers are allowed only for organisations that have self-certified and committed to comply. U.S. intelligence collection is described as limited to lawful, targeted purposes, with review, safeguards, and oversight requirements. The Commission must monitor the EU-U.S. Privacy Shield and review whether the United States still provides adequate protection for transferred personal data. Member States must notify the Commission without delay if they suspend or ban data flows to a Privacy Shield-listed U.S. organisation. The Department of Commerce must manage, monitor, and publicize the Privacy Shield program and may refer false claims or noncompliance matters for enforcement. Privacy Shield organizations must self-certify, follow the Principles, handle complaints, and can be bound to arbitration rules for unresolved claims.