Most Americans seem resigned to the fact that businesses are collecting all sorts of information about their personal lives–from the brand of shampoo they prefer to which magazines they buy to their credit card numbers from purchases on the Internet.
While privacy advocates at home are trying, mostly in vain, to limit the selling of personal information, a development in Europe may soon change everything.
Casual electronic encounters will likely become rarer as companies on this side of the Atlantic scramble to cope with strict European Union privacy regulations that took effect Oct. 25.
The rules are designed to prevent any transfer of personal data from the EU’s 15 member countries to other nations that don’t have laws the Europeans consider adequate to protect personal privacy.
European officials generally view U.S. privacy protections as weak. And while they could order a data blackout because U.S. privacy laws don’t match theirs, few think that’s likely. While American officials are negotiating with their counterparts in Europe to ensure that data won’t be halted at the borders, companies here–especially those that do business on the Internet or have big operations in Europe–are struggling to figure out ways to comply.
In the end, Americans are likely to end up with new personal information safeguards, privacy advocates said.
“American consumers will be the biggest winners as the privacy protection discussion between the U.S. and EU moves forward,” said Marc Rotenberg, executive director of the non-profit Electronic Privacy Information Center in Washington, D.C. “In the end, it simply draws attention to the lack of good privacy protection in the U.S. I don’t see the EU directive as a problem so much as a reminder of what needs to be done in the U.S.”
Under the EU rules, European citizens have a right to:
– See any information about them and know how the information will be used.
– Access the information and make corrections.
More Top Picks Best 4k Streaming Devices
– Be notified before the information is sold or shared elsewhere and choose who else can have access to the information.
– Sue if a company is in violation of these conditions.
The rules apply to any kind of data transfer, not just those over the Internet.
Ironically, many experts say individual European privacy laws now bundled together under the EU rules were inspired by U.S. legislation such as the Fair Credit Reporting Act of 1971 and the Privacy Act of 1974. In Europe, with memories of totalitarian regimes still fresh, privacy is considered a basic human right.
What worries American businesses is the mechanics of the law and the cost of compliance, estimated at hundreds of millions of dollars. Information covered by the rules includes employee records, medical and health information, transactions on the Internet, travel reservations and direct-mail lists.
Already an American company has landed in court. American Airlines was recently ordered by a Swedish judge not to transfer sensitive health data about passengers from Sweden to the company’s reservations systems in the United States without the travelers’ consent.
Even routine customer profile information, such as requests for a kosher meal or a wheelchair, can’t be kept in an airline’s computers once a trip has been completed, unless the passenger consents.
The U.S. Department of Commerce is talking with the European Commission, which represents the EU’s member countries, to prevent further suits. The U.S. government is pushing European countries to offer American companies a “safe harbor” in which American firms will be presumed to have adequate privacy protection if they agree to certain privacy practices and principles regarding choice, consent, access, security and dispute settlement.
“European companies stand to lose as much as American companies if the data flow is stopped,” said David Aaron, the undersecretary for international trade who has been meeting with European Commission officials. “It’s not a problem we have alone. That’s why it’s in our mutual benefit to come to a resolution.”
If the U.S. government can’t work out a safe harbor agreement, it would be up to individual companies to enter into contracts with the individual EU members for every type of data transfer that’s conducted. Complicating things is that only four European countries have completed implementing the continent-wide EU rules, though most countries already have their own privacy laws in effect.
“Your business is essentially tubed until you get this resolved,” said Kate McGee, vice president of corporate affairs for Emerald City, Calif.-based Oracle Inc. “It can be a life-or-death situation for some businesses.”
Oracle has responded by tightening access to its customer and employee databases. The database software giant also has been working with trade associations and the government to help its customers comply with the rules.
Though large multinational companies have kept abreast of the new regulations, experts say many Web site operators don’t know they exist. Today’s on-line world depends on consumer profiling to personalize sites–a practice that can run head-on into privacy protections in Europe, even if the request is for users’ birthdays to provide horoscopes or addresses to offer weather information.
“The majority of Web site developers don’t have a clue this is coming down the pike,” said Susan Scott, executive director of Palo Alto, Calif.-based TRUSTe, which gives its stamp of approval to member companies that meet a threshold of privacy practices. “It highlights a challenge for people doing business on the Web. They’re operating in a global marketplace. You might not know the laws and regulations of other countries, but it doesn’t mean you’re not responsible.”
Web search engine company Excite Inc. is one company that has been working on privacy issues, including the European rules, for the last couple of years. The Redwood City, Calif., company operates Web services in Germany and the United Kingdom, but officials said it doesn’t send personal information out of Europe. A TRUSTe member, it has enacted a privacy policy and even had its privacy measures audited by Ernst & Young at a cost of more than $1 million, said Steve Lucas, chief information officer of MatchLogic, a division of Excite.
One major sticking point in the discussions between the U.S. and European Commission is the issue of access, required as part of the EU rules.
American businesses generally collect more personal information and store more of it in databases than European companies do. Direct marketing isn’t a flourishing business in Europe because of the lack of databases. In fact, much of the information-gathering technology employed by U.S. businesses is just trickling into the European toolbox.
The Commerce Department and American businesses say that consumers’ access to their personal information should be granted if it’s practical, but not guaranteed in every case.
“We believe that people should have access, but it has to be tempered by practicality,” Aaron said.