idg.net
Premier 100 call for nominations

 
Computerworld Home
 
Go to advanced search
 
 
 

Home News Topics Departments Services Subscriptions Events
 
 
 
 
Home > Topics > Security > Security > Privacy > Story  

U.S. firms skipping 'safe harbor'


By PATRICK THIBODEAU
JUN 03, 2002

 
   
 


Empty Harbor
Not many companies are signing up with the Osafe harborO agreement on privacy rights between the EU and the U.S., and financial firms are among the least happy with Europe?s approach.
U.S. firms skipping 'safe harbor'

EU: U.S. Financial Law Not Enough



Security Knowledge Center
Discussions
Events
Glossary
Vendor Listing
Resource Links
White Papers
Event/Training Search
RFP Center

Knowledge Centers
Management
Careers
Security
Hardware
Software
More topics...

Departments
QuickStudies
SharkTank
FutureWatch
Careers
Opinions/Letters
More departments...

Services
Forums
Research
QuickPolls
WhitePapers
Vendor Solutions
More services...


 
 
Next month marks the two-year anniversary of the landmark U.S. and European "safe harbor" privacy agreement, which was designed to smooth data exchange across the Atlantic (see story). But thus far, the deal has been largely ignored by U.S. companies and unenforced by European data-protection authorities.

Approximately 200 U.S. companies, mainly high-tech vendors, have signed up for safe harbor. Most of the businesses are small or midsize, but there are notable exceptions, including Microsoft Corp., Hewlett-Packard Co., Procter & Gamble Co., Eastman Kodak Co. and Intel Corp.

European Union officials last week said that they're disappointed that more companies haven't signed up but they're not giving up on the safe-harbor agreement. Neither is the Bush administration, according to officials and experts in Europe and the U.S.

Companies that sign up for safe harbor agree to follow certain data privacy practices, such as getting users' consent to share their data and allowing customers to access their personal information, as well as data use restrictions.

There's no question that Europe's privacy rules are here to stay. But European authorities, with few exceptions, haven't been aggressively enforcing their rules, even against businesses in their own countries.

Privacy observers in Germany and England said data-protection authorities don't have the staff to enforce privacy laws. England is levying small fines against violators, but German privacy rules are so complex that it's impossible for local companies to fully comply, said Florian Baum, an attorney at Brobeck Hale and Dorr in Munich. "Nobody, really, is very eager to follow those rules," he said.

In the U.S., a company that violates its stated privacy policy is subject to Federal Trade Commission enforcement action. Some experts suggested that U.S. businesses are avoiding safe harbor because they fear that saying they comply with its stringent terms is akin to painting a bull's-eye on their companies and inviting inspection.

Scott Salley, chief privacy executive at McKesson Corp., said that fear is what's holding U.S. companies back. Nonetheless, his San Francisco-based health care products firm has signed up for safe harbor.

Self-Certification Difficult

Companies that adopt safe harbor self-certify that they're in compliance, but that's not necessarily an easy process.

McKesson created a multidepartmental task force to review its data practices, which led to new rules on data access and a procedure for annual auditing. It was an opportunity to centralize corporate privacy practices, said Salley.

There are alternatives to safe harbor. Companies can use individual contracts stipulating privacy protections. But Salley said safe harbor's blanket coverage is more attractive.

"We need something in place," he said. "If people blow off safe harbor, what are you going to do then?"

Despite questions about the future of safe harbor, the Bush administration supports the agreement, which was adopted during the Clinton presidency.

"The safe-harbor program is one of the easiest, most efficient ways for U.S. companies to comply with the European directive on data protection," said Michele O'Neil, deputy assistant secretary for IT at the U.S. Department of Commerce.

U.S. Compliance Lags on Privacy
A European Union report released earlier this year was critical of some safe-harbor compliance efforts.


Privacy policies: In some cases, privacy policies couldn't be accessed on company Web sites.
Pick and choose: Only half the firms that have signed up meet every privacy requirement. Some companies drop a provision about a user's right to access his own data.
Opt in: Some firms have opt-in rules on sensitive data but don't spell out what data qualifies.



Related Content

Safe harbor data security eyed after Web site glitch, JUL 09, 2001

Microsoft faces EU privacy probe, MAY 28, 2002

EU official calls U.S. financial privacy rules inadequate, MAY 30, 2002


Source: Computerworld

Page Utilities


Send feedback to editor
Printer friendly version
E-mail this article
Request reprints of this article



Security Knowledge Center

• Security Under the Gun, Monday - Jun. 03, 04:56 pm




 


Sponsored Links

ADIC:       Get your FREE Enterprise Backup Intelligence Kit.

IronMail      Protect Your Email Infrastructure - Free White Paper

Oracle9i Database for Windows:      Spend less, do more in IT.

Tripwire      Assure the Integrity of your Data. Get a Free Poster.



 
News  Latest News  Week in Review  E-mail Newsletters  Special Coverage  This Week in Print  Corrections
Technology  QuickStudies  Emerging Technologies  Future Watch  Reviews  Field Reports  Security Manager
Management  Book Reviews  Case Studies  Driving the Deal  Managing  ROI  Q&As
Careers  Career Adviser  Education  Salary/Skills Surveys  Best Places  Workstyles  Search/Post Jobs
Opinions  Editorial Columns  Letters to the Editor  Shark Tank  QuickPoll Center
Events  Premier 100 IT Leaders  Storage Networking World  Computerworld Honors Program
Services  Forums  Vendor Solutions  Research  White Papers  IT RFP  Find Events/Training  Media Kit  Subscriptions  Reprints

 

About Us Contacts Editorial Calendar Help Desk Advertise Privacy Policy
 


 
 
Copyright © 2002 Computerworld Inc. All rights reserved. Reproduction in whole or in part in any form or medium without express written permission of Computerworld Inc. is prohibited. Computerworld and Computerworld.com and the respective logos are trademarks of International Data Group Inc.