United States

Littler Mendelson logo

As the largest labor and employment law firm in the United States—with more than 800 attorneys, 51 locations, and a practice that extends into every area and sub-area of workplace law—Littler Mendelson has the ability to provide rapid, integrated solutions for any labor, employment, benefits or global migration issue.

Littler’s international experience is long-standing and diverse, positioning us to effectively assist employers with the significant challenges of managing employees in multiple countries. Our international employment law practice consists of 100+ lawyers who have worked on projects involving the employment laws of nations across the globe. Our attorneys are fluent in 20+ languages and are actively involved in various international associations, such as the U.S. Council on International Business and the International Bar Association.

Supporting Littler's international employment law practice is a well-established network of working relationships with pre-eminent employment lawyers around the world. Littler is the U.S. member of the Ius Laboris global alliance of leading human resources law practitioners, with member firms in 45 countries and coverage in more than 100 countries.

Visit Website

Multinationals Certified to the U.S.-E.U. Safe Harbor Agreement Beware: The Federal Trade Commission Has Bared Its Enforcement Teeth

Since its inception in the year 2000, the U.S.-E.U. Safe Harbor Agreement has attracted nearly 2,000 multinationals seeking to establish a lawful basis to transfer to the U.S. the personal data of their consumers and employees who reside in the European Union (E.U.). To obtain the benefits of the Safe Harbor, these organizations are required to (a) certify to the U.S. Department of Commerce that they have implemented the seven Safe Harbor principles, (b) post for their employees and/or customers (depending upon the type of personal data being imported from the E.U.) a Safe Harbor privacy policy that embodies those principles, and (c) implement policies and procedures to ensure that the organization processes personal data received from the E.U. in compliance with the privacy policy. The Safe Harbor certification must be updated annually.

Until just a few weeks ago, the Federal Trade Commission (FTC), which enforces the Safe Harbor, had not commenced a single enforcement action in the nine years that the Safe Harbor has been in effect. Last week, the FTC requested public comment on six separate settlements of complaints alleging that multinationals had violated the Safe Harbor by representing to the public that they were current members of the Safe Harbor even though their certification was not up-to-date. Notably, the settlements do not include any monetary penalties, but instead would enjoin the targets from future misrepresentations about their Safe Harbor status.

The lessons learned include the following:

  • Multinationals must take compliance with all of the Safe Harbor's requirements seriously; there is now some enforcement risk.
  • The nature of the enforcement risk is uncertain. The FTC's charges required virtually no enforcement resources. The agency had to do nothing more than compare the target's statements in their publicly posted Safe Harbor privacy policy against the certification records maintained by the Commerce Department. These settlements do not (at least yet) reflect the agency's intention to perform on-site audits to determine whether the multinational's internal process for handling personal data actually conforms to the seven Safe Harbor principles embodied in the organization's Safe Harbor privacy policy.
  • The next, most likely enforcement step would be the FTC's request to review the mandatory, annual self-assessment or third-party assessment of Safe Harbor compliance. The FTC would not have to expend any resources to "look behind" the assessment to find a violation. The failure to conduct the required annual assessment itself would be a violation.
  • Given the above, multinationals certified to the Safe Harbor should promptly confirm that their certification is current and conduct an assessment of their compliance with the Safe Harbor if they have not performed one during the preceding year. To the extent the assessment reveals any gaps in compliance, the gaps should be closed.

This entry was written by Philip L. Gordon.

Trackbacks (0) Links to blogs that reference this article Trackback URL
http://www.globalemploymentlaw.com/mtc/mt-tb.cgi/361
Comments (0) Read through and enter the discussion with the form at the end