Meet Stronger Obligations Under the New EU-US Privacy Shield Framework

EC confirms EU-US Privacy Shield to replace Safe Harbor data-sharing arrangement

The new EU-US Privacy Shield reflects requirements set out by the European Court of Justice in its ruling that invalidated Safe Harbor on October 6, 2015. The new arrangement necessitates that companies meet stronger obligations to protect the personal data of Europeans and stronger monitoring and enforcement by the US Department of Commerce (DOC) and Federal Trade Commission (FTC). Now more than ever, companies need guidance to ensure requirements under the new framework are met.

Companies come to TRUSTe when they’re concerned about the protection of customer and HR data in their global operations. Business teams especially want to mitigate any risks when expanding or acquiring operations in Europe requiring the collection, use and transfer of EU customer or employee data to non-EU nations.

Securing EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Self-Certification is a critical component of your global compliance strategy as it provides you with a mechanism for establishing “adequate” protections required for cross-border data transfer under EU laws.

TRUSTe offers comprehensive EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Assessments to analyze and verify compliance under the Safe Harbor Framework for both customer and employee data. We can also provide Certification services for companies needing additional remediation guidance and validation in preparation for EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Self-Certification under Department of Commerce authority.

If you want to address both Privacy Shield and Model Contract Clause compliance, check out our comprehensive two-in-one EU Data Transfer Privacy Assessment solution.

Key Benefits

  • Independent assessment – for a strong EU-US Privacy Shield (which replaces “US-EU Safe Harbor) submission, particularly with stronger obligations under the new framework
  • Accountability-on-demand – to respond to any inquiries, providing searchable evidentiary support of your privacy compliance
  • Demonstrated privacy commitment to build trust – with users, clients, business partners, press, and regulators
  • Detailed and actionable guidance – to implement immediate steps
  • Full-service team of privacy experts – with practical in-house business process experience, by your side throughout the process
  • Digital scanning – powered by TRUSTe’s state-of-the-art privacy technology
  • Streamlined process minimizes disruption – to your daily business operations and lightens the load for your in-house team
  • Flexibility – to extend Assessments to full Certification for remediation guidance and validation


Our Assessments provide you with the information you need to take control with specific steps to mitigate risks.

Comprehensive Assessment

We first define the scope of assessment by business units, product/service lines, and digital properties (websites, apps, cloud platforms). Then determine whether to extend review to employee data or offline practices. A dedicated Privacy Solutions Manager (PSM) works with your team to efficiently guide discovery of necessary information, including relevant data flows. We then evaluate your privacy policies and practices against the EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Framework requirements.

Findings Report

Our team delivers a findings report with a gap analysis dashboard and remediation recommendations so you have the privacy risk information you need to take actionable steps.

Tracker Scanning

TRUSTe will apply proprietary scanning technology to the applicable digital properties providing comprehensive insight into personally identifiable information (PII) data collection, first and third party trackers on your property, and level of risk through the Privacy Sensitivity Index (PSI).

Ongoing Guidance

You also get access to TRUSTe privacy experts for ongoing policy guidance, along with educational webinars, events, whitepapers, client advisories, privacy tips and research.

Dispute Resolution

TRUSTe provides a third-party dispute resolution service, which helps you efficiently manage privacy inquiries from customers, and addresses the dispute handling requirements of the EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Framework.


With Assessment results in hand, you have the flexibility to choose whether to obtain additional support for your EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Self-Certification with the Department of Commerce.

Remediation / Validation

We assist with any necessary remediation steps, including providing relevant templates and process change advice. We then validate that your privacy statements accurately reflect your privacy practices and are consistent with EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) requirements.


We provide a number of service tracks specifically designed to tackle the most important privacy challenges faced by our clients. TRUSTe EU-US Privacy Shield (which replaces “US-EU Safe Harbor”) Assessments and Certifications are part of our broad range of privacy services. You may also be interested in our Enterprise, Asia Cross Border, or Kids Privacy services to further expand your risk and compliance management efforts. Learn More »

TRUSTe Privacy Professionals

TRUSTe Privacy Services are delivered by our Privacy Consultants and Privacy Services Managers, a team of recognized data privacy experts with significant experience conducting privacy assessments. Our team has a unique hybrid background of privacy, technology, business process, and project management experience. All are CIPP trained or certified, many have law degrees, and have hands-on experience working for a wide range of companies including Adobe, American Express, Citrix, Comcast, HSBC Bank, IBM, Kimberly-Clark, Microsoft, Pfizer, and many more.

Our privacy team leverages nearly 20 years experience delivering data privacy management solutions for thousands of global brands along with our comprehensive technology platform. We also have key regulatory relationships and are a leading provider of privacy services supporting regulatory and self-regulatory compliance programs for a wide range of agencies including APEC, DOC, DAA, EDAA, and FTC.

TRUSTe Technology Platform

Our Data Privacy Management Services leverage the TRUSTe Platform, a comprehensive, SaaS technology solution that provides state of the art assessment management, compliance control, and website scanning / monitoring capabilities.

Data privacy management platform from TRUSTe offering web, cloud, mobile and ad privacy solutions.