Planning
Technology

Privacy Shield – The better Safe Harbor agreement?

It certainly seems to have its advantages when your event management software provider stores all participant data centrally on servers. This allows you to access it anytime, anywhere. And since there haven't been any issues with external attacks so far, you haven't been bothered by the fact that the servers are located in the USA. Everything is fine, then? The European Court of Justice disagreed in its ruling from October 2015, no longer viewing the USA as a safe harbor for European data. Continuing to rely on US servers is therefore risky in several respects.

Why data protection is now so important for event organizers,Why data protection is now so important for event organizers,Why data protection is now so important for event organizers,Why data protection is now so important for event organizers

(Un-)Safe Harbor

As soon as you, as an event organizer, collect and process personal data, you are obligated to comply with data protection regulations.
This includes knowing where specific data is stored and who has access to it. If the provider of the event management software you use transmits participants' personal data to a country outside the European Economic Area, one requirement must be met: the country where the servers are located must be on the list of safe third countries that can guarantee sufficient protection of data and the personal rights of the individuals concerned.
The USA is not on this list because there are no effective regulations there with a level of data protection comparable to that in Europe. However, data transfers were able to take place without any problems until last year. The reason for this was the Safe Harbor agreement between the EU and a number of US companies that committed to complying with European data protection standards.
In the wake of the NSA revelations in 2013, however, a different picture emerged. According to these, US authorities not only spy on data uncontrollably but also have unrestricted access to it. The European Court of Justice therefore concluded in October 2015 that the information was not sufficiently protected and declared the Safe Harbor agreement invalid after 15 years.

So, what now?

Once stored on a US server, no one can really say what happens to the data in detail. Furthermore, neither the participants nor the organizers are usually familiar with the exact legal situation in the USA. If software is used that transfers data to the USA, the data center there can at best implement measures against data theft and criminal external attacks. Against the backdrop of NSA activities, however, government access cannot be prevented.

Safe Harbor is to be followed by a new regulation with better data protection, the “EU-US Privacy Shield”. However, the planned shield is by no means as strong as the name suggests and is already attracting numerous critics before it even comes into effect.
They point out that surveillance by intelligence agencies continues seamlessly. While the new agreement does provide for checks to ensure compliance, the oversight body is provided by the US Department of State, which at the very least casts doubt on the independence of any audit.

If a German event organizer works with event management software that hosts personal data in the USA, this is currently even illegal – provided the transfer is still based on the Safe Harbor agreement and the companies involved have not established another legal basis in accordance with EU requirements since the ruling.

How can event organizers ensure greater security?

How the legal situation will develop remains to be seen, even if fundamental changes to data exchange with the USA are not to be expected in the foreseeable future.
However, do not forget that participant data does not necessarily have to be sent far away. With the Federal Data Protection Act, the legal situation in Germany is much clearer.
It is advisable to generally avoid US-based providers of participant management software and to inquire thoroughly with European providers about how they handle personal data. You should always be cautious if a European provider hosts data using cloud services. The data is then often stored in the USA, or the distributed server structure makes it completely impossible to determine the exact storage location.
Anything providers do beyond this in terms of security is an added bonus.
For example, Converia hosts all data on German servers located in an ISO 27001 certified data center. As a very strict, globally recognized certification standard, ISO 27001 sets high security requirements for stored information and helps to minimize risks and associated damages.

By mirroring hosted data, it remains reliably available at all times.
This is implemented via a mirror, an additional server that holds a copy of the data and steps in as soon as the first one fails. The hard drive architecture is set up similarly. If one of the drives fails, the mirrored one is used immediately.

In addition, the software provider should be able to fully comply with your data protection standards. This includes, for example, disclosing the purpose for which personal data is collected, used, or shared.

Inadequate data protection has consequences

Anyone who violates data protection regulations must expect severe penalties. Event organizers must be prepared for fines amounting to several thousand euros, especially if no measures are consciously taken to protect participant data.

Usually, the damage is not just financial. As soon as it becomes known that an organizer is not taking the handling of participants' personal data seriously, significant reputational damage also occurs. This is difficult to rectify with regard to future events. This becomes a problem as soon as potential participants prefer to forgo registration rather than entrust their data to someone who has proven in the past that they cannot protect it sufficiently.

About the author

Laura Wirsing
Laura Wirsing
Converia

Are you planning a conference with a complex program?

30-minute consultation: We will review your requirements and show you what a realistic setup could look like.
Schedule a consultation
Schedule a consultation

More articles