Privacy Shield FAQ – Medidata Is Certified Under Privacy Shield

US Department of Commerce Approval

Medidata’s self-certification to the Privacy Shield program has been approved by the Department of Commerce, and Medidata has been added to the list of self-certified Privacy Shield participants. Medidata’s participation in Privacy Shield is good news for our customers: it provides a new mechanism for the EU-to-US transfer of their personal data.

What is Privacy Shield?

The new EU-US Privacy Shield framework was developed by the US Department of Commerce and the European Commission to enable companies to receive personal data from Europe in compliance with European data protection laws. Privacy Shield replaces the Safe Harbor framework that was invalidated in October 2015, and provides stronger protections for data processing, such as more stringent requirements for the use of sub-processors and greater protections for individuals’ data rights. By complying with the Privacy Shield principles, Privacy Shield participants may transfer personal data from the European Union to the United States.

Standard Contractual Clauses Are Still Available

Standard Contractual Clauses (SCCs) are another mechanism for transferring personal data from the EU to the US. SCCs are contract templates approved by the European Commission that legalize the transfer of personal data outside of Europe.

Though it is self-certified under Privacy Shield, Medidata continues to recommend our data processing amendment (DPA), which incorporates SCCs as an alternative mechanism for EU-US transfers of personal data. Please see our Data Protection FAQ for more information about our DPA and SCCs.

Please contact us at mdsol.NAM.dataprivacy@3ds.com with any questions.