The latest newsletter from Privacy Laws and Business (PL&B) contained a news clip about US/EU negotiations over the exchange of personal data for law enforcement purposes. It prompted me to look for other reports elsewhere online, and these two articles on the IHT website seem as good as any (1, 2).
While I agree that law enforcement access is a valid use-case, a couple of things about this naturally raise concern. First, there's the obvious problem that this explicitly seems to over-ride EU national data protection laws - and presumably would lead to cases where the US-EU agreement allows data disclosures which would be illegal between (and indeed within) EU member states. Second, the agreement appears (from this coverage, at least) entirely aysmmetric.
In that sense, it would be joining other existing provisions such as the long-standing exchange of Air Passenger Data, or the bizarre extradition treaty in place between the US and UK. And if one were looking for shining examples of good practice, those would not really be candidates.


