The USA Data Bridge is designed to facilitate the free flow of data between the UK and the US.
In this blog, Clive Mackintosh, Founder of GDPR Rep, experts in GDPR Representative services digs into the details of the USA Data Bridge.
On 12th October 2023 the Data protection (Adequacy) (United States of America) Regulation 2023 comes into legal effect and creates a UK / USA ‘data bridge’.
The USA Data Bridge is a mechanism that is designed to allow the transfer of personal data from the UK to the US without the need for additional safeguards. It is based on the EU-US Data Privacy Framework (DPF), which is a bespoke, opt-in certification scheme for US organisations that meet high standards of data protection.
To be eligible for the USA Data Bridge, a US organisation must be certified to the DPF and must comply with its strict requirements. These requirements include:
The USA Data Bridge is designed to facilitate the free flow of data between the UK and the US, which is essential for businesses and organisations in both countries.
To transfer personal data to the US under the USA Data Bridge, a UK organisation must first identify a US organisation that is certified to the DPF. Once a suitable US partner has been identified, the UK organisation must enter into a data transfer agreement with them. This agreement must set out the terms and conditions under which the data will be transferred and used.
Once the data transfer agreement is in place, the UK organisation can start transferring personal data to the US partner. The US partner must then comply with all of the requirements of the DPF, including protecting the personal data from unauthorised access, use, disclosure, modification, or destruction.
The USA Data Bridge offers a number of benefits to businesses and organisations in both the UK and the US. These benefits include:
For further advice and assistance on meeting USA data bridge compliance contact speak to a member of the GDPR Rep team today.
GDPR Rep is on a mission to help every business achieve and maintain GPDR representation. If you are looking into how your organisation can fulfil its requirements why not schedule a no-commitment call with a GDPR representative expert today, or get a quote to understand how our value pricing makes compliance simple.