Beyond the Flip: Data Protection Considerations for U.S. Expansion
When considering a U.S. flip, data protection issues may not always be the top of a company’s list of concerns, but differences between U.S. data protection laws and those found in the UK and EU do create potential, material pitfalls for those looking to transfer personal data across the Atlantic and/or collect data in the United States. Data protection obligations need to be carefully navigated on both sides of the Atlantic before the flip, during the flip and after the flip occurs.
Different Data Protection Landscapes
In the UK and the EU, the General Data Protection Regulation (GDPR) (as implemented into UK law) generally governs the collection, use and protection of personal data collected by an organization.
The U.S. has no equivalent single federal law. Instead, data protection obligations in the U.S. arise from a patchwork of:
As such, a company embarking on a flip will be required to essentially comply with many different regulatory regimes with respect to the data it collects from its customers and employees, on each side of the Atlantic. This can of course be burdensome, with some transatlantic organizations opting to apply a “highest common denominator” approach with respect to the personal data it collects—but this is not always preferable.
UK/EU and U.S. data protection laws do have things in common, of course. For example, each jurisdiction generally requires a company to publish public-facing privacy notices and provide certain rights to individuals whose data they collect. The key will be for the company embarking on the flip to map the laws which will apply to it post-flip and seek to make changes to its compliance framework that comply with the new obligations to which it will become subject.
Data Security and Breach Response
Data security is a key consideration for lawmakers on both sides of the Atlantic. Under the GDPR, organizations must implement appropriate technical and organizational measures to protect personal data and, in certain cases, notify the relevant regulator and affected individuals of a personal-data breach within certain timeframes. In the U.S., notification triggers, deadlines and recipients vary by state. Depending on the incident, notifications may be required in regard to affected individuals, state regulators and consumer-reporting agencies.
A UK company expanding to the U.S. should therefore ensure its incident-response plan can support both GDPR reporting requirements and potentially overlapping U.S. state notification rules.
Transferring Data to the U.S. Group Entity
Giving a U.S. parent or subsidiary access to UK personal data may amount to a restricted transfer under the GDPR. This can include remote access from the U.S. and access through shared group systems.
Before transferring personal data to the U.S. (or allowing access in the U.S.) a UK company will need to ensure that the transfer is “adequately safeguarded.” There are different forms this can take. For example, the UK and U.S. companies could enter into off-the-shelf “standard contractual clauses” contained in a data transfer agreement (essentially, clauses which have been approved by the European Commission). Alternatively, the UK Extension to the EU-U.S. Data Privacy Framework (“UK-U.S. Data Bridge”) may be available where the U.S. recipient is eligible, has an active certification under this regime and its certification covers the relevant data.
Data Transfer Impact Assessments may also need to be undertaken depending on the sensitivity of the data being transferred.
Founder Checklist
Before enabling a U.S. parent or subsidiary to receive or access UK personal data, founders should consider the following key points, amongst others:
Build the Data Protection Structure Alongside the Corporate Structure
Data protection should form part of the U.S. expansion plan, rather than a post-incorporation exercise. Founders should adopt a “privacy by design” approach by addressing these issues head on in the early stages where a flip is being contemplated.
Enterprise customers, investors and acquirers increasingly expect companies to understand their data flows, document intercompany arrangements and demonstrate that their compliance framework can scale internationally.
The right approach will depend on the business. A UK company giving a small U.S. sales team limited CRM access faces a different profile from one centralizing engineering, HR and customer support in the U.S. In both cases, early planning can help avoid compliance gaps and data protection issues down the line.
Different Data Protection Landscapes
In the UK and the EU, the General Data Protection Regulation (GDPR) (as implemented into UK law) generally governs the collection, use and protection of personal data collected by an organization.
The U.S. has no equivalent single federal law. Instead, data protection obligations in the U.S. arise from a patchwork of:
- federal consumer-protection and sector-specific laws;
- comprehensive state data protection laws;
- state rules on marketing, cookies and tracking technologies; and
- state data-breach notification laws.
As such, a company embarking on a flip will be required to essentially comply with many different regulatory regimes with respect to the data it collects from its customers and employees, on each side of the Atlantic. This can of course be burdensome, with some transatlantic organizations opting to apply a “highest common denominator” approach with respect to the personal data it collects—but this is not always preferable.
UK/EU and U.S. data protection laws do have things in common, of course. For example, each jurisdiction generally requires a company to publish public-facing privacy notices and provide certain rights to individuals whose data they collect. The key will be for the company embarking on the flip to map the laws which will apply to it post-flip and seek to make changes to its compliance framework that comply with the new obligations to which it will become subject.
Data Security and Breach Response
Data security is a key consideration for lawmakers on both sides of the Atlantic. Under the GDPR, organizations must implement appropriate technical and organizational measures to protect personal data and, in certain cases, notify the relevant regulator and affected individuals of a personal-data breach within certain timeframes. In the U.S., notification triggers, deadlines and recipients vary by state. Depending on the incident, notifications may be required in regard to affected individuals, state regulators and consumer-reporting agencies.
A UK company expanding to the U.S. should therefore ensure its incident-response plan can support both GDPR reporting requirements and potentially overlapping U.S. state notification rules.
Transferring Data to the U.S. Group Entity
Giving a U.S. parent or subsidiary access to UK personal data may amount to a restricted transfer under the GDPR. This can include remote access from the U.S. and access through shared group systems.
Before transferring personal data to the U.S. (or allowing access in the U.S.) a UK company will need to ensure that the transfer is “adequately safeguarded.” There are different forms this can take. For example, the UK and U.S. companies could enter into off-the-shelf “standard contractual clauses” contained in a data transfer agreement (essentially, clauses which have been approved by the European Commission). Alternatively, the UK Extension to the EU-U.S. Data Privacy Framework (“UK-U.S. Data Bridge”) may be available where the U.S. recipient is eligible, has an active certification under this regime and its certification covers the relevant data.
Data Transfer Impact Assessments may also need to be undertaken depending on the sensitivity of the data being transferred.
Founder Checklist
Before enabling a U.S. parent or subsidiary to receive or access UK personal data, founders should consider the following key points, amongst others:
- What data will move to, or be accessible from, the U.S., including any sensitive, biometric or health data?
- Does the arrangement constitute a restricted transfer under the GDPR?
- How will the transfer be “adequately safeguarded”? Is a Data Transfer Impact Assessment needed before the data is transferred?
- Do privacy notices, employee notices and internal records reflect the new group structure and data uses?
- Which U.S. state data protection and breach-notification laws are likely to apply as the business grows? Does the existing compliance framework (internal policies, processes etc.) provide for these new laws?
- Does the incident-response plan address UK and U.S. requirements?
Build the Data Protection Structure Alongside the Corporate Structure
Data protection should form part of the U.S. expansion plan, rather than a post-incorporation exercise. Founders should adopt a “privacy by design” approach by addressing these issues head on in the early stages where a flip is being contemplated.
Enterprise customers, investors and acquirers increasingly expect companies to understand their data flows, document intercompany arrangements and demonstrate that their compliance framework can scale internationally.
The right approach will depend on the business. A UK company giving a small U.S. sales team limited CRM access faces a different profile from one centralizing engineering, HR and customer support in the U.S. In both cases, early planning can help avoid compliance gaps and data protection issues down the line.