Box gets EU binding corporate rules approval to safeguard European customer privacy following ‘extraordinary’ reversal of Safe Harbour last year
Box claims it now offers customers in Europe the highest possible standard for data protection after the European Union (EU) gave the company approval for Binding Corporate Rules (BCRs) – an alternative to the invalidated Safe Harbour legislation.
Safe Harbour, the previous data sharing agreement between the EU and US, was declared invalid in October last year and had been relied upon by Box and other major US tech firms to operate across the Atlantic.
Box COO Dan Levin told TechWeekEurope earlier this month at BoxWorks 2016 in San Francisco that invalidation was an “extraordinary” course of action for the European Court to take and that regulation needed to be adapted for cloud technology.
After months of negotiations, a proposed replacement for Safe Harbor called Privacy Shield has emerged, but Box said earlier this year it was still “looking” at the proposed regulations as well as a number of alternatives, namely BCRs.
Now the company has completed the EU approval process from various data protection authorities, including the UK’s Information Commissioner’s Office (ICO), Box can now act as both a data processor for its customers and a controller for its employees.
BCRs are company-specific, as opposed to the general regulations of Safe Harbor and Privacy Shield, and are deemed to be the EU’s highest possible data protection standard.
The cloud collaboration platform claims to be one of fewer than five US companies to have received the accreditation and the only one in its sector, highlighting the privacy and security it can afford potential clients, especially in regulated industries.
“This is a huge milestone as we continue to scale internationally while focusing on offering what we believe to be the most secure enterprise content management platform in the world,” said Joel Benavides, Box’s senior director for global legal and advocacy. “The DPA’s approval of our BCRs enables companies across Europe to deploy a validated cloud environment in accordance with the highest data protection standards available today.”
Box has made international expansion a priority and has made several moves to boost the security and privacy of its product to attract new users in regulated sectors such as finance, health and the public sector.
These include encryption key management, data retention polices and data residency options, such as Box Zones, which gives customers a choice of data centres around the world in which to store information.