TY - JOUR T1 - The EU-US Privacy Shield Regime for Cross-Border Transfers of Personal Data under the GDPR A1 - Minssen, Timo A1 - Seitz, Claudia A1 - Aboy, Mateo A1 - Corrales Compagnucci, Marcelo PY - 2020 N2 - Cloud-based technologies, big data, statistical signal processing algorithms, and Artificial Intelligence (AI) technologies are expected to play an increasingly important role in the medical field. Big data and AI-technologies rely on the cloud for data storage as well as for computational power and thus need effective and robust legal frameworks for international data transfer. Because of inconsistent data protection regulations, this is not always simple to achieve as it can be illustrated in the United States (US)-European Union (EU) context. Due to the lack of general data protection law at the federal level, the US currently does not have a general ‘adequacy decision’ from the European Commission to enable EU-US cross-border data transfers without the need for additional data protection safeguards under the General Data Protection Regulation. As a fallback, a ‘limited adequacy’ decision was adopted in 2016 on the so-called ‘EU-US Privacy Shield Framework’. This framework protects the fundamental rights of natural persons in the EU and allows the free transfer of personal data to companies that are certified under the EU-US Privacy Shield. However, the EU-US Privacy Shield has been recently contested at the Court of Justice of the European Union (CJEU). This paper analyses the EU-US Privacy Shield Framework, the associated legal challenges, and how these might affect organisations deploying or implementing cloud-based medical technologies relying on cross-border data transfers from EU data subjects. JF - European Pharmaceutical Law Review JA - European Pharmaceutical Law Review VL - 4 IS - 1 UR - https://doi.org/10.21552/eplr/2020/1/6 M3 - doi:10.21552/eplr/2020/1/6 ER -