Sources: US and EU are in talks to allow companies, including Facebook and other US tech firms, to keep storing and accessing Europeans' personal data in the US
Context & Ripple Effects
This report opens the latest round in a decade-long cycle: after Silicon Valley firms signed side agreements with the EU and built European data centers in 2015 to preserve transfers, a successor safe harbor arrangement followed in 2016 — one that privacy advocates warned they would legally challenge, and which the EU ultimately declared illegal in 2020.
The stakes are highest for companies like Facebook, whose business depends on moving Europeans' personal data to US servers; the talks reported here are what later produced a preliminary EU-US deal in March 2022 and an EU draft approval that December, contingent on promised US surveillance changes. The pattern matters because each collapse of a pact has forced ad-hoc workarounds rather than settled law.
First-order effects
- Facebook and other US tech firms gain a path to keep storing and accessing Europeans' personal data on US soil instead of being forced into full local-storage architectures or service disruptions in Europe.
- European users' data remains subject to US jurisdiction while negotiators work out surveillance safeguards, leaving the current legal footing provisional for both companies and regulators.
Second-order effects
- Privacy rights advocates, who signaled legal challenges against the last transatlantic deal, are positioned to contest any new agreement the same way — making court invalidation a recurring risk for every negotiated fix.
- Companies continue investing in EU-based data centers as insurance, since the 2015 workaround shows firms hedge against pact failures by localizing infrastructure regardless of diplomatic outcomes.
Third-order effects
- If the strike-down-then-renegotiate cycle holds, transatlantic data flows stay structurally dependent on periodic US surveillance-reform commitments rather than durable law, keeping compliance costs elevated for US firms operating in Europe.
- The trust deficit is measurable: surveys across six EU countries find roughly 84% of respondents don't trust US tech companies with their personal data, giving EU policymakers standing to demand stronger concessions in each successive deal.
The trend: Transatlantic data governance is settling into a recurring cycle of court-invalidated pacts followed by renegotiated deals, with each iteration trading more surveillance concessions for continued US access to European personal data.