by Rhys Dipshan
Vol. 101 No. 4 (2017) | Equal opportunity? | Download PDF Version of ArticleEDRM, the organization that devised the widely used Electronic Discovery Reference Model, has strived to keep e-discovery practitioners up to date on the ever-evolving digital landscape. Its guidance and standards, for instance, cover everything from proportionality in discovery to cybersecurity best practices when handling sensitive data. Now, EDRM is addressing the next big e-discovery challenge: adhering to the upcoming General Data Protection Regulation (GDPR) when performing data transfers from the U.S. to the EU.
The organization, which recently became a part of Duke Law School, announced an initiative in August 2017 to develop guidance for cross-border data transfers in advance of the GDPRâs spring 2018 implementation. Given the GDPRâs significant fines, vast scope, and complex directives, such guidance may prove pivotal for international teams and e-discovery practitioners, helping them navigate their U.S. obligations alongside the strict EU privacy rules.
Deena Coffman, managing director at BDO Consulting and an EDRM member who serves as project co-lead, said EDRMâs goal is to create âa practical set of guidelines that are focused solely on U.S.-Ireland data transfers within the context of litigation and outside of Privacy Shield.â She added that the guidance is expected to be released sometime around the latter half of 2018. While there are not any formal plans yet to expand the initiativeâs scope in the future, Coffman noted that there may be âyears of work neededâ to continually update the guidance âas new [direction] is provided [from the EU] to address a full range of scenarios.â She also expects the guidance to expand to cover data transfers to other EU countries, and not just Ireland.
For the time being, EDRM does not expect its guidance to be approved under GDPR Article 40 Code of Conduct â the formal industry guidance that the GDPR endorses, if the issuing organization can meet certain enforceability and certification requirements. But Coffman added that the current EDRM initiative lays âthe groundfloor foundation that can be matured into a full code of conduct in the future.â
Developing such cross-border guidance is sure to be a highly complex task given a number of factors. There is some uncertainty, for instance, over how some of the regulationâs provisions, such as the âright to be forgotten,â will be enforced in the market. Coffman noted, âThe GDPR, much like other regulations, could not be written to address every possible scenario and technology.â She expects EU agencies such as the Article 29 Working Party âto continue issuing guidance over the years to better clarify or focus GDPR provisions.â
Further exacerbating the challenge in drafting guidance are the vastly different legal and e-discovery cultures in the EU and the U.S. Coffman noted that while in the U.S. there is the belief that it is âbetter to have all permissible evidence, even if extremely costly to provide, than to miss an important piece of information,â in the EU, âan individualâs right to privacy is a fundamental human right.â
Indeed, once the GDPR goes into effect in 2018, it will require parties to get permission from EU citizens before processing their data. For Coffman, there is perhaps no bigger challenge for U.S. e-discovery teams than this mandate. This requirement âmay cause delays in legal proceedings which will be untenable,â she said. âUsing consent will not be practical because it can be revoked at any time by the data subject, and we know it will be impossible to âunproduceâ information already produced.â