The Federal Trade Commission is cracking down on companies that falsely certify compliance with the United States and EU safe harbor framework on data protection. Expect that scrutiny to only intensify in the coming year.

Developed in 2000 by the U.S. Department of Commerce and the European Commission, the U.S.-EU Safe Harbor Framework establishes a set of guidelines that provide a streamlined means for U.S.-based companies to legally transfer personal data from Europe into the United States. To participate, a company must self-certify to the Department of Commerce that it meets the EU’s stringent standard for data protection, and further must reaffirm its certification annually thereafter.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...