Newsletter            Wir rufen zurück            Impressum

Safe Harbour Agreement – Effects on SuccessFactors and SAP onPremise HR Systems?

Paperwork

In an action reminding me strongly of the fairy tale „The Emperors New Clothes“ and Austrian citizen shot down the „Safe Harbour“ agreement between America and the EU leaving many organisations storing HR data of EU citizens exposed as acting illegally at the stroke of a pen. Whilst the original cause for the case was facebook, the fall of „safe harbour“ has the potential to disrupt your SAP HCM or SuccessFactors based HR processes.

This article is a mere conversation starter to provide some food for thought. It doesn’t constitute legal advice in any shape or form.

What happened to the safe harbour agreement?

So far, the „Safe Harbour“ Agreement between the US and the EU made it easy to work under the assumption that the protection of personal data in the USA is as good as in the EU for legal purposes – to put it simply. Some considered it a pragmatic solution to facilitate trade with services. Others called it an outrage and claimed it violates basic rights of European citizens.

In a case triggered by a facebook user from Austria, the European Court of Justice confirmed, what most people already knew even before the NSA crisis: data privacy in the United States is not on the same reasonably high standard as in the EU. No surprises, really. But just as in the  „The Emperors‘ new Clothes“ fairy tale, a truth known and a truth spoken are two very different beasts.

The Safe Harbour agreement has basically been invalidated by the new court ruling.  – Read this article for more information on the ruling

What’s the impact on companies using SAP HCM, SuccessFactors or other HR systems?

If you keep personal data of EU employees and candidates on your own or hosted server within the boundaries of the EU, you’re fine. For SuccessFactors customers, SAP offers several EU based data centres and as most European customers insisted on using these for data protection reasons despite the Safe Harbour agreement, those customers are safe as well (similar for Concur). But: if you are not sure, where your data centre is, check it with your vendor.

Organisations using other hosted or cloud based HR systems should definitely check those regarding the data storage location.

It gets really interesting for global organisations. So far, most American corporates would have stored data of their European workforce on their own servers in the US or in SuccessFactors‘ American data centres relying on the Safe Harbour agreement. Will this still be possible in future – maybe by gaining permission from employees? Would many people sign this anyway? Is it legal to make this permission part of employment contracts?

Or will Eurocrats oblige and come up with a new version of Safe Harbour, so it will all be back to business as usual?

I don’t know. I’m not sure anybody really knows. Fact: here’s a risk for many organisations‘ HR systems strategies and it affects SAP HCM  on premise systems at least as much as SuccessFactors – and it may be even worse for other cloud HRIS vendors lacking EU data centres.

Will this data privacy challenge eventually be good for cloud adoption?

The end of the Safe Harbour agreement is part of a trend. There are similar rules or preferences elsewhere and most recently Russia put a very strict rule about storage of personal data in place. In the end HR systems may have to distribute HR data geographically as a standard procedure. If that happens, cloud solutions might actually be the way out of the dilemma, as it’s easier for large cloud vendors to spread data across multiple locations than it is for customers to do so with their on premise HR systems. Most notably cloud vendors with a strong infrastructure of global data centres like SuccessFactors could be in pole position. This would really turn things upside down, as data protection concerns so far have been perceived as a barrier to cloud adoption – rightly or wrongly.

Personally, I wouldn’t be surprised, if this change rather than slowing down cloud HRIS adoption, will end up pushing it. But: who knows. At this point in time many different options are still possible.

What are your thoughts?

  • How are your IT and HR teams responding?
  • Has the recent requirement from Russia helped you to prepare?
  • Do you have contingency plans in place for this kind of grey swan?

Related Posts

4 Responses
  1. Oliver

    Hi, any US-Company is bound to the PATRIOT-Act allowing US LE access to data on the server of us-companies worldwide even if the local law didn’t allow it without any warrant etc. It can’t be changed by any private law contracts like some us-companies pretend. In my opinion any use of us cloud services to store personal data is prohibited now. The cloud business is dead. Maybe the german cloud created by microsoft at this time is a solution.

    1. Sven Ringling

      Hi Oliver,

      a fair comment to begin with, but imo the conclusion is a bit over the top.
      A) there is already new legislation in place to replace the Safe Harbour agreement
      B) There are substantial non-US cloud companies by now like SAP, who own SuccessFactors (if need be, it would be easy for SAP to move subsidiearies‘ head offices to Germany as well, or just make them sell their servers to SAP holding), Ariba, Concur, Fieldglass and run some own brand clouds like CRM cloud.

  2. Oliver

    Successfactors is a US company – so it doesn’t matter where they store the data. It’s illegal for european companies!

    1. Sven Ringling

      Hi Oliver,

      so, you are saying it’s legally not allowed for European companies to hold data at any servers owned by US companies? So, if personal data was involved (and there’s always some), no EU companies could use google docs, Office 365, Amazon Web Services, Microsoft Azure, Rackspace, Salesforce, Tripit, Dropbox, iCloud, gmail, hotmail, Skype,…

      Sounds like an immediate break down of the European economy.
      Do you have a reference to that legislation? If there is something that can be interpreted that way.

      SuccessFactors may actually be the exception, because it’s a subsidiary of a German company, so really shouldn’t count as US (unless you say, it’s the subsidiary that counts, but then again the European datacentres will be held by European subsidiaries of SuccessFactors – how ever you look at it , SuccessFactors is one of the few cloud solutions you could still use, if that was true ;-) )

      Or, do you conclude that because US companies have a tendency to break other countries laws, because it’s usually much easier for them to get away with it than the other way round? Sadly that’s true and may be reason to think twice before trusting a US vendor to stick to EU law, but I don’t think that make sit illegal for European firms to use US cloud vendors?

Leave a Reply