Privacy Week: A Common Standard Across Borders?
During Cloudflare’s recent Privacy Week, a series of fireside chats examined the ongoing legal and political friction around data protection, especially the transatlantic debate on data sovereignty and cross-border access. The conversations pulled in perspectives from legal experts, security executives, and advocacy leaders, sketching out the path toward a more coherent global compliance landscape.
Bridging the Atlantic Differences
There is wide agreement that the current patchwork of regulations is unsustainable, but also a recognition that bridging the divide between the two major markets will require deliberate dialogue. Prof. Dr. Wilfried Bernhardt emphasized the need for a renewed effort by the European Commission and the incoming US administration to sit down together. While fundamental values like human rights and democracy are shared, he noted that privacy itself is interpreted differently: in the US, free expression can take precedence over privacy, while Europe leans the other way. That difference should not translate into unchecked interference with data belonging to European citizens.
The logic of dependency is central to this. Dr. Katrin Suder argued that a sober inventory of the present situation is the first step. European policymakers must decide where reliance on foreign technology is simply a tradeoff and where it is a true critical vulnerability. The emphasis, she said, should be on pushing the next generation of technology rather than cloning what already exists. Her suggestion is that the European Commission should be the one leading this structured process.
Shaping Europe’s Regulatory Engine
The European regulatory agenda for the year ahead is dense. Iverna McGowan, Director of the Europe Office at the Center for Democracy & Technology (CDT), highlighted the Digital Services Act as the central piece of legislation shaping the discussion in 2021. Her concern is not only data protection but also the balance between defending free expression and preventing harassment. The real test, she argued, lies in practice more than in law: protecting the Internet as a commons while building in safeguards for users. A multistakeholder approach, bringing companies and civil society together to inspect the specific technical realities of a policy proposal, is one area where the conversation can be productive.
Technical Risks in Content Moderation
Some proposals emerging in the European policy space worry the technical community. Marshall Erwin, Chief Security Officer at Mozilla, pointed to the absence of a strong privacy framework in the US but added that it also holds back mandatory data retention and forced blocking at the national level. In parts of Europe, the converse problem is rising: a drift towards retention regimes and an interest in using the DNS infrastructure as a means to impose content blocking from the central stack.
That strategy is misguided, according to Erwin. Not only does it raise red flags over free expression, but it is an unreliable instrument to filter malicious content. Decisions at that layer of the stack are technically blunt and present real risks to the open Web. His team continues to look for a workable policy mix targeting online harm without sweeping side effects—but the infrastructure-level imposition of law is the wrong approach.
Toward a Long-Term Model for Government Oversight
On a broader level, there is momentum for formalizing how states gain access to data located in other jurisdictions. Thomas Boué, Director General for Policy EMEA at BSA | The Software Alliance, framed this as the necessary next step: finding a standard agreed upon by like-minded democracies that defines when and how a government can access private data in the course of a national security investigation. That standard would begin with a set of safeguards for handling the data and end with meaningful avenues of redress or challenge.
The value of such an agreement would be twofold. It would introduce certainty for firms operating in multiple legal zones while also easing the tension between privacy protection and security needs. Boué pointed to work within specific international forums, such as the OECD, as a sign that governments are already beginning to engage on this topic; the hope is that this political momentum can be transformed into a durable, transparent legal framework.



