Regulatory Watch  /  European Union  /  Enforcement
Moderate impactEnforcementPublished

EDPS reprimands European Parliament for illegal EU‑US data transfers via Google and Stripe

The European Data Protection Supervisor (EDPS) issued a decision reprimanding the European Parliament for violating data protection law on its COVID‑testing website. The use of Google Analytics and Stripe was found to breach the CJEU's Schrems II ruling on EU‑US data transfers, and the Parliament’s cookie banners were deemed deceptive and non‑transparent. The EP was ordered to update its data‑protection notice within one month and to cease unlawful transfers.

Why it matters: The decision signals stricter enforcement of EU data‑transfer rules and consent requirements for public institutions using US services.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
EDPS sanctions Parliament over EU-US Data Transfers to Google and Stripe
noyb · primary source · Jan 11, 2022
EDPS sanctions Parliament over EU-US Data Transfers to Google and Stripe
noyb · Jan 11, 2022
Details
JurisdictionEuropean Union
RegulatorEuropean Data Protection Supervisor (EDPS)
LegislatureEuropean Parliament
LawGeneral Data Protection Regulation
StatusPublished
PublishedJanuary 11, 2022
Effectivenot stated
Penaltyreprimand and an order to comply; no fine
OrganisationsEuropean Parliament, Google, Stripe
Topicsconsent, transparency, cross border transfer, cookies, tracking, access
Datapersonal