(Reuters) – Companies based outside the European Union must meet Europe’s data protection rules, ministers agreed on Friday, although governments remain divided over how to enforce them on companies operating across the bloc.

The agreement to force Internet companies such as Google and Facebook to abide by EU rules is a first step in a wider reform package to tighten privacy laws – an issue that gained prominence following revelations of U.S. spying in Europe.

Vodafone’s disclosure on Friday of the extent of telephone call surveillance in European countries showed the practice was not limited to the United States. The world’s second-largest mobile phone company, Vodafone is headquartered in the United Kingdom.

“All companies operating on European soil have to apply the rules,” EU Justice Commissioner Viviane Reding told reporters at a meeting in Luxembourg where ministers agreed on a position that has also been backed by the Court of Justice of the European Union (ECJ).

Germany and the European Commission, the EU executive, have been highly critical of the way the United States accesses data since former U.S. National Security Agency contractor Edward Snowden last year revealed U.S. surveillance programs.

Disclosures that the United States carried out large-scale electronic espionage in Germany, including bugging Chancellor Angela Merkel’s mobile phone, provoked indignation in Europe.

“Now is the day for European ministers to give a positive answer to Edward Snowden’s wake-up call,” Reding said.

Commenting on Vodafone’s disclosure, she said: “All these kind of things show how important it is to have data protection clearly established.”

The reform package, which was approved by the European Parliament in March, has divided EU governments and still needs work to become law despite Friday’s progress…. see more

source: reuters