Latest Publications

Share:

CJEU Sets High Bar for Responses to Data Subject Access Requests

Organisations must provide individuals with information on the specific recipients of their data upon request. The Court of Justice of the European Union (CJEU) has ruled that organisations must generally disclose the...more

UK Data Protection Bill: Examination of Key Provisions (Part 2)

Areas of interest include anonymisation, “recognised legitimate interests”, and the ICO’s role. The UK Data Protection and Digital Information Bill (the Bill) sets out the government’s proposals for reforming the current...more

UK Data Protection Bill: Overview of Proposed Changes (Part 1)

The bill would largely build on the UK data protection regime’s EU GDPR-style framework, albeit with UK-specific provisions. The UK government introduced the Data Protection and Digital Information Bill (the Bill) to...more

CNIL Publishes White Paper on Digital Payments and Data Privacy

The French Data Protection Authority’s white paper discusses how companies can comply with data privacy and security obligations. The use of card, contactless, and innovative digital payment solutions has significantly...more

EDPB Issues New Guidance on Storing Credit Card Data for Future Purchases

Online retailers storing credit card data for the sole purpose of facilitating further purchases will likely need to obtain consumer consent. Online shopping has boomed in recent years. In 2020, the European statistics...more

NFTs: A Beginner’s Guide to Understanding the Hottest Crypto Craze

An NFT is a special, one-of-a-kind digital asset that raises a number of novel legal questions. Earlier this month, a blockchain firm bought a US$95,000 print by the British street artist Banksy, only to burn it in a...more

Privacy and Payments: New Draft EU Advice for Financial Institutions

As contactless transactions boom, EU regulators publish draft guidelines on the interplay between the GDPR and PSD2. Last year, more than half of all payments in the UK were made by card and contactless methods, while cash...more

CJEU Invalidates EU-US Privacy Shield

A ruling by the EU’s top court invalidates the key mechanism for transferring personal data from the EU to the US and imposes additional conditions for use of the standard contractual clauses. On 16 July 2020, the Court of...more

EDPB Guidelines – What is the Territorial Reach of the GDPR?

After the recent two-year anniversary of the GDPR, one fundamental question remains — who does the GDPR apply to? Last month marked the two-year anniversary of the General Data Protection Regulation (GDPR), but its...more

UK Supreme Court Clarifies Position on Vicarious Liability for Data Breaches

Judgment offers some comfort for data controllers, without eliminating the possibility of vicarious liability based on an employee’s actions. The UK Supreme Court (UKSC) has ruled that WM Morrisons Supermarkets plc...more

Adtech and Real Time Bidding in the Regulatory Crosshairs

UK data protection regulator demands companies in the RTB ecosystem re-evaluate privacy notices, use of personal data, and lawful basis. The UK Information Commissioner’s Office’s (ICO’s) latest report into adtech and real...more

Britische Datenschutzaufsicht ICO kündigt Rekordbußgelder wegen DSGVO-Verstößen an

Das ICO kündigt an, Bußgelder gegen British Airways und Marriott zu verhängen. Was ist passiert, wie geht es weiter? Am 8. Juli 2019 kündigte das Information Commissioner’s Office (ICO) an, gegen British Airways wegen...more

UK Regulator Imposes Two Substantial Fines for GDPR Data Breaches

The ICO issued notices of intent to fine British Airways and Marriott. What happened? On 8 July 2019, the UK Information Commissioner’s Office (ICO) announced a notice of intent to fine British Airways £183.39 million (about...more

GDPR & PSD2: Squaring the Circle

GDPR and PSD2 are two legal initialisms that have both generated a great deal of press coverage in recent months, but they are seldom considered together. There were around 122 billion non-cash payments in the European...more

GDPR Countdown: Latham’s National Implementation Tracker

The EU General Data Protection Regulation (GDPR) will come into force in May 2018, changing how businesses and the public sector manage customer information. With seven months before the deadline, governments, supervisory...more

Schrems Strikes Again? The Future of EU Standard Contractual Clauses

On October 3, 2017, the Irish High Court announced that it will make a reference to the Court of Justice of the European Union (CJEU) for a preliminary ruling on the validity of the Standard Contractual Clauses, which allow...more

UK Government sets out its preferred post-Brexit landscape for data protection

Her Majesty’s Government last week published a position paper outlining its preferred post-Brexit landscape for data protection. The high-level takeaways are hardly surprising: the government stresses that it intends to...more

The Countdown Continues: One Year to the GDPR

The General Data Protection Regulation (GDPR or Regulation) will become applicable in one year, as of May 25, 2018. A lot has happened since we set out the key provisions of the Regulation last year....more

Banking on IT

The European Banking Authority (EBA) has published its consultation document on security measures for operational and security risks under the revised Payment Services Directive (PSD2). The WannaCry ransomware attack that...more

GDPR Guidance: DPOs, Data Portability & the One-Stop-Shop

The Article 29 Working Party (WP29) – the group that represents the data protection authorities of all EU Member States – has published guidance and FAQs on a number of issues under the General Data Protection Regulation...more

20 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide