Latest Publications

Share:

6 Things to Know About the New EU-U.S. Data Privacy Framework

In early October, the United States (“U.S.”) and European Union (“EU”) came one step closer to the much-awaited new EU-US Data Privacy Framework (the “Framework”), designed to facilitate transatlantic data flows between the...more

"42", the Answer to the Number of Authorities Notified in Cross-Border Breaches – Don't Panic!

Last week, the European Data Protection Board ("EDPB") published a long-awaited update of its guidance on breach notification—which did not contain much news generally. However, it does bring a significant new burden for...more

Advocate General of ECJ on GDPR Damages. Is relief from non-substantial claims in sight?

While claims for damages in the event of data protection violations have theoretically existed for some time, they have been gaining in importance since the introduction of the General Data Protection Regulation ("GDPR")....more

EDPB Releases New Guidelines on the Calculation of Administrative Fines

After months of anticipation, the European Data Protection Board (EDPB) adopted new Guidelines on the calculation of administrative fines under the GDPR in May 2022. With the newly released Guidelines, the EDPB seeks to...more

Increased Scrutiny of Employee Monitoring Practices: Top 5 Takeaways Employers Need to Know

We are observing growing regulatory scrutiny of advanced employee monitoring practices, particularly from the European Union. Here are the key takeaways... ...more

10 Things to Know about the European Commission’s Questions and Answers on the GDPR Standard Contractual Clauses - Summer Global...

On June 4, 2021, the European Commission (the “Commission”) published its implementing Decision adopting standard contractual clauses for transfer of personal data to third countries (the “SCCs”) designed to comply with the...more

Update: European Subsidiaries of U.S. Cloud Providers Can Offer IT Services in the EU

The decision of the Procurement Chamber of Baden-Württemberg was annulled by the Higher Regional Court of Karlsruhe in its legally binding decision on September 9, 2022. In contrast to the approach chosen by the Procurement...more

Can European Subsidiaries of U.S. Cloud Providers No Longer Provide IT Services in the EU?

Analysis of the Baden-Württemberg Procurement Chamber on the admissibility of the use of IT services by European subsidiaries of U.S. cloud providers I. Background In its recently published decision (12 July 2022), a...more

Volkswagen Fined 1.1 Million Euros for GDPR Violations During Test Drives

On 26 July 2022, the Lower Saxony data protection authority ("Lower Saxony DPA") announced that it has imposed a fine of 1.1 million euros on Volkswagen ("VW") due to GDPR violations. It found that VW has violated data...more

Cyber Security Incidents in Multinational Companies in the EU and the US – Effective Crisis Management in Transatlantic IT...

Schnell ist es passiert. Ein Angriff auf die IT-Infrastruktur trifft Unternehmen fast immer zur Unzeit. Hacking und andere Infiltrationen der Unternehmenssysteme können binnen kürzester Zeit erhebliche Schadensketten in Gang...more

The New European Approach to Calculating Fines for Data Protection Breaches - Will it be More Predictable and Consistent?

On May 12, 2022, the European Data Protection Board (EDPB) published its long-awaited Guidelines 04/2022 on the calculation of fines under the General Data Protection Regulation (GDPR). After many data protection authorities...more

French and Italian Data Protection Authorities Take Issue with Google Analytics: Analysis and Key Takeaways

Google Analytics remains a hot topic for businesses and apparently also for data protection authorities (DPAs). With the advent of these new decisions and the new CNIL guidance, businesses have an even harder time justifying...more

The Four “W”s and One “H” of the European Commission’s Digital Services Act

After more than a year of negotiations the final text of Europe’s (EU) Digital Services Act (“DSA”) has been agreed upon by the EU Parliament, the French Presidency of the Council of the EU, and the European Commission (“EU...more

French Data Protection Authority Fines Processor for Failing to Enter into Data Processing Agreement

France’s data protection authority, the Commission Nationale de Informatique et des Libertés (“CNIL”), has issued one of its highest General Data Protection Regulation (“GDPR”) sanctions to-date against Dedalus Biologie SAS...more

The United States and European Commission Announce a New Trans-Atlantic Data Privacy Framework

The United States ("U.S.") and the European Commission ("EU Commission") recently announced an “agreement in principle” to develop a new Trans-Atlantic Data Privacy Framework (“Framework”). The Framework is intended to...more

8 Things You Need to Know About United Kingdom (UK) International Data Transfers

Update: UK international data transfer agreement and UK addendum to the EU standard contractual clauses now in force In February, the Information Commissioner’s Office (“ICO”), the United Kingdom (UK) data protection...more

French Bank Ordered to Pay Damages to Customer Following Inaccurate Personal Data Sharing Under FATCA

A “Kafkaesque” bank customer service experience in France has led to a “Right to be Forgotten” own-goal. Following a decision handed down by the judicial tribunal of Grenoble, France, on 7 February 2022, a French bank has...more

The ICO’s First Ransomware Monetary Penalty Notice: Key Takeaways

On March 10 2022, the UK Information Commissioner’s Office (ICO) handed down its first Monetary Penalty Notice in respect of a ransomware attack and data exfiltration incident under the UK General Data Protection Regulation...more

6 Things You Need to Know About United Kingdom (UK) International Data Transfers

In February 2022, the United Kingdom (UK) Information Commissioner’s Office (“ICO”), along with the data protection authority (“DPA”) in the UK, published three new documents ("UK Documents") which update the UK's position on...more

New EU Consumer Law Protections Applicable to Digital Goods and Digital Content Services Providers Take Effect, Requiring Ts & Cs...

From 1 January, 2022, contracts governed by French or German law for the sale of digital content and services, and goods with digital elements, will be subject to harmonised European rules that grant additional legal...more

The Austrian Data Protection Authority Ground-breaking Google Analytics Decision: Analysis and Key Takeaways

The Austrian data protection authority (Österreichische Datenschutzbehörde; Austrian DPA) recently ruled that the use of Google Analytics violated Chapter V (transfers of personal data to third parties) of the EU General Data...more

2021 Roundup: Global Artificial Intelligence, Cybersecurity & Privacy Developments

Significant developments in artificial intelligence, cybersecurity and consumer privacy occurred across the globe in 2021 with the anticipation of more activity in 2022. Our roundup for the year captures some of the major...more

6 Key Things to Know about the new EDPB Guidance on International Data Transfers

On November 19, 2021, the European Data Protection Board (“EDPB”) issued draft guidance on the interplay between Article 3 of the General Data Protection Regulation (“GDPR”) and the provisions on international transfers...more

With the September 27 Deadline Looming, 7 Key Things to Know About Europe’s New Standard Contractual Clauses (SCCs)

On June 7, 2021, the European Commission (Commission) published its long-awaited Implementing Decision adopting standard contractual clauses for the transfer of personal data to third countries referred to as the new Standard...more

10 Things You Should Know About the New Standard Contractual Clauses

Orrick's Cyber, Privacy & Data Innovation and IP Licensing & Technology Transactions groups cover the top 10 things you need to know about the new Standard Contractual Clauses ("SCCs") published today by the European...more

109 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide