On October 24, 2024, the Irish Data Protection Commission (DPC) issued a press release announcing its EUR 310 million fine of LinkedIn over the platform’s use of member personal data in breach of the EU’s General Data...more
Yesterday, March 13, 2024, the European Parliament approved the EU Artificial Intelligence Act (“AI Act”), a sweeping AI governance framework which presents the first comprehensive law in the world aimed at ensuring AI...more
3/15/2024
/ Artificial Intelligence ,
Compliance ,
Compliance Dates ,
Digital Services ,
EU ,
European Commission ,
European Parliament ,
Exceptions ,
General Data Protection Regulation (GDPR) ,
Machine Learning ,
Member State ,
Multinationals ,
Penalties ,
Regulatory Authority ,
Risk-Based Approaches ,
Technology
Generative AI (GenAI) surged to the forefront of corporate agendas and public policy debates last year, promising to boost productivity and innovation. What’s in store for AI in 2024?...more
1/17/2024
/ Artificial Intelligence ,
Authors ,
Authorship ,
Copyright ,
Copyright Infringement ,
Data Privacy ,
EU ,
General Data Protection Regulation (GDPR) ,
Innovative Technology ,
Inventors ,
Investors ,
IP License ,
Machine Learning ,
Patents ,
Pharmaceutical Industry ,
Popular ,
Privacy Concerns ,
Regulatory Oversight ,
Software ,
Technology Sector
On 25 August 2023, the EU’s Digital Services Act (“DSA”) came into effect for very large online platforms and very large online search engines. The DSA becomes fully applicable to other entities within its scope on 17...more
Generative AI models access vast pools of information from a wide variety of sources, including information users add in prompts. This can include private or sensitive information, which may be used without consent and may be...more
On June 4, 2021, the European Commission (the “EC”) abolished the old Standard Contractual Clauses (the “Old SCCs”) and published a new more flexible set of clauses (the “New SCCs”) for companies that wish to export personal...more
The European Data Protection Board (EDPB) recently published Minutes of its last plenary meeting held in September, which sheds light on how the EDPB plans to address the biggest open issue of the new Standard Contractual...more
The dust has settled on the new EU standard contractual clauses for cross-border data transfers (“New SCCs”), but confusion still reins on how the New SCCs cover data transfers and what companies need to do to take advantage...more
8/27/2021
/ Court of Justice of the European Union (CJEU) ,
Data Controller ,
Data Privacy ,
Data Processors ,
Data Protection ,
Data Transfers ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
Impact Assessments ,
Information Commissioner's Office (ICO) ,
International Data Transfers ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses ,
UK
Risks of non-compliance with the GDPR keep increasing with data protection authorities (DPAs) now ordering suspension of transfers of personal data to the U.S. In March, the Bavarian DPA found there was an unlawful transfer...more
On 31 March 2021 the Dutch Data Protection Authority (DPA) announced that it fined the online reservation platform Booking.com €475,000 for failing to notify the DPA of a data breach within the timeline established in the...more
The UK Information Commissioner’s Office (“ICO”) has published a letter sent to the U.S. Securities and Exchange Commission. The ICO confirms that it is possible for SEC regulated UK firms to transfer personal data to the...more
3/23/2021
/ Brokers ,
Financial Institutions ,
Financial Services Industry ,
General Data Protection Regulation (GDPR) ,
Information Commissioner's Office (ICO) ,
International Data Transfers ,
Investment Management ,
Personal Data ,
Public Interest ,
Securities and Exchange Commission (SEC) ,
UK
Earlier this year, the European Data Protection Board (“EDPB”) issued additional guidance on the application of the General Data Protection Regulation (“GDPR”) in the area of scientific health research.
In key takeaways...more
3/5/2021
/ Consent ,
Data Protection ,
Data Protection Impact Assessments (DPIAs) ,
EU ,
European Commission ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Member State ,
Personal Data ,
Scientific Research
On 15 January, 2021, the European Data Protection Board (“EDPB”) and the European Data Protection Supervisor (“EDPS”) adopted a joint opinion (“Joint Opinion”) on the draft new sets of Standard Contractual Clauses (“New...more
1/28/2021
/ Data Protection ,
EDPS ,
EU ,
EU Data Protection Laws ,
European Commission ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses
On December 15, 2020, Ireland’s Data Protection Commission (“DPC”) announced its decision to fine Twitter International Company (“Twitter”) €450,000 for failing to notify the DPC promptly of a data breach affecting EU...more
1/20/2021
/ Cyber Incident Reporting ,
Cybersecurity ,
Data Breach ,
Data Controller ,
Data Processors ,
Data Protection ,
Data Protection Commissioner ,
Data Security ,
EU ,
Failure to Notify ,
General Data Protection Regulation (GDPR) ,
Personal Data ,
Policies and Procedures ,
Twitter
Today (July 16) Europe’s highest court, the Court of Justice of the European Union (CJEU), in the case of Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (Schrems II) invalidated the EU–U.S. Privacy...more
7/17/2020
/ Court of Justice of the European Union (CJEU) ,
Data Controller ,
Data Processors ,
Data Protection ,
EU ,
EU-US Privacy Shield ,
European Economic Area (EEA) ,
General Data Protection Regulation (GDPR) ,
Information Commissioner's Office (ICO) ,
International Data Transfers ,
Standard Contractual Clauses
The Advocate General has issued an Opinion which states that the European Commission’s decision, enforcing the Standard Contractual Clauses (SCCs), is valid....more
The Berlin Commissioner for Data Protection (Berlin DPA) has fined Deutsche Wohnen SE, a German property company, €14.5 million for violating the General Data Protection Regulation. This is the largest GDPR fine issued to...more
On January 21, 2019, France’s data protection regulator (CNIL) imposed a €50 million fine on Google for violating core provisions of the European Union General Data Protection Regulation (GDPR). The action was initiated by...more
On November 16, 2018, the European Data Protection Board (Board) (comprised of EU member state data protection authorities), published draft guidelines on the territorial scope of the GDPR (Guidelines).The Guidelines provide...more