Latest Posts › Data Processors

Share:

Thinking About Revising a Privacy Statement? Here Are Some Pointers

There have been some highly publicized privacy statement revisions. Here are some lessons we are discussing with clients: •Regulators are putting a high value on transparency and they are looking specifically at privacy...more

A Helpful Guide on Data Processing Consent

The Office of the Data Protection Authority of the Bailiwick of Guernsey has issued concise guide on the definition of consent. This is helpful not only for GDPR, but also for understanding and implementing consent under the...more

Data Protection Professionals Like it Hot: 7 Hot Topics and Trends in Data Privacy Today

Please take note! 1.SchremsII and cross border transfers: Risk based, wherefore art thou? With the Google Analytics, Google Fonts, Amazon AWS, Google Workspace other cases, the SchremsII and DPA guidance is piling up....more

No Google Analytics for You? EDPS Decision on EU Parliament’s Use of Google Analytics and More

A few days before the Austria DSB decision, the European Data Protection Supervisor (EDPS) issued a decision on the use of Google Analytics by the European Parliament. For Schrems II: EDPS says “if you don’t have any...more

You Use A US-based Sub Processor, You Lose, German Court says

If you use a U.S.-based sub processor (even for data processed in the EU), you lose, the German administrative court of Wiesbaden said in an interim decision. No transfer. No worries. TIA anyway...more

The Interplay Between GDPR’s Article 3.2 and Chapter V and (Finally) a Definition of ‘Transfer’

The European Data Protection Board has issued draft guidelines on the interplay between Art 3.2 and Chapter V of GDPR. And they also have finally defined the term “transfer.” Here are some key takeaways:...more

A (Slight) Light at the End of the Schrems II Tunnel: EDPS on the Explicit Consent Derogation

The European Data Protection Supervisor (EDPS) has issued an opinion on the European Union Agency for Cybersecurity’s (ENISA) use of the explicit consent derogation as a legal basis for cross border transfers to the US...more

Key Takeaways: The KVKK Fine Against WhatsApp

Key practice takeaways from the Kişisel Verileri Koruma Kurumu (KVKK) Turkey EUR 195,000 fine against WhatsApp (which echoes the Data Protection Commission Ireland decision in many respects):.....more

EDPB Issues Final Recommendations On Third Country Data Transfers

Third country laws – more than meets the eye. In practice – problematic legislation in disguise. The European Data Protection Board has issued a “Transformers” style plan for assessing whether or not you can transfer...more

UN Committee Issues Recommendations On The Right Of Children In Digital Environments

The UN Committee on the Rights of the Child has issued new recommendations on children’s rights in relation to the digital environment. Key data protection takeaways: The rights of every child must be respected,...more

A Template And Questions: The EDPB’s Draft Article 28 Standard Contractual Clauses

While we are all digesting (and lamenting) the European Data Protection Board's post-Schrems II Guidelines and cross-border transfer standard contractual clauses, the European Commission issued standard clauses that are meant...more

EDPB Controller-Processor Guidelines: German State Offers FAQs

The Data Protection Authority for the German state of Baden-Württemberg has issued FAQs on the European Data Protection Board's (EDPB) Controller-Processor Guidelines. Legal Concepts- •Contractual clauses can represent...more

Key Data Privacy Considerations For Vendor Management

Key takeaways from my recent presentation titled “Service Providers v. Data Processors: What Should Your Agreement Address?” with Lexology and Exterra...more

France Offers Guide For Processing COVID-19 Related Data Under GDPR

France’s Data Processing Authority CNIL weighs in on Coronavirus and GDPR. Employers should NOT: •Collect in a systematic and generalized manner, or through individual inquiries and requests, information relating to the...more

UK ICO Provides Guidance On Processing Sensitive Information

The United Kingdom's Information Commissioner's Office has updated its guidance on Special Category Data (Article 9 General Data Protection Regulation). Key takeaways: Genetic Data- Genetic analysis that includes enough...more

European Data Protection Board Issues Final Guidelines On Extraterritorial Application Of GDPR

The European Data Protection Board has issued long-awaited final guidelines for the extraterritorial application of the General Data Protection Regulation (GDPR). Key changes: (1) GDPR can apply extraterritorially to some...more

European Guidance On Data Controller And Processor Relationship Has Takeaways For GDPR, CCPA Compliance

The European Data Protection Supervisor (EDPS) has issued guidance on the concepts of data controller and processor for European Union organizations. Though it covers EU institutions, the guidance contains many concepts that...more

Isle Of Man Issues Guidance On Accountability Under GDPR

The Information Commissioner of the Isle of Man has issued guidance on “accountability” under GDPR. Key takeaways: You need to develop, embed and maintain a culture of data protection in your processing activities, with...more

Dutch Data Protection Authority Offers Its Take On ‘Legitimate Interest” Data Processing Authority

The Dutch DPA has issued guidance on the use of “legitimate interest” as a legal basis for processing data under GDPR. Key takeaways on what constitutes “legitimate”: The interest needs to be pursuant to a written or...more

Latin American And Spanish DPAs Issue Joint Statement On Data Processing And Artificial Intelligence

Latin American Data Protection Authorities and the Spanish Data Protection Authority have issued a joint statement on data processing and Artificial Intelligence....more

Ten Examples Of Data Processing Activities That Don’t Require A DPIA According To France’s CNIL

The French Data Protection Authority CNIL has issued guidance on types of data processing for which a Data Protection Impact Assessment (DPIA) is not required under GDPR: HR-related processing, not including profiling, for...more

EDPB Guidelines Explain ‘Necessary For The Performance Of A Contract’ Data Processing Basis

The European Data Protection Board (EDPB) has issued final guidelines on the General Data Protection Resolution's (GDPR) legal basis of "Necessary for the Performance of a Contract" (Article 6(1)(b)....more

Who Is Responsible Under GDPR For Putting A Data Processing Agreement In Place?

Who is responsible for putting a GDPR Article 28 Data Processing Agreement in place? Dutch Data Protection Authority, Autoreitpersoonsgegevens, says: BOTH the data controller and the data processor....more

New Zealand Privacy Commissioner: Companies Need To Be Fully Transparent About Data Processing

Click to accept – not always good enough, says the New Zealand Privacy Commissioner. Companies need to be fully transparent about their data processing practices and take steps to ensure that this is conveyed to the...more

40 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide