In response to the increasing number of cyberattacks and the acceleration of digital transformation across sectors, the European Union has revised and improved its Network and Information Security (NIS) Directive.
The...more
The European Union Digital Services Act (DSA) now applies to all digital “intermediary services” that provide users with access to online goods, services, and content. The DSA took effect on November 16, 2022, and regulates a...more
2/27/2024
/ Brand ,
Compliance ,
Data Storage ,
Data Storage Providers ,
Digital Marketplace ,
Digital Service Providers ,
Digital Services ,
EU ,
European Commission ,
Goods or Services ,
Online Platforms ,
Regulatory Requirements ,
Regulatory Standards ,
Traders
On December 8, 2023, European Union policymakers brokered a deal on a broad law to regulate the development and use of artificial intelligence (AI) in the European Union....more
The world’s first artificial intelligence (AI) regulatory framework is “a step closer” to becoming law, the European Parliament recently announced. Following the European Commission’s 2021 draft proposal, a draft negotiating...more
On March 25, 2022, the European Union (EU) announced that the United States and the EU had reached an agreement in principle to replace the EU-U.S Privacy Shield framework, which the European Court of Justice (CJEU) struck...more
4/1/2022
/ Corporate Counsel ,
Court of Justice of the European Union (CJEU) ,
Data Collection ,
EU ,
EU-US Privacy Shield ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses
The Information Commissioner’s Office (ICO) recently released its response to the UK government consultation, ‘Data: A new direction’. The consultation was conducted by the Department for Digital, Culture, Media and Sport...more
12/23/2021
/ Adequacy Requirement ,
Binding Corporate Rules ,
Consultation ,
Data Privacy ,
Data Protection ,
Data Protection Impact Assessments (DPIAs) ,
Data Subject Access Requests ,
Electronic Communications ,
EU ,
Information Commissioner's Office (ICO) ,
International Data Transfers ,
Personal Data ,
Risk-Based Approaches ,
Standard Contractual Clauses ,
UK
On June 4, 2021, the European Commission adopted two new sets of standard contractual clauses (SCCs): one for data transfers from data controllers to data processors and one for data transfers from data exporters to data...more
6/14/2021
/ Compliance ,
Corporate Counsel ,
Data Controller ,
Data Processors ,
Data Protection ,
Data Transfers ,
Employee Privacy Rights ,
EU ,
European Commission ,
European Data Protection Board (EDPB) ,
European Economic Area (EEA) ,
General Data Protection Regulation (GDPR) ,
Human Resources Professionals ,
International Data Transfers ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses
After the political and constitutional upheaval of the last four years that has been Brexit, a trade deal - the EU-UK Trade and Cooperation Agreement - was finally reached between the United Kingdom (UK) and the European...more
1/27/2021
/ Data Privacy ,
EU ,
European Economic Area (EEA) ,
Grace Period ,
Information Commissioner's Office (ICO) ,
International Data Transfers ,
Member State ,
Privacy Laws ,
Trade Agreements ,
UK ,
UK Brexit
The Court of Justice of the European Union (CJEU) recently declared that the EU-U.S. Privacy Shield is invalid because it does not provide an adequate level of protection for the transfer of personal data from the European...more
On July 16, 2020, the Court of Justice of the European Union (CJEU) announced its judgment in the so-called Schrems II case (Case C-311/18), declaring that the EU-U.S. Privacy Shield is invalid because it does not provide an...more
7/17/2020
/ Court of Justice of the European Union (CJEU) ,
EU ,
EU-US Privacy Shield ,
European Commission ,
International Data Transfers ,
Personal Data ,
Safe Harbors ,
Schrems I & Schrems II ,
Standard Contractual Clauses ,
Surveillance ,
U.S. Commerce Department
As coronavirus disease 2019 (COVID-19) continues to spread, employers have been trying to strike a balance between safety and privacy as they apply their own policies and attempt to follow laws such as the General Data...more
3/4/2020
/ Centers for Disease Control and Prevention (CDC) ,
Coronavirus/COVID-19 ,
Emergency Management Plans ,
Employee Privacy Rights ,
Employer Liability Issues ,
EU ,
General Data Protection Regulation (GDPR) ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Infectious Diseases ,
Public Health ,
Workplace Safety
Much has happened since the European Union (EU) General Data Protection Regulation (GDPR) went into effect on May 25, 2018. Many EU countries have enacted national legislation to implement and expand the requirements of the...more
5/22/2019
/ Austria ,
CCTV ,
CNIL ,
Data Breach ,
Data Protection ,
Data Protection Authority ,
Employer Liability Issues ,
Enforcement Actions ,
EU ,
European Data Protection Board (EDPB) ,
France ,
General Data Protection Regulation (GDPR) ,
Germany ,
Human Resources Professionals ,
Netherlands ,
Personal Data ,
Personnel Records ,
Portugal ,
Regulatory Violations ,
Risk Management ,
Social Networks ,
Surveillance ,
Video Recordings
Much has happened since the European Union (EU) General Data Protection Regulation (GDPR) went into effect on May 25, 2018. Many EU countries have enacted national legislation to implement and expand the requirements of the...more
On April 19, 2018, the Article 29 Working Party (Working Party), which is comprised of representatives from the data protection authorities in each of the 28 European Union (EU) member states, issued a position paper stating...more
On March 27, 2018, Helen Dixon, the data protection commissioner for Ireland, outlined the enforcement priorities of the Irish data protection authority (DPA) for the General Data Protection Regulation (GDPR) during the...more
On October 18, 2017, the European Commission published its report and supporting documents regarding its first annual review of the EU-U.S. Privacy Shield (Privacy Shield), which sets forth procedures and safeguards for...more
How do you sum up what just happened in the United Kingdom’s parliamentary election? I thought the journalist Hugo Rifkind did it rather well last Saturday on BBC Radio 4’s The News Quiz, a show that takes a satirical and...more
On May 25, 2018, a short 12 months from now, employers must be in full compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) for EU human resources data. The GDPR requirements regarding...more
As employers catch their breaths after an action-packed 2016, they need to gear up for another turbulent year for international data privacy issues in 2017. The top five international data privacy issues follow....more
On July 12, 2016, the European Commission formally adopted the EU-U.S. Privacy Shield to replace the previously invalidated Safe Harbor Framework as an adequate method of transferring personal data from the European Economic...more
7/14/2016
/ Data Protection Authority ,
Employer Liability Issues ,
EU ,
EU-US Privacy Shield ,
Federal Trade Commission (FTC) ,
International Data Transfers ,
Ireland ,
Personal Data ,
Privacy Policy ,
Schrems I & Schrems II ,
Self-Certification ,
Standard Contractual Clauses ,
Surveillance ,
U.S. Commerce Department ,
US-EU Safe Harbor Framework
Just four days after the Brexit vote the FTSE 100 has recovered much of the ground it lost and the strength of the pound against the dollar has recovered a little from a 31-year low. Why? And what do we say to US businesses...more
On June 24, 2016, the European Commission announced that it had reached a final agreement with the United States on the terms of the EU-U.S. Privacy Shield, which will permit U.S. companies to transfer the personal data of...more
6/28/2016
/ Corporate Counsel ,
Data Retention ,
EU ,
EU-US Privacy Shield ,
European Commission ,
International Data Transfers ,
Ombudsman ,
Personal Data ,
Popular ,
Surveillance ,
UK ,
UK Brexit ,
Young Lawyers
The people of the United Kingdom have spoken on the issue of whether the United Kingdom should leave or remain in the European Union (EU), and by a narrow margin have decided to leave. In fact, by region, the voters of...more
6/24/2016
/ Currency Fluctuation ,
EU ,
EU-US Privacy Shield ,
Financial Markets ,
Foreign Subsidiaries ,
General Data Protection Regulation (GDPR) ,
International Finance ,
International Labor Laws ,
London Stock Exchange ,
Member State ,
Popular ,
Referendums ,
Treaty on the Functioning of the European Union (TFEU) ,
UK ,
UK Brexit
On February 29, 2016, the European Commission (EC) and U.S. Department of Commerce (DOC) published a series of documents providing details for the implementation of the new EU-US Privacy Shield framework for the transfer of...more
3/7/2016
/ Article 29 Working Party (WP29) ,
Binding Corporate Rules ,
EU ,
EU-US Privacy Shield ,
European Commission ,
International Data Transfers ,
Ombudsman ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses ,
Surveillance ,
U.S. Commerce Department ,
US-EU Safe Harbor Framework
On February 3, 2016, the Article 29 Working Party, the EU body representing the data protection authorities (DPA) of each EU member country, announced that all of the DPAs across the EU have agreed to extend the current...more
2/5/2016
/ Article 29 Working Party (WP29) ,
Binding Corporate Rules ,
Data Protection Authority ,
Enforcement Actions ,
EU ,
EU-US Privacy Shield ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Moratorium ,
Standard Contractual Clauses ,
US-EU Safe Harbor Framework