Latest Posts › General Data Protection Regulation (GDPR)

Share:

The EU’s Cyber Resilience Act: New Cybersecurity Requirements for Connected Products and Software

The CRA will affect a broad range of digital products placed on the EU market (including by those based outside the EU), including connected hardware/devices, software and remote data processing solutions. The EU has adopted...more

EU AI Act: First Set of Requirements Go into Effect February 2, 2025

The first binding obligations of the European Union’s landmark AI legislation, the EU AI Act (the Act), came into effect on February 2, 2025. Essentially, from this date, AI practices which present an unacceptable level of...more

GDPR Enforcement: Lessons from Recent Data Privacy Penalties

Recent decisions by the French data protection authority (CNIL) have highlighted the importance of GDPR compliance, particularly in the areas of data retention, consent for processing sensitive personal data, and marketing...more

The New UK-U.S. Data Bridge

The UK and U.S. Governments have now formalized the UK-U.S. Data Bridge. The U.S. Attorney General designated the UK as a “qualifying state” for the purposes of the Executive Order 14086 on September 18, 2023, and the UK...more

Upcoming EU Rules on Digital Operational Resilience

There will be additional compliance obligations and mandatory contractual provisions introduced for financial entities and outsourced IT service providers. The new DORA seeks to strengthen the resilience of financial...more

Landmark Federal Privacy Bill Clears First Congressional Hurdle

American Data Privacy and Protection Act would require organizations to limit collection of personal information, grant consumers access to their own data, enhance data protections for children, mandate implementation of...more

New EU Guidance Clarifies When Data Transfers Need to be “Safeguarded”

The European Data Protection Board (EDPB), the body which represents EU data protection authorities, has adopted guidelines (Guidelines) confirming when transfers need to be “safeguarded” in accordance with the GDPR (and...more

Data Transfers from Europe: Final Version of New SCCs Published

The European Commission’s decision of 4 June 2021 finalises the new SCCs for transferring personal data from the EEA. After invalidation of the Privacy Shield by Europe’s top court, many businesses came to rely upon...more

UK-EU Brexit Agreement Finally Agreed – Key Takeaways

Just one day before New Year’s Eve, EU Commission President Ursula von der Leyen, EU Council President Charles Michel and UK Prime Minister Boris Johnson finally signed the EU-UK Trade and Cooperation Agreement. Effective as...more

Data Transfers from Europe: New Draft SCCs Published and Regulator Guidance Issued on Schrems II Privacy Shield Decision

The EDPB has issued recommendations concerning how organisations may lawfully transfer personal data from Europe to “third countries” (e.g., the U.S. and currently the UK from 1.1.2021) in light of the recent Schrems II...more

Privacy Shield: The International Data Transfer Scheme Struck Down

Trans-Atlantic transfer scheme relied on by thousands of EU and U.S. organisations to transfer personal data from the EU to the U.S. deemed invalid by the Court of Justice of the European Union (CJEU). Privacy Shield has...more

A Landmark Ruling on the Vicarious Liability of Employers for Data Breaches Caused by Rogue Employees

UK Supreme Court ruled this week in favour of retailer facing vicarious liability class action claims following significant data breach caused by rogue employee. The case is a stark reminder of the responsibilities of...more

Countdown to CCPA #2: GDPR Compliance Does Not Equal CCPA Compliance

Similarities aside, there are significant differences between the two privacy laws. The CCPA grants rights to individuals who are residents of California under a definition used for income tax purposes....more

New EU Data Laws—What Nonprofit Organizations Need To Know; Including Template for US/EU Privacy Notice

How will the new European Union data protection law affect U.S. nonprofit organizations? Nonprofit organizations based in the U.S. can often handle large amounts of data which originates in the EU—for example, they may...more

NHS Digital Publishes Guidance for Health and Care Organisations Using Cloud Services and Data Offshoring

NHS and social care organisations in the UK are being encouraged to take a fresh look at public cloud services given the myriad benefits of doing so. The guidance is timely given the coming into force of the GDPR in May,...more

DPO as a Service – Outsourcing the Role of Data Protection Officer

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing...more

EU Data Transfer Solutions Under Further Judicial Scrutiny – What Next For Model Contract Clauses?

The European Union Court of Justice (“CJEU”) to rule on the validity of Model Contractual Clauses (“MCCs”) following referral by the Irish High Court. The Irish High Court has “well-founded” concerns that there is no...more

The ICO’s Draft Guidance Leaves Unanswered Questions on Processor Obligation to Notify Infringing Instructions

Those of us who have been grappling with how best to approach GDPR compliance in outsourcing and other commercial contracts will be all too familiar with Article 28 of the GDPR, which sets out a number of minimum contract...more

UK Government Publishes Statement on GDPR Compliance, Post-Brexit

The UK Government has published a statement of intent containing details of its proposed Data Protection Bill. The full text of the Bill is expected in September 2017, when the UK Parliament returns from its summer...more

EU General Data Protection Regulation (GDPR) - Overview of Key Points

A new data protection framework (the GDPR) has been adopted, significantly changing current EU laws. It will take the form of a Regulation and so will be directly applicable in all EU Member States from 25 May 2018. Once in...more

28 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide