Why does this topic matter to organisations?
National Data Protection Authorities ("DPAs") are appointed to implement and enforce data protection law, and to offer guidance. As set out in Chapter 16, DPAs have significant...more
4/22/2019
/ Compliance ,
Data Protection ,
Data Protection Authority ,
Enforcement ,
Enforcement Authority ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Jurisdiction ,
Member State ,
One-Stop Shop ,
Personal Data ,
Personally Identifiable Information ,
Popular
Why does this topic matter to organisations?
In today's world, it is increasingly important to be able to move data freely to wherever those data are needed. However, the transfer of personal data to recipients outside the...more
4/20/2019
/ Adequacy Requirement ,
Binding Corporate Rules ,
Certifications ,
Cloud Service Providers (CSPs) ,
Code of Conduct ,
Consumer Rights Directive ,
Data Controller ,
Data Protection Authority ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
Human Resources Professionals ,
International Data Transfers ,
Jurisdiction ,
Model Clauses ,
Personal Data ,
Personally Identifiable Information ,
Public Interest ,
Technology Sector
Why does this topic matter to organisations?
A significant aspect of complying with EU data protection law is demonstrating compliance—making it evident to DPAs that an organisation is meeting its obligations. Three of the...more
4/18/2019
/ Code of Conduct ,
Compliance ,
Data Protection ,
Data Protection Officers (DPOs) ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
Impact Assessments ,
International Data Transfers ,
Personal Data ,
Personally Identifiable Information
Why does this topic matter to organisations?
Under the GDPR, the concept of a "processor" has not changed. Any entity that was a processor under the Directive likely continues to be a processor under the GDPR. However,...more
4/18/2019
/ Compliance ,
Confidentiality Policies ,
Data Breach ,
Data Controller ,
Data Processors ,
Data Protection ,
Data Protection Officers (DPOs) ,
Data Security ,
DPA ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Popular ,
Reporting Requirements
Why does this topic matter to organisations?
Each time an organisation processes personal data, it will do so as either a controller or a processor. These roles bear different responsibilities. Therefore, it is critically...more
4/16/2019
/ Compliance ,
Data Breach ,
Data Controller ,
Data Processors ,
Data Protection Officers (DPOs) ,
Data Security ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Liability ,
Notification Requirements ,
Personal Data ,
Personally Identifiable Information ,
Reporting Requirements
Why does this topic matter to organisations?
EU data protection law provides data subjects with a wide array of rights that can be enforced against organisations that process personal data. These rights may limit the...more
4/16/2019
/ Consumer Privacy Rights ,
Data Collection ,
Data Controller ,
Data Processors ,
Data Protection ,
Direct Marketing ,
Duty to Inform ,
Employee Training ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Personally Identifiable Information ,
Portability ,
Privacy Policy ,
Rectification ,
Right of Access ,
Right to Be Forgotten ,
Right to Object ,
Right to Restrict ,
Time Restrictions ,
Transparency
Why does this topic matter to organisations?
Processing of personal data is lawful only if, and to the extent that, it is permitted under EU data protection law. Each and every data processing activity requires a lawful...more
4/15/2019
/ Consent ,
Data Collection ,
Data Controller ,
Data Processors ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
Informed Consent ,
International Data Transfers ,
Opt-In ,
Personal Data ,
Personally Identifiable Information ,
Withdrawal
Why does this topic matter to organisations?
Processing of personal data is lawful only if, and to the extent that, it is permitted under EU data protection law. If the controller does not have a lawful basis for a given...more
4/12/2019
/ Consent ,
Data Controller ,
Data Processing Rules ,
Data Processors ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Legitimate Business Interest ,
Member State ,
Personal Data ,
Personally Identifiable Information
Why does this topic matter to organisations?
The GDPR does not necessarily apply to every organisation in the world. It applies to all organisations that are established in the EU. However, for organisations established...more
4/12/2019
/ Compliance ,
Data Protection ,
EU ,
EU Data Protection Laws ,
Extraterritoriality Rules ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Multinationals ,
Personal Data ,
Personally Identifiable Information ,
Risk Assessment ,
Risk Management
Why does this topic matter to organisations?
Understanding the subject matter and the scope of EU data protection law is fundamental to determining whether this law applies to an organisation’s business activities. In...more
Overview of key issues -
The GDPR raises a number of key issues that organisations should consider, including the following...more
4/11/2019
/ Breach Notification Rule ,
Compliance ,
Consent ,
Data Processors ,
Data Protection ,
Data Protection Impact Assessments (DPIAs) ,
Data Protection Officers (DPOs) ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Personally Identifiable Information ,
Popular
Directive 95/46/EC -
Prior to the GDPR, the EU's data protection regime was governed by the Directive. The Directive (as with all EU Directives) did not apply automatically, and had to be transposed into the national laws...more
Why does this topic matter to organisations?
The defined terms set out in this Chapter are of critical importance to understanding how EU data protection law applies to an organisation. For example, the question of whether...more
4/3/2019
/ Consent ,
Data Breach ,
Data Controller ,
Data Processors ,
Data Protection ,
EU ,
EU Data Protection Laws ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Personally Identifiable Information
On 29 March 2019, the UK will formally leave the EU unless an extension, or a negotiated solution, is agreed between the UK and the European Commission. There is currently no agreement regarding the UK's status from a data...more
1/31/2019
/ BCRs ,
Compliance ,
Consent ,
Data Protection ,
EU ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Model Contracts ,
No-Deal Brexit ,
Personal Data ,
UK ,
UK Brexit ,
UK ICO
The European Commission and the Personal Information Protection Commission of Japan have agreed mutual adequacy decisions regarding the transfer of personal data. This is a significant development, and allows businesses to...more
1/31/2019
/ Adequacy Requirement ,
Bilateral Agreements ,
EU ,
European Commission ,
European Economic Area (EEA) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Japan ,
Mutual Recognition Agreement ,
Personal Data ,
Privacy Laws ,
Reciprocity Rules