News & Analysis as of

Corporate Counsel Data Protection Authority

Alston & Bird

Dutch Data Protection Authority Warns that Using AI Chatbots Can Lead to Personal Data Breaches

Alston & Bird on

On August 6th, the Dutch Data Protection Authority (DPA) issued guidance cautioning companies about the potential data protection risks associated with the use of Artificial Intelligence (AI)-powered chatbots....more

Hogan Lovells

Brazil’s Data Protection Authority releases guidance on data protection officer responsibilities and duties

Hogan Lovells on

On July 16, 2024, the National Data Protection Authority (ANPD) published Resolution No. 18/2024 (Resolution 18) outlining rules on the appointment, definition, duties and activities of a Data Protection Officer (DPO) in...more

BakerHostetler

DSIR Deeper Dive: Absent Legislation, Privacy Regulators Offer Guidance on AI

BakerHostetler on

By now, many of us are using AI, advising others about how to use AI, and waiting for some legislative miracle to give us some guardrails for what we can or cannot be doing with AI. A lot of effort has been put into tracking...more

Hogan Lovells

Comprendre et tirer les leçons de la riche activité de la CNIL de ces derniers mois

Hogan Lovells on

Les derniers mois ont vu une activité bouillonnante de la CNIL avec l’adoption de nombreuses délibérations. Nous avons analysé ces décisions pour comprendre les principales orientations prises par l’autorité française....more

Fisher Phillips

Brazil Publishes Data Protection Sanctions: 3 Steps Your Company Should Take to Avoid Problems

Fisher Phillips on

Brazil’s data protection authority recently published regulations that could lead businesses and employers that violate the country’s data privacy laws to be punished with administrative penalties – adding yet more incentive...more

Morgan Lewis

Switzerland Publishes Adequacy List of Countries Receiving Personal Data Transfers

Morgan Lewis on

The Swiss government has drafted a proposed list of countries that are approved to receive personal data transfers out of Switzerland. Japan and South Korea are excluded from the current and proposed lists, requiring...more

BCLP

Ransomware - why paying up earns no credit with the UK's Data Protection Authority and others

BCLP on

In a joint letter this summer, the UK’s data protection regulator (the ICO) and the UK’s National Cyber Security Centre (the NCSC) sought to convey some key messages to the legal profession relevant to advising clients...more

WilmerHale

EDPB Adopts Guidelines on Calculation of GDPR Fines and on Facial Recognition Technology in Law Enforcement

WilmerHale on

On May 16, 2022, the European Data Protection Board (EDPB), the independent body of data protection supervisors that promotes consistent data protection rules and application thereof throughout the European Union (EU),...more

Robins Kaplan LLP

GDPR Enforcement Alert: Danske Bank Faces $1.5 million Fine for GDPR Violation

Robins Kaplan LLP on

Danske Bank, Denmark’s largest bank, faces a fine of approximately $1.5 million from the Danish Data Protection Agency (DPA) for a failure to comply with the GDPR’s data deletion requirements. The GDPR requires all personal...more

Alston & Bird

Colorado Issues Pre-Rulemaking Considerations for the Colorado Privacy Act

Alston & Bird on

On April 12, 2022, the Colorado Department of Law (the “Department”) released its Pre-Rulemaking Considerations for the Colorado Privacy Act (the “CPA”), following state Attorney General Phil Weiser’s remarks at the...more

Orrick, Herrington & Sutcliffe LLP

8 Things You Need to Know About United Kingdom (UK) International Data Transfers

Update: UK international data transfer agreement and UK addendum to the EU standard contractual clauses now in force In February, the Information Commissioner’s Office (“ICO”), the United Kingdom (UK) data protection...more

BakerHostetler

International Data Protection Update - Winter 2021/2022

BakerHostetler on

This Update highlights some of the international data protection issues that caught our attention and the attention of our clients over the winter, including updates on European data transfers and cookie compliance,...more

A&O Shearman

The EU Data Act - what could this mean for you?

A&O Shearman on

On 23 February 2022, Margrethe Vestager (European Commission’s Executive Vice President for a Europe fit for the Digital Age) unveiled proposals for the EU’s latest legislative development, the EU Data Act. Originally...more

Epstein Becker & Green

Cookies Resulting in Cross Border Data Transfers to the United States Draw Scrutiny from European Data Privacy Regulators

Recent decisions from the European Union (EU) have placed renewed focus on the use of common cookies used on ecommerce and other websites used by consumers and employees and transfers of personal data collected through...more

WilmerHale

The French Data Protection Authority Joins the Austrian Data Protection Authority in Ruling that the Use of Google Analytics...

WilmerHale on

French regulators have held that the use of Google Analytics violates the GDPR, a decision that likely has broad implications for web analytics companies and website operators. On February 10, 2022, the French Data...more

Orrick, Herrington & Sutcliffe LLP

The Austrian Data Protection Authority Ground-breaking Google Analytics Decision: Analysis and Key Takeaways

The Austrian data protection authority (Österreichische Datenschutzbehörde; Austrian DPA) recently ruled that the use of Google Analytics violated Chapter V (transfers of personal data to third parties) of the EU General Data...more

Alston & Bird

Belgian Supreme Court Rules That Data Protection Authority May Impose Administrative Fines Even Where a Data Subject’s Personal...

Alston & Bird on

The Belgian Supreme Court ruled in a judgment of Oct. 7, 2021 that a data subject has the right to lodge a complaint with the Data Protection Authority against a processing practice that violates the GDPR (in this case, the...more

BCLP

BCLP Global Data Privacy FAQs: UK gets its Adequacy Decision from the EU, now what does that mean in practice?

BCLP on

On 28 June, the European Commission adopted its Adequacy Decision for the UK, putting to an end (at least for now), the uncertainty surrounding EU to UK personal data flows. This averted a “cliff edge” in the shape of the 30...more

Goodwin

Late Breach Notice In Europe Leads To Nearly €500K Fine

Goodwin on

On 31 March 2021 the Dutch Data Protection Authority (DPA) announced that it fined the online reservation platform Booking.com €475,000 for failing to notify the DPA of a data breach within the timeline established in the...more

Orrick, Herrington & Sutcliffe LLP

Have EU Employees? Beware: H&M Slapped with Massive GDPR Fine for Wrongful Processing of Employee Data, Despite Cooperation

On October 1st, 2020, the Data Protection Authority of Hamburg (“DPA”) announced that it issued a massive EUR 35.3 million fine against the clothing company H&M Hennes & Mauritz Online Shop A.B. & Co. KG (“H&M”) for the...more

Akin Gump Strauss Hauer & Feld LLP

European Data Protection Board Forms Two New Taskforces to Address Schrems II Aftermath

On Friday September 4, 2020, the European Data Protection Board (EDPB), a body consisting of representatives of all the Data Protection Authorities (DPAs) in the European Economic Area, announced that it had formed two new...more

Alston & Bird

German DPA Publishes Schrems II Transfer Compliance Checklist and Suggested Modifications to SCCs

Alston & Bird on

On August 24, 2020, the data protection authority of the German state of Baden-Württemberg (the “DPA”) published guidance (the “Guidance”) on international transfers of personal data following the Schrems II judgment....more

Hogan Lovells

EU Data Exports After Schrems II – Guidance by data protection authorities

Hogan Lovells on

The table below sets out the guidance provided by data protection authorities (DPA) in response to the European Court of Justice’s landmark judgment in Case C-311/18 Data Protection Commissioner v. Facebook Ireland and...more

K&L Gates LLP

EU Data Protection: Privacy Shield Shattered by the Sword of European Justice - What Comes Next for Transatlantic Dataflows?

K&L Gates LLP on

In a highly anticipated Schrems II decision, the Court of Justice of the European Union (CJEU) invalidated the Privacy Shield, the legal framework allowing transatlantic exchanges of personal data for commercial purposes...more

Orrick - Employment Law and Litigation

Privacy Shield Sunk – SCCs Treading Water: What Can Companies Do to Keep Their Head Above Water

The European Court of Justice (CJEU) published its highly anticipated judgement in the case of Data Protection Commissioner Ireland v Facebook Ireland Limited, Maximillian Schrems, colloquially known as “Schrems 2.0”. There...more

63 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide