News & Analysis as of

Data Protection International Data Transfers CNIL

A&O Shearman

CNIL publishes Data Transfer Impact Assessment guide

A&O Shearman on

On January 31, 2025, the French supervisory authority (CNIL) published the final version of its guide on transfer impact assessments (TIA). A TIA must be undertaken by organisations relying on one of the ‘appropriate...more

Hogan Lovells

Transfer Impact Assessments: the CNIL is seeking public input on TIA guide

Hogan Lovells on

On January 8, 2024, the CNIL launched a public consultation on a draft guide (Draft Guide) covering Transfer Impact Assessments (TIA). Under GDPR, as interpreted by the Court of Justice of the European Union (CJEU) and...more

Hogan Lovells

Member of French Parliament lodges first request for annulment of EU-US Data Privacy Framework

Hogan Lovells on

P. Latombe, who is not only a Member of the French Parliament, but also seated at the French Data Protection Authority (CNIL)'s Commission, lodged a request for annulment of the DPF on 6 September 2023 before the Court of...more

Orrick, Herrington & Sutcliffe LLP

Analisi del Recente Provvedimento del Garante Privacy Francese

Alla luce del recente provvedimento dell’Autorità Garante per la Protezione dei Dati Personali Francese, la Commission nationale de l'informatique et des libertés (“Garante” o “CNIL”), riportiamo di seguito un’analisi del...more

Hogan Lovells

Reform of the procedure before the French Data Protection Authority

Hogan Lovells on

On 24 January and 8 April 2022, the procedure before the French Data Protection Authority (CNIL) was reformed with the aim notably to better respond to the growing number of complaints that the CNIL receives each year...more

K&L Gates LLP

French Supervisory Authority Publishes Guidance on the Use of Website Analytics in Compliance With GDPR Requirements

K&L Gates LLP on

Following the 2020 Court of Justice of the European Union’s (CJEU) ruling invalidating the Privacy Shield (see our alert here), personal data transfers from the European Union to the United States required EU companies to...more

Stikeman Elliott LLP

Transferring Data from the EU: What to Take Away from the Recent Google Analytics GDPR Rulings

Stikeman Elliott LLP on

Companies using Google Analytics (“Analytics”) or similar platforms may be interested in recent rulings of several European data protection authorities that found Analytics data transfers to the U.S. to be non-compliant with...more

Davis Wright Tremaine LLP

Growing Trouble for EU-U.S. Data Transfers Through Google Analytics

France's data protection authority (DPA), Commission Nationale de l'Informatique et des Libertés (CNIL), announced its ruling on February 10, 2022, that the use of Google Analytics by companies in the EU violates Article 44...more

Latham & Watkins LLP

CNIL Publishes White Paper on Digital Payments and Data Privacy

Latham & Watkins LLP on

The French Data Protection Authority’s white paper discusses how companies can comply with data privacy and security obligations. The use of card, contactless, and innovative digital payment solutions has significantly...more

A&O Shearman

Schrems II: French Conseil d’Etat provides insight into sufficient safeguards for EU personal data accessed from the US

A&O Shearman on

On 12 March 2021, the Conseil d’Etat, the highest administrative court of France, issued a decision that might have significant impact on personal data transfers to third countries in the aftermath of the Schrems II decision...more

Foley Hoag LLP - Security, Privacy and the...

French Data Protection Authority Rules on Transfers of Health Data

The French Conseil d’Etat handed down an important decision October, 13th regarding privacy and personal data protection. This decision comes in the wake of the “Schrems II” ruling of the Court of Justice of the European...more

Carlton Fields

EU Data Protection Authority Levies Its First Fine for Violations of the GDPR

Carlton Fields on

The French Data Protection Authority, CNIL, has levied its first fine for enforcement of the General Data Protection Regulation (GDPR). The enforcement target, Spartoo, is a French online shoe retailer that makes its website...more

McDermott Will & Emery

[Webinar] Ce que vous avez peut-être manqué des actualités RGPD: la montée en puissance de l’accountability? - June 25th, 1:30 pm...

McDermott Will & Emery on

McDermott Will & Emery a le plaisir de vous convier à un webinaire sur le thème "Ce que vous avez peut-être manqué des actualités RGPD: la montée en puissance de l’accountability?" qui abordera les thèmes suivants: -...more

McDermott Will & Emery

[Webinar] What You Might Have Missed in GDPR: The Rise of Accountability? - June 25th, 1:30 pm CEST

McDermott Will & Emery on

In our latest webinar we will be examining what you may have missed in the development of GDPR in the current global landscape, focusing in particular on: - Data transfers outside the EU: what to do with its standard...more

Jones Day

Jones Day Global Privacy & Cybersecurity Update | Vol. 24

Jones Day on

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - FTC Submits Comment on the Preliminary Draft for the NIST Privacy Framework - On October 24, 2019, the Federal Trade Commission ("FTC") announced that...more

Sheppard Mullin Richter & Hampton LLP

CNIL Issues Record-Keeping Guidance

Under GDPR, companies are required to keep certain records of their processing activities. There has been some question about the types of records controllers should keep. To help clarify the questions arising from many...more

Hogan Lovells

GDPR – The Year in Review

Hogan Lovells on

Following the one-year anniversary of the coming into effect of the GDPR, Hogan Lovells’ Privacy and Cybersecurity practice has prepared a compilation of key GDPR-related developments of the past 12 months. The compilation...more

Latham & Watkins LLP

No Deal Brexit and Data Transfers: Companies Must Prepare Now

Latham & Watkins LLP on

Companies should identify data flows, implement a data transfer solution, and update internal documents and privacy notices. Since our blog on “What a “No Deal” Brexit Means for UK Data Privacy”, the European Data...more

Shook, Hardy & Bacon L.L.P.

Privacy and Data Security Client Alert | February 2019

Google Receives Record GDPR Fine - Marking the first major penalty against a U.S. tech company under the General Data Protection Regulation (GDPR), the French data-protection authority, CNIL, has fined Google a record $57...more

Akin Gump Strauss Hauer & Feld LLP

Non-profit Activists’ Strategic Pursuit of Alleged GDPR Violations Spurs Compliance Developments

• Non-profit organizations are testing companies’ GDPR compliance through targeted requests for information and other means and are filing complaints against allegedly non-compliant companies. • Main areas for non-profit...more

Jones Day

Jones Day Global Privacy & Data Security Update | Vol. 20

Jones Day on

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - NIST Releases Internal Report Regarding IoT Cybersecurity - In September, the National Institute of Standards and Technology ("NIST") released a draft...more

Robinson+Cole Data Privacy + Security Insider

French Data Protection Authority Issues Guidance on Interaction of Blockchain Technology with GDPR

Last month, the French data protection authority (the CNIL) issued initial guidance addressing issues that applications utilizing blockchain technology should consider in order to comply with the European General Data...more

Perkins Coie

French Data Protection Authority Issues Guidance on Application of Blockchain to the GDPR

Perkins Coie on

On September 24, 2018, the French data protection authority, Commission Nationale de l’Informatique et des Libertés (CNIL), became the first data protection authority to issue written guidance on the intersection of the use...more

Hogan Lovells

French Data Protection Authority’s Latest Newsletter Includes Assessment of First Four Months of GDPR & Several Guidelines

Hogan Lovells on

The French Data Protection Authority (the CNIL) published its assessment of the first four months of  GDPR and several guidelines, including one on how to make a GDPR compliant blockchain. ...more

Jones Day

Global Privacy & Cybersecurity Update Vol. 16

Jones Day on

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - United States and China Renew Promise Not to Hack - On October 4, U.S. and Chinese officials agreed to not engage in targeted hacking. Per a...more

26 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide