Latest Posts › General Data Protection Regulation (GDPR)

Share:

Zooming in on AI #15: Regulatory spaghetti and AI – how to make sense of the EU GDPR and the EU AI Act

Given the rapid speed of development in the field of AI, it is increasingly important that businesses develop effective governance to address the regulatory framework governing the development, training, use and deployment of...more

Zooming in on AI – #13: EU AI act– Focus on fundamental rights impact assessment for high-risk AI systems

Companies deploying high-risk artificial intelligence (AI) systems must prepare to conduct Fundamental Rights Impact Assessment (FRIA) by 2 August 2026. In this edition of our “Zooming in on AI” series we explain what this...more

Zooming in on AI #11: EU AI Act – What are the obligations for the limited-risk AI systems

The EU Artificial Intelligence Act (“AI Act”) exemplifies a highly advanced risk-based approach to European regulation. One of its distinguishing features is the detailed classification of various risk levels associated with...more

Zooming in on AI – #10: EU AI Act – What are the obligations for “high-risk AI systems”?

Companies deploying high-risk artificial intelligence (AI) systems must prepare to navigate a complex landscape of new obligations by August 2, 2026. In this post we explain the key obligations for providers and deployers of...more

ICO publishes a UK BCR Addendum for use with the EU Binding Corporate Rules

This blog notes some of the key features of the Addendum.  At its core, the Addendum can be used in relation to both controller BCRs and processor BCRs. Organisations then have a choice as to whether they use the Addendum in...more

EU-U.S. Data Privacy Framework: adequacy decision adopted, the framework becomes operational

On 10 July 2023, the European Commission adopted the adequacy decision for the EU-U.S. Data Privacy Framework (DPF). This decision enables the free flow of personal data from the EU and three EEA countries (Iceland,...more

EU - EDPB issues final guidelines on the calculation of administrative fines

The European Data Protection Board (EDPB) published the final version of the Guidelines on the calculation of administrative fines under the GDPR (Guidelines) on 7 June 2023. The Guidelines aim to harmonize the approach to...more

Pakistan – MITT releases final draft of the personal data protection bill

The Pakistan Ministry of Information Technology and Telecommunication (MITT) released a new draft of the Personal Data Protection Bill, 2023 (the PDPB) on 19 May 2023. The PDPB aims to regulate the collection, processing,...more

Happy birthday, GDPR – five lessons from five years of EU data protection law

In the five years since the European Union’s General Data Protection Regulation came into force, what have been the main learnings for business, and what will the future hold?...more

EU EDPB publishes 2022 activity report

The EDPB published its 2022 activity report “Streamlining Enforcement Through Cooperation” (the Activity Report) on 17 April 2023, which provides an overview of the work it carried out in 2022. The report reflects on, amongst...more

Increasing global cybersecurity regulation of private companies on the near horizon

Within the past year, a number of countries around the world, including the United States, United Kingdom, France, and The Netherlands have initiated regulatory inquiries and developed new strategies for the purpose of more...more

CJEU rules that national derogations on employees data protection must respect the conditions and limits of Article 88 GDPR

The Court of Justice of the European Union (CJEU) considered appropriate conditions that apply in respect of specific national legislation which EU member states may adopt under Article 88 GDPR to regulate the processing of...more

EDPB updates the guidelines on data breach notification, addresses data processing in upcoming AML legislation

The European Data Protection Board (EDPB) held its 77th plenary meeting on 28 March 2023. The EDPB considered the following key topics...more

AG CJEU addresses data subject rights and automated decision-making by credit rating agencies

The Advocate General (AG) Pikamäe of the Court of Justice of the European Union (CJEU) issued his opinions in three cases concerning the credit rating agency SCHUFA Holding AG (SCHUFA) on 16 March 2023....more

Germany – Schrems II: German court overturns presumption of international data transfer from EU-subsidiary to non-EU parent...

On 13 July 2022, the Public Procurement Chamber of the German state of Baden-Württemberg (the Public Procurement Chamber) issued a decision confirming that personal data processed by an EU subsidiary of a parent entity...more

EU – EDPB publishes Guidelines on certification as transfer tool

The European Data Protection Board (EDPB) has adopted, on 16 June 2022, the draft guidelines on certification as a tool for transfers of data to third countries without adequacy status (the Guidelines). The text of the...more

EU – Joint opinion of EDPB and EDPS raises concerns about alignment of the proposed EU Data Act with current data protection...

On 5 May 2022, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) issued a joint opinion (Opinion) addressing the legislative proposal of the European Commission for the EU Data Act,...more

International Data Transfer Agreement and the addendum to EC Standard Contractual Clauses expected in force 21 March 2022

On 2 February 2022, the Department for Digital, Culture, Media and Sport (DCMS) laid before Parliament the international data transfer agreement (IDTA), the international data transfer addendum to the European Commission’s...more

EDPB adopts draft guidelines on the GDPR provisions on international transfers and the territorial scope

On 19 November 2021, the European Data Protection Board (EDPB) published the much-awaited draft guidance on the interplay between the provisions of the GDPR on territorial scope (in Article 3) and on international data...more

German Court asks CJEU to clarify whether calculating consumer credit scores falls within the scope of automated decision-making...

On 25 October 2021, the Administrative Court of Wiesbaden (the Court) announced its decision, issued in early October, to submit two questions to the Court of Justice of the European Union (CJEU) regarding the scope of the...more

EDPB opinion on the draft adequacy decision for South Korea confirms essential equivalence for cross-border transfers but requires...

On 27 September 2021, the European Data Protection Board (EDPB) published its opinion on the draft adequacy decision of the European Commission in relation to the Republic of Korea (the Opinion). This is the first opinion on...more

European Parliament publishes briefing on ethical aspects of biometric recognition and behavioural detection techniques in public...

On 8 September 2021, the European Parliament’s Policy Department for Citizens’ Rights and Constitutional Affairs published a briefing about the report that considered the ethical issues surrounding use of biometric...more

Irish DPC issues a EUR 225 million fine against WhatsApp

The Irish supervisory authority (Irish DPC) published its final decision to impose a fine of EUR 225 million on WhatsApp Ireland Ltd (WhatsApp)(on 2 September 2021). This decision follows a cross-border investigation into...more

35 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide