Latest Publications

Share:

Health Care Organizations and Cloud Service Providers Receive Guidance on Cloud Security Measures

The Situation: The health care sector is currently going through a digital transformation phase with the promise of achieving improved patient care and higher efficiency—and the implementation of cloud-based services is a...more

Jones Day Global Privacy & Cybersecurity Update | Vol. 27

United States - Regulatory—Policy, Best Practices, and Standard - NIST Unveils Draft Guidance to Protect Critical Infrastructure - On October 22, 2020, the National Institute of Standards and Technology ("NIST")...more

Strong Customer Authentication in the United States: When, Not If

The Situation: Although the deadline keeps getting extended, e-commerce merchants and payment processors across the European Union are racing to implement the strong customer authentication ("SCA") requirements of the Revised...more

No-Deal Brexit—Preventing Disruption to Data Transfers

The Situation: The European Union and United Kingdom have both warned companies to prepare for a no-deal Brexit. The Result: There is a real possibility that the Brexit Implementation Period will end on 31 December 2020...more

Jones Day Global Privacy & Cybersecurity Update | Vol. 26

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - NIST Releases Revision to Security Standard - On September 23, the National Institute of Standards and Technology ("NIST") released Revision 5 to...more

Ensuring International Data Flows after Schrems II

The Situation: After the invalidation of the EU-U.S. Privacy Shield by the Court of Justice of the European Union ("CJEU"), the conditions under which international data may flow from the European Union continue to remain...more

End of the EU's Data Retention Saga? CJEU Clarifies Conditions for State Surveillance Regimes

The Situation: On October 6, 2020, the Court of Justice of the European Union ("CJEU") held that the national security laws of the United Kingdom, France, and Belgium, which each require that providers of electronic...more

Schrems II Confirms Validity of EU Standard Contractual Clauses, Invalidates EU–U.S. Privacy Shield

The Situation: The Court of Justice of the European Union ("CJEU") has ruled that international data flows under the European Union's comprehensive data protection regime, the GDPR, can continue to be based on EU Standard...more

A Guide to Navigating Cybersecurity, Privacy, and Employment Law Issues with COVID-19 Contact Tracing in the Private Sector

As the United States and other countries gradually ease stay-at-home orders and mandatory lockdowns, data-driven technologies have become increasingly discussed as a potential strategy for tracing and mitigating the further...more

Getting Cautious on Cloud Outsourcing: ESMA Consults on Proposed Guidelines

The Situation: On June 3, 2020, the European Securities Market Authority ("ESMA") published a consultation paper on Outsourcing to Cloud Service Providers ("Proposed Guidelines"), which will apply to any institution under the...more

EU Unveils Roadmap for Single Digital Market for Data and AI - The European Commission published new white papers on its goals of...

This week, the European Commission published white papers detailing its strategies regarding the use of data and artificial intelligence ("AI"). Several additional reports accompany the white papers and cover topics such as...more

French Data Protection Authority Issues Draft Recommendations on Consent for Cookies

The Situation: On July 4, 2019, the French data protection authority ("CNIL") published revised guidelines on the implementation of cookies or similar tracking technologies in order to take into account the new requirements...more

Data Protection: Reducing the Risk of Disruption on a "No Deal" Brexit

The Situation: The United Kingdom is due to leave the European Union ("EU") on 31 October 2019. Negotiations between member states of the EU excluding the United Kingdom ("EU27") and the United Kingdom are ongoing, but it is...more

GDPR vs. ePrivacy Directive: CNIL's Revised Guidelines for Use of Cookies and Other Trackers

The Situation: The European Union's General Data Protection Regulation ("GDPR") has been effective since May 2018 and has resulted in increased requirements for obtaining consent for the processing of personal data. However,...more

ECJ Rules Companies Using Social Plugins Are Joint Controllers

The Situation: Fashion ID, a German online clothing retailer, embedded on its website the Facebook "Like" button. When a user consults the website of Fashion ID, that user's personal data are transmitted to Facebook Ireland....more

The EU Cybersecurity Act is Now Applicable

The Situation: The European Union's Cybersecurity Act becomes effective on June 27, 2019. The Result: The Act will strengthen the ability of the European Union Agency for Network and Information Security ("ENISA") to help...more

Data Protection: Risk of Disruption if There Is a "No Deal" Brexit

The Situation: The UK Parliament has not approved the draft Brexit Withdrawal Agreement and Political Declaration on the future relationship of the European Union and United Kingdom. The next steps in the Brexit process are...more

European Data Protection Board Provides Clarifications on Territorial Scope of GDPR

The Situation: The General Data Protection Regulation has a broad territorial scope and can apply to businesses based outside the European Union. The Result: The European Data Protection Board has provided important...more

Driverless, Networked Vehicles on the Rise, French Liability Regulations Lag Behind

The Situation: Autonomous cars with incorporated artificial intelligence ("AI") are now a reality whereas French regulations have yet to adjust. The Issue: The phenomenon of new autonomous cars using AI gives rise to...more

Jones Day Global Privacy & Data Security Update | Vol. 19

On the heels of the European Union's General Data Protection law, which went into effect in May 2018, California has enacted the California Consumer Privacy Act ("CCPA")—the result of an 11th-hour compromise between...more

Royal Decree-Law Approved to Ensure Application of GDPR in Spain

The Situation: Spain approved emergency legislation regarding data protection that mainly focuses on regulating inspection and sanctioning procedures. The Purpose: The purpose of this legislation is to allow for the correct...more

French Data Protection Authority Confirms Enforcement Trend on Security Obligations for Data Controllers

The Situation: Even before the General Data Protection Regulation ("GDPR") became effective on May 25, there has been a noticeable trend in the enforcement of security obligations through increased sanctions. The...more

59 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide