News & Analysis as of

Data Breach General Data Protection Regulation (GDPR) Corporate Counsel

Womble Bond Dickinson

The ICO’s Penalty Against 23andMe Brings New Emphasis on Cybersecurity Risks - Key Takeaways for U.S. Companies

Womble Bond Dickinson on

The dramatic increase in global reach that the internet provides U.S.-based companies comes as a double edge sword. While it significantly increases a company’s potential customer pool, it also subjects companies to...more

DLA Piper

EU: DLA Piper GDPR Fines and Data Breach Survey: January 2025

DLA Piper on

The seventh annual edition of DLA Piper’s GDPR Fines and Data Breach Survey has revealed another significant year in data privacy enforcement, with an aggregate total of EUR1.2 billion (USD1.26 billion/GBP996 million) in...more

Pillsbury - Consumer Protection Dispatch

GDPR Enforcement: Lessons from Recent Data Privacy Penalties

Recent decisions by the French data protection authority (CNIL) have highlighted the importance of GDPR compliance, particularly in the areas of data retention, consent for processing sensitive personal data, and marketing...more

Alston & Bird

Dutch Data Protection Authority Warns that Using AI Chatbots Can Lead to Personal Data Breaches

Alston & Bird on

On August 6th, the Dutch Data Protection Authority (DPA) issued guidance cautioning companies about the potential data protection risks associated with the use of Artificial Intelligence (AI)-powered chatbots....more

Ius Laboris

Employers liable for employees’ GDPR errors

Ius Laboris on

A recent judgment of the European Court of Justice (ECJ) sheds light on the question of whether a data controller can be exempted from liability for the error of a person acting under its authority....more

Cooley LLP

European Court of Justice Clarifies Rules on Damages Compensation for GDPR Breaches

Cooley LLP on

On 4 May 2023, the Court of Justice of the European Union (CJEU) delivered its decision in the Österreichische Post case (Case C-300/21), in essence deciding that a mere infringement of the General Data Protection Regulation...more

Alston & Bird

EU Supervisory Authorities Clarify Breach Notification Requirements

Alston & Bird on

Background - On April 4th, 2023, the European Data Protection Board (‘EDPB’), which is composed of representatives of the EU national supervisory authorities and the European Data Protection Supervisor (‘EDPS’), published an...more

Pillsbury Winthrop Shaw Pittman LLP

AI Warning: ChatGPT Blocked for Data Laws Breach

The future development and use of AI systems is under fire as an EU regulator blocks ChatGPT for GDPR breaches. The Garante, the Italian data regulator, has blocked high-profile AI tool ChatGPT for various breaches of the...more

Wilson Sonsini Goodrich & Rosati

EU Court Opinion: Competition Authorities May Consider Data Protection Breaches in Their Investigations

On September 20, 2022, an adviser to the EU’s top court opined that competition authorities may consider a company’s compliance with the EU’s data protection rules as part of an abuse of dominance investigation....more

Orrick, Herrington & Sutcliffe LLP

"42", the Answer to the Number of Authorities Notified in Cross-Border Breaches – Don't Panic!

Last week, the European Data Protection Board ("EDPB") published a long-awaited update of its guidance on breach notification—which did not contain much news generally. However, it does bring a significant new burden for...more

Alston & Bird

Heavier Breach Notification Obligations for U.S. Companies Subject to the EU GDPR According to Proposed Regulatory Guidance from...

Alston & Bird on

On October 18, 2022, the European Data Protection Board (“EDPB”) published a proposed updated version of its regulatory guidance on personal data breaches under the EU GDPR (the “Proposed Updated Guidance”). The Proposed...more

Jackson Lewis P.C.

Connecticut Likely to Become Fifth State to Enact Comprehensive Consumer Privacy Law

Jackson Lewis P.C. on

When the California Consumer Privacy Act of 2018 (CCPA) became law, it was only a matter of time before other states adopted their own statutes intending to enhance privacy rights and consumer protection for their residents. ...more

Jones Day

English High Court Confirms Narrow Approach to Assessment of Data Breach Liability

Jones Day on

On 31 January 2022, the English High Court delivered its judgment in Stadler v Currys Group Limited (EWHC 160 (QB)); the latest in a series of rulings which appear set to constrain the relatively nascent UK data breach claims...more

Wyrick Robbins Yates & Ponton LLP

5 Key Takeaways from the EDPB’s Final Guidelines on Examples Regarding Personal Data Breach Notification

Following a public consultation on an initial version released last January, the European Data Protection Board (“EDPB”) last month adopted a final version of its Guidelines on Examples regarding Personal Data Breach...more

Alston & Bird

EDPB Issues New Guidance for Assessing Personal Data Breaches under the EU GDPR

Alston & Bird on

On Monday, 3 January 2022, the European Data Protection Board (“EDPB”) published the finalized version of its regulatory guidance entitled “Examples regarding Personal Data Breach Notification” (the “Guidelines”), following a...more

Pillsbury Winthrop Shaw Pittman LLP

Record €210 Million in Fines for Breach of Cookies and Website Tracking Rules—Note e-Privacy Directive, Not Just GDPR

France’s data protection regulator (the CNIL) said this week it has fined Google and Facebook a combined €210 million for breaches of laws on cookies use and tracking of user online activity. These fines were not under the...more

Faegre Drinker Biddle & Reath LLP

Significant Changes Proposed to UK GDPR

On September 10, the U.K. government launched a consultation “Data: A New Direction” (Consultation), which proposes significant changes to the U.K.’s data protection framework. The U.K. government has signalled its...more

Orrick, Herrington & Sutcliffe LLP

Warren v DSG Retail Ltd – Shifting the Liability Landscape in Post‐Cyberattack Litigation

Since the General Data Protection Regulations ("GDPR") came into force in 2018, companies in the United Kingdom (UK) that have suffered cybersecurity attacks often face civil claims from individuals whose data has been...more

Goodwin

Late Breach Notice In Europe Leads To Nearly €500K Fine

Goodwin on

On 31 March 2021 the Dutch Data Protection Authority (DPA) announced that it fined the online reservation platform Booking.com €475,000 for failing to notify the DPA of a data breach within the timeline established in the...more

Society of Corporate Compliance and Ethics...

[Virtual Event] 2021 Alaska Regional Compliance & Ethics Conference - February 26th, 8:25 am - 4:30 pm AKST

Our Virtual Regional Compliance Conferences provide updates on the latest news in regulatory requirements, compliance enforcement, and strategies to develop effective compliance programs. Watch, listen, and ask questions from...more

Fox Rothschild LLP

Valuable Data Privacy Lessons In CNIL’s Enforcement Action Against Carrefour France

Fox Rothschild LLP on

In addition to the not-insignificant €2.25 million fine, CNIL's enforcement action against Carrefour France raises some universal points for companies handling data, both in the EU and in the U.S. Big Picture Takeaways:...more

Orrick, Herrington & Sutcliffe LLP

Marriott Secures 80% Reduction in ICO Fine, but Here’s What You Missed…

Hot on the heels of the £20 million fine issued to British Airways, the Information Commissioner’s Office (“ICO“) has issued Marriott International Inc. (“Marriott“) with a long-awaited penalty notice for its failure to...more

A&O Shearman

What Might The BA And Marriott Fines Tell Us About The ICO’s Approach To Penalties?

A&O Shearman on

Few will have been surprised that, when the ICO eventually published details of the BA and Marriott fines, the final penalties were very much lower than the £183+ million and £99+ million proposed in the original notices of...more

Faegre Drinker Biddle & Reath LLP

Marriott Cyberattack Fine Reduced as ICO Shifts Penalty Policy

On 30 October 2020, the UK’s data privacy regulator, the Information Commissioner’s Office (ICO) issued a final penalty notice (Penalty Notice) to fine the hotel chain Marriott International, Inc. (Marriott) for a GDPR data...more

Morgan Lewis - Tech & Sourcing

ICO GDPR Fines Reduced to £20m and £18.4m to Reflect British Airways and Marriott Mitigating Factors

The UK Information Commissioner’s Office (ICO) has recently handed down two of the largest fines relating to a data breach in UK history. In August 2018, British Airways (BA) was subject to a cyberattack which breached the...more

57 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide