Refine By
Clear all filter
About 91501 results for "*"
NEWS
MLex: The EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) procedural reform should be wrapped up by 30 June 2025, Karolina Mojzesowicz, a senior European Commission official responsible for data protection, said on 18 March 2025. She supports the lead European legislator’s tight schedule, despite criticism from tech companies and civil society that the process has been rushed. Mojzesowicz also provided a timeline for EU GDPR’s simplification strategy—announced in March 2025, saying it should be proposed by the end of June 2025.
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these Standard Contractual Clauses (the Clauses) is to ensure compliance with [OPTION 1: Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). OR OPTION 2: Article 29(3) and (4) of Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC.] (b) The controllers and processors listed in Annex I have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or Article
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. (d) The Appendix to these Clauses
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. (d) The Appendix to these Clauses
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. (d) The Appendix to these Clauses
PRACTICE NOTES
This Practice Note provides guidance on the set of standard contractual clauses (SCCs) for international transfers of personal data published by the European Commission in June 2021 (the 2021 EU SCCs). It provides a more in-depth analysis of international transfers under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) than the introductory Practice Note: EU GDPR—transfers of personal data internationally and to international organisations and assumes general knowledge of key concepts under the EU GDPR regime and of its international transfers regime. If you are unfamiliar with this topic, you may wish to read those Practice Notes first. For more introductory information and background on the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). In brief Data protection law in the EEA seeks to ensure information about living individuals (ie within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU GDPR imposes a large
PRACTICE NOTES
FORTHCOMING CHANGE: On 15 January 2026, the European Data Protection Board adopted, for public consultation, Recommendations 1/2026 on the Application for Approval and on the elements and principles to be found in Processor Binding Corporate Rules (Art 47 GDPR). These recommendations repeal and replace, while in substance build on, Working Party Guidance—WP 257 rev.01: Working Document on BCRs for processors and Working Party Guidance—WP 265: Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data. The recommendations are open to public consultation until 2 March 2026 and become effective on the date of the publication of the final version after public consultation. For further information, see Practice Note: EU GDPR—EDPB supranational level guidance tracker. This Practice Note discusses Binding Corporate Rules (BCRs), which are one of the mechanisms that allow for the transfer of personal data outside of the EEA in compliance with Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR).
PRACTICE NOTES
This Practice Note tracks European Data Protection Board (EDPB) guidance and opinions relating to the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) or Directive 2002/58/EC (the ePrivacy Directive) and any Article 29 Working Party (WP29) guidance under the previous Directive 95/46/EC (Data Protection Directive) (which was superseded by the EU GDPR), that has been endorsed by the EDPB. The EDPB and Article 29 Working Party The EDPB was established under Article 68 of the EU GDPR. The EDPB replaced the WP29 which was an independent advisory body established under the Data Protection Directive. The WP29 played a central role in shaping and harmonising data protection policies and practices across the EU before it was replaced by the EDPB on 25 May 2018, when the EU GDPR came into force. During its first plenary meeting, the EDPB formally endorsed certain key documents adopted by the WP29. The EDPB’s goal is to ensure a consistent application and enforcement of data protection law across the EEA and it is charged with a number of responsibilities
PRACTICE NOTES
This Practice Note is intended to be used to track the status of adequacy decisions relating to cross-border/international transfers of personal data under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (the EU GDPR). It includes relevant opinions, reports and guidance issued by EU bodies relating to the status of new and existing decisions. For a comprehensive introduction to the EU GDPR, collating key practical guidance, see: UK data protection law collection. Background Although the text of the EU GDPR refers throughout to the ‘Union’, it is stated on page one of the regulation that it is a text ‘with EEA relevance’, meaning all provisions are intended to be applicable in respect of all EEA members, not just those that also have EU membership. Since the EU GDPR has been incorporated into the EEA Agreement and is in force, references to EU Member States in the EU GDPR can generally be read to also include EEA members. For further information on that incorporation, see the European Free Trade Association’s GDPR tracker. Article 44 of the EU GDPR prohibits
CHECKLISTS
This Checklist sets out key considerations a controller should typically take into account when conducting an audit for the purposes of evaluating the suitability of a prospective or existing processor of personal data under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). Note that this Checklist considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. For further information about the EU GDPR and arrangements between controllers and processors, see Practice Notes: The EU’s General Data Protection Regulation (EU GDPR), EU GDPR—outsourcing and data protection and Supply chains under EU GDPR—arrangements between controllers and processors. Audits of processors Although processors subject to the EU GDPR have their own particular responsibilities under the legislation, controllers remain responsible for the processor’s processing of personal data under their instructions. Under: • the accountability principle of the EU GDPR: the controller is responsible for,