Refine By
Clear all filter
About 703 results for "cybersecurity"
PRACTICE NOTES
ARCHIVED: This archived Practice Note provides information on the Privacy Shield framework for transfers of personal data to the US and reflects the position before the introduction of the EU-US Data Privacy Framework (DPF) and the UK Extension to the EU-US Data Privacy Framework (also known as the UK-US Data Bridge). It is not maintained and is for background information only. Article 44 of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) prohibits the transfer of personal data to a third country outside of the EEA, or an ‘international organisation’ (an international transfer). However, in certain circumstances, an international transfer of personal data may be permitted where the transfer is: • based on an adequacy decision • subject to appropriate safeguards • in accordance with specific exceptions/derogations Under Article 45 of the EU GDPR, the European Commission, has the power to determine whether a country outside of the EEA offers an adequate level of data protection, based on its domestic legislation or the international commitments it has entered into. The
NEWS
MLEX: OpenAI, X, Google and Meta will be able to use legitimate interests as a legal basis for processing personal data for developing and deploying AI models provided that adequate mitigation measures are in place, the European Data Protection Board (EDPB) said in an influential opinion today. The EDPB opinion also touched upon how to address unlawful data processing for AI model development, and in what circumstances AI models can be considered anonymised.
NEWS
EU law analysis: On 17 December 2024, the European Data Protection Board (EDPB) adopted Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (the Opinion). In this News Analysis Alex Jameson of Bird & Bird considers the background to the Opinion and the key takeaways.
NEWS
MLex: Finnish pharmacy Yliopiston Apteekki has had a €1.1 million GDPR fine overturned by a Helsinki court. The pharmacy is a public-sector entity as it is owned by the University of Helsinki, and so under Finnish law it can’t be issued a financial penalty, the court said. Lawmakers are currently reviewing a bill to extend fines to the public sector, the privacy regulator said.
NEWS
MLex Privacy activist Lisa Ballmann won a legal battle at the EU’s lower-tier General Court after challenging a European data protection body’s (EDPB) refusal to give her access to a file related to her complaint against Meta’s data-processing practices with online advertising.
NEWS
MLex: Two rulings at the EU’s top court on the interpretation of how penalties should be calculated under the General Data Protection Regulation (GDPR) indicate that national regulators of all kinds are unlikely to be given much leeway, according to an EU analysis of the findings. A note by the Council of the EU, which represents EU national governments, argued that the court is likely to make a similarly ‘strict’ interpretation of fining rules in other cases.
PRACTICE NOTES
This Practice Note explores issues and best practice relating to the sharing of personal data between controllers (including joint controllers and independent controllers) in general business-to-business commercial situations under the requirements of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). It assumes a degree of familiarity with key data protection concepts and terms and the role of key supervisory organisations. For a general introduction to the EU GDPR and related issues, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). In brief—summary of steps controllers should often take before data sharing The EU GDPR seeks to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. One of the key protections under the EU GDPR is the obligations placed on ‘controllers’ (usually meaning those that decide the purposes and means of processing). ‘Processing’ is broadly defined to include doing most things with data, including storing, deleting, collecting, disclosing or using it. In summary, commercial organisations should generally do the following before the
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. (d) The Appendix to these Clauses
PRACTICE NOTES
FORTHCOMING CHANGE: On 15 January 2026, the European Data Protection Board adopted, for public consultation, Recommendations 1/2026 on the Application for Approval and on the elements and principles to be found in Processor Binding Corporate Rules (Art 47 GDPR). These recommendations repeal and replace, while in substance build on, Working Party Guidance—WP 257 rev.01: Working Document on BCRs for processors and Working Party Guidance—WP 265: Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data. The recommendations are open to public consultation until 2 March 2026 and become effective on the date of the publication of the final version after public consultation. For further information, see Practice Note: EU GDPR—EDPB supranational level guidance tracker. This Practice Note discusses Binding Corporate Rules (BCRs), which are one of the mechanisms that allow for the transfer of personal data outside of the EEA in compliance with Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR).
PRACTICE NOTES
A key objective of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (the EU GDPR) is to achieve a level of consistency in relation to how data protection is implemented and enforced across the EU and EEA. Under the EU GDPR, each Member State can specify one or more independent public authorities to be responsible for monitoring the application of the EU GDPR, ie a ‘supervisory authority’. This Practice Note: • introduces the European Data Protection Board (EDPB) • introduces the European Data Protection Supervisor (EDPS) • provides a consolidated list of supervisory authorities in the EU and EEA For guidance on sanctions and enforcement under the EU GDPR, see Practice Note: EU GDPR—sanctions and enforcement. The EDPB The EDPB is at the centre of the EU GDPR regime and its guidance and opinions are highly influential. It consists of the head of each of the EU national supervisory authorities, and the EDPS. The EDPB replaced the Article 29 Working Party (Working Party) which was established under Directive 95/46/EC (Data Protection
NEWS
MLex: A US Supreme Court ruling allowing the president to fire executive officers at will has injected fresh uncertainty into the EU-US Data Privacy Framework.
PRACTICE NOTES
This Practice Note considers the general prohibition under Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) on the cross-border transfer of personal data outside of the EEA or to an international organisation. Among other things, it considers how to identify a restricted international transfer, onward transfers, data export restrictions, adequacy decisions, standard contractual clauses (Model Clauses or SCCs), Binding Corporate Rules (BCRs) and other appropriate safeguards (ie using Article 46 tools) and derogations. It also includes guidance on amending SCCs and links to further practical guidance on how to use SCCs. In brief Data protection law in the EEA seeks to ensure information about living individuals (ie within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU GDPR imposes a large number of obligations on those undertaking or controlling the ‘processing’ of personal data. In summary, ‘processing’ includes doing almost anything with personal data, including storing, sharing, deleting, using or transferring it. One of the key protections under