Refine By
Clear all filter
About 703 results for "cybersecurity"
PRACTICE NOTES
In summary, organisations with an establishment in the EEA that process personal data and that cannot rely on an exception under the General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) will be within the scope of the EU GDPR. Those organisations without a physical presence in the EEA but that process personal data, whether regularly or sporadically, should consider whether they are likely to be caught by the EU GDPR and/or required to appoint a representative in the EEA. This Practice Note covers: • Key guidance • Territorial scope under the Data Protection Directive • Territorial scope under the EU GDPR • Extra-territorial enforceability of the EU GDPR • Complying with the EU GDPR • Appointing a representative in the EEA • Exceptions • Equivalent provisions under the UK GDPR Although the text of the EU GDPR refers throughout to the ‘Union’, it is stated on page one of the EU GDPR that it is a text ‘with EEA relevance’, meaning all provisions are intended to be applicable in respect of all EEA
Q&As
This Q&A assumes that: • personal data is being transferred by an entity in the EU, which offers goods/services to or monitors the behaviour of data subjects in the EU (and that the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) applies) • personal data is being received by an entity in a jurisdiction other than the EEA • the movement of data in question falls within the category of international transfers restricted by Article 44 of the EU GDPR The issue of international transfers of personal data is a complex one; this answer summarises some of the main legal points relevant to the question and signposts other materials which should be consulted (along with relevant legislation and regulatory guidance) for further details. Those new to data protection law may wish to start by reading: EU GDPR regime (EU Law)—overview and International transfers
NEWS
EU Law analysis: The Court of Justice has clarified that offering a free user account may under certain conditions amount to a ‘sale’ of a service under Article 13(2) of the ePrivacy Directive, permitting companies to send direct marketing emails to such users under the so-called soft opt-in exception. The court held that indirect economic benefit, rather than direct payment, suffices for establishing a commercial relationship. Further, the court, in line with the Advocate General, found that Article 13(2) of the ePrivacy Directive is exhaustive, meaning that organisations meeting the soft opt-in criteria do not require a separate EU GDPR justification to send marketing emails. The decision is significant for practitioners advising on direct marketing compliance and demonstrates the precedence of ePrivacy rules over the EU GDPR where sector-specific provisions exist. Companies using freemium or similar models now have greater legal certainty, but must still ensure all conditions of the soft opt-in are rigorously met. Written by Wiebke Reuter, salary partner at Taylor Wessing, and Susan Hillert, associate at Taylor Wessing.
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module two (controller to processor) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A the data exporter is a controller and the data importer is a processor, and the name, address, contact person’s details and relevant activities for each of them is as set out in [insert where set
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
PRACTICE NOTES
This Practice Note provides guidance on the set of standard contractual clauses (SCCs) for international transfers of personal data published by the European Commission in June 2021 (the 2021 EU SCCs). It provides a more in-depth analysis of international transfers under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) than the introductory Practice Note: EU GDPR—transfers of personal data internationally and to international organisations and assumes general knowledge of key concepts under the EU GDPR regime and of its international transfers regime. If you are unfamiliar with this topic, you may wish to read those Practice Notes first. For more introductory information and background on the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). In brief Data protection law in the EEA seeks to ensure information about living individuals (ie within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU GDPR imposes a large
PRACTICE NOTES
STOP PRESS: This Practice Note reflects the current legislative position, however please note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025 pursuant to the Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note examines the law on the use of cookies and similar technologies in the EU, and covers the following: • Types of cookies and similar technologies • ePrivacy Directive and cookies • Responsibility for compliance • Consent • Clear and comprehensive information • Exemptions • EU GDPR and cookies • Territorial scope • Intranets • Sanctions and enforcement • Cookie audits • Reform • Resources and guidance Cookies are small data files stored on a user’s computer, phone or tablet. They allow an online service, such as a website, to recognise an individual user and store certain information about them such as login details, the contents of shopping baskets and site preferences. They are also commonly used to target advertising at a user based on their browsing history. Although
PRACTICE NOTES
Background Data subjects have the right to bring complaints and to seek judicial remedies and compensation if their rights under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) are breached. This includes a right of any person who has suffered ‘material or non-material damage’ as a result of an infringement of the EU GDPR to receive compensation from the controller or processor for that damage under Article 82 of the EU GDPR. Equivalent provisions apply under Regulation (EU) 2018/1725 (the EU GDPR equivalent applicable to the EU institutions). Consequently, compensation may be recovered for both pecuniary and non-pecuniary losses. Indeed, Recital 146 of the EU GDPR explains that the ‘concept of damage should be broadly interpreted’ and ‘in a manner which fully reflects the objectives of this Regulation’. Under the EU GDPR controllers have much broader liability than processors. Any controller involved in unlawful processing is liable for the damage caused. On the other hand, a processor is liable only for the damage caused by processing where
PRACTICE NOTES
This Practice Note provides guidance for a party involved in a commercial transaction between businesses to help them determine whether they are an independent controller, joint controller or processor under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). For a general introduction to the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). In brief Data protection law in the EEA (the EU plus Iceland, Norway, and Liechtenstein) is intended to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EEA data protection laws impose a large number of obligations on those ‘processing’ personal data (and on those who control such processing) and grant rights to those whose personal data is processed (the ‘data subjects’). In summary, ‘processing’ includes doing almost anything with personal data, including storing, sharing, deleting or using it. It is vital that natural persons and organisations involved
PRACTICE NOTES
We have produced a collection that collates key practical guidance on the specific legal and practical implications of data protection law in the EEA. The collection focuses on the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) regime. In relation to the subject matter of the collection, there are significant similarities between the EU GDPR regime and the
NEWS
MLex: A Greek scientist has won €50,000 in damages for mental distress and reputational harm after the European Anti-Fraud Office (OLAF) published a press release revealing her personal data and making it possible for any reader to identify her. The case has attracted attention on how it addresses a person that is identifiable under the EU data protection rules.
NEWS
MLex: Meta Platforms may end up having to rethink its approach to advertising again, thanks to the European Commission’s probe into the ‘consent or pay’ model it introduced for EU users of Facebook and Instagram. Meta is trying to devise a new, ‘less intrusive’ way to deliver ads to its users, in a bid to avoid penalties from both the EU competition regulator and the Irish data protection watchdog. The search for a balance is complex and will resonate with other platform companies that rely on serving ads to users.