This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
Our top-eleven European dataprotection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU.
International data transfers in GDPR compliance are complex, as data are transferred to third countries outside the European Union (EU) or the European Economic Area (EEA). Suppose you are interested in personal dataprotection issues. How does conducting a DTIA relate to GDPR compliance?
Our top-five European dataprotection developments from February are: European Commission publishes guidelines on prohibited AI practices : The EU Commission has published non-binding guidance on the EU AI Acts prohibited use cases. 10(5) allows for the exceptional processing of special category data (as defined under the GDPR Art.
Our top five European dataprotection developments from January are: UK ransomware reporting proposals. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. UK ICO acts on cookie compliance.
For example, in 2020, the DataProtection Authority of Hamburg imposed a 35.3 This fact became known when the H&M servers encountered a technical error, and the data on the network drive became accessible to all employees for a few hours. Different local laws require employers to retain employee data.
privacy legislation, is now addressing these technologies with a new set of proposed rules by the California Privacy Protection Agency (CPPA). The European Unions General DataProtection Regulation (GDPR) , particularly Article 22 , addresses similar concerns by regulating decisions made solely through automated processing.
Therefore, individual states took matters into their own hands and passed local laws to protect the privacy of their residents. In this article, we will review who needs to know the new rules of the US legislation, when exactly they will come into force and what obligations these laws provide.
Those who process personal data of EU residents should comply with the requirements of the General DataProtection Regulation or GDPR. Non-compliance with GDPR may result in hefty fines and reputational losses. However, DPO is not a mere formality needed to comply with the law.
Given that AI models require large swathes of data to operate, the GDPRs expansive definition of personal data means that many applications of AI involve complex dataprotection issues especially where those datasets are obtained from third-party sources.
GDPR Compliance: From theory to practice GDPR has become a real challenge for businesses. GDPR compliance is not about formalities, but about real processes. That is why GDPR compliance is not just a set of rules or documents. So what does real GDPR compliance look like? So what does real GDPR compliance look like?
When Compliance Gets Complicated, So Does Risk In todays regulatory climate, investigations go far beyond fact-finding. This is especially true in complex, cross-border matterswhere regulatory regimes, languages, and dataprotection frameworks collide. They require foresight, agility, and control.
Between the Clean Companies Act (Lei Anticorrupo) and the evolving requirements of the General DataProtectionLaw (LGPD), organizations operating in Brazil must do more than simply complythey must demonstrate accountability, transparency, and operational precision in the face of mounting enforcement.
The New Compliance Reality: Rising Expectations, Expanding Risks European legal and compliance teams are under increasing pressure. Regulatory investigations are growing in complexity, data sources are multiplying, and enforcement is becoming more aggressive.
In May 2023, the Spanish Supervisory Authority (“SA”) issued a detailed guidance paper on GDPR compliance in the context of data spaces. If you have questions about data spaces, we are happy to assist.
On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and dataprotection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. AI has been a strategic priority for the ICO for several years.
Law firms are often targeted by cybercriminals due to the sensitive information they handle and the potential for financial gain. In 2020, the American Bar Association reported that over 25% of law firms had experienced a data breach, with smaller firms being particularly vulnerable. What is Cyber Security Compliance?
On 19 June 2023, the Information Commissioner’s Office (ICO) has released new Guidance on Privacy-Enhancing Technologies (PETs) for DataProtectionCompliance. Understanding PETs PETs are software and hardware systems that can help minimize use of personal data use while maximizing information security.
A dataprotection officer ( DPO ) is a specialist who helps companies ensure compliance with international dataprotectionlaws. In a nutshell, the DPO is a key person who helps the company in all business processes to ensure compliance with the dataprotectionlaw.
China’s new law, just passed on Aug. 20, is similar to Europe’s General DataProtection Regulation (GDPR) and applies to any organization that has employees in China or does business in China. China’s new law, just passed on Aug. Organizations must comply with the law by Nov.
We also didn’t have citizen journalism platforms enabling lawyers and law firms to openly publish insight on the implications of matters such as AI. When AI hit last year, law firms started publishing about AI, perhaps like no other subject before. For clients needing insight on AI, for lawyer and law firm name recognition and more.
Privacy law is a growing and dynamic area of practice for many attorneys. A wave of state legislation with dataprotection requirements places new obligations on businesses and public institutions. The history of privacy law The roots of privacy law in the U.S. Seven more states passed such laws in 2024.
New dataprotectionlaws, increasing regulation, greater risk of cyber attacks: The challenges for entrepreneurs are becoming ever greater. However, compliance can be largely automated through artificial intelligence. On September 1, a new dataprotectionlaw (revDSG) has come into force in Switzerland.
While they will continue to serve lawyers and law firms, modern clients demand innovation. Law firm innovation must become a foundational part of your business strategy if you want to thrive in the legal environment of tomorrow. Staying Ahead: Why Innovation Is Crucial for Law Firms There were over 1.33
A dataprotection impact assessment (DPIA) sounds like something big, complicated and problematic. DPIA stands for DataProtection Impact Assessment. A DPIA is typically conducted when a new project involving the specific processing of personal data is being implemented. Well, it is true. Let’s check.
Since the entry into force of the General DataProtection Regulation (GDPR), many companies processing the data of Europeans have faced the task of achieving the much desired GDPR-compliance. Why do we need this?
In today’s digital age, data security is a critical concern for law firms. As custodians of sensitive client information, law firms must take proactive measures to safeguard data from cyber threats and ensure compliance with dataprotection regulations.
In this regard, we describe below what they should take under consideration in light of Polish labour law and dataprotectionlaw. Bossware and the rules for processing personal data As a rule, the operation of bossware will involve the processing of employee personal data.
Building on prior European guidance , the French and Irish DPAs published guidance on the deployment of generative AI, large language models and dataprotection. To that end, the EDPB proposed designating DPAs as the “national competent authorities” under the AI Act to create a single point of contact.
Brazil’s Lei Geral de Proteção de Dados Pessoais (or LGPD), similar to GDPR, CCPA and PIPEDA, regulates personal dataprotection. If the company does not process personal data in Brazil but still processes data to offer or supply goods or services to Brazil, the LGPD also applies in this case. Apparently not.
Our top five European dataprotection developments from May are: UK guidance on ransom payments: The UK NCSC and various insurance industry bodies co-published guidance on key considerations for ransomware payments. 22, then there must be sufficient human-involvement in that processing for it to be GDPR-compliant.
million fine against Austrian Post for channelling electronic dataprotection-related inquiries to a web form and not offering an additional email address, irrespective of the data subject option to also use non-electronic postal mail or customer service. Standard Contractual Clauses).
This article discusses the first step for fintechs to get ready for the new datalaw. No piece of legislation has taken more punches than our elusive dataprotectionlaw. The datalaw is nearly here! The Digital Personal DataProtection Bill, 2023 was introduced in Parliament on 3 August 2023.
EDPB “Consent or pay” models: Businesses operating large online platforms should consider the European DataProtection Board’s recent opinion indicating that “consent or pay” models are unlikely to be GDPR-compliant. These developments, and more, are covered below.
There were a few European dataprotection developments in February that companies may want to have on their radar. On the regulatory front, German DPAs have set up a taskforce to conduct random checks on companies’ cross-border data transfer compliance following Schrems II. We cover those developments (and more) below.
Just as installing a high-tech engine on a car with flat tires wont get you far (and probably isnt the safest choice), simply adding AI to outdated systems wont drive sustainable success for your law firm. This step-by-step guide will walk you through how to introduce AI into your law firm’s tech stack. Ready to get started?
Here are our highlights: European Commission adopts new Standard Contractual Clauses What happened : As reported in our blog post , the European Commission adopted its new Standard Contractual Clauses (“SCCs”) for the cross-border transfer of personal data from the EEA to “third countries”.
On 3 October 2023, the UK Information Commissioner’s Office organised its annual DataProtection Practioner’s Conference 2023 (DPPC 2023). NIST), the ICO’s response was that there have been a number of laws introduced recently that require certain security measures to be adopted. Supply chains were also covered.
Managing a law firm requires more than overseeing cases and delegating tasksit demands a strategic approach that balances client expectations, regulatory compliance, and operational efficiency. What Is Law Firm Management? Law firm management refers to administrating and overseeing all aspects of running a legal practice.
million for vendor oversight failings, unlawful cross-border transfers What happened : The AEPD, the Spanish dataprotection authority (“DPA”), fined Vodafone Spain €8.15 million for various breaches of the GDPR and Spanish e-privacy laws, topping the €6 million CaixaBank penalty from earlier this year. €4
The post Digital Transformation for Law Firms: A Guide to Modernizing Your Practice appeared first on Rocket Matter. But if this is the case for what clients require, then why are there still too many law firms buried in the unnecessary abundance of physical paperwork? What Is Legal Digital Transformation ?
The AEPD held that a DPO cannot hold a position that leads them to determine the purposes and means of data processing. The scale and dataprotection risks associated with such technologies has been further complicated recently by their increasing integration with artificial intelligence systems.
Dataprotection & AI: In particular: (i) the French CNIL published its first set of guidance on GDPR compliance when developing AI tools; and (ii) the UK ICO issued a preliminary enforcement notice against Snap over its AI chatbot, alleging that Snap had not adequately assessed the privacy risks posed to child users of the tool.
Introduction In our previous articles , we have already drawn your attention to the Brazilian dataprotection legislation which is quite similar to the General DataProtection Regulation (GDPR). Also, the ANPD has shared a new form which should be used for sending security incident reports by a data controller.
Our top-five European dataprotection developments from August are: Uber fined for personal data transfer: The Dutch DataProtection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., without sufficient safeguards.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content