Remove Compliance Remove Data protection Remove State law
article thumbnail

EU Rules Restricting the International Transfers of Non-Personal Data

Inside Privacy

This regulation is directly applicable in all EU Member States since May 28, 2019. Note that the data localization prohibition in this Regulation applies to individual EU Member Stateslaws; it does not preclude the EU from implementing data localization requirements.

article thumbnail

Getting Ready for 2023: What Companies Can Do Now to Prepare for New Privacy Laws

Debevoise Data Blog

The Virginia Consumer Data Protection Act (“VCDPA”) and amendments to the California Consumer Privacy Act (“CCPA”)—enshrined in the California Privacy Rights Act (“CPRA”)—take effect on January 1, 2023. These developments have companies understandably concerned about complying with a patchwork of state laws.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Face Forward Part 2: Proposed Legislation and Strategies for Compliant Use of Facial Recognition

Debevoise Data Blog

This would seem to eliminate not just the possibility of compliance-by-signage but also the possibility of online consent. Massachusetts would also completely ban “monetizing” – a term defined broadly –biometric identifiers as well as geolocation data. Compliance. Has the company obtained those individuals’ consent?

article thumbnail

Utah Joins the Comprehensive State Privacy Law Club

Debevoise Data Blog

In prior posts, we have written about the evolving state privacy law landscape, including how to prepare for state privacy laws coming into effect in 2023 here ; various aspects of the CCPA and CPRA, including here and here ; and the Virginia Consumer Data Protection Act (“VCDPA”) here.

Law 52
article thumbnail

Connecticut’s Next Generation Data Privacy Law

Debevoise Data Blog

Here, we highlight key aspects of the CTPA with a focus on the provisions that companies should consider in their compliance preparations. We also provide an overview of the CTPA’s enforcement mechanisms and explain how the CTPA modifies prior laws’ safe harbor with a nod towards prosecutorial discretion. CTPA § 4(b).

Law 40
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

article thumbnail

Face Forward: Strategies for Complying with Facial Recognition Laws

Debevoise Data Blog

The TDPA provides for a private right of action for violation of the prohibition to sell, lease, or disclose data. State Laws Permitting but Regulating Collection and Use of Biometric Identifiers, including Facial Data.

Law 52