article thumbnail

EU Rules Restricting the International Transfers of Non-Personal Data

Inside Privacy

Note that the data localization prohibition in this Regulation applies to individual EU Member Stateslaws; it does not preclude the EU from implementing data localization requirements. X (Recent Council versions remove this obligation.)

article thumbnail

The FCC Expands Scope of Data Breach Notification Rules

Inside Privacy

This Order follows recent activity from the FCC’s Privacy and Data Protection Task Force , including the announcement last month of a partnership between the FCC and state attorneys general on data privacy enforcement.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Utah Joins the Comprehensive State Privacy Law Club

Debevoise Data Blog

In prior posts, we have written about the evolving state privacy law landscape, including how to prepare for state privacy laws coming into effect in 2023 here ; various aspects of the CCPA and CPRA, including here and here ; and the Virginia Consumer Data Protection Act (“VCDPA”) here.

Law 52
article thumbnail

Getting Ready for 2023: What Companies Can Do Now to Prepare for New Privacy Laws

Debevoise Data Blog

The Virginia Consumer Data Protection Act (“VCDPA”) and amendments to the California Consumer Privacy Act (“CCPA”)—enshrined in the California Privacy Rights Act (“CPRA”)—take effect on January 1, 2023. These developments have companies understandably concerned about complying with a patchwork of state laws.

article thumbnail

Face Forward Part 2: Proposed Legislation and Strategies for Compliant Use of Facial Recognition

Debevoise Data Blog

Further, in a case that we have covered previously involving a supermarket using video surveillance with facial recognition capabilities, the Spanish data protection authority (the “AEDP”) fined grocer Mercadona for violating numerous provisions of the EU’s General Data Protection Regulation.

article thumbnail

Connecticut’s Next Generation Data Privacy Law

Debevoise Data Blog

Like other state privacy laws, the CTPA contains a number of entity-based and data-based exemptions, including financial institutions covered by the Gramm-Leach-Bliley Act, national securities associations that are registered under the Securities Exchange Act of 1934, and data regulated by the Fair Credit Reporting Act, among other exemptions.

Law 40
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.