On 10 July 2023, the European Commission adopted its long-awaited adequacy decision for the EU-U.S. Data Privacy Framework (the DPF). With immediate effect, the adequacy decision provides a new lawful basis for transfers from the EU to the U.S. This means that companies that participate in the DPF are able to transfer data from the EU to the U.S. without relying on another data transfer mechanism, such as Standard Contractual Clauses (SCCs) or binding corporate rules (BCRs).
Background to the Adequacy Decision
Pursuant to Article 45(3) of the GDPR, the European Commission has the power, by means of an adequacy decision, to decide that a non-EU country has sufficient standards of data protection to be treated as equivalent to those afforded in the EU.
Continue reading “The European Commission Adopts Adequacy Decision on EU-U.S. Data Privacy Framework”
Yesterday, the Irish Data Protection Commission (DPC) issued Meta Platforms Ireland Limited with a EUR 1.2 billion (approximately 1.3 billion U.S. dollar) fine for breaches of the GDPR with respect to EU-U.S. personal data transfers associated with its Facebook service. Meta Ireland has also been ordered to suspend all Facebook-related personal data transfers from the EU to the U.S., and to bring the processing of any previously transferred data into compliance.
Continue reading “Meta Fined EUR 1.2 Billion for Violating GDPR”
On 4 May 2023, the European Court of Justice (CJEU) delivered its highly anticipated judgement in Österreichische Post (Case C-300/21) on a crucial issue: the extent to which data subjects affected by a breach of the GDPR have a right to compensation for non-material damage under Article 82 GDPR.
The underlying case arose from a data subject in Austria seeking 1,000 EUR ($1,009) in compensation for alleged non-material damages arising from Österreichische Post’s processing of his personal data for the purposes of political advertising. The individual had not consented to the processing and claimed that he felt offended by the fact that an affinity to a certain political party was attributed to him, alongside feelings of great upset, loss of confidence and exposure caused by the retention of his data on these supposed political opinions.
Continue reading “Österreichische Post: The CJEU Specifies the Requirements for Compensation for Breaches of the GDPR”
On 11 May 2023, the European Parliament Internal Market and Consumer Protection (IMCO) and Civil Liberties, Justice and Home Affairs (LIBE) committees voted by a large majority to adopt a compromise position on the draft text of the proposed AI Act. The AI Act is a landmark legislative proposal set to be one of the first and most significant set of rules on artificial intelligence. This compromise text approved by the Committees makes some key changes to the European Commission’s initial draft of the AI Act, outlined below.
Continue reading “The AI Act Progresses Ahead With Approval of Key European Parliament Committees”
On 29 March 2023, the UK Government published its latest proposals on regulating Artificial Intelligence (“AI”). The White Paper follows on from an initial policy paper published in July 2022 (the “2022 Policy Paper”), which we discussed in detail in our previous blog post. The proposals set out in the White Paper have been informed by the feedback received as part of the UK Government’s consultation on the 2022 Policy Paper.
A central theme is that the regulatory framework in the UK must not stifle innovation, but rather harness AI’s ability to drive growth and prosperity, and increase public trust in its use and application.
Continue reading “The UK’s New AI Proposals”
The UK government recently introduced a new Data Protection and Digital Information (No. 2) Bill (the “New Bill”). The reforms are intended to update and simplify the UK’s data protection framework and reduce burdens on organisations, while maintaining high data protection standards.
The New Bill replaces the original Data Protection and Digital Information Bill introduced in July 2022 (the “Previous Bill”), which we discussed in detail in our previous blog post. Much of the original drafting remains the same in the New Bill. However, there are some key changes to the proposals, outlined below.
Continue reading “UK’s Updated Data Protection Reform Proposals”