French Data Protection Authority Creates Working Group on Access of Personal Data by Foreign Public Authorities

On June 14, 2013, the French Data Protection Authority (“CNIL”) announced that last March it had created an internal working group to study the privacy issues arising from the access of the personal data of French citizens by foreign public authorities. The CNIL further announced that the working group has decided to organize meetings with the various concerned stakeholders (attorneys, telecommunications operators, public institutions and non-governmental organizations) and that it has already had discussions with some of them. A summary of the CNIL’s findings is expected to be published in September 2013.

Continue reading…

Tags: Cloud Computing, CNIL, Cybersecurity, European Union, France, Information Security, International, Legislation

UK ICO Publishes Social Networking and Online Forums Guidance

The UK Information Commissioner’s Office (“ICO”) has published guidance on the application of the Data Protection Act 1998 (“DPA”) to social networking sites and online forums. The guidance emphasizes that organizations and individuals that process data for non-personal purposes must comply with DPA requirements in their use of social networking sites and online forums just as they would in any other context.

Continue reading…

Tags: Christopher Graham, Compliance, Data Controller, Data Protection Act, European Union, Information Commissioners Office, International, Online Privacy, Social Media, United Kingdom

Japan Applies to Participate in APEC Cross-Border Privacy Rules Framework

On June 7, 2013, the Japanese Government applied to participate in the APEC Cross-Border Privacy Rules program. Japan’s application will be reviewed to verify that Japan has the necessary legal mechanisms to ensure that certified companies can be held accountable. If approved, Japan will join the United States and Mexico, which also are APEC-certified economies, and it is likely a number of Japanese seal programs will apply for certification as accountability agents. Once the requisite elements are in place, Japanese companies will be able to apply for approval of their cross-border privacy rules.

Continue reading…

Tags: Accountability, APEC, Binding Corporate Rules, Centre for Information Policy Leadership, European Commission, European Union, International, Japan

Hunton Publishes Analysis Paper on the Irish Presidency’s Draft Compromise Text on the Proposed EU Data Protection Regulation

As we previously reported, on May 31, 2013, the Irish Presidency of the Council of the European Union’s Justice and Home Affairs released a draft compromise text in response to the European Commission’s proposed General Data Protection Regulation (the “Proposed Regulation”). This compromise text narrows the scope of the Proposed Regulation and seeks to move from a detailed, prescriptive approach toward a risk-based framework.

Continue reading…

Tags: Council of the European Union, EU Data Protection Directive, EU Member States, EU Regulation, European Commission, European Union, International, Right to Be Forgotten

Council of the European Union Discusses Progress on the Proposed EU Data Protection Regulation

On June 6, 2013, the European Union’s Justice and Home Affairs Council held legislative deliberations regarding key issues concerning the European Commission’s proposed General Data Protection Regulation (the “Proposed Regulation”). The discussions were based on the Irish Presidency’s draft compromise text on Chapters I to IV of the Proposed Regulation, containing the fundamentals of the proposal and reflecting the Presidency’s view of the state of play of negotiations. At the Council meeting, the Presidency was seeking general support for the conclusions drawn in their draft compromise text on the key issues in Chapters I to IV.

Continue reading…

Tags: Belgium, Council of the European Union, Estonia, EU Members States, EU Regulation, European Commission, European Union, France, Germany, Hungary, International, Italy, Legislation, Poland, Slovenia, Sweden, United Kingdom, Viviane Reding

Hunton Hosts Next EU Regulation Seminar on the Consistency Mechanism

On June 5, 2013, Hunton & Williams hosted a seminar in the firm’s London office: Tracking the Draft EU Regulation ̶ General Update and the Concept of the “One-Stop Shop.” Bridget Treacy, Rosemary Jay and Tim Hickman of Hunton & Williams gave a presentation on the operation and effects of the “consistency mechanism” to be introduced in the proposed General Data Protection Regulation. The June 5 update was the most recent in Hunton & Williams’ ongoing series of Executive Briefings on the Proposed Regulation. The consistency mechanism is intended to ensure that, once the Proposed Regulation comes into force, it is applied consistently across all 27 EU Member States. Accordingly, the mechanism is of particular importance to organizations that carry out any processing of EU personal data, as it will have significant implications for the regulation of such organizations.

View consolidated notes from the presentation.

Continue reading…

Tags: Bridget Treacy, Data Controller, Data Processor, Data Protection Authority, EU Member States, EU Regulation, European Commission, European Union, Events, International, Rosemary Jay, Tim Hickman, United Kingdom

French Data Protection Authority Welcomes BCRs for Data Processors

On June 3, 2013, the French Data Protection Authority (“CNIL”) published an article outlining the importance of binding corporate rules (“BCRs”) for data processors, and describing how to use them.

Continue reading…

Tags: Accountability, Adequacy, Article 29 Working Party, Binding Corporate Rules, CNIL, Data Controller, Data Processor, Data Protection Authority, Data Transfers, EU Regulation, European Commission, European Union, France, International, Service Provider

First International Data Protection Congress in Colombia

On June 6, 2013, a group of 300 gathered in Santa Marta, Colombia, the second oldest city in South America, for the First Latin America Congress on Data Protection. The Congress was organized by Colombia’s data protection authority, the Superintendency of Industry and Commerce, and the Centre for Information Policy Leadership at Hunton & Williams LLP. “Latin America is very important to Centre member companies, and education is a key element of the Centre’s Latin America Project. So, we were very pleased to help the Superintendent organize the program,” said Centre President Marty Abrams.

Continue reading…

Tags: Accountability, Centre for Information Policy Leadership, Colombia, European Union, Events, International, Marty Abrams, Mobile Device

Sweden Fined for Delaying Implementation of the Data Retention Directive

On May 30, 2013, the Court of Justice of the European Union held that Sweden failed to fulfill its obligations under EU law when it delayed complying with the Court’s 2010 ruling regarding the country’s implementation of the EU Data Retention Directive 2006/24/EC (the “Data Retention Directive”). The Court ordered Sweden to pay a lump sum of €3,000,000.

Continue reading…

Tags: EU Member States, European Commission, European Union, International, Legislation, Penalty, Sweden, Telecommunications

Hunton Webinar on the Proposed EU Regulation: Developing a More Creative Approach

On May 29, 2013, Hunton & Williams hosted a webinar, A Discussion on the Proposed EU Regulation: Developing a More Creative Approach. Hunton & Williams partner Bridget Treacy moderated the session with former UK Information Commissioner Richard Thomas, Global Strategy Advisor of the Centre for Information Policy Leadership at Hunton & Williams. Richard Thomas discussed the need for a more creative and flexible approach to the proposed EU General Data Protection Regulation, with better-defined outcomes and targeting businesses that present the greatest risks. He also discussed using a risk-based framework, the Accountability Principle, and binding corporate codes as the building-blocks for this proposed approach.

View a recording of the webinar now.

Tags: Accountability, Binding Corporate Rules, Bridget Treacy, EU Regulation, European Union, Events, International, Multimedia Resources, Richard Thomas