Tag Archives: EU Data Protection Directive

European Data Protection Supervisor Issues Opinion on EU Cybersecurity Strategy

On June 14, 2013, the European Data Protection Supervisor (the “EDPS”) issued an Opinion regarding a joint communication by the European Commission and the High Representative of the Union for Foreign Affairs and Security Policy, Cyber Security Strategy of the European Union: an Open, Safe and Secure Cyberspace (the “Strategy”), as well as the European Commission’s proposed draft directive to ensure uniformly high security measures for network and information security across the EU (the “NIS Directive”). The EDPS welcomes recognizing privacy and data protection as core values of a robust cybersecurity policy, as opposed to separating out security and privacy, but draws attention to several deficiencies, stating that “the ambitions of the strategy are not reflected in how it will be implemented.”

Continue reading…

Tags: Cybersecurity, Data Protection Authority, E-Privacy Directive, EU Data Protection Directive, EU Regulation, European Data Protection Supervisor, European Union, Information Security, International, Peter Hustinx, Security Breach

Hunton Publishes Analysis Paper on the Irish Presidency’s Draft Compromise Text on the Proposed EU Data Protection Regulation

As we previously reported, on May 31, 2013, the Irish Presidency of the Council of the European Union’s Justice and Home Affairs released a draft compromise text in response to the European Commission’s proposed General Data Protection Regulation (the “Proposed Regulation”). This compromise text narrows the scope of the Proposed Regulation and seeks to move from a detailed, prescriptive approach toward a risk-based framework.

Continue reading…

Tags: Council of the European Union, EU Data Protection Directive, EU Member States, EU Regulation, European Commission, European Union, International, Right to Be Forgotten

Council of the European Union Releases Draft Compromise Text on the Proposed EU Data Protection Regulation

On May 31, 2013, the Council of the European Union’s Justice and Home Affairs released a draft compromise text in response to the European Commission’s proposed General Data Protection Regulation (the “Proposed Regulation”). This compromise text narrows the scope of the Proposed Regulation and seeks to move from a detailed, prescriptive approach toward a risk-based framework.

Continue reading…

Tags: Anonymization, Belgium, Council of the European Union, Data Controller, Data Transfers, EU Data Protection Directive, EU Member States, EU Regulation, European Commission, European Union, International, Ireland, Legislation, Lithuania, Marketing, Online Privacy, Security Breach, Social Media, United Kingdom, Viviane Reding

French Data Protection Authority Launches Public Consultation on Digital Right to Be Forgotten

On May 30, 2013, the French Data Protection Authority (“CNIL”) launched a public consultation on the digital “right to be forgotten.”

The CNIL recalled that the principle of a digital “right to be forgotten” is established in the Proposed EU Data Protection Regulation and that this new right will have to be exercised in accordance with freedom of expression, freedom of the press and the duty of remembrance.

In this context, the CNIL decided to consult web users with a goal of defining the broad outlines of the digital right to be forgotten. The CNIL also announced that it will consult industry experts and other professionals in parallel.

Tags: CNIL, EU Data Protection Directive, EU Regulation, European Union, France, International, Internet, Online Privacy, Right to Be Forgotten

LIBE Committee Postpones Vote on Amendments to the Proposed EU General Data Protection Regulation

On May 6, 2013, the European Parliament’s Committee on Civil Liberties, Justice and Home Affairs (“LIBE”) discussed the progress of the proposed General Data Protection Regulation (”Proposed Regulation”). LIBE’s lead rapporteur, Jan Philipp Albrecht, noted that, in light of the significant number of amendments tabled, more time is needed for the other rapporteurs to deliberate. As a result, the vote originally scheduled for May 29, 2013 on the lead rapporteur’s report regarding amendments to the Proposed Regulation has been postponed.

Continue reading…

Tags: Anonymization, EU Data Protection Directive, EU Member States, EU Regulation, European Commission, European Parliament, European Union, International, Right to Be Forgotten

Article 29 Working Party Clarifies Purpose Limitation Principle; Opines on Big and Open Data

On April 2, 2013, the Article 29 Working Party (the “Working Party”) adopted an Opinion (the “Opinion”) that elaborates on the purpose limitation principle set out in Article 6(1)(b) of the current EU Data Protection Directive 95/46/EC (the “Data Protection Directive”). The Opinion analyzes the scope of this principle under the Data Protection Directive, clarifies its limits and makes recommendations to strengthen it in the proposed General Data Protection Regulation (the “Proposed Regulation”). It also focuses on how to apply this principle in the context of big data and open data.

Continue reading…

Tags: Advertisement, Article 29 Working Party, Behavioral Advertising, CCTV, Data Transfer, EU Data Protection Directive, EU Regulation, European Union, Geolocation, Health Privacy, International, Online Privacy, Opt-In Consent, Smart Metering

Baltic DPAs Hold Annual Meeting on Data Protection

On March 21-22, 2013, the data protection authorities (“DPAs”) of the Baltic states of Estonia, Latvia and Lithuania met in Riga, Latvia, for their second annual meeting to discuss several practical cooperation matters regarding data protection.

Continue reading…

Tags: Data Protection Authority, Estonia, EU Data Protection Directive, EU Regulation, European Union, International, Latvia, Lithuania

UK ICO Publishes Further Analysis of Commission’s Revised Data Protection Framework

On February 12, 2013, the UK Information Commissioner’s Office published a further analysis of the European Commission’s proposed General Data Protection Regulation (the “Proposed Regulation”). This latest analysis supplements the initial analysis paper on the Proposed Regulation published on February 27, 2012. Although the general views expressed in its initial paper stand, the ICO has now provided greater detail regarding its views of the substantive provisions of the Proposed Regulation.

Continue reading…

Tags: Accountability, Data Controller, Data Processor, Data Transfer, Enforcement, EU Data Protection Directive, EU Regulation, European Commission, European Union, Information Commissioners Office, International, Privacy By Design, Social Media, United Kingdom

European Data Protection Supervisor Issues Additional Comments on EU Data Protection Reform Package

On March 15, 2013, European Data Protection Supervisor Peter Hustinx sent a letter to Juan Fernando López Aguilar, Chair of the European Parliament’s Committee on Civil Liberties, Justice and Home Affairs (“LIBE”), with his comments regarding certain aspects of the European Commission’s proposed revised data protection framework. On March 20, 2013, Peter Hustinx was invited to present his comments during a LIBE Committee meeting, together with the President of the Article 29 Working Party, Jacob Kohnstamm.

Continue reading…

Tags: Accountability, Anonymization, Article 29 Working Party, Binding Corporate Rules, Data Controller, Data Processor, EU Data Protection Directive, EU Regulation, European Data Protection Supervisor, European Union, International, Jacob Kohnstamm, Peter Hustinx

German DPAs Adopt Resolutions on Proposed U.S.–EU Free Trade Zone, Social Networks and EU Data Protection

On March 14, 2013, the 85th Conference of the German Data Protection Commissioners concluded in Bremerhaven. This biannual conference provides a private forum for the 16 German state data protection authorities (“DPAs”) and the Federal Commissioner for Data Protection and Freedom of Information, Peter Schaar, to share their views on current issues, discuss relevant cases and adopt Resolutions aimed at harmonizing how data protection law is applied across Germany.

Continue reading…

Tags: Data Controller, Data Processor, Data Protection Authority, EU Data Protection Directive, EU Regulation, European Commission, European Union, Events, Germany, International, Online Privacy, Social Media