On March 31, 2021, the Dutch Data Protection Authority, announced a fine of 475,000 Euros for Dutch headquartered online travel agency Booking.com for failure to report a data breach within 72 hours of becoming aware of the incident in 2019.
Continue Reading Dutch Regulator Fines Booking.com 475,000 Euros for Late Breach Reporting
Data Protection Authority
CIPL Organizes Webinar on EU Approach to Regulating AI and Regulatory Experimentation
On March 25, 2021, the Centre for Information Policy Leadership at Hunton Andrews Kurth organized an expert roundtable on the EU Approach to Regulating AI–How Can Experimentation Help Bridge Innovation and Regulation? Roundtable panelists explored how methodologies, such as policy prototyping and regulatory sandboxes, can help create the right rules and frameworks and interpret them constructively for regulating AI in a way that enables responsible innovation and risk mitigation.…
Continue Reading CIPL Organizes Webinar on EU Approach to Regulating AI and Regulatory Experimentation
European Union and South Korea Complete Adequacy Talks
On March 30, 2021, the European Commission announced the successful conclusion of the adequacy talks with the Republic of Korea.…
Continue Reading European Union and South Korea Complete Adequacy Talks
China Issues the Measures for the Supervision and Administration of Online Transactions
China’s State Administration for Market Regulation has recently issued Measures for the Supervision and Administration of Online Transactions. The Measures implement rules for the E-commerce Law of China and provide the specific rules for addressing registration of an online operation entity, supervision of new business models (such as social e-commerce and livestreaming), platform operators’ responsibilities, protection of consumers’ rights and protection of personal information.…
Continue Reading China Issues the Measures for the Supervision and Administration of Online Transactions
CIPL Submits Comments on Irish DPC’s Guidance on Safeguarding Personal Data of Children
The Centre for Information Policy Leadership at Hunton Andrews Kurth has submitted its comments on the Irish Data Protection Commissioner’s draft guidance on the safeguarding of the personal data of children when providing online services.…
Continue Reading CIPL Submits Comments on Irish DPC’s Guidance on Safeguarding Personal Data of Children
Bavarian DPA Declares Transfers to E-mail Marketing Service Prohibited Due to Lack of Controller’s Assessment and Supplementary Measures
On March 15, 2021, the state Data Protection Authority of Bavaria declared the use of U.S. e-mail marketing service Mailchimp by a fashion magazine in Bavaria impermissible due to lack of compliance with Schrems II mitigation steps for the transfer of e-mail addresses to the U.S.…
Continue Reading Bavarian DPA Declares Transfers to E-mail Marketing Service Prohibited Due to Lack of Controller’s Assessment and Supplementary Measures
French Highest Court Rejects Suspension of Partnership with EU Service Provider Using AWS; Extends Application of the Schrems II Requirements
France’s highest administrative court recently issued a summary judgment that rejected a request for the suspension of the partnership between the French Ministry of Health and Doctolib, a leading provider of online medical consultations in Europe, for the management of COVID-19 vaccination appointments. …
Continue Reading French Highest Court Rejects Suspension of Partnership with EU Service Provider Using AWS; Extends Application of the Schrems II Requirements
CIPL Submits Response to the EDPB Guidelines on Examples Regarding Data Breach Notification
The Centre for Information Policy Leadership at Hunton Andrews Kurth has submitted its response to the European Data Protection Board consultation on draft guidelines on examples regarding data breach notification. CIPL welcomes the Guidelines which come at a time at which cyber attacks are surging as a result of the move to remote working triggered by the COVID-19 crisis, and should help organizations avoid over-reporting.…
Continue Reading CIPL Submits Response to the EDPB Guidelines on Examples Regarding Data Breach Notification
CIPL Submits Response to New Brazilian Data Protection Authority’s First Public Consultation on SMEs
On March 1, 2021, the Centre for Information Policy Leadership at Hunton Andrews Kurth submitted a response to the new Brazilian data protection authority’s call for preliminary inputs on the impact of the Brazilian data protection law on small and medium-sized enterprises. …
Continue Reading CIPL Submits Response to New Brazilian Data Protection Authority’s First Public Consultation on SMEs
Regulatory Sandboxes are Gaining Traction with European Data Protection Authorities
The concept of regulatory sandboxes has gained traction in the data protection community. Since the UK Information Commissioner’s Office completed its pilot program of regulatory sandboxes in September 2020, two European Data Protection Authorities have created their own sandbox initiatives following the ICO’s framework.…
Continue Reading Regulatory Sandboxes are Gaining Traction with European Data Protection Authorities