Categories
Closed Consultations

Privacy online: is a separate Directive still needed?

Now that the General Data Protection Regulation has been completed, the European Commission is reviewing the ePrivacy Directive. This law was introduced in 2002 as part of the telecommunications framework, and it was recognised at the time that it was likely to be largely replaced by a future general privacy law. That has taken longer […]

Categories
Presentations

Referendum: has the GDPR gone away?

A few hours after the result of Thursday’s referendum on membership of the European Union, I gave a presentation on the significance of the EU’s General Data Protection Regulation, due to come into force in May 2018. That might seem a waste of time, but my suggestion was that the referendum result might in fact […]

Categories
Articles

Privacy Shield – Unfinished Business

The Article 29 Working Party’s new Opinion on the US–EU Privacy Shield draft adequacy decision leaves a lot of questions unanswered and further prolongs the period of uncertainty for anyone transferring personal data from Europe to the USA. That began last October when the European Court of Justice declared that the US-EU Safe Harbor agreement […]

Categories
Articles

Federated Access Management and the GDPR

[this article is based on the draft text published by the European Council on 28th January 2016. Recital and article numbers, at least, will change before the final text] When individuals register to access a website or other on-line service, it’s common to have to provide a significant amount of personal data. Some of this […]

Categories
Articles

Incident Response and the GDPR

The Commission’s original draft Regulation included explicit support for the work of computer security and incident response teams, recognising that such activities were a legitimate interest that involved processing of personal data. Furthermore the legal requirements implied by using the legitimate interests justification (notably ensuring that those interests not be overridden by the rights and […]

Categories
Articles

GDPR – the final text?

The European Council of Ministers have now published a proposed text for the General Data Protection Regulation. This still needs to be edited by the Commission’s “lawyer-linguists” to check for inconsistencies, sort out the numbering of recitals and articles etc. But the working parties of both the Parliament and the Council have recommended that the […]

Categories
Articles

Safe Harbor/Privacy Shield

The European Commission has now published draft texts that could be used to implement an EU/US Privacy Shield to replace the previous Safe Harbor agreement. It appears that the new scheme would only cover “commercial exchanges” of personal data between the EU and US so it is unlikely to be appropriate for export of personal […]

Categories
Articles

Safe Harbor: Advice Postponed

The Article 29 Working Party of European data protection supervisors had hoped to make a full statement on the EU/US Safe Harbor agreement at the end of January. However this has now been postponed, probably until mid-April. The European Court of Justice declared last October that the original Safe Harbor did not guarantee adequate protection […]

Categories
Articles

Breach Notification and the GDPR

[this article is based on the draft text published by the European Council on 28th January 2016. Recital and article numbers, at least, will change before the final text] The final version of the Data Protection Regulation’s breach notification proposals has addressed many of my concerns with the original draft. Rather than applying the same […]

Categories
Articles

Future of Data Protection Forum

Some very interesting and positive messages came out of this week’s Future of Data Protection Forum. Interestingly the forum didn’t just focus on the draft European Regulation: partly because the final state of that is still unclear, but also because there was general agreement that reputable organisations shouldn’t aim merely to comply with data protection […]