The luxury offering at K&L Gates LLP consists mainly of Claude-Etienne Armingaud and E. Drouard, who specialize in IT and data privacy matters. In recent highlights, a leading fashion brand appointed the group to assist with the implementation of radio frequency identification device tags in its products to track them through the supply, distribution and sale process. The team also advised on the remodeling of IT structures, data privacy issues and matters pertaining to e-commerce platforms.


K&L Gates LLP‘s healthcare and life sciences offering covers corporate, IT, intellectual property and regulatory mandates within the sector under the leadership of Jean-Patrice Labautière. He recently assisted Axonics with its €35m fundraising from Gilde Healthcare and represented a bidder in the sale of a business division by a leading global healthcare company. While Nicola Di Giovanni focuses on corporate and private equity mandates, Claude-Etienne Armingaud collaborated with Labautière to advise a heavyweight healthcare player on the implementation of a startup acceleration programme for the development of new technology.


At K&L Gates LLP, the IP, IT and privacy group encompasses the firm’s corporate and commercial offering in the technological space under the joint leadership of Claude-Etienne Armingaud and E. Drouard, whose ‘perfect mastery of the law, outstanding understanding of complex issues and personal courage‘ impresses clients. The group was recently instructed by three major transport companies to advise on the provision of WiFi services in their train and subway stations and airports. Drouard is currently advising BNP Paribas on the regulatory and transactional aspects of the development of a digital mobile wallet app, and Armingaud is assisting a utility provider with the implementation of a smart city hub. Also notable is the group’s work in the online marketing and advertising, connected device and new technology, and online distribution sectors.


On January 21, 2019, the French Data Protection Authority (Commission Nationale de l’Information et des Libertés, or “CNIL”) published its first sanction rendered under the General Data Protection Regulation (“GDPR”).

Barely eight months after GDPR entered into force, and the subsequent group actions that were introduced in France, the CNIL followed in their footsteps its other European counterparts. However, while Portugal in July drew first against a hospital with a EUR 400,000 fines, the Austrian and German follow-ups, respectively for EUR 4,800 and 20,000 underwhelmed in contrast with the EUR 20 million, or 4% of the global turnover of a company (which ever the greatest) maximum fines allowed under GDPR.

Today’s CNIL decision nevertheless set the possible path for upcoming application of GDPR, by striking a EUR 50 million fine against Google LLC.

This sanction followed the group complaints formed by Maximilian Schrems’s association “None Of Your Business” (“NOYB” – already behind the cancellation of the Safe Harbor in 2015 and currently litigating against the Standard Contractual Clauses in Ireland) and La Quadrature du Net (“LQDN”), which received a mandate from 10,000 individuals to refer the matter to the CNIL.

The CNIL grounded its decision on the lack of transparency and inadequate information of the individuals in order to deem the consent regarding the ads personalization invalid.

On the one hand, the CNIL highlighted that the information of the data subjects was diluted in a myriad of documents while applying to a plurality of services at once (e.g. Google search, You Tube, Google Home, Google Maps, Playstore…). This did not allow the user to gain a “just perception of the nature and the volume of data collected.”

On the other hand, the consent-gathering mechanism was deemed inadequate to obtain the “specific” and “unambiguousconsent required for such data processing operations. The CNIL notably criticized the blanket acceptance of “the processing of [users’] information as described above and further explained in the Privacy Policy”, which, according to the Regulator, does not allow the users to opt-it to the each particular processing operation at stake without additional steps for the users to reach the required information.

This decision, in addition to be the first rendered by the CNIL under GDPR, will also in all likelihood be the last under the current Secretary General, Isabelle Falque-Pierrotin, who will be replaced on February 1st, after heading the CNIL since 2011.

Amidst the international tidal wave caused by the entry into force of the EU General Data Protection Regulation (“GDPR”) in May 2018, many half, or even false truths have been spread about hindrance on a global scale of innovative technologies. However, we must keep in mind that Europe has adopted a long-standing position of technology-neutral regulations and data protection is no exception.

Indeed, from a GDPR perspective, no technology would be prohibited or regulated by nature – only its application to a specific purpose may be regulated, inasmuch as it involves personal data -whether relating to the participants and miners or the payload data itself- and falls within its broad geographical scope (see our previous Alert for more details).
(more…)

While Capitol Hill is inundated with proposed privacy legislations from the Data Breach Prevention and Compensation Act (DBPCA), the CLOUD Act and the ENCRYPT Act, organizations the world over are trying to understand how to get their own regulations deemed adequate enough to ensure the flow of business in the EU, now that GDPR is a reality.
(more…)

On 2 July 2018, the French Data Protection Authority (“Commission Nationale de l’Informatique et des Libertés” or “CNIL”) published its yearly thematic guidance for the priority axes of its control activities, notably further to the entry into force of the recent General Data Protection Regulation (“GDPR”).

As for the previous periods, the CNIL is expecting to launch 300 dawn-raids, either on premises or online, in order to control compliance of companies subject to French and European data protection regulations, notably on newly introduced aspects relating to the implementation of GDPR (right to portability, data protection impact assessments…).

(more…)

K&L Gates ranked “Excellent” with E. Drouard & Claude-Etienne Armingaud.

Source: Leaders League

K&L Gates ranked “Highly Recommended – Band 1” with E. Drouard & Claude-Etienne Armingaud.

Source: Leaders League

K&L Gates ranked “Recommended – Band 2” with E. Drouard & Claude-Etienne Armingaud.

Source: Leaders League