Backed by a global network spanning five continents, the data protection, privacy and security group at K&L Gates LLP assists financial institutions and multinationals in mining, biotech (Anika Therapeutics), energy (Envision), home appliances (SharkNinja), pharmaceuticals (Ipsen), manufacturing (K&N Engineering), luxury goods and tech, on wide array of matters across the practice area. Headed by Claude-Etienne Armingaud, an expert in multi-jurisdictional transactional matters, dealing with IT outsourcing and data protection, the group also assists clients with GDPR compliance, data sharing agreements and data protection elements of M&A transactions.

Leading individuals: Claude-Etienne Armingaud – K&L Gates LLP

Practice head(s): Claude-Etienne Armingaud

(more…)

Well, that’s a wrap on #DPI23 France!

Claude-Étienne Armingaud, CIPP/E, Partner, Data Protection Privacy and Security Practice Group Coordinator, K&L Gates

Gabriela MercuriManaging Director, SCOPE Europe

Jörn WittmannDirector Privacy Legislative Strategy and Public Policy, Volkswagen AG

Codes of conduct overseen by accredited monitoring bodies are one of the breakthrough innovations introduced by EU General Data Protection Regulation. As part of its accountability framework, GDPR not only shifted the onus of demonstrative compliance, but also created the possibility for stakeholders to engage in co-regulatory practices. The goal was to allow the industry to support regulatory implementation by developing workable guidance to concretize the GDPR’s provisions. More flexible than other previously adopted compliance tools, CoCs generated high expectations, particularly in the wake of Schrems II, as a possible solution to address international data transfers and enable legal foreseeability. CoCs have not yet reached their full potential, with only a handful of national CoCs deployed and even less at the pan-European level. However, as the cloud ecosystem leads the way, this panel will explore the background of this sectoral success while highlighting CoC’s benefits, as well as their limitations.

What you will learn:

• How to understand the relevancy of CoCs in a post-GDPR, post-Schrems II era.

• What CoCs can bring to an ecosystem, as well as what they should not be pursued for.

• The future of international data transfers amid emerging data protection systems at global levels.

More information.

K&L Gates ranked “Recommended” with Claude-Etienne Armingaud.

Source: Leaders League

(more…)

K&L Gates ranked “Highly Recommended, Band 2/2” with Claude-Etienne Armingaud.

Source: Leaders League

(more…)

K&L Gates ranked “Highly Recommended – Band 1” with Claude-Etienne Armingaud.

Source: Leaders League

(more…)

This survey follows the CNIL’s announcement on 24 November 2022 that it aims at “better understanding the economic challenges associated with the collection and processing of personal data in mobile applications” as part of its 2022-2024 strategic plan.

The CNIL considered data collection via mobile applications greatly lacks transparency as opposed to cookies collection on websites.

The expected inputs are to be used for the purpose of drafting recommendations to be submitted to public consultation during the second semester of this year.

Concurrently to its ever-active enforcement of website cookie framework, the CNIL also recently started going after mobile applications for their use of personal data, often leverage as a primary source of revenue for free-to-play mobile games. The most recent example being the French mobile game publisher Voodoo SAS, with a fine of EUR3 million for breach of user consent for targeted ads on 29 December 2022. Indeed, the CNIL considered that even when users did not consent to the tracking for advertising purposes, Voodoo still accessed the IDFV (Apple’s “IDentifier For Vendors” (“IDFV”) – an identifier assigned to app operators, which facilitates targeted advertising) and processed browsing information for advertising purposes, constituting a violation of French privacy law and the GDPR.

The CNIL now calls for economic contributions from experts, interest groups, regulatory entities and experienced private individuals in the field. The call for contributions closes on 10 February 2023. Contributions can be submitted by completing a questionnaire and/or a written statement at the following email address: ecodesapplis@cnil.fr.

All contributions will be covered by professional secrecy and will be published in the form of a synthetic and aggregated report.

First publication on Cyber Law Watch with Camille Scarparo.

Très heureux d’avoir accueilli ce matin en nos locaux GEOTAB pour la conférence « Flottes connectées, réglementation et expériences réussies », modérée par François Denis, Directeur Général France GEOTAB.

Claude-Etienne Armingaud, CIPP/E, associé Protection des données, nous a exposé les enjeux du droit des données à caractère personnel en lien avec les véhicules connectés.

Pascal Six, Business Development Manager, a retracé la manière dont GEOTAB a développé et continue d’adapter son offre, dans le respect des lois applicables en matière de protection des données à caractère personnel.

Pour terminer, Bertrand MATHIEU Directeur des Opérations VAC / Hardouin Loc, nous a fait part de son expérience client réussie avec GEOTAB.

Merci aux intervenants et participants !

Claude-Etienne, Armingaud, Associé
K&L Gates

Stéphane Bonifassi, Associé fondateur
Bonifassi Avocats

Les options d’examen et d’analyse assistées par la technologie sont de plus en plus utilisées dans les enquêtes internes et externes, notamment par les multinationales. L’utilisation de l’analyse des données peut apporter efficacité, précision et réduction des coûts. Cependant, le croisement entre le droit et la technologie soulève des préoccupations uniques en matière de protection de la vie privée et d’autres questions juridiques lors des enquêtes internes et externes : cette session permettra de vous mettre à niveau. Les sujets de discussion incluront :

  • Étudier la manière dont l’analyse des données et la découverte électronique peuvent aider les enquêtes multinationales.
  • Comprendre vos obligations selon la loi Schrems II, le RGPD et d’autres législations.
  • Apprendre les meilleures pratiques pour se conformer à ces obligations lors des enquêtes internes ou externes, de la diligence raisonnable et de la dénonciation des dysfonctionnements.
  • Comparer et intégrer des lignes directrices de la CNIL et du Conseil européen de la protection des données, entre autres.
  • Déterminer l’impact de la proposition de cadre transatlantique pour la protection des données sur votre pratique quotidienne.

Plus d’information

On 29 June 2022,  Decree n° 2022-946 (the “Decree”) supplemented the regulatory framework resulting from the Ordinance n° 2021-1247 of 29 September 2021 on the legal warranty of conformity for goods, digital content and digital services (the “Ordinance”). Stakeholders have under 1 October 2022 to implement the following measures, aiming at protecting consumers of digital goods.

1. General information about the Ordinance

Implementing two 2019 European directives on certain aspects of contracts for the supply of digital content and digital services and contracts for the sale of goods (respectively Directives (EU) 2019/770 and 2019/771 dated 20 May 2019), the Ordinance aimed to foster the safety of consumers when purchasing both physical and digital goods and, to a lesser extent, to reduce the environmental impact of digital goods.

This Ordinance amended the French Consumer Code in depth, notably by expanding the legal warranty of conformity, which now covers digital products and services but is also applicable to both B2C as well as B2B contracts, when the latter are executed between professionals and non-professionals (i.e. legal entities acting outside of their direct professional activities).

(more…)