- Adoption of the minutes and of the agenda, Information given by the Chair
- Minutes of the 41st EDPB meeting
- Draft agenda of the 42nd EDPB meeting
- Publication of minutes of 40th Plenary meeting
- Request to extend the deadline for public consultation re recommendation 01/2020 on sup. measures
- Current Focus of the EDPB Members
- Presentation by the European Commission of the new (updated) two sets of SCCs
- FOR DISCUSSION AND/OR ADOPTION – Expert Subgroups and Secretariat
- Technology ESG
- Statement on eprivacy regulation
- Letter to News Media Europe and others regarding cookie walls
- International Transfer ESG
- Template for BCR approval decision by a supervisory authority
- Technology ESG
- Any other business
41st EDPB Meeting
November 17th, 2020 | Posted by in Data Transfer | Europe | Privacy - (0 Comments) - Adoption of the minutes and of the agenda, Information given by the Chair
- Minutes of the 40th EDPB meeting
- Draft agenda of the 41st EDPB meeting
- Current Focus of the EDPB Members
- Art. 65 ongoing procedure
- Draft Art. 65 Decision
- FOR DISCUSSION AND/OR ADOPTION – Expert Subgroups and Secretariat
- Recommendation on measures that supplement transfer instruments to ensure compliance with the EU level of protection of personal data
- Update of the European Essential Guarantees recommendations
GDPR/Brexit – What Future For UK-EU Data Flows
October 29th, 2020 | Posted by in Data Transfer | Europe | Privacy - (0 Comments) With the Brexit transition period ending on 31 December 2020, and no deal in sight, the future of cross-border data transfers between the European Economic Area (the EEA) and the United Kingdom remains unclear. On 1 January 2021, the United Kingdom will be considered as a “third country” and, unless a Brexit deal is proposed dealing with data protection and how data transfers between the EEA and the United Kingdom are to be treated, it could be significantly more difficult for European Union (EU)-based entities to transfer personal data to the United Kingdom.
(more…)Leaders League Ranking 2020 – Health, pharma & biotechnology – E-Health – France
October 2nd, 2020 | Posted by in eHealth | France | IT | Privacy | Rankings - (0 Comments) GPDR – European Data Protection Board Publishes Guidelines on the Concepts of Controller and Processor, Brings New Light on the Notion of “Joint-Controllers”
September 29th, 2020 | Posted by in Europe | Privacy - (0 Comments) The European Data Protection Board (EDPB) published two sets of new guidelines on 2 September 2020, on the concepts of controller and processor (Guidelines 07/2020, the Guidelines) and on the targeting of social media users (Guidelines 08/2020 – see our Alert here). The earlier aims to replace the previous opinion by EDPB’s predecessor, the WP29, on these concepts by clarifying the main concepts of “controller”, “joint-controllers” and “processor” and by specifying the consequences attached to these notions.
(more…)Guidelines 07/2020 on the concepts of controller and processor in the GDPR v 1.0
September 10th, 2020 | Posted by in Europe | Guidelines | Privacy - (0 Comments) Version 1.0 dated 06 September 2020 adopted for public consultation. Go to the finalized version.
Go to official PDF version.
EXECUTIVE SUMMARY
The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA).
The concepts of controller, joint controller and processor are functional concepts in that they aim to allocate responsibilities according to the actual roles of the parties and autonomous concepts in the sense that they should be interpreted mainly according to EU data protection law.
(more…)EU Data Protection: Standard Contractual Clauses May have Been Confirmed by the CJEU, But At What Price?
July 16th, 2020 | Posted by in Data Transfer | Europe | Privacy - (0 Comments) The long awaited Schrems II decision was published by the Court of Justice of the European Union (CJEU) on 16 July 2020 (Court of Justice of the European Union – Grand Chamber – 16 July 2020 – C-311/18 – Schrems II) and while it has already been summarized as the death blow to the Privacy Shield framework and the confirmation of the validity of the Standard Contractual Clauses (SCCs) by many, it may only be a Pyrrhic victory for the latter, as far as transfers to the US are concerned.
(more…)EU Data Protection: In a Post-Privacy Shield, Sectorial Code of Conduct Could Lead the Way to Safeguard Data Transfers Outside the EU/EEE
July 16th, 2020 | Posted by in Data Transfer | Europe | Privacy - (0 Comments) With the recent decision from the Court of Justice of the European Union (CJEU) invalidating the Privacy Shield framework (Court of Justice of the European Union – Grand Chamber – 16 July 2020 – C-311/18 – Schrems II – see our alert here) and subjecting the Standard Contractual Clauses (SCCs) to higher standard of enforcement, global companies with the need to transfer data across the world, and especially across the Atlantic, are now required to re-assess their data transfer mechanisms.
While both Privacy Shield and the SCCs predates the General Data Protection Regulation 2016/79 dated 27 April 2016, which enter into force on 25 May 2018 (GDPR) , the new regulation aimed at providing stakeholders with additional tools to self-regulate and safeguard the privacy of individuals in the European Union
Among them, and while still confidential, the implementation of codes of conduct is encouraged under Art. 40 GDPR and by the dedicated Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/79 dated 04 June 2019 of the European Data Protection Board (EDPB). As a matter of fact, the advantages of such codes of conducts go beyond the mere facilitation of data transfers, and provide data controllers and data processors alike with a complete sectorial framework for GDPR compliance.
(more…)