Data export: EU provides more clarity after Schrems II

In documents published last week, the EU provided some welcome clarity on how organisations should address the invalidation of Privacy Shield as a basis for exporting personal data from the EU. On 10 November 2020, the European Data Protection Board (EDPB) adopted recommendations on ‘supplemental measures’, which can be considered to ensure compliance with the …

Read more

EDPB guidance on ‘supplemental measures’ for data export

On 10 November, the European Data Protection Board adopted a recommendation on supplemental measures which might be used to ensure compliance with the EU level of protection of personal data when exported to third countries with an insufficient level of protection. The recommendation both sets out a process to be followed by data exporters and, …

Read more

European Data Protection Board releases updated controller / processor guidance for comment

Are you sure you are a data processor? Introduction On 7 September 2020, the European Data Protection Board (EDPB), successor to the ‘article 29 working party’, released updated guidance on the concepts of ‘data controller’ and ‘data processor’ under European Privacy law (i.e. General Data Protection Regulation or GDPR). Whilst this has already been subject …

Read more

EU and US start work on enhanced Privacy Shield: Mr Schrems to be persuaded…

On 10 August 2020, Following the European Court’s Schrems II judgment invalidating the US Privacy Shield (and calling into question the legal basis for other transatlantic data transfers), the EU Commission and US Department of commerce issued a short, joint statement: “The U.S. Department of Commerce and the European Commission have initiated discussions to evaluate …

Read more

Exporting data from the EU after Schrems II: what to do now

As previously discussed, the European Court of Justice’s recent Schrems II decision both (i) invalidated the US privacy shield; and (ii) threw into question alternative justifications for the export of personal data from the EU to the US. Whilst there is yet to be a substantive response from the European Commission, initial reactions from the …

Read more

European Court invalidates US Privacy Shield and questions blanket use of Standard Contractual Clauses

Schrems II disrupts data export from EU: on 16 July 2020, the European Court of Justice decided, overturning the 2016 Privacy Shield Decision of the European Commission, that the US Privacy Shield did not, and does not, provide an adequate level of protection for the transfer of personal data from the EU to the US.

UK’s Financial Conduct Authority issues guidance on cloud

On 7 July 2016, the UK’s Financial Conduct Authority (FCA) issued finalised guidance for authorised UK financial institutions use of cloud services. In a marked contrast to some other jurisdictions’ approach, this guidance is issued against a policy backdrop of FCA’s ‘Project Innovate’ which is a initiative to foster innovation and competition. The FCA say:

Read more