|
| 1 | Overview of EU data protection regime An overview of the nature and scope of data protection and privacy laws in the European Union. | Practice Note: Overview | Maintained |
|
| 1 | Corporate whistleblowing hotlines and EU data protection ... A note which describes the data protection and employment issues that arise when European companies listed at US stock exchanges set up corporate compliance (whistleblowing) hotlines in order to fulfil obligations under section 301(4) of the US Sarbanes-Oxley Act 2002. The note also discusses recent regulatory developments in the EU relating to whistleblowing hotlines, and suggests compliance strategies to ensure that hotlines comply with EU data protection laws. | Practice Notes | Maintained |
|
| 1 | Standard contractual clauses for the transfer of personal data ... A standard clause approved for the purposes of Directive 95/46/EC for the transfer of personal data to processors in third countries that do not ensure an adequate level of protection as set out in the Annex to Commission Decision 2010/87/EU. This Standard document has been adapted by PLC IPIT & Communications from the original text available at the EUR-Lex website with the permission of the Publications Office of the European Union. © European Communities, eur-lex.europa.eu/ Only European Union legislation printed in the paper edition of the Official Journal of the European Union is deemed authentic. | Standard Clauses | 15-May-2010 |
| 2 | Standard contractual clauses for the transfer of personal data ... Standard clauses approved for the purposes of Directive 95/46/EC for the transfer of personal data to data controllers in third countries that do not ensure an adequate level of protection as set out in the Annex to Decision 2004/915/EC. This Standard document has been adapted by PLC IPIT & Communications from the original text available at the EUR-Lex Website with the permission of the Publications Office of the European Union. © European Communities, http://eur-lex.europa.eu/ Only European Union legislation printed in the paper edition of the Official Journal of the European Union is deemed authentic. | Standard Clauses | 27-Oct-2009 |
|
| 1 | Data protection in Finland: overview A Q&A guide to data protection in Finland. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-May-2013 |
| 2 | Privacy in Finland: overview A Q&A guide to privacy in Finland. The Q&A guide gives a high-level overview of privacy rules and principles, including what national laws regulate the right to respect for private and family life and freedom of expression; to whom the rules apply and what privacy rights are granted and imposed. It also covers the jurisdictional scope of the privacy law rules and the remedies available to redress infringement. To compare answers across multiple jurisdictions, visit the Privacy Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-May-2013 |
| 3 | Data protection in Sweden: overview A Q&A guide to data protection in Sweden. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 4 | Data protection in the UK (England and Wales): overview A Q&A guide to data protection in the UK. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 5 | Privacy in Sweden: overview A Q&A guide to privacy in Sweden. The Q&A guide gives a high-level overview of privacy rules and principles, including what national laws regulate the right to respect for private and family life and freedom of expression; to whom the rules apply and what privacy rights are granted and imposed. It also covers the jurisdictional scope of the privacy law rules and the remedies available to redress infringement. To compare answers across multiple jurisdictions, visit the Privacy Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 6 | Privacy in the UK (England and Wales): overview A Q&A guide to privacy in the UK (England and Wales). The Q&A guide gives a high-level overview of privacy rules and principles, including what national laws regulate the right to respect for private and family life and freedom of expression; to whom the rules apply and what privacy rights are granted and imposed. It also covers the jurisdictional scope of the privacy law rules and the remedies available to redress infringement. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 7 | Data protection in India: overview A Q&A guide to data protection in India. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jan-2013 |
| 8 | Data protection in Saudi Arabia: overview A Q&A guide to data protection in Saudi Arabia. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Oct-2012 |
| 9 | Data protection in Canada: overview A Q&A guide to data protection in Canada. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Aug-2012 |
| 10 | Data protection in Australia: overview A Q&A guide to data protection in Australia. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 11 | Data protection in Brazil: overview A Q&A guide to data protection in Brazil. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 12 | Data protection in China: overview A Q&A guide to data protection in China. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 13 | Data protection in France: overview A Q&A guide to data protection in France. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 14 | Data protection in Germany: overview A guide to data protection in Germany. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 15 | Data protection in Ireland: overview A Q&A guide to data protection in Ireland. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 16 | Data protection in Japan: overview A Q&A guide to data protection in Japan. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 17 | Data protection in Norway: overview A Q&A guide to data protection in Norway. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 18 | Data protection in Poland: overview A Q&A guide to data protection in Poland. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 19 | Data protection in Romania: overview A Q&A guide to data protection in Romania. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 20 | Data protection in South Africa: overview A Q&A guide to data protection in South Africa. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 21 | Data protection in Spain: overview A Q&A guide to data protection in Spain. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 22 | Data protection in Thailand: overview A Q&A guide to data protection in Thailand. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 23 | Data protection in Turkey: overview A Q&A guide to data protection in Turkey. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 24 | Data protection in the Czech Republic: overview A Q&A guide to data protection in the Czech Republic. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 25 | Data protection in the Russian Federation: overview A Q&A guide to data protection in the Russian Federation. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 26 | Data protection: Country Q&A tool This tool enables subscribers to search the Country Q&A in the Data Protection multi-jurisdictional guide by question and jurisdiction. Simply select the questions and the jurisdictions that you are interested in and click the "submit" button. Please note that the law stated dates for each jurisdiction covered may not be the same. To check the law stated dates for each jurisdiction, please visit the individual article. | Articles | 01-Jun-2012 |
| 27 | Sanctions for data breaches This table is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 28 | Data protection and the right to be forgotten The European Commission published a proposed new data protection framework for the EU on 25 January 2012. The proposed legislation not only reflects the change in the way personal data is used, but also the change in public opinion about how it should be used. The new framework proposes, among other things, that data controllers can no longer rely on implied consent in the processing of personal data and that data subjects have the right to be forgotten. This article discusses the current and future position of data protection legislation in the EU. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 29 | Data protection compliance policies This analysis article examines the importance of observing data protection law and introducing a compliance system for companies operating across jurisdictions. This is particularly the case in light of the likelihood of reinforced rules at EU level. A comprehensive compliance system can help companies to avoid the potential minefields and reduce the potential risks associated with non-compliance, particularly in view of the increasing significance of data protection for individuals and companies, the growing body of law in this area, and the existing obligations provided under data protection laws. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 30 | Data protection in Austria: overview A Q&A guide to data protection in Austria. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 31 | Data protection in Belgium: overview A Q&A guide to data protection in Belgium. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 32 | Data protection in Hungary: overview A Q&A guide to data protection in Hungary. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 33 | Data protection in Italy: overview A Q&A guide to data protection in Italy. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 34 | Data protection in Luxembourg: overview A Q&A guide to data protection in Luxembourg. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 35 | Data protection in Mexico: overview A Q&A guide to data protection in Mexico. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 36 | Data protection in Qatar including Qatar Financial Centre ... A Q&A guide to data protection in the Qatar Financial Centre (QFC). This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 37 | Data protection in Qatar: overview A Q&A guide to data protection in Qatar. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 38 | Data protection in the United Arab Emirates, Dubai ... A Q&A guide to data protection in the Dubai International Financial Centre (DIFC). This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 39 | Data protection in the United Arab Emirates: overview A Q&A guide to data protection in the United Arab Emirates. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 40 | Data protection in the United States: overview A Q&A guide to data protection in the United States. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 41 | Dealing with data breaches in Europe and beyond This article gives an overview of the EU/EEA legal framework concerning breach notification and local breach notification requirements. It goes on to consider global trends concerning the emergence of data breach legislation and provides some guidance on preparing a data breach response plan. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 42 | Global investigations: managing the risks Recent trends towards increased co-operation and exchange of information between regulators and prosecutors mean that multinational companies frequently have to deal with the same regulatory issues across many jurisdictions. This article sets out the key issues that a company must consider when facing a multi-jurisdictional regulatory investigation. | Articles | 28-Apr-2011 |
| 43 | Data protection in Hong Kong: overview A Q&A guide to data protection in Hong Kong. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2011 |
| 44 | Data protection aspects in an outsourcing transaction This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. This article explores the key issues faced by companies operating in multiple jurisdictions that are dealing with or planning for a scenario where personal data has been accidentally lost, destroyed or disclosed. | Articles | 01-Apr-2010 |
| 45 | Data security: breach notification This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. This article explores the key issues faced by companies operating in multiple jurisdictions that are dealing with or planning for a scenario where personal data has been accidentally lost, destroyed or disclosed. | Articles | 01-Apr-2010 |
| 46 | Obtaining documents and information in Switzerland: the use ... This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. The production and disclosure of documents showing a company's relations with other parties is usually not intended, though this may be important in legal proceedings. Data protection laws have introduced new potential tools to obtain documents and gather information outside legal proceedings. This article examines the grounds for these requests under Swiss law and the rights under the Swiss Data Protection Act. | Articles | 01-Apr-2010 |
| 47 | Solutions to the cross-border transfers of personal data from ... This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. This chapter examines the basic principles of the Data Protection Directive, the Model Contract Clauses introduced by the Article 29 Working Party and their most recent amendments, the Alternative Model Clauses, the Binding Corporate Rules, the Safe Harbour Principles, certain issues around the transfer of data in legal proceedings outside the EEA and the new bank data transfer agreement (SWIFT II).This article is part of the PLC multi-jurisdictional guide to data protection law. | Articles | 01-Apr-2010 |
| 48 | Data Protection: Greece A Q&A guide to data protection law in Greece. | Articles | 01-Mar-2009 |
| 49 | Data Protection: Norway A Q&A guide to data protection law in Norway. | Articles | 01-Mar-2009 |
| 50 | Data protection issues on an EU outsourcing This chapter considers EU data protection issues that arise on an outsourcing, in particular: the role of the data controller and data processor; data protection issues to be addressed in pre-contractual negotiations; data protection issues to be addressed when drafting the outsourcing contract; and the national law governing the transfer of personal data in France, Italy and the UK. | Articles | 01-Jan-2008 |
|
| 1 | Council Presidency proposals on aspects of EU data ... A note from the EU Council Presidency to the Committee of Permanent Representatives on specific issues included in the proposed data protection reform has been leaked and published on the website of the civil liberties organisation, Statewatch. | Legal Update: archive | 08-May-2013 |
| 2 | Article 29 Working Party adopts opinion on data protection ... The EU’s Article 29 Working Party has adopted an opinion (04/2013) on the data protection impact assessment template for smart grid and smart metering systems (WP205) in the energy sector. | Legal Update: archive | 02-May-2013 |
| 3 | Article 29 Working Party publishes explanatory document on ... The Article 29 Working Party has published an explanatory document on processor binding corporate rules (WP204). | Legal Update: archive | 02-May-2013 |
| 4 | Article 29 Working Party publishes opinion on purpose ... The Article 29 Working Party has published its Opinion 03/2013 on purpose limitation (WP 203), which provides guidance for the principle's practical application under the Data Protection Directive (1995/46/EC) and includes recommendations with regard to the ongoing review of the EU data protection framework. | Legal Update: archive | 11-Apr-2013 |
| 5 | Article 29 Working Party publishes further comments on EU ... The Article 29 Working Party has published further comments on the draft Data Protection Regulation published by the European Commission in January 2012. | Legal Update: archive | 07-Mar-2013 |
| 6 | European Council publishes comparative table of draft Data ... The European Council has published a comparative table of the Data Protection Regulation and the Data Protection Directive. | Legal Update: archive | 14-Feb-2013 |
| 7 | European Commission publishes code of online rights The European Commission has published a code of online rights, collating rights that are to be accorded to citizens of the EU in the course of their use of electronic services and networks. | Legal Update: archive | 27-Dec-2012 |
| 8 | Article 29 Data Protection Working Party publishes further ... The Article 29 Data Protection Working Party has adopted an opinion providing further guidance on the European Commission's proposals for a revised data protection legislative framework. (Free access.) | Legal Update: archive | 11-Oct-2012 |
| 9 | Article 29 Working Party opinion on cloud computing The Article 29 Data Protection Working Party has adopted an opinion setting out the data protection risks and concerns associated with cloud computing and making a series of recommendations on how to mitigate them. | Legal Update: archive | 05-Jul-2012 |
| 10 | Article 29 Working Party adopts guidance on binding ... The EU's Article 29 Working Party has adopted a new working document providing guidance on binding corporate rules for data processors. | Legal Update: archive | 21-Jun-2012 |
| 11 | Article 29 Data Protection Working Party opinion on data ... The Article 29 Data Protection Working Party has adopted an opinion on the European Commission's proposals for a revised data protection legislative framework. | Legal Update: archive | 02-Apr-2012 |
| 12 | French data protection authority sends privacy questions to ... The French data protection authority CNIL has sent a list of 69 questions to Google Inc on various aspects of its data protection procedures. | Legal Update: archive | 21-Mar-2012 |
| 13 | Seventh Circuit Limits Availability of Statutory Damages under ... On March 6, 2012, the US Court of Appeals for the Seventh Circuit issued an opinion on an interlocutory appeal in Sterk v. Redbox finding that Redbox cannot be found liable for statutory damages under the Video Privacy Protection Act for failing to destroy personal information because no injury actually occurred. | Legal Update: archive | 08-Mar-2012 |
| 14 | French data protection authority criticises new Google privacy ... The French data protection authority, CNIL, has written to Google, saying that Google's new privacy policy does not meet the requirements of the Data Protection Directive (95/46/EC). | Legal Update: archive | 28-Feb-2012 |
| 15 | SEC and CFTC Propose Joint Red Flag Rules and Guidelines ... On February 28, 2012, the SEC and CFTC issued a joint red flag rule and guideline proposal to protect investors from identity theft by requiring mutual funds, broker-dealers and other SEC-regulated entities to develop and implement programs that identify and detect identity theft red flags and outline appropriate responses. The proposed rules implement portions of the Dodd-Frank Act. | Legal Update: archive | 28-Feb-2012 |
| 16 | European Commission proposes new data protection ... The European Commission has published its proposal for a new EU data protection framework. (Free access.) | Legal Update: archive | 26-Jan-2012 |
|
| 1 | Standard contractual clauses for the transfer of personal data ... A drafting note providing guidance on the standard contractual clauses adopted by the European Commission for the transfer of personal data from data controllers in the EU to data processors in jurisdictions outside the European Economic Area (EEA) (Decision 2010/87/EU). The standard contractual clauses are one of several mechanisms approved by the European Commission to ensure adequate safeguards for personal data transferred from the EU to countries which the European Commission has not found to offer adequate protection for personal data. This drafting note is an unofficial document which has been prepared by PLC IPIT & Communications without input from the European Commission, the UK Information Commissioner or any other EU or UK data protection authority. | Drafting Notes | Maintained |
| 2 | Standard contractual clauses for the transfer of personal data ... A drafting note providing guidance on the standard contractual clauses (adopted by European Commission Decision 2004/915/EC on 27 December 2004) for the transfer of personal data from data controllers in the EU to data controllers in jurisdictions outside the European Economic Area (controller-to-controller transfers). The standard contractual clauses are one of several mechanisms approved by the European Commission to ensure adequate safeguards for personal data transferred from the EU to countries which the European Commission has not found to offer adequate protection for personal data. This drafting note is an unofficial document which has been prepared by PLC IPIT & Communications without input from the European Commission, the UK Information Commissioner or any other EU or UK data protection authority. | Drafting Notes | Maintained |