THE PRIVACYPERFECT BLOG

EDPB Recommendations explained to ensure compliance after Schrems II

Nov 20, 2020 9:22:39 AM / by PrivacyPerfect posted in International Data Transfer, SchremsII

16 July 2020, the Court of Justice of the European Union invalidated the EU-US Privacy Shield in the Schrems II case, making most EU-US data transfers illegal overnight. The Court has also provided clarification on some extensive hurdles for using its most obvious alternative, Standard Contractual Clauses (SCC). Organizations have to:

Read More

Brexit checklist for data protection

Nov 10, 2020 2:59:56 PM / by PrivacyPerfect

On Dec 31st, 2020, the clock strikes zero for the Brexit transition period. Unless the EU and UK can strike a deal on privacy within the limited time that is left, the UK will become a third country for the member states of the European Economic Area. This has several consequences in the area of privacy. To help you during this time of uncertainty, we have compiled a checklist with things you need to check before the deadline. 

Read More

Cookies and other trackers: French supervisor publishes amended guidelines & recommendations

Oct 8, 2020 9:29:59 AM / by PrivacyPerfect posted in Cookies

France's data protection supervisor, the Commission nationale de l'informatique et des libertés, (CNIL) announced on 1 October it’s amended guidelines on cookies and other trackers (‘trackers’) and it’s final non-binding recommendations. The CNIL amended it’s guideline after the French Council of State, the Conseil d’État, determined the ban on cookie walls in the previous version (dated 4 July 2019) was not valid. Publication of the guidelines and recommendations is highly relevant for organisations having an online presence in France, or whose websites are accessible in France.

Read More

First code of conduct approved by Dutch DPA: What is it, and why is it important?

Sep 17, 2020 4:21:48 PM / by PrivacyPerfect posted in SchremsII, CodeOfConduct

The Dutch Data Protection Authority (AP) has recently approved the “Data Pro Code”,  the first code of conduct approved by the Dutch DPA under the GDPR.  The code was drafted by industry trade association of the Dutch digital sector, NLdigital, composed of 600 members, including SMEs and tech giants, and is intended to help companies in the ICT sector to comply with the obligations laid down in the EU privacy regulation.

Read More

A month and a half after the Schrems II ruling

Sep 3, 2020 11:55:26 AM / by PrivacyPerfect posted in SchremsII

In the ground-breaking judgement of DPC v Facebook Ireland & Schrems, also known as Schrems 2.0,  the Court of Justice of the EU declared the European Commission's EU-US Privacy Shield Decision invalid, making the majority of EU-US data transfers in violation of EU Privacy law. The reason? US mass surveillance making the level of protection of personal data to the US not “adequate” to that in the EU. While the CJEU upheld the use of Standard Contractual Clauses ('SCCs'), Privacy Shields most obvious alternative, it clarified some extensive considerations that organisations and authorities should assess when they use these model clauses.

...And now

Since then, a lot has happened, but uncertainty remains. Now that the dust has settled somewhat, this blog post aims to clear up some of the uncertainties through an overview of relevant events.

Read More

Transfer of personal data to the US deemed illegal - key steps that your organisation can take after Schrems II

Aug 6, 2020 2:54:24 PM / by PrivacyPerfect posted in Privacy Shield, US, Standard Contractual Clauses

Many European organisations share data with organisations outside the EU, or rather the EEA, with data often being transferred to the US. Most of these organisations, 60% of them, relied on the Privacy Shield as a data transfer mechanism to the US. However, on July 16, 2020, the Court of Justice of the European Union invalidated the Privacy Shield, making the transfer of personal data to more than 5,500 US organisations (including the most used software tools) be in violation of the EU privacy law, the GDPR. The reason for invalidation: the law and practice of access to personal data by US intelligence services means that the protection of personal data by EU standards does not have an adequate level of protection.

Read More

Doorgifte persoonsgegevens naar VS onwettig - belangrijke stappen die uw organisatie kan nemen na Schrems II

Aug 6, 2020 2:51:55 PM / by PrivacyPerfect posted in Privacy Shield, US

Veel Europese organisaties delen gegevens met organisaties in landen buiten de EU (of eigenlijk de EER: EU en Noorwegen, Liechtenstein en IJsland). Vaak is dit naar de VS. Op 16 juli 2020 zette het Hof van Justitie van de Europese Unie een streep door het PrivacyShield, waarop 60% van de organisaties die gegevens delen buiten de EU vertrouwt voor wettige doorgifte naar de VS. Dit maakt de doorgifte van persoonsgegevens aan meer dan 5.500 Amerikaanse organisaties (waaronder de meest gebruikte softwaretools) in een klap in strijd met de Europese privacywet AVG. De reden: het recht en de praktijk omtrent toegang tot persoonsgegevens door Amerikaanse inlichtingendiensten betekent dat de bescherming van persoonsgegevens naar EU-maatstaven niet een passend beschermingsniveau geniet.

Read More

PrivacyPerfect introduceert nieuwe DSR-module voor eenvoudig afhandelen informatieverzoeken

Jul 30, 2020 12:48:36 PM / by PrivacyPerfect posted in Data Subject Requests, DSR

Verwerking ‘verzoeken van betrokkenen’ conform de AVG niet langer een zeer kostbaar en tijdrovend proces 

30 juli 2020 - De Algemene Verordening Gegevensbescherming (AVG) verleent personen rechten om controle te houden over de verwerking van hun persoonsgegevens. Via een ‘verzoek van betrokkene’ kan ieder individu gebruik maken van deze rechten. Het kan onder andere gaan om het recht op inzage, het recht op vergetelheid, het recht op rectificatie en het recht op overdraagbaarheid van gegevens. Het reageren op deze verzoeken is een kostbaar en tijdrovend proces met veel handmatige taken en een strakke deadline van een maand. Om de afhandeling van verzoeken eenvoudiger en sneller te maken, introduceert PrivacyPerfect, leverancier van privacy compliance-oplossingen, de DSR-module. 

Read More

Remote working & Data security

Jul 23, 2020 10:22:00 AM / by The Trust Bridge posted in Data Security, remote work

Given the strange situation we all find ourselves in at the moment, with so many people suddenly
working from home for the first time, organizations have little time to prepare for the consequences that may arise from increased risk of cyber attacks and data breaches. All the data they have is not where it perhaps should be or protected to the same extent as it is normally. It is likely that many employees will continue to work from home for many months, if not forever.

Read More

Overcoming the challenges of conducting a DPIA

Jul 22, 2020 1:20:58 PM / by PrivacyPerfect posted in DPIA, Data Protection Impact Assessments

Carrying out a Data Protection Impact Assessment (DPIA) is often considered a challenging task by data protection professionals due to the complexity of the process, which often involves big and detailed projects, and relies on the involvement and support of other stakeholders within an organisation. Fortunately, there are several methods that can help make the performing of DPIAs easier, simpler, and more efficient. In this blog post, our privacy experts highlight the key steps that may help make the process painless.

Read More

    Lists by Topic

    see all
    harmas_Rajztábla 1-1
    Keep informed!
    Sign up to the Weekly GDPR Digest now.