GDPR and the Privacy Shield

As we previously discussed, the GDPR sets forth new regulations governing the cross-border transfer of personal data. For U.S. companies that might fall within the GDPR’s scope, one particular concern regarding cross border data transfers is how the GDPR affects the applicability and enforcement of the EU–U.S. Data Privacy Shield, which is the current mechanism… Continue reading GDPR and the Privacy Shield

Cross-Border Transfers under the GDPR

The GDPR generally prohibits data transfers to non-EU countries unless the data can expect an “adequate level of protection” abroad. The GDPR provides various mechanisms for permitting data transfers and establishes a clear hierarchy among those mechanisms. The first is whether there is an adequate level of protection in place. If there is no adequate… Continue reading Cross-Border Transfers under the GDPR

The GDPR and Special Category Data

The GDPR articulates certain principles governing the processing of personal data, which is broadly defined to include any information that can be used to directly or indirectly identify a particular person. Beyond these general provisions however, the GDPR, like its predecessor the Data Protection Directive, enumerates certain restrictions and requirements for the processing of certain… Continue reading The GDPR and Special Category Data

The GDPR’s Territorial Scope

The GDPR represents a complete overhaul to the EU’s current privacy framework. The GDPR is intended to have broader and more comprehensive rules regarding the processing, use, and storage of personal data than the EU’s prior Data Protection Directive 95/46/EC. More importantly, unlike the Data Protection Directive the GDPR will not require transposition into legislation… Continue reading The GDPR’s Territorial Scope

SEC Issues Interpretive Guidance on Cybersecurity Disclosures

Last week the U.S. Securities and Exchange Commission (SEC) published new cybersecurity guidance for public companies. The guidance reinforces and expands upon a 2011 SEC publication, and highlights two additional topics: (1) the importance of robust cybersecurity disclosure policies and procedures and (2) the application of insider trading prohibitions in the cybersecurity context. Disclosure Controls and… Continue reading SEC Issues Interpretive Guidance on Cybersecurity Disclosures