Author

Patricia Pérez

Browsing

28 January 2023 is Data Protection Day (or Data Privacy Day outside of Europe), which marks the anniversary of the Council of Europe’s Convention 108. To mark Data Protection Day 2023, Baker McKenzie’s Global Data Privacy and Security Team is pleased to present this special edition update of key data protection and privacy developments and trends across the globe, as well summarising future legislative changes, predictions, and enforcement priorities to look out for during 2023.…

On December 13, the European Commission (“EC”) announced a draft decision on the adequacy of the U.S data protection regime to protect the personal data of European Union (“EU”) residents, the EU-U.S. Data Privacy Framework (“DPF”). The DPF, which was initially announced in March 2022 as a political agreement between the EU and the U.S., and then bolstered by President Biden’s Executive Order (“EO”) in October 2022, opens the door for an EU-U.S. data transfer…

In March 2022, U.S. and EU leaders reached an agreement in principle on a new accord to protect data flows entitled the Trans-Atlantic Data Privacy Framework (“EU-U.S. DPF”).  Today, the US Government has taken important steps to implement this critical data flow framework, and strengthen legal certainty for EU to US personal data transfers.   First, President Biden signed an Executive Order on “Enhancing Safeguards for United States Signals Intelligence Activities” (“EO”). The EO enhances privacy…

El Parlamento Europeo aprobó el 5 de julio el articulado final del Reglamento de Servicios Digitales (DSA) y del Reglamento de Mercados Digitales (DMA). Estas normas regulan la posición jurídica de proveedores de servicios digitales de intermediación (p. e. plataformas como marketplace, motores de búsqueda, redes sociales, servicios de hosting, etc.) y, consecuentemente, afectan también a todos los demás players (usuarios y empresas de todos los tamaños) que interactúan a través de sus servicios.…

Earlier in October, the Spanish Data Protection Agency (AEPD) and the National Data Protection Authority of Brazil (ANPD) signed a memorandum of understanding for the development of joint actions aimed at promoting the dissemination and practical application of data protection regulations. With the signing of this memorandum, the AEPD and the ANPD undertake, among other aspects: to promote technical cooperation mechanisms for the exchange of knowledge and acquired experiencesto promote the carrying out of studies…

The European Commission (“EC”) recently issued its revised standard contractual clauses for data transfers to third countries (“Ex-EU SCCs”) and a companion set of standard clauses for controllers and processors in the EU/EEA (“Intra-EU SCCs”). Both are now published in the Official Journal. The following is an introduction to the core elements of the Ex-EU SCCs and a brief overview of the Intra-EU SCCs. Legal Context The Ex-EU SCCs are a mechanism that companies can…

It has been two years since the GDPR came into force on 25 May 2018 and during that time, we have seen more guidance published at an EU level as well as from data protection authorities in Member States which has impacted how organisations approach areas of GDPR compliance. We have also seen enforcement action from data protection authorities across the EU and UK. There have also been other significant developments, over the past two…