SlideShare uma empresa Scribd logo
1 de 2
Baixar para ler offline
GAMABrief:
Understanding the EU’s Data Privacy Reforms
The European Union (“EU”) is in the process of strengthening its digital data privacy laws, the far-reaching effects of which will be
felt by any United States company doing business in the EU. The latest move toward implementation of the General Data
Protection Regulation (“Regulation”) occurred in late October 2013, when the European Parliament approved certain
amendments to the current draft of the legislation. If passed, these amendments will further strengthen online data privacy and
severely restrict the transfer of EU citizens’ personal data to non-EU countries.
EU’s	
  Privacy	
  Status	
  Quo
Currently, the 1995 Data Privacy Directive (“Directive”) regulates data privacy in the EU, directing each of the twenty-eight EU
member countries to create its own set of data privacy laws that comply with the Directive’s provisions. That means a company
with customers in all twenty-eight member countries must learn and comply with the unique data protection rules of twentyeight different countries.
To ease this burden, the U.S. Department of Commerce and the EU developed a Safe Harbor certification program under which
U.S. companies that can demonstrate an adequate level of privacy protection are able to transfer personal data outside the EU
without violating the Directive. To meet Safe Harbor certification standards, companies must implement privacy frameworks that
abide by seven principles on topics like notice, choice and data security. Thus, even with the ability to obtain Safe Harbor
Certification, U.S. companies operating in the EU must nonetheless pay special attention to the manner in which they handle
personal data or face sanctions by governing bodies in both the United States and EU.
The	
  Proposed	
  Overhaul
The October vote moves the EU one step closer to overhauling the inconsistent patchwork of country-specific rules and
replacing it with a single, uniform piece of legislation. The European Parliament is aiming to have the provisions of the Regulation
fully agreed upon by May of 2014 and to take effect two years after that. This may seem like a long way off, but the anticipated
changes are substantial and certain countries are already rushing to legislate their own stricter data privacy laws in the meantime.
Companies should begin preparing for the changes now. Once in force, companies whose data privacy polices have not been
updated to comply with the Regulation will be in violation of the law.
The new Regulation acknowledges the vast changes brought about by the growth of the Internet—changes concerning how
personal data is generated, stored, shared and viewed—and seeks to better protect the privacy of EU citizens. Influenced by this
goal and in light of the NSA’s secret spying activities, the European Parliament has just voted overwhelmingly in favor of every
proposed pro-privacy amendment to the latest draft of the Regulation.
A	
  few	
  of	
  the	
  key	
  changes	
  included	
  in	
  the	
  amendments	
  are	
  discussed	
  below:

•

Right	
  to	
  deleCon,	
  data	
   access	
   and	
  correcCon – Internet users have the right to have their online data deleted. Upon
request, companies—both big and small—must delete the personal data of the user and communicate the deletion
request to any third party to whom they sent the data. Moreover, companies must clearly explain to users what they do
with the user’s personal data and hand over the data upon request.

•

Informed	
  consent	
   – Users should be clearly informed about what happens with their data, and they must explicitly
agree to such use. That means companies must provide users with easy-to-understand privacy policies and only track
users if the privacy settings of the user’s browser clearly permit it.

A  GAMA  White  Paper  produced  by  Chris4na  Gagnier  &  Emily  Poole                                            ©  2013.  Gagnier  Margossian  LLP.    All  rights  reserved.  
A	
  few	
  of	
  the	
  key	
  changes	
  (cont.):

•

Right	
   to	
   informaCon	
   and	
   transparency	
   – Companies must provide users with clear and easy-to-understand
information on how their data is collected, used and stored and must inform users when or if the company transfers
personal data to public prosecution authorities or intelligence services.

•

Data	
   transfer	
  to	
  non-­‐EU	
  countries – Companies may not transfer personal data of EU citizens to the authorities of a
non-EU country unless the transfer complies with European law. This means that communication and Internet companies
may no longer hand over data to U.S. authorities unless explicitly allowed by EU law or an international treaty.

•

IdenCfying	
  data	
   – All data which can directly or indirectly identify an individual, even if it comes from a mass collection
of “Big Data,” must be protected. In this way, the Regulation is encouraging pseudonymized data that cannot be linked to
other data.

•

Heavy	
  sancCons – Companies that violate the Regulation will face tough sanctions. Violations could result in fines up to
the greater of 100 million euros ($137 million) or 5% of the company’s annual worldwide revenue.

•

Privacy	
   by	
   design – Companies should operate with a “Privacy by Design” mindset: develop and integrate privacy
procedures into every level and aspect of their operations. Further, companies should minimize their data use and
collection practices and implement the most data protection-friendly settings possible. In other words, companies should
only collect data that is necessary for the functioning of their service. Users should also be able to use services
anonymously or pseudonymously.

•

Data	
   protecCon	
  officer – Companies that regularly deal with personal data must appoint a data protection officer. The
size of the company does not determine whether such an officer is required, rather the amount and relevance of the
company’s data use and collection practices will make this determination.

•

Uniform	
  enforcement	
  of	
  the	
  rules – A European Data Protection Board will ensure the data protection law is applied
consistently throughout the EU. In this way, companies may not avoid strong data protection laws by racing to those
countries with weak law enforcement, nor will they be unwittingly subject to the more aggressive data enforcement
practices of countries like Spain or Germany.

Preparing	
  for	
  the	
  Change
While the Regulation has not yet been finalized and certain provisions will likely be amended, companies can and should begin
taking steps to prepare for the inevitable changes. First, companies should review their privacy policies to ensure they are
accurate and up to date. Some policies may need to be re-written to comply with the requirement that they be clear and easyto-understand. Second, companies should appoint a Data Protection Officer. An existing employee may be able to absorb the
role, or the company should consider hiring outside legal counsel to take on the position. Third, companies should conduct an
audit to determine their strengths and weaknesses with respect to privacy. The results of the audit will help the company
determine whether its privacy safeguards are sufficient and will reveal whether the company is collecting more data than
necessary. Finally, companies should experiment with and test their privacy controls. Any errors or oversights could result in
sanctions and/or substantial fines.
For	
  more	
  informaCon	
  or	
  guidance	
  on	
  geOng	
  your	
  business	
  ready	
  for	
  the	
  new	
  EU	
  privacy	
  regulaCons,
	
  contact	
  a	
  privacy	
  aPorney	
  at	
  Gagnier	
  Margossian	
  LLP.

Internet
Intellectual Property
Privacy
Social Media
Technology
The Good Stuff

#nerdlawyers
Los Angeles

Sacramento

T: 415.766.4591
F: 909.972.1639
E: consult@gamallp.com

gamallp.com
@gamallp

San Francisco

Mais conteúdo relacionado

Mais de Christina Gagnier

European Union General Data Protection Regulation (GDPR) Checklist
European Union General Data Protection Regulation (GDPR) ChecklistEuropean Union General Data Protection Regulation (GDPR) Checklist
European Union General Data Protection Regulation (GDPR) ChecklistChristina Gagnier
 
EU Privacy Shield Self Certification
EU Privacy Shield Self Certification EU Privacy Shield Self Certification
EU Privacy Shield Self Certification Christina Gagnier
 
The United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsThe United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsChristina Gagnier
 
Regulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarRegulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarChristina Gagnier
 
China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"Christina Gagnier
 
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaInitial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaChristina Gagnier
 
Conducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsConducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsChristina Gagnier
 
SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017Christina Gagnier
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistChristina Gagnier
 
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Christina Gagnier
 
Student Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomStudent Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomChristina Gagnier
 
Gender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsGender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsChristina Gagnier
 
ABC's of Privacy and Security
ABC's of Privacy and SecurityABC's of Privacy and Security
ABC's of Privacy and SecurityChristina Gagnier
 
Starting a Business: The Legal Details
Starting a Business: The Legal DetailsStarting a Business: The Legal Details
Starting a Business: The Legal DetailsChristina Gagnier
 
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Christina Gagnier
 
Revenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentRevenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentChristina Gagnier
 
Seth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingSeth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingChristina Gagnier
 
Student Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomStudent Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomChristina Gagnier
 
Employees, Employers & Social Media
Employees, Employers & Social MediaEmployees, Employers & Social Media
Employees, Employers & Social MediaChristina Gagnier
 
Gagnier's Portion of TechWeek Chicago Presentation
Gagnier's Portion of TechWeek Chicago PresentationGagnier's Portion of TechWeek Chicago Presentation
Gagnier's Portion of TechWeek Chicago PresentationChristina Gagnier
 

Mais de Christina Gagnier (20)

European Union General Data Protection Regulation (GDPR) Checklist
European Union General Data Protection Regulation (GDPR) ChecklistEuropean Union General Data Protection Regulation (GDPR) Checklist
European Union General Data Protection Regulation (GDPR) Checklist
 
EU Privacy Shield Self Certification
EU Privacy Shield Self Certification EU Privacy Shield Self Certification
EU Privacy Shield Self Certification
 
The United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin OfferingsThe United Kingdom Raises Red Flag on Initial Coin Offerings
The United Kingdom Raises Red Flag on Initial Coin Offerings
 
Regulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in GibraltarRegulatory Regime for Cryptocurrencies in Gibraltar
Regulatory Regime for Cryptocurrencies in Gibraltar
 
China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"China Bans Initial Coin Offerings, "Illegal Public Financing"
China Bans Initial Coin Offerings, "Illegal Public Financing"
 
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaInitial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
 
Conducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and ConsiderationsConducting an Initial Coin Offering: Costs and Considerations
Conducting an Initial Coin Offering: Costs and Considerations
 
SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017SEC Update: Virtual Organizations and the SEC - July 2017
SEC Update: Virtual Organizations and the SEC - July 2017
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation Checklist
 
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
Revenge Pornography: Legal and Policy Issues - Computers, Data & Privacy Prot...
 
Student Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the ClassroomStudent Privacy Rights: In and Out of the Classroom
Student Privacy Rights: In and Out of the Classroom
 
Gender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All StudentsGender Issues: Creating a Safe Environment for All Students
Gender Issues: Creating a Safe Environment for All Students
 
ABC's of Privacy and Security
ABC's of Privacy and SecurityABC's of Privacy and Security
ABC's of Privacy and Security
 
Starting a Business: The Legal Details
Starting a Business: The Legal DetailsStarting a Business: The Legal Details
Starting a Business: The Legal Details
 
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
Privacy Identity Innovation 2013: Ignite Talk Slides - Content. Conduct. Cont...
 
Revenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without ConsentRevenge Porn: Posting Images Without Consent
Revenge Porn: Posting Images Without Consent
 
Seth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" BullyingSeth's Law (AB 9) - Understanding "Cyber" Bullying
Seth's Law (AB 9) - Understanding "Cyber" Bullying
 
Student Privacy Rights in the Classroom
Student Privacy Rights in the ClassroomStudent Privacy Rights in the Classroom
Student Privacy Rights in the Classroom
 
Employees, Employers & Social Media
Employees, Employers & Social MediaEmployees, Employers & Social Media
Employees, Employers & Social Media
 
Gagnier's Portion of TechWeek Chicago Presentation
Gagnier's Portion of TechWeek Chicago PresentationGagnier's Portion of TechWeek Chicago Presentation
Gagnier's Portion of TechWeek Chicago Presentation
 

Último

How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service AvailableBerhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Availablepr788182
 
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGBerhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGpr788182
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizharallensay1
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Falcon Invoice Discounting
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingNauman Safdar
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Adnet Communications
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165meghakumariji156
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfwill854175
 
QSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptx
QSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptxQSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptx
QSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptxDitasDelaCruz
 
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGpr788182
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Timegargpaaro
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSpanmisemningshen123
 
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur DubaiUAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubaijaehdlyzca
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptxRoofing Contractor
 

Último (20)

How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service AvailableBerhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
 
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGBerhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdf
 
QSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptx
QSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptxQSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptx
QSM Chap 10 Service Culture in Tourism and Hospitality Industry.pptx
 
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur DubaiUAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptx
 

GAMABrief: Understanding the EU’s Data Privacy Reforms

  • 1. GAMABrief: Understanding the EU’s Data Privacy Reforms The European Union (“EU”) is in the process of strengthening its digital data privacy laws, the far-reaching effects of which will be felt by any United States company doing business in the EU. The latest move toward implementation of the General Data Protection Regulation (“Regulation”) occurred in late October 2013, when the European Parliament approved certain amendments to the current draft of the legislation. If passed, these amendments will further strengthen online data privacy and severely restrict the transfer of EU citizens’ personal data to non-EU countries. EU’s  Privacy  Status  Quo Currently, the 1995 Data Privacy Directive (“Directive”) regulates data privacy in the EU, directing each of the twenty-eight EU member countries to create its own set of data privacy laws that comply with the Directive’s provisions. That means a company with customers in all twenty-eight member countries must learn and comply with the unique data protection rules of twentyeight different countries. To ease this burden, the U.S. Department of Commerce and the EU developed a Safe Harbor certification program under which U.S. companies that can demonstrate an adequate level of privacy protection are able to transfer personal data outside the EU without violating the Directive. To meet Safe Harbor certification standards, companies must implement privacy frameworks that abide by seven principles on topics like notice, choice and data security. Thus, even with the ability to obtain Safe Harbor Certification, U.S. companies operating in the EU must nonetheless pay special attention to the manner in which they handle personal data or face sanctions by governing bodies in both the United States and EU. The  Proposed  Overhaul The October vote moves the EU one step closer to overhauling the inconsistent patchwork of country-specific rules and replacing it with a single, uniform piece of legislation. The European Parliament is aiming to have the provisions of the Regulation fully agreed upon by May of 2014 and to take effect two years after that. This may seem like a long way off, but the anticipated changes are substantial and certain countries are already rushing to legislate their own stricter data privacy laws in the meantime. Companies should begin preparing for the changes now. Once in force, companies whose data privacy polices have not been updated to comply with the Regulation will be in violation of the law. The new Regulation acknowledges the vast changes brought about by the growth of the Internet—changes concerning how personal data is generated, stored, shared and viewed—and seeks to better protect the privacy of EU citizens. Influenced by this goal and in light of the NSA’s secret spying activities, the European Parliament has just voted overwhelmingly in favor of every proposed pro-privacy amendment to the latest draft of the Regulation. A  few  of  the  key  changes  included  in  the  amendments  are  discussed  below: • Right  to  deleCon,  data   access   and  correcCon – Internet users have the right to have their online data deleted. Upon request, companies—both big and small—must delete the personal data of the user and communicate the deletion request to any third party to whom they sent the data. Moreover, companies must clearly explain to users what they do with the user’s personal data and hand over the data upon request. • Informed  consent   – Users should be clearly informed about what happens with their data, and they must explicitly agree to such use. That means companies must provide users with easy-to-understand privacy policies and only track users if the privacy settings of the user’s browser clearly permit it. A  GAMA  White  Paper  produced  by  Chris4na  Gagnier  &  Emily  Poole                                            ©  2013.  Gagnier  Margossian  LLP.    All  rights  reserved.  
  • 2. A  few  of  the  key  changes  (cont.): • Right   to   informaCon   and   transparency   – Companies must provide users with clear and easy-to-understand information on how their data is collected, used and stored and must inform users when or if the company transfers personal data to public prosecution authorities or intelligence services. • Data   transfer  to  non-­‐EU  countries – Companies may not transfer personal data of EU citizens to the authorities of a non-EU country unless the transfer complies with European law. This means that communication and Internet companies may no longer hand over data to U.S. authorities unless explicitly allowed by EU law or an international treaty. • IdenCfying  data   – All data which can directly or indirectly identify an individual, even if it comes from a mass collection of “Big Data,” must be protected. In this way, the Regulation is encouraging pseudonymized data that cannot be linked to other data. • Heavy  sancCons – Companies that violate the Regulation will face tough sanctions. Violations could result in fines up to the greater of 100 million euros ($137 million) or 5% of the company’s annual worldwide revenue. • Privacy   by   design – Companies should operate with a “Privacy by Design” mindset: develop and integrate privacy procedures into every level and aspect of their operations. Further, companies should minimize their data use and collection practices and implement the most data protection-friendly settings possible. In other words, companies should only collect data that is necessary for the functioning of their service. Users should also be able to use services anonymously or pseudonymously. • Data   protecCon  officer – Companies that regularly deal with personal data must appoint a data protection officer. The size of the company does not determine whether such an officer is required, rather the amount and relevance of the company’s data use and collection practices will make this determination. • Uniform  enforcement  of  the  rules – A European Data Protection Board will ensure the data protection law is applied consistently throughout the EU. In this way, companies may not avoid strong data protection laws by racing to those countries with weak law enforcement, nor will they be unwittingly subject to the more aggressive data enforcement practices of countries like Spain or Germany. Preparing  for  the  Change While the Regulation has not yet been finalized and certain provisions will likely be amended, companies can and should begin taking steps to prepare for the inevitable changes. First, companies should review their privacy policies to ensure they are accurate and up to date. Some policies may need to be re-written to comply with the requirement that they be clear and easyto-understand. Second, companies should appoint a Data Protection Officer. An existing employee may be able to absorb the role, or the company should consider hiring outside legal counsel to take on the position. Third, companies should conduct an audit to determine their strengths and weaknesses with respect to privacy. The results of the audit will help the company determine whether its privacy safeguards are sufficient and will reveal whether the company is collecting more data than necessary. Finally, companies should experiment with and test their privacy controls. Any errors or oversights could result in sanctions and/or substantial fines. For  more  informaCon  or  guidance  on  geOng  your  business  ready  for  the  new  EU  privacy  regulaCons,  contact  a  privacy  aPorney  at  Gagnier  Margossian  LLP. Internet Intellectual Property Privacy Social Media Technology The Good Stuff #nerdlawyers Los Angeles Sacramento T: 415.766.4591 F: 909.972.1639 E: consult@gamallp.com gamallp.com @gamallp San Francisco