SlideShare uma empresa Scribd logo
1 de 24
Thank you for joining the webinar Brexit Data Protection
Update
• We will be starting a couple minutes after the hour
• This webinar will be recorded and the recording and slides sent out
later today
• Please use the GoToWebinar control panel on the right hand side
to submit any questions for the speakers
1
© 2019 TrustArc Inc Proprietary and Confidential Information
Brexit Data Protection Update:
The EU, US and UK Perspective
TrustArc Privacy Insight Series
Webinar, 3 March 2020
TrustArc
PAUL
BREITBARTH
Director
EU Policy & Strategy
TrustArc
JOSH
HARRIS
Director
International
Regulatory Affairs
TrustArc
RALPH
O’BRIEN
Principal Consultant,
EU
Speakers
TrustArc - Nymity Combined Platform Components
Outline
● Brexit: the current state of play
● What will happen next?
○ In the UK itself
○ EU – UK / UK – EU relations
○ EU – US / US – UK relations
● How to prepare for the various scenarios?
● Q&A
© 2019 TrustArc Inc Proprietary and Confidential Information6
Brexit: The Current State of Play
EU28 > EU27
● 31 January 2020 (midnight CET)
The United Kingdom has left the European
Union.
●
----
● Transition Period
----
● 31 December 2020 (midnight CET)
End of the transition period*
* Extension possible by joint EU – UK decision before 1 July 2020,
but ruled out by the European Union (Withdrawal Agreement) Act 2020.
Transition Period
Revised Political Declaration (19 October 2019) – Part I, Section I – B. Data Protection
8. In view of the importance of data flows and exchanges across the future relationship, the Parties are
committed to ensuring a high level of personal data protection to facilitate such flows between them.
9. The Union's data protection rules provide for a framework allowing the European Commission to
recognise a third country's data protection standards as providing an adequate level of protection,
thereby facilitating transfers of personal data to that third country. On the basis of this framework, the
European Commission will start the assessments with respect to the United Kingdom as soon as
possible after the United Kingdom's withdrawal, endeavouring to adopt decisions by the end of 2020,
if the applicable conditions are met. Noting that the United Kingdom will be establishing its own
international transfer regime, the United Kingdom will in the same timeframe take steps to ensure
the comparable facilitation of transfers of personal data to the Union, if the applicable conditions
are met. The future relationship will not affect the Parties' autonomy over their respective personal data
protection rules.
10. In this context, the Parties should also make arrangements for appropriate cooperation between
regulators.
© 2019 TrustArc Inc Proprietary and Confidential Information9
What Will Happen Next?
- In the UK itself
UK Data Protection Act 2018
● GOAL 1:
○ Harmonise UK privacy law with GDPR – the “APPLIED EU GDPR”
○ Search “DPA Keeling schedule for the amended GDPR”
○ Repeal/alter some UK laws to align
● GOAL 2:
○ Harmonise UK law enforcement law with EU Law Enforcement Directive
● GOAL 3:
○ EU law cannot touch national security, so sets up privacy regime for UK security
services
● GOAL 4:
○ Set up UK supervisory Body as ICO
○ Powers and criminal offences
UK Data Protection Act 2018
Passed 24th May 2018: It is the current UK law, enacts the “applied EU GDPR”
DPA
18
Part 1
Schedules
Part 7
Part 6
Part 5
Part 4
Part 3
Part 2
Preliminary
1-18
Preliminary
supplement final
provisions
ICO Enforcement
Information
Commissioner
Intelligence
Service
Processing
Law
Enforcement
Processing
General Processing
GDPR etc.
The Data Protection, Privacy and Electronic
Communications (Amendments etc) (EU Exit) Regulations
2019 S.I.419
● The EU’s GDPR has been amended into a new “UK-GDPR” (United Kingdom General Data
Protection Regulation) that took effect on January 31, 2020.
● The Data Protection Act 2018 has been amended to be read in conjunction with the new
UK-GDPR instead of the EU GDPR.
● The current ”EU GDPR” will apply to the UK in the transition period lasting from January
31, 2020 until December 31, 2020 (unless further extensions are agreed upon between the
UK and EU).
● It is likely that the UK government will move to consolidate the two amended laws (UK-
GDPR and DPA2018) into one, comprehensive piece of data protection law at a later point.
● https://www.legislation.gov.uk/uksi/2019/419/pdfs/uksiem_20190419_en.pdf
UK Data Protection Act 2018 - Criminal Offences (Personal!)
● Unlawfully obtaining, or disclosing, personal data without the consent of the data controller
● To retain personal data without the consent of the data controller
● The re-identification of de-identified personal data without consent of the data controller
● To require an individual to exercise their subject access rights to gain their personal information
in relation to their employment or for a contract for services or the provision of goods and
services
● Alteration of personal data to prevent disclosure to data subject
● Obstructing the Commissioner in inspecting personal data to discharge an international
obligation.
● Making a disclosure prohibited by the Regulation of Investigatory Powers Act 2016.
● ICO or ICO staff disclosing information obtained in the course of their role (which is not available
to the public).
● False statement made in response to an ICO information notice.
● Intentional obstruction of a warrant, or failure without reasonable excuse to assist in the
execution of a warrant.
● Not undertaking notification to the ICO when required (monetary penalty)
Brexit Impact on Data Protection
Now the UK has left the European Union:
● NOW: It stays a member of the Council of Europe;
○ It is still subject to the European Convention on Human Rights and the European
Court of Human Rights
○ It has signed Modernized Convention 108+ and is duty-bound to implement it
● NOW: ICO no longer an EU supervisory authority;
○ BCRs/Ad hoc clauses reapproved,
○ Do you need a new lead EU SA?
● NOW: It retains the “EU/UK GDPR” under the DPA 2018 – very similar laws to EU apply
● 31 Dec 2020: Review EU and UK representatives if no UK or EU establishment
● 31 Dec 2020: It may become a third party country, so no longer automatically adequate
for data transfers, will be applying for adequacy… Achievable? Time gap?
● Future: Any new ePrivacy Regulation will likely not apply in the UK,
○ current 2003 PECR applies.
● Future: It could diverge further from this however in the future…
Brexit Impact on Data Protection
© 2019 TrustArc Inc Proprietary and Confidential Information16
What Will Happen Next?
- EU – UK / UK – EU relations
Brexit Impact on EU - UK Data Flows
31 January 2020
Brexit with a Deal
Until
31 December 2020
Transition Period
Deal?
EU-UK Adequacy
Decision*
Data flows continue
unobstructed
No Deal?
UK becomes third
country
Data transfers
require transfer
mechanism
* A mutual adequacy decision is required to ensure the free flow of data from and to the UK and EU
Onward Transfers
Onward Transfers
EU-UK Mutual Adequacy Decision
● European Commission may decide that a third country ensures an adequate level of
protection (also possible for a territory, sector or international organisation) (Art. 45(1)
GDPR).
● Obligation for European Commission to monitor functioning of adequacy decisions:
○ Periodic review at least every four years (Art. 45(3) GDPR);
○ EC may repeal, amend or suspend decisions (Art. 45(5) GDPR).
● Negotiating Guidelines (adopted 25 February 2020): “The envisaged partnership should
affirm the Parties’ commitment to ensuring a high level of personal data protection, and fully
respect the Union’s personal data protection rules, including the Union’s decision-making
process as regards adequacy decisions”.
● UK Government still needs to announce criteria to assess third country adequacy.
EU-UK Mutual Adequacy Decision
The term adequate level of protection must be understood as requiring the third
country in fact to ensure, by reason of its domestic law or its international commitments, a level of
protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed
within the European Union (Schrems, §73).
During the assessment ALL relevant legislation needs to be assessed, including laws interfering
with the fundamental right to data protection. An interference is only allowed under four
guarantees:
A. Processing should be based on clear, precise and accessible rules
B. Necessity and proportionality with regard to the legitimate objectives pursued need to be
demonstrated
C. An independent oversight mechanism should exist
D. Effective remedies need to be available to the individual
Source: WP237 - Working Document 01/2016 on the
justification of interferences with the fundamental
rights to privacy and data protection through surveillance
measures when transferring
personal data (European Essential Guarantees)
© 2019 TrustArc Inc Proprietary and Confidential Information20
What Will Happen Next?
- US – UK / UK – US relations
Privacy Shield
Guidance from US Department of Commerce
● Privacy Shield will continue to apply to the UK during the transition period
without change
● From 31 December 2020:
○ a Privacy Shield organization must update its public commitment to
comply with the Privacy Shield to include the UK.
○ organizations must maintain a current Privacy Shield certification,
recertifying annually as required by the Framework.
Steps to Take Now
22
• Review your EU “lead authority”1
• Review data transfers in/out of UK and onwards2
• Review legal basis for transfers3
• Review need for EU or UK representatives4
• Review risk (regulators have stated not an
enforcement priority in short term)5
• Amend privacy notices & records of processing6
7 • Amend breach notification protocols
Q&A
Ask your questions via the GoToWebinar Control Panel
TrustArc
PAUL
BREITBARTH
Director
EU Policy & Strategy
TrustArc
JOSH
HARRIS
Director
International
Regulatory Affairs
TrustArc
RALPH
O’BRIEN
Principal Consultant,
EU
© 2019 TrustArc Inc Proprietary and Confidential Information
24
Thank You!
See http://www.trustarc.com/insightseries for the 2020
Privacy Insight Series and past webinar recordings.
If you would like to learn more about how TrustArc can
support you with compliance, please reach out to
sales@trustarc.com for a free demo.

Mais conteúdo relacionado

Mais procurados

General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR FrameworkDavid Erdos
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?David Erdos
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeDavid Erdos
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...David Erdos
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...TrustArc
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands legalandgeneral
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionDavid Erdos
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowSophos Benelux
 
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and RequirementsPrivacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and RequirementsAnitafin
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoKeithBudden3
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 

Mais procurados (20)

General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and RequirementsPrivacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
Privacy Practice Fundamentals: Understanding Compliance Regimes and Requirements
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
Evertio Schrems II
Evertio Schrems IIEvertio Schrems II
Evertio Schrems II
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
Fasten Your Belts for #GDPR
Fasten Your Belts for #GDPRFasten Your Belts for #GDPR
Fasten Your Belts for #GDPR
 

Semelhante a Brexit Data Protection Update: The EU, US and UK Perspective

The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...TrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyKate Chan
 
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR ReformsTrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR ReformsTrustArc
 
Brexit webinar-2.12.2020
Brexit webinar-2.12.2020Brexit webinar-2.12.2020
Brexit webinar-2.12.2020PwC Polska
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer UpdateTrustArc
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterTrustArc
 
Gemserv - Accounting for Brexit in the New Normal
Gemserv - Accounting for Brexit in the New NormalGemserv - Accounting for Brexit in the New Normal
Gemserv - Accounting for Brexit in the New NormalExecutive Leaders Network
 
The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand TrustArc
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborGayle Gorvett
 
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...Nick Stringer
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?EngageHub
 
mHealth Israel_Brexit Update for MedTech_Feb 2019
mHealth Israel_Brexit Update for MedTech_Feb 2019mHealth Israel_Brexit Update for MedTech_Feb 2019
mHealth Israel_Brexit Update for MedTech_Feb 2019Levi Shapiro
 
How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...Carrenza
 
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?TrustArc
 

Semelhante a Brexit Data Protection Update: The EU, US and UK Perspective (20)

The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
 
Brexit Webinar Series 3
Brexit Webinar Series 3Brexit Webinar Series 3
Brexit Webinar Series 3
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR ReformsTrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
 
Brexit webinar-2.12.2020
Brexit webinar-2.12.2020Brexit webinar-2.12.2020
Brexit webinar-2.12.2020
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer Update
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
Gemserv - Accounting for Brexit in the New Normal
Gemserv - Accounting for Brexit in the New NormalGemserv - Accounting for Brexit in the New Normal
Gemserv - Accounting for Brexit in the New Normal
 
The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand
 
FINAL REPORT
FINAL REPORTFINAL REPORT
FINAL REPORT
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe Harbor
 
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
 
CIPR - Brexit a practical guide
CIPR - Brexit a practical guideCIPR - Brexit a practical guide
CIPR - Brexit a practical guide
 
Brexit Alert
Brexit AlertBrexit Alert
Brexit Alert
 
PL&B _UK_80
PL&B _UK_80PL&B _UK_80
PL&B _UK_80
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
mHealth Israel_Brexit Update for MedTech_Feb 2019
mHealth Israel_Brexit Update for MedTech_Feb 2019mHealth Israel_Brexit Update for MedTech_Feb 2019
mHealth Israel_Brexit Update for MedTech_Feb 2019
 
How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...How will your business be affected and what you can do to stay ahead of the n...
How will your business be affected and what you can do to stay ahead of the n...
 
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
 

Mais de TrustArc

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...TrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 

Mais de TrustArc (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 

Último

Introducing Microsoft’s new Enterprise Work Management (EWM) Solution
Introducing Microsoft’s new Enterprise Work Management (EWM) SolutionIntroducing Microsoft’s new Enterprise Work Management (EWM) Solution
Introducing Microsoft’s new Enterprise Work Management (EWM) SolutionOnePlan Solutions
 
%in Harare+277-882-255-28 abortion pills for sale in Harare
%in Harare+277-882-255-28 abortion pills for sale in Harare%in Harare+277-882-255-28 abortion pills for sale in Harare
%in Harare+277-882-255-28 abortion pills for sale in Hararemasabamasaba
 
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Steffen Staab
 
Architecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastArchitecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastPapp Krisztián
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park masabamasaba
 
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...masabamasaba
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrandmasabamasaba
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...masabamasaba
 
%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in sowetomasabamasaba
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️Delhi Call girls
 
Announcing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK SoftwareAnnouncing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK SoftwareJim McKeeth
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsJhone kinadey
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsArshad QA
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2
 
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...Bert Jan Schrijver
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...masabamasaba
 
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With SimplicityWSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With SimplicityWSO2
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️Delhi Call girls
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2
 
8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech studentsHimanshiGarg82
 

Último (20)

Introducing Microsoft’s new Enterprise Work Management (EWM) Solution
Introducing Microsoft’s new Enterprise Work Management (EWM) SolutionIntroducing Microsoft’s new Enterprise Work Management (EWM) Solution
Introducing Microsoft’s new Enterprise Work Management (EWM) Solution
 
%in Harare+277-882-255-28 abortion pills for sale in Harare
%in Harare+277-882-255-28 abortion pills for sale in Harare%in Harare+277-882-255-28 abortion pills for sale in Harare
%in Harare+277-882-255-28 abortion pills for sale in Harare
 
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
 
Architecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastArchitecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the past
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
 
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
 
%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Announcing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK SoftwareAnnouncing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK Software
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview Questions
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
 
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With SimplicityWSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students
 

Brexit Data Protection Update: The EU, US and UK Perspective

  • 1. Thank you for joining the webinar Brexit Data Protection Update • We will be starting a couple minutes after the hour • This webinar will be recorded and the recording and slides sent out later today • Please use the GoToWebinar control panel on the right hand side to submit any questions for the speakers 1
  • 2. © 2019 TrustArc Inc Proprietary and Confidential Information Brexit Data Protection Update: The EU, US and UK Perspective TrustArc Privacy Insight Series Webinar, 3 March 2020
  • 3. TrustArc PAUL BREITBARTH Director EU Policy & Strategy TrustArc JOSH HARRIS Director International Regulatory Affairs TrustArc RALPH O’BRIEN Principal Consultant, EU Speakers
  • 4. TrustArc - Nymity Combined Platform Components
  • 5. Outline ● Brexit: the current state of play ● What will happen next? ○ In the UK itself ○ EU – UK / UK – EU relations ○ EU – US / US – UK relations ● How to prepare for the various scenarios? ● Q&A
  • 6. © 2019 TrustArc Inc Proprietary and Confidential Information6 Brexit: The Current State of Play
  • 7. EU28 > EU27 ● 31 January 2020 (midnight CET) The United Kingdom has left the European Union. ● ---- ● Transition Period ---- ● 31 December 2020 (midnight CET) End of the transition period* * Extension possible by joint EU – UK decision before 1 July 2020, but ruled out by the European Union (Withdrawal Agreement) Act 2020.
  • 8. Transition Period Revised Political Declaration (19 October 2019) – Part I, Section I – B. Data Protection 8. In view of the importance of data flows and exchanges across the future relationship, the Parties are committed to ensuring a high level of personal data protection to facilitate such flows between them. 9. The Union's data protection rules provide for a framework allowing the European Commission to recognise a third country's data protection standards as providing an adequate level of protection, thereby facilitating transfers of personal data to that third country. On the basis of this framework, the European Commission will start the assessments with respect to the United Kingdom as soon as possible after the United Kingdom's withdrawal, endeavouring to adopt decisions by the end of 2020, if the applicable conditions are met. Noting that the United Kingdom will be establishing its own international transfer regime, the United Kingdom will in the same timeframe take steps to ensure the comparable facilitation of transfers of personal data to the Union, if the applicable conditions are met. The future relationship will not affect the Parties' autonomy over their respective personal data protection rules. 10. In this context, the Parties should also make arrangements for appropriate cooperation between regulators.
  • 9. © 2019 TrustArc Inc Proprietary and Confidential Information9 What Will Happen Next? - In the UK itself
  • 10. UK Data Protection Act 2018 ● GOAL 1: ○ Harmonise UK privacy law with GDPR – the “APPLIED EU GDPR” ○ Search “DPA Keeling schedule for the amended GDPR” ○ Repeal/alter some UK laws to align ● GOAL 2: ○ Harmonise UK law enforcement law with EU Law Enforcement Directive ● GOAL 3: ○ EU law cannot touch national security, so sets up privacy regime for UK security services ● GOAL 4: ○ Set up UK supervisory Body as ICO ○ Powers and criminal offences
  • 11. UK Data Protection Act 2018 Passed 24th May 2018: It is the current UK law, enacts the “applied EU GDPR” DPA 18 Part 1 Schedules Part 7 Part 6 Part 5 Part 4 Part 3 Part 2 Preliminary 1-18 Preliminary supplement final provisions ICO Enforcement Information Commissioner Intelligence Service Processing Law Enforcement Processing General Processing GDPR etc.
  • 12. The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 S.I.419 ● The EU’s GDPR has been amended into a new “UK-GDPR” (United Kingdom General Data Protection Regulation) that took effect on January 31, 2020. ● The Data Protection Act 2018 has been amended to be read in conjunction with the new UK-GDPR instead of the EU GDPR. ● The current ”EU GDPR” will apply to the UK in the transition period lasting from January 31, 2020 until December 31, 2020 (unless further extensions are agreed upon between the UK and EU). ● It is likely that the UK government will move to consolidate the two amended laws (UK- GDPR and DPA2018) into one, comprehensive piece of data protection law at a later point. ● https://www.legislation.gov.uk/uksi/2019/419/pdfs/uksiem_20190419_en.pdf
  • 13. UK Data Protection Act 2018 - Criminal Offences (Personal!) ● Unlawfully obtaining, or disclosing, personal data without the consent of the data controller ● To retain personal data without the consent of the data controller ● The re-identification of de-identified personal data without consent of the data controller ● To require an individual to exercise their subject access rights to gain their personal information in relation to their employment or for a contract for services or the provision of goods and services ● Alteration of personal data to prevent disclosure to data subject ● Obstructing the Commissioner in inspecting personal data to discharge an international obligation. ● Making a disclosure prohibited by the Regulation of Investigatory Powers Act 2016. ● ICO or ICO staff disclosing information obtained in the course of their role (which is not available to the public). ● False statement made in response to an ICO information notice. ● Intentional obstruction of a warrant, or failure without reasonable excuse to assist in the execution of a warrant. ● Not undertaking notification to the ICO when required (monetary penalty)
  • 14. Brexit Impact on Data Protection Now the UK has left the European Union: ● NOW: It stays a member of the Council of Europe; ○ It is still subject to the European Convention on Human Rights and the European Court of Human Rights ○ It has signed Modernized Convention 108+ and is duty-bound to implement it ● NOW: ICO no longer an EU supervisory authority; ○ BCRs/Ad hoc clauses reapproved, ○ Do you need a new lead EU SA? ● NOW: It retains the “EU/UK GDPR” under the DPA 2018 – very similar laws to EU apply ● 31 Dec 2020: Review EU and UK representatives if no UK or EU establishment ● 31 Dec 2020: It may become a third party country, so no longer automatically adequate for data transfers, will be applying for adequacy… Achievable? Time gap? ● Future: Any new ePrivacy Regulation will likely not apply in the UK, ○ current 2003 PECR applies. ● Future: It could diverge further from this however in the future…
  • 15. Brexit Impact on Data Protection
  • 16. © 2019 TrustArc Inc Proprietary and Confidential Information16 What Will Happen Next? - EU – UK / UK – EU relations
  • 17. Brexit Impact on EU - UK Data Flows 31 January 2020 Brexit with a Deal Until 31 December 2020 Transition Period Deal? EU-UK Adequacy Decision* Data flows continue unobstructed No Deal? UK becomes third country Data transfers require transfer mechanism * A mutual adequacy decision is required to ensure the free flow of data from and to the UK and EU Onward Transfers Onward Transfers
  • 18. EU-UK Mutual Adequacy Decision ● European Commission may decide that a third country ensures an adequate level of protection (also possible for a territory, sector or international organisation) (Art. 45(1) GDPR). ● Obligation for European Commission to monitor functioning of adequacy decisions: ○ Periodic review at least every four years (Art. 45(3) GDPR); ○ EC may repeal, amend or suspend decisions (Art. 45(5) GDPR). ● Negotiating Guidelines (adopted 25 February 2020): “The envisaged partnership should affirm the Parties’ commitment to ensuring a high level of personal data protection, and fully respect the Union’s personal data protection rules, including the Union’s decision-making process as regards adequacy decisions”. ● UK Government still needs to announce criteria to assess third country adequacy.
  • 19. EU-UK Mutual Adequacy Decision The term adequate level of protection must be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union (Schrems, §73). During the assessment ALL relevant legislation needs to be assessed, including laws interfering with the fundamental right to data protection. An interference is only allowed under four guarantees: A. Processing should be based on clear, precise and accessible rules B. Necessity and proportionality with regard to the legitimate objectives pursued need to be demonstrated C. An independent oversight mechanism should exist D. Effective remedies need to be available to the individual Source: WP237 - Working Document 01/2016 on the justification of interferences with the fundamental rights to privacy and data protection through surveillance measures when transferring personal data (European Essential Guarantees)
  • 20. © 2019 TrustArc Inc Proprietary and Confidential Information20 What Will Happen Next? - US – UK / UK – US relations
  • 21. Privacy Shield Guidance from US Department of Commerce ● Privacy Shield will continue to apply to the UK during the transition period without change ● From 31 December 2020: ○ a Privacy Shield organization must update its public commitment to comply with the Privacy Shield to include the UK. ○ organizations must maintain a current Privacy Shield certification, recertifying annually as required by the Framework.
  • 22. Steps to Take Now 22 • Review your EU “lead authority”1 • Review data transfers in/out of UK and onwards2 • Review legal basis for transfers3 • Review need for EU or UK representatives4 • Review risk (regulators have stated not an enforcement priority in short term)5 • Amend privacy notices & records of processing6 7 • Amend breach notification protocols
  • 23. Q&A Ask your questions via the GoToWebinar Control Panel TrustArc PAUL BREITBARTH Director EU Policy & Strategy TrustArc JOSH HARRIS Director International Regulatory Affairs TrustArc RALPH O’BRIEN Principal Consultant, EU
  • 24. © 2019 TrustArc Inc Proprietary and Confidential Information 24 Thank You! See http://www.trustarc.com/insightseries for the 2020 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.