On 13 September 2018, institutions in the European Union (EU) started negotiations to reach a final agreement on the EU Cybersecurity Act (Act). When adopted, the Act will create EU cybersecurity certification schemes for ICT products (i.e., hardware and software elements of network and information systems); services (i.e., services involved in transmitting, storing, retrieving or processing information via network and information systems); and processes (i.e., Continue Reading The Clock Is Ticking: Negotiating an Enhanced EU Cybersecurity Framework

On 16 July 2018, the District Court of Gießen, Germany, ruled that a custodian’s representation rights also cover consent to data processing activities related to the person under custodianship. Under the EU General Data Protection Regulation (GDPR), the processing of personal data is, in principle, prohibited unless there is a legal basis for such processing. Pursuant to Art. 6 para. 1 lit. a) GDPR, one possible legal basis is the data subject’s consent. However, the legitimacy of a declaration of consent may be in doubt if Continue Reading German Court Issues GDPR Ruling on Data Subject’s Consent for Persons Under Custodianship

According to media reports, the first cease-and-desist letters have been issued in relation to alleged violations of the EU General Data Protection Regulation (GDPR). The cease-and-desist letters seem to concern, inter alia, data protection declarations on websites. In particular, the letters seem to address specific website tools (e.g., Google Fonts, Like buttons) and whether their use and description in the data protection declaration is compliant with the GDPR. Continue Reading German Legislature Announces Plans to Prevent Abusive GDPR Cease-And-Desist-Letters

Aktuellen Presseberichten zufolge sind erste Abmahnungen aufgrund von behaupteten Verstößen gegen die EU Datenschutzgrundverordnung (DSGVO) ergangen. Die ergangenen Abmahnungen betrafen etwa Datenschutzerklärungen auf Web-Seiten; im Konkreten die datenschutzkonforme Einbindung und Beschreibung von bestimmten Tools (bspw. Google-Fonts, Like Buttons). Continue Reading Deutsche Gesetzesinitiativen wollen rechtsmissbräuchliche DSGVO-Abmahnungen verhindern

On 29 May 2018, only five days after the GDPR became applicable, the Regional Court of Bonn issued the first ruling applying the GDPR in Europe (file no. 10 O 171/18). The dispute involved the Internet Corporation for Assigned Names and Numbers (ICANN) and the ICANN-accredited registrar EPAG Domainservices GmbH (EPAG).

Continue Reading First Decision Applying the GDPR Issued by the Regional Court of Bonn (Germany)

On 25 May 2018, the General Data Protection Regulation (GDPR) of the European Union entered into force, accompanied by some uncertainties regarding its application. For example, some legal commentators believe there are “irreconcilable” differences between blockchain technologies and some of GDPR’s core principles, raising doubts as to whether the technology can achieve widespread adoption under the new data protection regime.  Continue Reading GDPR Implications for Blockchain and Distributed Ledger Technologies

The European Union (“EU”) General Data Protection Regulation 2016 (“GDPR”) entered into effect on 25 May 2018. A brief summary of the GDPR can be found in our Legal Update.

Organisations in Hong Kong may need to comply with the GDPR if it (1) has an establishment in the EU, where personal data is processed in the context of the activities of the establishment, regardless Continue Reading Privacy Commissioner for Personal Data Issues Booklet on how Hong Kong Businesses Should Prepare for GDPR

On 1 May 2018, the “Information Security Technology – Personal Information Security Specification” (PI-Specification) by China’s National Information Security Standardization Technical Committee (NISSTC) will come into effect. The PI-Specification, inter alia, provides guidance on the collection, storage, use, transfer and disclosure of personal information. While the PI Specification is voluntary and not legally binding, it is likely that Chinese regulators will take into account breaches of the PI Specification when enforcing cybersecurity obligations.

The requirements for the collection, use, and storage of personal information are briefly outlined below. Continue Reading China Issues New Standards on Personal Information Security

Christian Wulff, a former German Federal President who resigned in February 2012, caught the attention of the public in May 2015 with his announcement that he was back together with his ex-wife Bettina Wulff. Following this, the press published a photograph of him pushing a cart at the parking lot of a supermarket next to his wife, Bettina Wulff. Mr. Wulff felt hurt in his right to privacy. He filed a lawsuit aiming to prohibit the publication of this private photo. In first and second instance Mr. Wulff was successful; the German Federal Court now overruled the previous decisions and decided that Mr. Wulff’s right to privacy were not infringed by the publication of the photo. Continue Reading The Right to Privacy of a Former Federal President

An increasing number of financial institutions and fintech companies are coming together to create consortia or shared utility service providers that will identify, design, build and provide emerging technologies like blockchain and the possibility of using decentralized, distributed ledger technology that can be accessed and used by market participants to record information. Continue Reading Challenges with the Evolution of Blockchain