Since enacted in August 2018, the entry into force of the Brazilian Data Protection Law (No. 13,709 – “LGPD”) has been subject to several changes. First it was supposed to be effective as of February 2020; then August 2020; and more recently 3 May 2021 (Provisional Measure No. 959/2020 dated 29 April 2020). The future of the LGPD remains uncertain, since this Provisional Measure needs to be rejected, approved or changed by the National Congress, or else it will expire on 27 August 2020.
Continue Reading Sanction Provisions in Brazil’s Data Protection Law Will Take Effect on 1 August 2021

On 1 October 2019, the Court of Justice of the European Union (CJEU) ruled on a number of questions which, inter alia, relate to the validity of consent to cookies “by way of a pre-checked checkbox” (Case C 673/17). Although the questions referred to the CJEU primarily related to provisions of the Privacy and Electronic Communications Directive (2002/58/EG), the CJEU stated that the questions  must be answered also in regard to the EU General Data Protection Regulation (GDPR).
Continue Reading Court of Justice of the EU: A “Pre-Checked Checkbox” Is Not Valid Consent to Cookies under the GDPR

According to recent press reports, the German data protection authorities have agreed on a new way to calculate administrative fines under the General Data Protection Regulation (“GDPR”). The new scoring model, which has not yet been officially published, could make fines of tens of millions of euros a reality in Germany. In contrast to their French and UK counterparts, Germany’s data protection authorities have so far been more restrictive in imposing GDPR fines.
Continue Reading German Data Protection Authorities Agree on New GDPR Fining Model

In its second statement of intent of the week, on 9 July 2019, the UK’s Information Commissioner’s Office (“ICO”) announced its intention to fine Marriott International, Inc (“Marriott”) £99.2m under the General Data Protection Regulation (“GDPR”) for a personal data breach that occurred in relation to the Starwood guest reservation database system.
Continue Reading UK ICO Intends to Fine Marriott over £99m for Personal Data Breach under the GDPR

The UK’s Information Commissioner’s Office (“ICO”) today (8 July 2019) announced its intention to fine British Airways (“BA”) £183.39m under the General Data Protection Regulation (“GDPR”) for a personal data breach. This is the highest fine issued so far by a European Union data protection supervisory authority for a personal data breach under the GDPR.
Continue Reading British Airways Fined over £183m for Personal Data Breach Under the GDPR

On 21 March 2019, Advocate General (AG) Maciej Szpunar delivered his opinion on a number of questions which, inter alia, relate to the validity of consent to cookies “by way of a pre-checked checkbox” (Case C 673/17). While the questions referred to the Court of Justice of the European Union (CJEU) primarily related to provisions of the Privacy and Electronic Communications Directive (2002/58/EG), the AG stated that the principles established in his opinion were equally valid for the EU General Data Protection Regulation (GDPR).
Continue Reading CJEU Advocate General Opinion: A “Pre-Checked Checkbox” Is Not Valid Consent to Cookies under the GDPR

On 13 February 2019, the data protection officer for the German state of Baden-Wuerttemberg published a guideline on password security under the EU General Data Protection Regulation (GDPR). The guideline aims to advise data controllers (e.g., service providers, administrators) on how to set up effective password policies and securely store passwords, and data subjects (users) on how to choose secure passwords.
Continue Reading German Data Protection Authority Publishes Guideline on GDPR Requirements for Passwords

According to recent press reports, since the EU General Data protection Regulation (GDPR) came into force in May 2018, German data protection authorities have issued 41 GDPR-related fines. The highest fine in a single case is reported to have been EUR 80,000, and the majority of fines (33) originated from the state of North-Rhine Westphalia.
Continue Reading 41 GDPR Fines Issued by German Data Protection Authorities

On 23 January 2019, the European Commission (the “EU Commission”) authorized the free flow of personal data to Japan. This “adequacy decision,” issued jointly with a mirroring decision by the Japanese government, allows personal data to transfer between the European Union (the “EU”) and Japan freely and under strong guarantees of protection. The outcome of lengthy negotiations resulting in Japan strengthening its privacy rules to follow EU standards,
Continue Reading Free Flow of Personal Data Between the European Union and Japan Starts Now

Foi publicada hoje a Medida Provisória 869/2018, emitida ontem pelo Presidente Michel Temer. A Medida Provisória cria a Autoridade Nacional de Proteção de Dados e aumenta o prazo de vacatio legis para a entrada em vigor da Lei Geral de Proteção de Dados (“LGPD”) de 18 para 24 meses após a sua publicação, ocorrida em 15 de agosto de 2018 (alteração do artigo 65 da LGPD pela Medida Provisória 869/2018).
Continue Reading Presentes de Natal tardios: uma Autoridade Nacional de Proteção de Dados e mais tempo para se adequar à LGPD