• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Regulatory Enforcement

German DPA Publishes Schrems II Transfer Compliance Checklist and Suggested Modifications to SCCs

August 26, 2020 By Daniel Felz and Paul Greaves

On August 24, 2020, the data protection authority of the German state of Baden-Württemberg (the “DPA”) published guidance (the “Guidance”) on international transfers of personal data following the Schrems II judgment (which we have previously covered here). This represents the first comprehensive guidance by a European privacy supervisor indicating how it intends to enforce the […]

Filed Under: Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement, Uncategorized Tagged With: Cross-border, European Court of Justice, European Union (EU), GDPR, International Data Transfers, Max Schrems Decision, Regulatory Enforcement

EU DPAs Announce Post-Schrems Enforcement Plans

July 16, 2020 By Daniel Felz

Today, the European Court of Justice (ECJ) issued its much-anticipated decision in the Schrems II case.  As we analyze in detail in an earlier blog post, the ECJ’s decision invalidates Privacy Shield while leaving Standard Contractual Clauses (SCCs) formally intact – although relying on SCCs may become more complicated than in the past. A number […]

Filed Under: Board Governance & Cyber Risk Management, European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement Tagged With: Data Transfers, European Court of Justice, European Union (EU), GDPR, Germany, Max Schrems Decision, Privacy Shield, Regulatory Enforcement

Schrems 2.0: CJEU invalidates EU-US Privacy Shield and emphasizes exporter obligations when using Standard Contractual Clauses

July 16, 2020 By Paul Greaves and Wim Nauwelaerts

Executive Summary Today, the Court of Justice of the European Union (‘CJEU’) handed down its long-awaited judgment in the ‘Schrems 2.0’ case (Facebook Ireland and Schrems (Case C-311/18)), about the validity of two means of legitimizing transfers of personal data outside the EEA under the EU General Data Protection Regulation (‘GDPR’)[1]. In somewhat of a […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, Consumer Protection/FTC, European Privacy & Cybersecurity, National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement Tagged With: EU Data Protection, EU Regulation, European Court of Justice, European Union (EU), Federal Trade Commission (FTC), GDPR, International Data Transfers, Max Schrems Decision, Regulatory Enforcement

California AG Publishes Final CCPA Regulations, Seeks Possible July 1 Effective Date

June 4, 2020 By Daniel Felz

Since the California Consumer Privacy Act (CCPA) entered into force on January 1, 2020, many companies have been closely following the development of CCPA Regulations by the California Attorney General’s Office (AG’s Office).  The AG’s Office released an initial draft of the CCPA Regulations in October 2019, prompting over 3,000 pages of public comment (read […]

Filed Under: Board Governance & Cyber Risk Management, California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement Tagged With: California Consumer Privacy Act (CCPA), Regulatory Enforcement, US State Law

COVID-19 Is Not A Free Pass For Privacy And Security Compliance

April 21, 2020 By Privacy, Cyber & Data Strategy Team

In the wake of stay-at-home orders stemming from the COVID-19 pandemic, companies have rushed to provide work-from-home options for many, if not all, of their employees.  As exigency fades into the new normal, however, the California Attorney General and New York’s Department of Financial Services (NYDFS) – two key privacy and security regulators – have […]

Filed Under: California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement Tagged With: California Consumer Privacy Act (CCPA), Data Breach Notification, Regulatory Enforcement

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • Page 10
  • Interim pages omitted …
  • Page 16
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • The EU Digital Omnibus: A European Data Law Shake-Up May Be Coming
  • UK Cybersecurity Legislation Soon to be Introduced
  • Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables
  • HIPAA Security Rule: Still on Track for Finalization
  • UK’s National Cyber Security Centre Releases 2025 Annual Review
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.