Overview Status of European Union Data Protection Law Reform (Aug. 2015) Martin Braun

Similar documents
***I DRAFT REPORT. EN United in diversity EN 2012/0010(COD)

REGULATION (EU) 2016/679 General Data Protection Regulation

Cybersecurity, Privacy & Data Protection Alert

LEGAL BASIS OBJECTIVES ACHIEVEMENTS

16 March Purpose & Introduction

THE LEGAL FRAMEWORK FOR THE PROTECTION OF PERSONAL DATA IN INTERNATIONAL POLICE AND JUDICIAL COOPERATION. Matko Pajčić *

The European Union General Data Protection Regulation (GDPR) Barmak Nassirian, Federal Director Thursday, February 22, 2018

Article 1. Federal Data Protection Act (BDSG)

A Legal Overview of the Data Protection Act By: Mrs D. Madhub Data Protection Commissioner

LEGAL BASIS OBJECTIVES ACHIEVEMENTS

Privacy International's comments on the Brazil draft law on processing of personal data to protect the personality and dignity of natural persons

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Data Protection Bill, House of Lords second reading Information Commissioner s briefing

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,7November /1/13 REV1. InterinstitutionalFile: 2012/0011(COD) LIMITE

EXECUTIVE SUMMARY. 3 P a g e

ECB-PUBLIC. Recommendation for a

29 October 2015 Conference of the Independent Data Protection Authorities of the Federation and the Federal States

The EDPS has limited the comments below to the provisions of the Proposal that are particularly relevant from a data protection perspective.

ANNEX CORRIGENDUM. (Official Journal of the European Union L 119 of 4 May 2016) On page 14, recital (71), fifth and sixth sentences: for:

Proposal for a COUNCIL DECISION

Introduction to the Environmental Crime Directive 2008/99/EC

EDPS Opinion on the proposal for a recast of Brussels IIa Regulation

EU LEGISLATION (MILK AND DAIRIES) (JERSEY) ORDER 2017

COMP Article 1. Article 1 Subject matter and objectives

Presentation to IAPP November 18, EU Data Protection. Monday 18 November 13

Be transparent and keep it transparent

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE. Commission Decision C(2010)593 Standard Contractual Clauses (processors)

Opinion 3/2016. Opinion on the exchange of information on third country nationals as regards the European Criminal Records Information System (ECRIS)

PREPARING FOR NEW PRIVACY REGIMES: PRIVACY PROFESSIONALS VIEWS ON THE GENERAL DATA PROTECTION REGULATION AND PRIVACY SHIELD

Adequacy Referential (updated)

Meijers Committee standing committee of experts on international immigration, refugee and criminal law

Data Protection in the European Union: the role of National Data Protection Authorities Strengthening the fundamental rights architecture in the EU II

COMMISSION OF THE EUROPEAN COMMUNITIES. Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Introduction to the Environmental Crime Directive 2008/99/EC

Information Notice. Information Notice. Reference: ComReg 17/49

6153/1/18 REV 1 VH/np 1 DGD2

Free and Fair elections GUIDANCE DOCUMENT. Commission guidance on the application of Union data protection law in the electoral context

A Modern European Data Protection Framework Safeguarding Privacy in a Connected World

Global Anti Bribery and Corruption Compliance Program Be transparent and keep it transparent

EUROPEAN UNION. Brussels, 3 February 2006 (OR. en) 2005/0182 (COD) PE-CONS 3677/05 COPEN 200 TELECOM 151 CODEC 1206 OC 981

ARTICLE 29 Data Protection Working Party

closer look at Rights & remedies

DATA PROTECTION LAWS OF THE WORLD. Ukraine

Supreme Court of the United States

Data Protection Bill [HL]

PERSONAL DATA PROTECTION

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL

Report Annual report on administrative and criminal sanctions and other administrative measures under MAR

Comments. made by the Conference of the German Data Protection Commissioners of the Federation and of the Länder. of 11 June 2012

EN United in diversity EN A8-0328/1. Amendment. Eleonora Evi, Laura Agea, Rosa D Amato on behalf of the EFDD Group

Interinstitutional File: 2012/0011 (COD)

ARTICLE 29 Data Protection Working Party

Act No. 502 of 23 May 2018

The modernised Convention 108: novelties in a nutshell

Should Cartel Laws Be Criminalised?

Table of content What is data protection? Why was is necessary? Beginnings of Data Protection Development of International Data Protection Data Protec

Council of the European Union Brussels, 12 July 2016 (OR. en)

UNIT 1: GUILT AND LIABILITY

T he European Union s Article 29 Data Protection

Attachment 1. Commission Decision C(2010)593 Standard Contractual Clauses (processors)

Explanatory Memorandum to The Sea Fishing (Miscellaneous Amendments) Regulations 2018

Infringement Proceedings & References to the Court of Justice of the EU. Adam Weiss The AIRE Centre

17506/1/10 REV 1 ADD 1 ott/lb/ms 1 DQPG

PROVISIONAL AGREEMENT RESULTING FROM INTERINSTITUTIONAL NEGOTIATIONS

A Modern European Data Protection Framework. Bruno Gencarelli DG JUSTICE and CONSUMERS

DATA PROTECTION LAWS OF THE WORLD. Colombia vs Germany

1. The Commission proposed on 25 January 2012 a comprehensive data protection package comprising of:

Port Glasgow St Andrew s Data Protection Policy

With the current terrorist threat facing European Union Member States, including the UK

EU STANDARD CONTRACTUAL CLAUSES (PROCESSORS)

OPINION OF THE EUROPOL, EUROJUST, SCHENGEN AND CUSTOMS JOINT SUPERVISORY AUTHORITIES

Implementation of GDPR and control mechanisms of data protection institutions in Germany

Factsheet on the Right to be

We would like to inform you that we have included you on this insider list.

Mannofield Parish Church. Registered Scottish Charity No: SC (the Congregation ) Data Protection Policy

Antitrust: Commission introduces settlement procedure for cartels frequently asked questions (see also IP/08/1056)

Data Protection Policy

Exhibit MC - Standard Contractual Clauses (processors)

International Privacy Laws: Those New EU Data Protection Regulations Do Apply to You!

AmCham EU Proposed Amendments on the General Data Protection Regulation

Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Proposal to protect the euro and other currencies against counterfeiting

LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 25 October /06 Interinstitutional File: 2004/0287 (COD) LIMITE

STATUTORY INSTRUMENT 2002 NO THE ELECTRONIC COMMERCE (EC DIRECTIVE) REGULATIONS Statutory Instruments No. 2013

Official Journal of the European Union

INVESTIGATING AND PROSECUTING

SAFE HARBOR: STAYING ALIVE?

EUROPEAN PARLIAMENT Committee on the Internal Market and Consumer Protection

1.4. There have been no environmental crime cases where the courts would have had to rely on the right to be tried within a reasonable time.

The Right to Data Protection and the Commissions Adequacy Decision

COMPETITION LAW AND FUNDAMENTAL RIGHTS: SOME UNRESOLVED ISSUES. Aidan O Neill QC

ANNEXES. to the COMMISSION IMPLEMENTING REGULATION (EU).../...

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,

Legal Aid in the EU: main features of Directive 2016/1919/EU

GDPR. EU General Data Protection Regulation. ebook Version 1.2

2014 No. 379 SEA FISHERIES. The Sea Fishing (Points for Masters of Fishing Boats) (Scotland) Regulations 2014

5418/16 AV/NT/vm DGD 2

Social Media and the Protection of Privacy Jan von Hein

International cooperation on the protection of personal data: Moroccan practice

Data Protection Bill [HL]

Transcription:

Overview Status of European Union Data Protection Law Reform (Aug. 2015) Martin Braun

Overview General Background Where are we now in the process? Key changes under the new regime WilmerHale 2

General Background WilmerHale 3

Current Legal Framework Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) [updated 2009] WilmerHale 4

Background Directives need to be implemented into national law by each EU Member State Directive 1995/46/EC is unchanged since 1995 Technology has significantly evolved European law has significantly evolved WilmerHale 5

Charter of Fundamental Rights of the European Union Article 8 Protection of personal data 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority WilmerHale 6

Where are we now in the process? WilmerHale 7

European Commission Proposal (January 2012) Proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) Proposal for a Directive of the European Parliament and the Council on the protection of individuals with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data WilmerHale 8

Position of European Parliament and the Council March 12, 2014: Vote of the European Parliament; adoption of a compromise text (621 votes in favor, 10 against, 22 abstentions) June 15, 2015: Council agrees on a general approach on the general data protection regulation WilmerHale 9

Next Steps So-called trilogue between European Commission, European Parliament and Council has started in June 2015 Parties hope to reach agreement by the end of the year 2015 Final text would then be published in the Official Journal in Q1/2016 or Q2/2016 Legal effects: (expected) two years after publication in the Official Journal (2018) WilmerHale 10

Key changes under the new regime WilmerHale 11

Key Changes Text will be available in all official languages of the European Union; each language version has equal value Regulation, not directive = identical legal text for the entire European Union But: the draft Regulation contains a significant number of express permissions for EU Member States to introduce additional/specific national provisions European Commission will have the right to pass implementing acts with additional details WilmerHale 12

Key Changes Applicability of the Regulation: jurisdiction and territorial scope Enforcement, sanctions significant fines of up to the greater of 100 million or 2-5% annual worldwide turnover Role of the data protection authorities One Stop Shop principle (with exceptions) Need for accountability programs Profiling Data Breach Reporting WilmerHale 13

Key changes Impact on outsourcing agreement controller-processor agreements Cross-border transfers Fate of the Safe Harbor regime WilmerHale 14

Thank you for your attention WilmerHale 15

Dr. Martin Braun martin.braun@wilmerhale.com +49 69 27107-8019 www.wilmerhale.com/martin_braun/ de.linkedin.com/in/xmbraun/ WilmerHale Ulmenstrasse 37-39 60325 Frankfurt am Main Germany www.wilmerhale.com WilmerHale 16