Colorado Privacy Act Signed by Governor

As part of the continued movement towards increased privacy regulation, Colorado joins California and Virginia as it becomes the third state to enact a comprehensive data privacy law.  On July 8, 2021, Colorado Governor Jared Polis signed SB21-190, the Colorado Privacy Act (“the Act”), into law. The Act will go into effect on July 1, 2023, with some specific provisions taking effect at later dates. The Act applies to companies conducting business in Colorado or that produce or deliver commercial products or services targeted to Colorado residents.  These include those that either (1) control or process the personal data pertaining to at least 100,000 consumers during a calendar year;…

READ MORE

Data Transfers from the European Union to the United Kingdom Will Continue as EU Commission Assesses Adequacy during Six Month Transition Period

The European Commission now has an additional six months to complete its adequacy assessment of the UK’s data protection laws, thanks to an agreement in principle reached by the European Union and the United Kingdom regarding the EU-UK Trade and Cooperation Agreement (“the Agreement”). As a result, companies can – at least for now – continue to move data from the EU to the UK without putting in place additional safeguards. The UK’s transition out of the EU ended December 31, 2020, and as of January 1, 2021 it is treated as a third country for purposes of the EU General Data Protection Regulation (“GDPR”). Article 45 of…

READ MORE

2020 Developments in Privacy Law Create New Obligations for Companies, Foreshadow More Changes in 2021

While Covid-19 and national and state governments’ efforts to respond to the impact of the disease took center stage in 2020 among lawmakers, the year still brought significant changes in privacy and data protection law. Companies will need to take measures to meet new obligations created by court decisions and legislation and to prepare for more changes expected in 2021. Invalidation of Privacy Shield – On July 16, the Court of Justice of the European Union (CJEU) invalidated the Privacy Shield framework, an agreement between the European Commission and U.S. Department of Commerce to facilitate the legal movement of data from the EU to the U.S. Invalidation of…

READ MORE

European Commission Publishes New Standard Contractual Clauses and Guidance on Implementation

On November 12, 2020, the European Commission published a draft implementing decision on standard contractual clauses (“SCCs”) for the transfer of personal data to third countries. It also published a draft set of new SCCs. For U.S. companies, the EU General Data Protection Regulation (“GDPR) establishes SCCs as a means by which companies may lawfully transfer data from the EU to the U.S. Companies that have in the past relied on the U.S. Privacy Shield to transfer data from the EU to the U.S. will need to pay particular attention to the new SCCs and guidance. The decision in the Schrems case (discussed previously in this blog) invalidated the Privacy…

READ MORE

101 Lawsuits Against Companies Post Schrems II Decision

In the wake of the recent decision of the European Court of Justice (CJEU) in which it struck down the Privacy Shield data transfer arrangement – commonly referred to as the Schrems case after the Austrian activist, Max Schrems, who brought the action – the practices of companies moving data from the European Union to the United States are now under scrutiny. The privacy activist group noyb, headed by Mr. Schrems, has filed complaints against 101 websites which it alleges are still sending data in the absence of the Privacy Shield and without the measures required by the EU’s General Data Protection Regulation. In bringing its legal complaints, nyob…

READ MORE