Google is compelled to surrender information stored abroad, a federal court holds

On February 3, 2017, the Pennsylvania US District Court granted the Government’s motions to compel Google to comply with search warrants, holding that this was not an extraterritorial application of the stored Communications Act 18 U.S.C. (“SCA“). The District Court had issued two search warrants, pursuant to section 2703 of the SCA §§ 2701 et seq., […]

Irish High Court to decide whether to ask ECJ to issue preliminary ruling on Model Clauses vis-a-vis Safe Harbor decision

Starting on February 7, 2017, the Irish High Court will hear a case brought by the Irish Data Protection Authority (DPA) against Facebook Ireland Ltd and Mr Schrems over EU-US data transfers after the Snowden disclosures. After the ECJ invalidated the “Safe Harbor” decision, Facebook performed its data transfer to the US using the “Model Clauses”. Mr. Schrems […]

Data controllers have no duty to disclose data enabling an aggrieved party to bring a suit, the Advocate General opines

European Court of Justice — Case C‑13/16 On January 26, 2017, the Advocate General (AG) to the Court of Justice of the European Union (CJEU) Mr. Bobek opined that there is no legal obligation for a data controller under EU data protection law to disclose data enabling the identification of a person allegedly responsible for an administrative offence. In […]

Eleventh Circuit restricts FTC’s interpretation of unfair privacy practices

On November 10, 2016, the Eleventh U.S. Circuit Court of Appeals held that merely exposing sensitive data is not reasonably likely to harm consumers. LabMD operated as a clinical laboratory and as part of its business, receives patients’ sensitive personal information, which included their names, birthdates, addresses, and Social Security numbers. LabMD’s billing manager allegedly […]

Compliance with GDPR is a priority in data-privacy agenda of 92% of big US organizations, a PWC’s survey finds

In a recent PWC’s survey, 92% of the surveyed organizations declared that compliance with EU General Data Protection Regulation (GDPR) is a “top priority on their data-privacy and security agenda in 2017”, being either a top priority or one of the top priorities. The survey was conducted among companies with more than 500 employees. More information here. […]

FCC’s Consumer Broadband Privacy Rules (effective Jan. 2017) have already been challenged

On November 2, 2016, the Federal Communications Commission (“FCC”) published a Report and Order entitled “Protecting the Privacy of Customers of Broadband and Other Telecommunications Services” (“Order”) as a final rule in the Federal Register. The Order applies the privacy requirements of the Communications Act of 1934 as amended (“Act”) to broadband Internet access service (BIAS) […]

The US & Switzerland sign new Privacy Shield Framework to allow data transfer

On January 12, 2017, Switzerland approved the Swiss-U.S. Privacy Shield Framework. Switzerland considers the agreement as a valid legal mechanism to comply with Swiss requirements when transferring personal data from Switzerland to the United States. The Swiss-U.S. Privacy Shield Framework will replace the U.S.-Swiss Safe Harbor immediately. Switzerland will begin accepting Privacy Shield certifications starting […]

60% of the requests to be forgotten are granted in Italy

According to Italia Oggi, in 2016 60% of the received request to be forgotten from search results has been granted. The percentage concerns the request to be removed from search results after the European Court of Justice issued its famous “right-to-be-forgotten” decision in the Costeja case, C-131/12. According to the source, the percentage consider the cases where the  Garante […]

Microsoft addresses Windows 10 privacy flaws

On January 10, 2017, Terry Myerson, Window’s Executive Vice President, published a post acknowledging Window’s 10 privacy concerns and disclosing which actions have been taken  to solve the issue. Meyerson answered as follows to the several privacy flaws addressed by many, including the French Data Protection Authority (CNIL): Many of you have asked for more control […]