article thumbnail

European Data Protection Roundup – November 2023

Debevoise Data Blog

This guidance, which draws on the GDPR as well as national and EU case law, contains relevant advice for using AI in the healthcare space more broadly. For example, the Garante notes the need to incorporate data protection by design and by default principles within any AI systems used in the healthcare space. UK and U.S.

article thumbnail

Spanish Data Protection Authority Issues Guidance on Data Spaces

Inside Privacy

If you have questions about data spaces, we are happy to assist.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Where to Begin With Data Governance Frameworks and How Software Can Help (Brandon Wiebe, GC & Head of Privacy, Transcend)

Technically Legal

Brandon’s company is a privacy platform that helps legal and compliance teams automate data compliance tasks. Brandon explains that most data privacy laws, like the General Data Protection Regulation (GDPR) in the EU and U.S.

article thumbnail

Does Your Company Have a Data Privacy Plan? Here’s Where to Start

Percipient

Brandon Wiebe , GC and Head of Privacy at Transcend offers a good overview of various privacy regulations, tips on how to start thinking about a data plan and how software can help automate certain parts of the process. Brandon explains that most data privacy laws , like the General Data Protection Regulation (GDPR) in the EU and U.S.

article thumbnail

EU Rules Restricting the International Transfers of Non-Personal Data

Inside Privacy

Note that the data localization prohibition in this Regulation applies to individual EU Member Stateslaws; it does not preclude the EU from implementing data localization requirements. X (Recent Council versions remove this obligation.)

article thumbnail

CJEU’s Advocate General Issues Opinion on GDPR Fines Against Companies

Inside Privacy

He opined that Member Stateslaw may not stipulate conditions going beyond those set out in the GDPR that make it more difficult to impute GDPR infringements to companies. Member States laws may not require this to be a pre-condition to impose a GDPR administrative fine. (2) companies).

article thumbnail

What the ADPPA Means for U.S. Data Regulation

Debevoise Data Blog

Even if not enacted, its provisions are likely to influence a future federal privacy law. And, in many ways, the ADPPA may set a new minimum standard that will shape any state laws passed to fill the void left by the lack of a federal privacy law. We’ve previously written about the development of U.S. ADPPA § 302(a).