data protection
Subscribe to data protection's Posts

Digital Health 2021 Year in Review

The continuation of the COVID-19 public health emergency (PHE) and consumer demand for digitally delivered healthcare not only necessitated the shift from in-person to virtual care, but also continued to drive interest, adoption, investment and transactions in digital health in 2021. Digital health funding in 2021 far surpassed 2020’s totals, with no signs of slowing down in 2022, and the potential permanence of some regulatory flexibilities beyond the PHE are charting a course for continued digital health growth in 2022 and beyond.

Access the report.




GDPR 6 Months After Implementation: Where are We Now?

The General Data Protection Regulation (GDPR) was the biggest story of 2018 in the field of global privacy and data protection. The GDPR became enforceable in European Union Member States on May 25, 2018, significantly expanding the territorial reach of EU data protection law and introducing numerous changes that affected the way organizations globally process the personal data of their EU customers, employees and suppliers. These important changes required action by companies and institutions around the world. In almost six months after the GDPR’s effective date, organizations are still working on compliance—and will be for years to come.

Critical provisions

The GDPR applies to organizations inside and outside the EU. Organizations “established” inside the EU, essentially meaning a business or unit located in the EU, must comply with the GDPR if they process personal data in the context of that establishment. The GDPR also applies to organizations outside the EU that offer goods or services to, or monitor the behavior of, individuals located in the EU.

The GDPR uses other terms not familiar to US businesses but which need to be understood. Both “data controllers” and “data processors” have obligations under the GDPR, and data subjects can bring actions directly against either or both of those parties. A data controller is an organization that has control over and determines how and why to process data. A data controller is often, but not always, the organization that has the direct relationship with the data subject (the individual about whom the data pertains). A data processor is an organization that processes personal data on behalf of a data controller, typically a vendor or service provider. The GDPR defines “processing” to mean any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means (e.g., collection, recording, storage, alteration, use, disclosure and structuring).

The GDPR also broadly defines “personal data” as any information directly or indirectly relating to an identified or identifiable natural person, such as a name, identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Organizations in the US are used to a narrower definition of personal data, which typically includes information that, if breached, would put an individual at risk of identity theft or fraud and require notice (e.g., Social Security numbers, driver’s license numbers, and financial account, credit and debit card numbers). (more…)




The Impact of the EU Data Protection Regulation

The EU General Data Protection Regulation 2016/679 (GDPR) was published in the Official Journal of the European Union on 4 May 2016 following the compromise agreed among the Council of the European Union and the European Parliament.

The GDPR will essentially affect any business coming into contact with European personal data.

Read the full article here to learn of the impact and next steps.




Any Port in a Storm? EU-US Data Transfers After Schrems and Safe Harbor

Last week, the Court of Justice of the European Union (CJEU) gave an important data privacy ruling, which any business transferring personal data between the EU and US should know about – particularly those that have made use of the “Safe Harbor” scheme for data transfer, which the CJEU has now ruled to be invalid.

Read the full UK Employment Alert.




STAY CONNECTED

TOPICS

ARCHIVES