Archive:2023

1
CJEU Decides on Use of Automatically Generated Scoring Values
2
CJEU Holds German Provisions for Imposing Fines on Companies for GDPR Violations Invalid
3
Provisional Political Agreement on Landmark AI Regulation in Europe
4
UK’s top Websites Receive Cookie Warnings from the Information Commissioner
5
California Privacy Protection Agency Proposes Draft Rules for Automated Decision Making, Including Artificial Intelligence
6
Australia’s Privacy Framework set to be Revamped Following the Government’s Response to the Privacy Act Review Report
7
California Proposes Cybersecurity Requirements for Businesses
8
China Will Issue Safe Harbor Rules to Facilitate Cross-Border Data Flow
9
UK Government Approves Adequacy of UK-US Data Bridge
10
Japanese Government Identified Issues Related to AI and Copyrights

CJEU Decides on Use of Automatically Generated Scoring Values

By Dr. Thomas Nietsch

In its judgment dated 7 December 2023 (C-634/21 – Schufa) presented by the Administrative Court Wiesbaden (Germany), the court held that Article 22 of the GDPR (Art. 22 GDPR) applies also to probability values that are created by credit scoring agencies on the basis of personal data and used by third parties in order to decide whether the respective individual is eligible for a credit or establishing a contract.

Read More

CJEU Holds German Provisions for Imposing Fines on Companies for GDPR Violations Invalid

By Dr. Thomas Nietsch

In a judgment dated 5 December 2023 (Case C-807/21 – Deutsche Wohnen) presented by the Higher Regional Court Berlin (Kammergericht), the Court of Justice for the European Union (CJEU) held that a German law permitting administrative fines against corporate entities where an identified legal representative of that entity was proven to have committed a criminal or administrative offence, which at the same time led to the corporate entity breaching its obligations, is not in line with GDPR.

Read More

Provisional Political Agreement on Landmark AI Regulation in Europe

By Giovanni Campi, Petr Bartoš, and Kathleen Keating

In a landmark development, EU lawmakers reached on 8 December 2023 a provisional political agreement on the Artificial Intelligence Act (AI Act). Once adopted, this regulation will be the first of its kind, and could set a global standard for AI laws around the world.

Read More

UK’s top Websites Receive Cookie Warnings from the Information Commissioner

By Claude-Étienne Armingaud and Sophie Verstraeten

The UK’s Information Commissioner (the “ICO”) has recently sent warnings to the UK’s most visited websites to inform them that they may face enforcement action if they do not make changes to their cookie banner to ensure compliance with UK data protection law. For example, some websites warned by the ICO do not provide their user with a fair choice on tracking for personalised advertising. This position aligns with the EU’s stance, noting France (see prior Alert here).

Read More

California Privacy Protection Agency Proposes Draft Rules for Automated Decision Making, Including Artificial Intelligence

By Eric Vicente Flores and Michael Stortz

Executive Summary: The California Privacy Protection Agency has proposed a new set of draft regulations that aim to regulate the use of artificial intelligence and automated decision making technology. These regulations will be discussed alongside other draft regulations the agency has previously proposed regarding risk assessments and cybersecurity assessments. The three sets of draft regulations will be discussed at the agency’s meeting on 8 December.

Read More

Australia’s Privacy Framework set to be Revamped Following the Government’s Response to the Privacy Act Review Report

By: Cameron Abbott, Rob Pulham, Stephanie Mayhew,and Maddy Bassal

Last week the federal Government released its response (the Response) to the recommendations proposed by the AGD’s Privacy Act Review Report released in February 2023 (the Report).

Read More

California Proposes Cybersecurity Requirements for Businesses

By: Eric Vicente Flores, Avril Love, and Whitney McCollum

In recognition of Cybersecurity Awareness Month in the US, we will be bringing awareness to relevant 2023 cybersecurity updates each week.

On 28 August, the California Privacy Protection Agency (CPPA) published draft regulations regarding risk assessments and cybersecurity audits for consideration at the Board’s September meeting. The draft regulations precede the formal rulemaking process, but provide insight into CPPA’s current priorities.

Read More

China Will Issue Safe Harbor Rules to Facilitate Cross-Border Data Flow

By Amigo L. Xie and Dan Wu

On 28 September 2023, the Cyberspace Administration of China (CAC) released draft Provisions on Regulating and Facilitating Cross-Border Data Flow (in Chinese) for a public comment period ending on 15 October 2023.1

Read More

UK Government Approves Adequacy of UK-US Data Bridge

By Claude-Étienne Armingaud and Nóirín McFadden

The UK Government has laid adequacy regulations before Parliament that, once in force from 12 October 2023, will permit use of the UK – US “Data Bridge” as a safeguard for personal data transfers from the UK to the US under Article 44 UK GDPR.

Read More

Japanese Government Identified Issues Related to AI and Copyrights

By Aiko Yamada and Yuki Sako

Aiming to address creators’ concerns and to minimize risks of copyright infringement by artificial intelligence (AI) developers and users, the Agency for Cultural Affairs, Government of Japan convened panels at the Legal System Subcommittee of the Copyright Committee on 26 July 2023 and 5 September 2023 to identify issues to resolve in relation with generative AI and copyrights as roughly noted below:

Read More

Copyright © 2024, K&L Gates LLP. All Rights Reserved.