Data Protection & Privacy 2021
Total Page:16
File Type:pdf, Size:1020Kb
Data Protection & Privacy 2021 & Privacy Data Protection Data Protection & Privacy 2021 Contributing editors Aaron P Simpson and Lisa J Sotto © Law Business Research 2020 Leaders in Privacy and Cybersecurity Keep the trust you’ve earned. Complying with global privacy, data protection and cybersecurity rules is challenging, especially for businesses that operate across borders. Our top-ranked privacy team, in combination with the firm’s Centre for Information Policy Leadership, advises on all aspects of US and European data protection law and cybersecurity events. We help businesses develop global compliance frameworks addressing regulatory obligations in the US, the EU and across the world. The firm is widely recognized globally as a leading privacy and data security firm. For more information, visit www.huntonprivacyblog.com. ©2020 Hunton Andrews Kurth LLP | HuntonAK.com © Law Business Research 2020 Publisher Tom Barnes [email protected] Subscriptions Claire Bagnall Data Protection & [email protected] Senior business development manager Adam Sargent Privacy [email protected] Published by Law Business Research Ltd Meridian House, 34-35 Farringdon Street 2021 London, EC4A 4HL, UK The information provided in this publication Contributing editors is general and may not apply in a specific situation. Legal advice should always Aaron P Simpson and Lisa J Sotto be sought before taking any legal action based on the information provided. This Hunton Andrews Kurth LLP information is not intended to create, nor does receipt of it constitute, a lawyer– client relationship. The publishers and authors accept no responsibility for any acts or omissions contained herein. The Lexology Getting The Deal Through is delighted to publish the ninth edition of Data Protection & information provided was verified between Privacy, which is available in print and online at www.lexology.com/gtdt. May and August 2020. Be advised that this Lexology Getting The Deal Through provides international expert analysis in key areas of is a developing area. law, practice and regulation for corporate counsel, cross-border legal practitioners, and company directors and officers. © Law Business Research Ltd 2020 Throughout this edition, and following the unique Lexology Getting The Deal Through format, No photocopying without a CLA licence. the same key questions are answered by leading practitioners in each of the jurisdictions featured. First published 2012 Our coverage this year includes new chapters on Canada and Romania. Ninth edition Lexology Getting The Deal Through titles are published annually in print. Please ensure you ISBN 978-1-83862-322-7 are referring to the latest edition or to the online version at www.lexology.com/gtdt. Every effort has been made to cover all matters of concern to readers. However, specific legal advice should always be sought from experienced local advisers. Printed and distributed by Lexology Getting The Deal Through gratefully acknowledges the efforts of all the contribu- Encompass Print Solutions tors to this volume, who were chosen for their recognised expertise. We also extend special Tel: 0844 2480 112 thanks to the contributing editors, Aaron P Simpson and Lisa J Sotto of Hunton Andrews Kurth LLP, for their continued assistance with this volume. London August 2020 Reproduced with permission from Law Business Research Ltd This article was first published in September 2020 For further information please contact [email protected] www.lexology.com/gtdt 1 © Law Business Research 2020 Contents Introduction 5 Germany 95 Aaron P Simpson and Lisa J Sotto Peter Huppertz Hunton Andrews Kurth LLP Hoffmann Liebs Fritsch & Partner EU overview 9 Greece 102 Aaron P Simpson, Claire François and James Henderson Vasiliki Christou Hunton Andrews Kurth LLP Vasiliki Christou, Attorney at Law The Privacy Shield 12 Hong Kong 109 Aaron P Simpson and Maeve Olney Gabriela Kennedy, Karen H F Lee and Cheng Hau Yeo Hunton Andrews Kurth LLP Mayer Brown Australia 17 Hungary 118 Alex Hutchens, Jeremy Perier and Meena Muthuraman Endre Várady and Eszter Kata Tamás McCullough Robertson VJT & Partners Law Firm Austria 25 India 126 Rainer Knyrim Stephen Mathias and Naqeeb Ahmed Kazia Knyrim Trieb Rechtsanwälte Kochhar & Co Belgium 33 Indonesia 133 David Dumont and Laura Léonard Abadi Abi Tisnadisastra, Prihandana Suko Prasetyo Adi and Hunton Andrews Kurth LLP Noor Prayoga Mokoginta AKSET Law Brazil 45 Fabio Ferreira Kujawski, Paulo Marcos Rodrigues Brancher and Italy 142 Thiago Luís Sombra Paolo Balboni, Luca Bolognini, Antonio Landi and Davide Baldini Mattos Filho Veiga Filho Marrey Jr e Quiroga Advogados ICT Legal Consulting Canada 53 Japan 150 Doug Tait and Catherine Hamilton Akemi Suzuki and Tomohiro Sekiguchi Thompson Dorfman Sweatman LLP Nagashima Ohno & Tsunematsu Chile 60 Malaysia 159 Claudio Magliona, Nicolás Yuraszeck and Carlos Araya Jillian Chia Yan Ping and Natalie Lim Magliona Abogados SKRINE China 67 Malta 166 Gabriela Kennedy, Karen H F Lee and Cheng Hau Yeo Terence Cassar, Ian Gauci and Bernice Saliba Mayer Brown GTG Advocates Colombia 76 Mexico 174 María Claudia Martínez and Daniela Huertas Vergara Abraham Diaz and Gustavo A Alcocer DLA Piper OLIVARES France 83 Netherlands 182 Benjamin May and Farah Bencheliha Inge de Laat and Margie Breugem Aramis Law Firm Rutgers Posch Visée Endedijk NV 2 Data Protection & Privacy 2021 © Law Business Research 2020 Contents New Zealand 190 Sweden 253 Derek Roth-Biester and Megan Pearce Henrik Nilsson Anderson Lloyd Lawyers Wesslau Söderqvist Advokatbyrå Portugal 197 Switzerland 261 Helena Tapp Barroso and Tiago Félix da Costa Lukas Morscher and Leo Rusterholz Morais Leitão, Galvão Teles, Soares da Silva & Associados Lenz & Staehelin Romania 206 Taiwan 271 Daniel Alexie, Cristina Crețu, Flavia Ștefura and Laura Dinu Yulan Kuo, Jane Wang, Brian Hsiang-Yang Hsieh and MPR Partners | Maravela, Popescu & Asociații Ruby Ming-Chuang Wang Formosa Transnational Attorneys at Law Russia 214 Ksenia Andreeva, Anastasia Dergacheva, Anastasia Kiseleva, Turkey 278 Vasilisa Strizh and Brian L Zimbler Esin Çamlıbel, Beste Yıldızili Ergül and Naz Esen Morgan Lewis Turunç Serbia 222 United Kingdom 286 Bogdan Ivanišević and Milica Basta Aaron P Simpson, James Henderson and Jonathan Wright BDK Advokati Hunton Andrews Kurth LLP Singapore 229 United States 296 Lim Chong Kin and Charis Seow Aaron P Simpson and Lisa J Sotto Drew & Napier LLC Hunton Andrews Kurth LLP South Korea 243 Young-Hee Jo, Seungmin Jasmine Jung and Kwangbok Kim LAB Partners www.lexology.com/gtdt 3 © Law Business Research 2020 United States Aaron P Simpson and Lisa J Sotto Hunton Andrews Kurth LLP LAW AND THE REGULATORY AUTHORITY is the FTC’s primary enforcement tool in the privacy arena. The FTC has used its authority under section 5 to bring numerous privacy enforce- Legislative framework ment actions for a wide range of alleged violations by entities whose 1 Summarise the legislative framework for the protection information practices have been deemed ‘deceptive’ or ‘unfair’. Although of personally identifiable information (PII). Does your section 5 does not give the FTC fining authority, it does enable it to bring jurisdiction have a dedicated data protection law? Is the data enforcement actions against alleged violators, and these enforcement protection law in your jurisdiction based on any international actions typically have resulted in consent decrees that prohibit the instruments on privacy or data protection? company from future misconduct and often require audits biennially for up to 20 years. Under section 5, the FTC is able to fine businesses that The United States’ legislative framework for the protection of PII histori- have violated a consent order. cally has resembled a patchwork quilt. Unlike other jurisdictions, the At the state level, attorneys general also have the ability to bring US does not have a single dedicated data protection law at the federal enforcement actions for unfair or deceptive trade practices, or to enforce level, but instead regulates privacy primarily by industry, on a sector- violations of specific state privacy laws. The California attorney general, by-sector basis. There are numerous sources of privacy law in the for example, will be empowered to enforce violations of the CCPA. Some US, including laws and regulations developed at both the federal and state privacy laws allow affected individuals to bring lawsuits to enforce state levels. These laws and regulations may be enforced by federal violations of the law and state authorities, and many provide individuals with a private right to bring lawsuits against organisations they believe are violating the Cooperation with other data protection authorities law. Starting in 2018, increased legislative activity at the state level 3 Are there legal obligations on the data protection authority to signalled a shift in focus toward more broad-based consumer privacy cooperate with other data protection authorities, or is there a legislation in the United States. California became the first state to enact mechanism to resolve different approaches? such legislation with the passage of the California Consumer Privacy Act (CCPA), a broad privacy law inspired in part by the General Data There are no regulations or structures that require the various federal Protection Regulation (GDPR) in the European Union that is aimed at and state data protection authorities to cooperate with one another. In protecting personal information