Data Protection & Privacy 2020
Total Page:16
File Type:pdf, Size:1020Kb
Data Protection & Privacy 2020 Contributing editors Aaron P Simpson and Lisa J Sotto Hunton Andrews Kurth LLP © Law Business Research 2019 Leaders in Privacy and Cybersecurity Keep the trust you’ve earned. Complying with global privacy, data protection and cybersecurity rules is challenging, especially for businesses that operate across borders. Our top-ranked privacy team, in combination with the firm’s Centre for Information Policy Leadership, advises on all aspects of US and European data protection law and cybersecurity events. We help businesses develop global compliance frameworks addressing regulatory obligations in the US, the EU and across the world. The firm is widely recognized globally as a leading privacy and data security firm. For more information, visit www.huntonprivacyblog.com. ©2019 Hunton Andrews Kurth LLP | HuntonAK.com © Law Business Research 2019 19268_GettingTheDealThrough_SponsorAd_R2.indd 2 7/9/19 9:22 AM Publisher Tom Barnes [email protected] Subscriptions Claire Bagnall Data Protection & [email protected] Senior business development managers Adam Sargent Privacy [email protected] Dan White [email protected] 2020 Published by Law Business Research Ltd 87 Lancaster Road London, W11 1QQ, UK Contributing editors Tel: +44 20 3780 4147 Aaron P Simpson and Lisa J Sotto Fax: +44 20 7229 6910 Hunton Andrews Kurth LLP The information provided in this publication is general and may not apply in a specific situation. Legal advice should always be sought before taking any legal action based on the information provided. This Lexology Getting The Deal Through is delighted to publish the eighth edition of Data Protection information is not intended to create, nor and Privacy, which is available in print and online at www.lexology.com/gtdt. does receipt of it constitute, a lawyer– Lexology Getting The Deal Through provides international expert analysis in key areas of client relationship. The publishers and law, practice and regulation for corporate counsel, cross-border legal practitioners, and company authors accept no responsibility for any directors and officers. acts or omissions contained herein. The information provided was verified between Throughout this edition, and following the unique Lexology Getting The Deal Through format, June and July 2019. Be advised that this is the same key questions are answered by leading practitioners in each of the jurisdictions featured. a developing area. Our coverage this year includes new chapters on Hungary, Iceland, Indonesia and Malaysia. Lexology Getting The Deal Through titles are published annually in print. Please ensure you © Law Business Research Ltd 2019 are referring to the latest edition or to the online version at www.lexology.com/gtdt. No photocopying without a CLA licence. Every effort has been made to cover all matters of concern to readers. However, specific First published 2012 legal advice should always be sought from experienced local advisers. Eighth edition Lexology Getting The Deal Through gratefully acknowledges the efforts of all the contribu- ISBN 978-1-83862-146-9 tors to this volume, who were chosen for their recognised expertise. We also extend special thanks to the contributing editors, Aaron P Simpson and Lisa J Sotto of Hunton Andrews Kurth Printed and distributed by LLP, for their continued assistance with this volume. Encompass Print Solutions Tel: 0844 2480 112 London July 2019 Reproduced with permission from Law Business Research Ltd This article was first published in August 2019 For further information please contact [email protected] www.lexology.com/gtdt 1 © Law Business Research 2019 Contents Introduction 5 Greece 90 Aaron P Simpson and Lisa J Sotto Vasiliki Christou Hunton Andrews Kurth LLP Vasiliki Christou EU overview 9 Hungary 97 Aaron P Simpson, Claire François and James Henderson Endre Várady and Eszter Kata Tamás Hunton Andrews Kurth LLP VJT & Partners Law Firm The Privacy Shield 12 Iceland 104 Aaron P Simpson and Maeve Olney Áslaug Björgvinsdóttir and Steinlaug Högnadóttir Hunton Andrews Kurth LLP LOGOS legal services Australia 16 India 112 Alex Hutchens, Jeremy Perier and Meena Muthuraman Stephen Mathias and Naqeeb Ahmed Kazia McCullough Robertson Kochhar & Co Austria 24 Indonesia 119 Rainer Knyrim Abadi Abi Tisnadisastra, Prihandana Suko Prasetyo Adi Knyrim Trieb Attorneys at Law and Filza Adwani AKSET Law Belgium 32 David Dumont and Laura Léonard Italy 126 Hunton Andrews Kurth LLP Rocco Panetta and Federico Sartore Panetta & Associati Brazil 43 Fabio Ferreira Kujawski, Paulo Marcos Rodrigues Brancher Japan 136 and Thiago Luís Sombra Akemi Suzuki and Tomohiro Sekiguchi Mattos Filho Nagashima Ohno & Tsunematsu Chile 50 Korea 144 Carlos Araya, Claudio Magliona and Nicolás Yuraszeck Young-Hee Jo, Seungmin Jasmine Jung and Kwangbok Kim Magliona Abogados LAB Partners China 56 Lithuania 153 Vincent Zhang and John Bolin Laimonas Marcinkevičius Jincheng Tongda & Neal Juridicon Law Firm Colombia 66 Malaysia 159 María Claudia Martínez Beltrán and Daniela Huertas Vergara Jillian Chia and Natalie Lim DLA Piper Martínez Beltrán Abogados Skrine France 73 Malta 166 Benjamin May and Farah Bencheliha Ian Gauci and Michele Tufigno Aramis Gatt Tufigno Gauci Advocates Germany 83 Mexico 174 Peter Huppertz Abraham Díaz Arceo and Gustavo A Alcocer Hoffmann Liebs Partnerschaft von Rechtsanwälten mbB OLIVARES 2 Data Protection & Privacy 2020 © Law Business Research 2019 Contents Netherlands 182 Inge de Laat and Margie Breugem Rutgers Posch Visée Endedijk NV Portugal 188 Helena Tapp Barroso and Tiago Félix da Costa Morais Leitão, Galvão Teles, Soares da Silva & Associados Russia 196 Ksenia Andreeva, Anastasia Dergacheva, Anastasia Kiseleva, Vasilisa Strizh and Brian Zimbler Morgan, Lewis & Bockius LLP Serbia 204 Bogdan Ivanišević and Milica Basta BDK Advokati Singapore 212 Lim Chong Kin Drew & Napier LLC Sweden 229 Henrik Nilsson Wesslau Söderqvist Advokatbyrå Switzerland 236 Lukas Morscher and Nadja Flühler Lenz & Staehelin Taiwan 245 Yulan Kuo, Jane Wang, Brian, Hsiang-Yang Hsieh and Ruby, Ming-Chuang Wang Formosa Transnational Attorneys at Law Turkey 252 Esin Çamlıbel, Beste Yıldızili and Naz Esen TURUNÇ United Kingdom 259 Aaron P Simpson, James Henderson and Jonathan Wright Hunton Andrews Kurth LLP United States 268 Lisa J Sotto and Aaron P Simpson Hunton Andrews Kurth LLP www.lexology.com/gtdt 3 © Law Business Research 2019 Introduction Aaron P Simpson and Lisa J Sotto Hunton Andrews Kurth LLP This introductory piece aims to highlight the main developments in the International instruments international privacy and data protection arena in the past year. The There are a number of international instruments that continue to have first introduction to this publication in 2013 noted the rapid growth of a significant influence on the development of privacy and data protec- privacy and data protection laws across the globe and reflected on the tion laws. commercial and social pressures giving rise to this global development. The main international instruments are the Convention for the Those economic and social pressures have not diminished since that Protection of Individuals with regard to the Automatic Processing of first edition, and they are increasingly triggering new initiatives from Personal Data (Convention 108) of the Council of Europe, the OECD legislators to regulate the use of personal information. Privacy Recommendations and Guidelines (OECD Guidelines), the The exponential increase of privacy and data protection rules fuels European Union General Data Protection Regulation (GDPR), the Asia- the idea that personal information has become the new ‘oil’ of today’s Pacific Economic Cooperation Privacy Framework (the Framework) data-driven economies, with laws governing its use becoming ever and the African Union Convention on Cyber Security and Personal Data more significant. Protection. The same caveat as in previous editions still holds true today: as Convention 108 has been ratified by 53 countries; in June 2018, privacy and data protection rules are constantly evolving, any publica- Cape Verde and Mexico became the fifth and sixth non-European tion on the topic is likely to be outdated shortly after it is circulated. countries – after Mauritius, Uruguay, Senegal and Tunisia – to ratify Therefore, anyone looking at a new project that involves the jurisdic- Convention 108. Morocco, Burkina Faso and Argentina have been invited tions covered in this publication should verify whether there have been to accede to Convention 108 and are expected to be the next countries new legislative or regulatory developments since the date of writing. to become parties. All parties to Convention 108 have passed domestic laws that implement the Convention’s standards. An Additional Protocol Convergence of laws to the Convention requires each party to establish an independent In previous editions of this publication, the variation in the types and authority to ensure compliance with data protection principles and sets content of privacy and data protection laws across jurisdictions has out rules on international data transfers. Convention 108 is open to been highlighted. It has also been noted that, although privacy and data signature by any country and claims to be the only instrument providing protection laws in different jurisdictions are far from identical, they often binding standards that have the potential to be applied globally. It has focus on similar principles and