SlideShare a Scribd company logo
1 of 44
THE EUROPEAN UNION
GENERAL DATA PROTECTION REGULATION
WHAT IS IT & WHY SHOULD YOU CARE?
THE EU GDPR
WHY US COMPANIES SHOULD CARE
JAMES C. ROBERTS III, ESQ.
GLOBALCAPITAL
GLOBAL CAPITAL STRATEGIC GROUP | GLOBAL CAPITAL LAW GROUP PC
WHO IS GLOBALCAPITAL?
Disruptive Tech Counsel
globalcaplaw.com
Our clients create, finance, distribute or implement disruptive tech
A FEW PROJECTS OF OURS
1st digital licenses
for Snoopy & for
Barney.
Outside corporate
counsel
Counsel on 1st music VR project
THIS IS NOT LEGAL ADVICE
For example,
1. You and we have not agreed to an engagement
2. We don’t know your particular situation--e.g., your
facts
THE PRESENTATION IS BASED ON
GENERALIZATIONS
• As an introduction to GDPR and its impact on US
companies, these slides include generalizations that
might not (probably do not) apply to all situations.
• There is a lot of disagreement about the application
of all of GDPR in all circumstances.
• Courts will change the current understanding.
PART 1: WHAT IS THE GDPR?
WHAT IS THE GDPR?
• It is among the first regulations enforced at the EU
level
• Typically introduced at the EU level and implemented but
national laws by member states
• “Uniform” regulation of collection and use of all
“personal” data of EU citizens
(AT LEAST) THESE CORE PRINCIPLES OF GDPR
• “Data protection by design”
• EU Citizens own the data you collect, receive or use
• Companies need data “plumbing” to demonstrate that
their use of the data conforms to the regulations
US PRIVACY LAWS V. GDPR
• US privacy law is a patchwork of federal and state laws
• GDPR (largely) consolidates regulation & enforcement
• GDPR creates rights in the data and those rights are
controlled by the EU Citizens
• Requires certain legal bases for collecting, using &
sharing data, even after consent has been given
• Significant risk of substantial penalties
EXAMPLE: CONSENT
US privacy law:
• Consent can be inferred
• Once consent is received, data can be collected, used and
shared (largely) without risk
GDPR:
• EU Citizens must give informed and affirmative consent (or
there must be an alternative legitimate basis)
• EU Citizens can control data and its use
PART 2: IMPORTANT GDPR CONCEPTS
EU CITIZEN OWNERSHIP OF THE DATA
EU citizens own their data. Therefore:
• EU citizens have rights in their data that they can
exercise
• They can let you use (and create) data based on
“informed and affirmative” consent
• They can have you change the data, give you a copy,
erase it and forget them
THINK OF: THE EU CITIZEN AS DATA LICENSOR
The EU citizen:
• Owns his or her data
• Lets others use it only with affirmative consent (or other
legitimate basis)
• And “opt in” to specific uses.
As with any license, the owner may:
• Revoke consent (the license), or amend or request
removal of data.
CONTROLLER V. PROCESSOR
GDPR maintains the Controller/Processor distinction
• Controller determines the “purposes and means” of
processing data.
• Processor processes PII on behalf of the Controller.
• If the Controller is outside of the EU, it must appoint
an EU representative.
EXAMPLE: CONTROLLER V. PROCESSOR
P&G engages a market research firm
• Market research firm determines scope, goals,
means, message: includes NA, EU, ME.
• P&G approves.
• Market research firm is the controller.
• Passes the “purpose and means test.”
“LAWFUL BASIS” REQUIREMENT
• Processing must be ‘necessary’
• No “lawful basis” if you can reasonably achieve the
same purpose without the processing
OK TO COMMUNICATE RE: A CONTRACT
• Can communicate in anticipation of, and in relation
to, a contract (e.g., contacts for notice provisions or
fulfilling the contract)
• Does not permit wider use of personal data (e.g.,
newsletter, other marketing)
CONSENT: HOW DO YOU GET IT?
Consent is:
freely given, specific, informed and unambiguous
indication of the data subject's wishes by which he or
she, by statement or by a clear affirmative action,
signifies agreement to the processing of personal data
relating to him or her.
Be prepared to show your process meets these conditions
CONSENT: WHAT DOES IT MEAN?
Affirmative opt-in, i.e.
• no pre-ticked boxes or other default consent.
• Clear and specific statement of consent.
• Consent requests separate from other terms and
conditions.
• Vague or “overall” consent is not enough: specific
consent for specific things.
SAYING ADIOS TO CONSENT
User must be able to withdraw consent at any time
as easily as giving consent.
WHAT IS “PERSONAL DATA” UNDER GDPR?
“Personal Data” is (basically) any information that:
• Identifies or
• Could identify someone when combined with
other information
PART 3: COMPANIES & GDPR
GDPR “OVERALL” REQUIREMENTS
• Have a legal reason (“lawful basis”) to collect and use the
data
• Consent is a lawful basis if it is clear and affirmative
consent
• Implement internal procedures: safeguards and training
• Keep it for the minimum period necessary
• The right to be forgotten is paramount, as is permanent
erasure
GDPR “OVERALL” REQUIREMENTS (2)
• Inform all EU citizen users of their rights
• Transborder transfer, processing & use subject to
GDPR
• Comply with data breach notifications
• Larger organizations (or ones collecting a lot of data)
must have a Data Officer
• Companies might have to conduct an impact analysis
and report it
COMPANIES OBLIGATIONS
Company obligations are based on the principles of:
• Collect the minimum amount of data for specific
purposes
• Keep it and use it for the shortest time possible
• Use the data only for those legitimate purposes
• Provide it to third parties under narrow circumstances
COMPANIES OBLIGATIONS (2)
• Do not transfer it outside of the EU & EEA, except
under specific conditions
• Always know what you have, where it is, who is using
it and what the basis of consent is
• Promptly and transparently respond to the exercise of
rights of EU Citizens
• (Other requirements such as internal training)
PART 4: HOW DOES GDPR AFFECT US COMPANIES?
GDPR COVERS ALL EU CITIZENS
Covers data on EU citizens, irrespective of
location of collection/servers, etc.
• If a US company acquires EU citizen data but is
not in the EU, could be subject to GDPR
GDPR CAN APPLY TO US COMPANIES . . .
(Basically) depends on the extent of targeting
of, or involvement with, EU citizens
• Collects and/or processes EU citizens’ PII as a regular part of its
business
• E-commerce, payable in Euros and with local language
• Global surveys, especially if in a local language
• EU citizens get “hit” with cookies then GDPR applies
GDPR CAN APPLY TO SUBSIDIARIES
• US subsidiaries of EU companies are likely to be subject to
GDPR
• EU subsidiaries of US companies will definitely be subject
to GDPR
• Minority interests will likely trigger coverage
BASIC “SMELL TEST”
HOW MUCH OF YOUR BUSINESS DEPENDS ON EU CITIZENS?
• The higher the number—or the higher the percentage of your
business—the greater the risk.
• The bigger you are the greater the risk.
• The more control you have over collection, the greater the risk.
• Controlling or processing.
• Intentional or unintentional.
INCIDENTAL COLLECTION: IN THEORY, YES, BUT . . .
Global marketing, per se, that results in such info
unlikely to trigger GDPR
• Even though the law could permit the EU to chase you
BE CAREFUL: THIS IS JUST A GUESS
No one really knows how the EU data authorities will
respond.
IN OTHER WORDS:
ARE EU CITIZENS A TARGET MARKET FOR YOU?
Then building the data privacy structure implied by the
GDPR is probably a good idea.
GDPR: IT’S NOT JUST A PRIVACY POLICY
It’s more about:
• your “data plumbing” than about your privacy policy
(privacy notice)
• Your control of the data you collect and use, i.e.,
knowing what it is, the consent basis for it and where
it is.
• Your responsiveness to EU Citizens’ requests
• Your control through contract provisions of your
relationships with others in the data plumbing
PART 5: POSSIBLE RELIEF
SOME RELIEF . . . JUST DO IT.
Some companies are perfectly happy to implement
privacy policies and procedures “compliant” with
GDPR specifications.
It’s best practices. That’s good business.
SOME RELIEF . . .
• The EU/US Privacy Shield
• Model clauses/model contracts
THE EU/US PRIVACY SHIELD
The “privacy shield” permits companies to fulfill some of the
obligations under GDPR and “shield” themselves from (some)
risk. But
• [the company] “must include robust mechanisms for assuring
compliance with the Principles, recourse for individuals who are
affected by non-compliance with the Principles, and consequences
for the organization when the Principles are not followed.”
“MODEL CONTRACTS”
AKA BONDING CORPORATE RULES
Companies in a “group” or a “joint economic undertaking” can
enter into “binding corporate rules” to govern their
transatlantic data transfers under GDPR
• Good for parent/sub relationships
• Must apply with the relevant “data protection authority” at the
member state level
WHAT TO DO
• EU/US Privacy Shield and “Binding Corporate Rules” take
time and money and are a little tricky.
• Still not necessarily a bad idea. Some rigidity v. some
flexibility.
• Good for larger firms.
CONCLUSION
Keep your
users happy.
You stand out.
THANK YOU
GLOBALCAPITAL
JAMES C. ROBERTS III | jcr@globalcaplaw.com
www.globalcaplaw.com
© 2009-2018. Global Capital Law Group PC. All rights reserved.

More Related Content

What's hot

DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
Rachel Aldighieri
 
US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border Data
Mark Aldrich
 

What's hot (19)

Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
 
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
 
The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Legal update - 1 July
Legal update - 1 JulyLegal update - 1 July
Legal update - 1 July
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
 
Foipressy2
Foipressy2Foipressy2
Foipressy2
 
Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy
 
US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border Data
 
Foipressy
FoipressyFoipressy
Foipressy
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your BusinessWebinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
 
Education law conference, March 2017 - London - Understanding and discharging...
Education law conference, March 2017 - London - Understanding and discharging...Education law conference, March 2017 - London - Understanding and discharging...
Education law conference, March 2017 - London - Understanding and discharging...
 
Education law conference, March 2017 - Nottingham - Understanding & dischargi...
Education law conference, March 2017 - Nottingham - Understanding & dischargi...Education law conference, March 2017 - Nottingham - Understanding & dischargi...
Education law conference, March 2017 - Nottingham - Understanding & dischargi...
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
 

Similar to GDPR for US Companies: A Primer

How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and ExperianHow to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
PECB
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
Spain-Holiday.com
 

Similar to GDPR for US Companies: A Primer (20)

Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and ExperianHow to keep out of trouble with GDPR: The case of Facebook, Google and Experian
How to keep out of trouble with GDPR: The case of Facebook, Google and Experian
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Gdprplan.com affiliate huddle 10th may 2018
Gdprplan.com   affiliate huddle 10th may 2018Gdprplan.com   affiliate huddle 10th may 2018
Gdprplan.com affiliate huddle 10th may 2018
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To Prepare
 

More from James C. Roberts III

Blog Global Capital Social Media Policy 012510
Blog Global Capital Social Media Policy 012510Blog Global Capital Social Media Policy 012510
Blog Global Capital Social Media Policy 012510
James C. Roberts III
 
Ppt Valuation Legal Issues V2 Jcr 042909
Ppt Valuation Legal Issues V2 Jcr 042909Ppt Valuation Legal Issues V2 Jcr 042909
Ppt Valuation Legal Issues V2 Jcr 042909
James C. Roberts III
 

More from James C. Roberts III (16)

Ppt oops i just lost a billion euros part 1 3 q18
Ppt oops i just lost a billion euros part 1 3 q18Ppt oops i just lost a billion euros part 1 3 q18
Ppt oops i just lost a billion euros part 1 3 q18
 
Scaleup and startup curriculum from Global Capital
Scaleup and startup curriculum from Global CapitalScaleup and startup curriculum from Global Capital
Scaleup and startup curriculum from Global Capital
 
Virtual reality & venture capital
Virtual reality & venture capitalVirtual reality & venture capital
Virtual reality & venture capital
 
PPT Global Capital Startup Pitch Decks 2Q13.pptx
PPT Global Capital Startup Pitch Decks 2Q13.pptxPPT Global Capital Startup Pitch Decks 2Q13.pptx
PPT Global Capital Startup Pitch Decks 2Q13.pptx
 
Global Capital VC Term Sheets 1Q13
Global Capital VC Term Sheets 1Q13Global Capital VC Term Sheets 1Q13
Global Capital VC Term Sheets 1Q13
 
Global Capital 2011 Digital Trends & Licensing Implications January Febr...
Global Capital 2011 Digital Trends & Licensing Implications January  Febr...Global Capital 2011 Digital Trends & Licensing Implications January  Febr...
Global Capital 2011 Digital Trends & Licensing Implications January Febr...
 
Global Capital Roundtable VCs & the US Market SUMMARY SLIDES
Global Capital Roundtable VCs & the US Market SUMMARY SLIDESGlobal Capital Roundtable VCs & the US Market SUMMARY SLIDES
Global Capital Roundtable VCs & the US Market SUMMARY SLIDES
 
Jailbreaking OK'd by Librarian
Jailbreaking OK'd by LibrarianJailbreaking OK'd by Librarian
Jailbreaking OK'd by Librarian
 
VC Pitch Deck Principles. Part 1.
VC Pitch Deck Principles.  Part 1.VC Pitch Deck Principles.  Part 1.
VC Pitch Deck Principles. Part 1.
 
VC Pitch Deck Principles. Part 1
VC Pitch Deck Principles.  Part 1VC Pitch Deck Principles.  Part 1
VC Pitch Deck Principles. Part 1
 
Blog Global Capital Social Media Policy 012510
Blog Global Capital Social Media Policy 012510Blog Global Capital Social Media Policy 012510
Blog Global Capital Social Media Policy 012510
 
Ppt Global Capital Liceng Comm 2010 Trends 120209
Ppt Global Capital Liceng Comm 2010 Trends 120209Ppt Global Capital Liceng Comm 2010 Trends 120209
Ppt Global Capital Liceng Comm 2010 Trends 120209
 
Ppt Cal Bar Licensing Global Capital 092708
Ppt Cal Bar Licensing Global Capital 092708Ppt Cal Bar Licensing Global Capital 092708
Ppt Cal Bar Licensing Global Capital 092708
 
Ppt Valuation Legal Issues V2 Jcr 042909
Ppt Valuation Legal Issues V2 Jcr 042909Ppt Valuation Legal Issues V2 Jcr 042909
Ppt Valuation Legal Issues V2 Jcr 042909
 
Revenue Models & Legal Risks In 3 Screen Convergence Valuations
Revenue Models & Legal Risks In 3 Screen Convergence ValuationsRevenue Models & Legal Risks In 3 Screen Convergence Valuations
Revenue Models & Legal Risks In 3 Screen Convergence Valuations
 
21st Century Licensing Strategies
21st Century Licensing Strategies21st Century Licensing Strategies
21st Century Licensing Strategies
 

Recently uploaded

一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
ss
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
e9733fc35af6
 
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
trryfxkn
 
一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理
一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理
一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理
e9733fc35af6
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
e9733fc35af6
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
F La
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
yogita9398
 
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
e9733fc35af6
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
Airst S
 
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
ss
 

Recently uploaded (20)

Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 
The Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in GreeceThe Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in Greece
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptx
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
 
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
 
一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理
一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理
一比一原版(AUT毕业证书)新西兰奥克兰理工大学毕业证如何办理
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
 
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
一比一原版(UCB毕业证书)英国伯明翰大学学院毕业证如何办理
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentation
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf
 
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
 
Reason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaReason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in India
 

GDPR for US Companies: A Primer

  • 1. THE EUROPEAN UNION GENERAL DATA PROTECTION REGULATION WHAT IS IT & WHY SHOULD YOU CARE?
  • 2. THE EU GDPR WHY US COMPANIES SHOULD CARE JAMES C. ROBERTS III, ESQ. GLOBALCAPITAL GLOBAL CAPITAL STRATEGIC GROUP | GLOBAL CAPITAL LAW GROUP PC
  • 3. WHO IS GLOBALCAPITAL? Disruptive Tech Counsel globalcaplaw.com Our clients create, finance, distribute or implement disruptive tech
  • 4. A FEW PROJECTS OF OURS 1st digital licenses for Snoopy & for Barney. Outside corporate counsel Counsel on 1st music VR project
  • 5. THIS IS NOT LEGAL ADVICE For example, 1. You and we have not agreed to an engagement 2. We don’t know your particular situation--e.g., your facts
  • 6. THE PRESENTATION IS BASED ON GENERALIZATIONS • As an introduction to GDPR and its impact on US companies, these slides include generalizations that might not (probably do not) apply to all situations. • There is a lot of disagreement about the application of all of GDPR in all circumstances. • Courts will change the current understanding.
  • 7. PART 1: WHAT IS THE GDPR?
  • 8. WHAT IS THE GDPR? • It is among the first regulations enforced at the EU level • Typically introduced at the EU level and implemented but national laws by member states • “Uniform” regulation of collection and use of all “personal” data of EU citizens
  • 9. (AT LEAST) THESE CORE PRINCIPLES OF GDPR • “Data protection by design” • EU Citizens own the data you collect, receive or use • Companies need data “plumbing” to demonstrate that their use of the data conforms to the regulations
  • 10. US PRIVACY LAWS V. GDPR • US privacy law is a patchwork of federal and state laws • GDPR (largely) consolidates regulation & enforcement • GDPR creates rights in the data and those rights are controlled by the EU Citizens • Requires certain legal bases for collecting, using & sharing data, even after consent has been given • Significant risk of substantial penalties
  • 11. EXAMPLE: CONSENT US privacy law: • Consent can be inferred • Once consent is received, data can be collected, used and shared (largely) without risk GDPR: • EU Citizens must give informed and affirmative consent (or there must be an alternative legitimate basis) • EU Citizens can control data and its use
  • 12. PART 2: IMPORTANT GDPR CONCEPTS
  • 13. EU CITIZEN OWNERSHIP OF THE DATA EU citizens own their data. Therefore: • EU citizens have rights in their data that they can exercise • They can let you use (and create) data based on “informed and affirmative” consent • They can have you change the data, give you a copy, erase it and forget them
  • 14. THINK OF: THE EU CITIZEN AS DATA LICENSOR The EU citizen: • Owns his or her data • Lets others use it only with affirmative consent (or other legitimate basis) • And “opt in” to specific uses. As with any license, the owner may: • Revoke consent (the license), or amend or request removal of data.
  • 15. CONTROLLER V. PROCESSOR GDPR maintains the Controller/Processor distinction • Controller determines the “purposes and means” of processing data. • Processor processes PII on behalf of the Controller. • If the Controller is outside of the EU, it must appoint an EU representative.
  • 16. EXAMPLE: CONTROLLER V. PROCESSOR P&G engages a market research firm • Market research firm determines scope, goals, means, message: includes NA, EU, ME. • P&G approves. • Market research firm is the controller. • Passes the “purpose and means test.”
  • 17. “LAWFUL BASIS” REQUIREMENT • Processing must be ‘necessary’ • No “lawful basis” if you can reasonably achieve the same purpose without the processing
  • 18. OK TO COMMUNICATE RE: A CONTRACT • Can communicate in anticipation of, and in relation to, a contract (e.g., contacts for notice provisions or fulfilling the contract) • Does not permit wider use of personal data (e.g., newsletter, other marketing)
  • 19. CONSENT: HOW DO YOU GET IT? Consent is: freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Be prepared to show your process meets these conditions
  • 20. CONSENT: WHAT DOES IT MEAN? Affirmative opt-in, i.e. • no pre-ticked boxes or other default consent. • Clear and specific statement of consent. • Consent requests separate from other terms and conditions. • Vague or “overall” consent is not enough: specific consent for specific things.
  • 21. SAYING ADIOS TO CONSENT User must be able to withdraw consent at any time as easily as giving consent.
  • 22. WHAT IS “PERSONAL DATA” UNDER GDPR? “Personal Data” is (basically) any information that: • Identifies or • Could identify someone when combined with other information
  • 24. GDPR “OVERALL” REQUIREMENTS • Have a legal reason (“lawful basis”) to collect and use the data • Consent is a lawful basis if it is clear and affirmative consent • Implement internal procedures: safeguards and training • Keep it for the minimum period necessary • The right to be forgotten is paramount, as is permanent erasure
  • 25. GDPR “OVERALL” REQUIREMENTS (2) • Inform all EU citizen users of their rights • Transborder transfer, processing & use subject to GDPR • Comply with data breach notifications • Larger organizations (or ones collecting a lot of data) must have a Data Officer • Companies might have to conduct an impact analysis and report it
  • 26. COMPANIES OBLIGATIONS Company obligations are based on the principles of: • Collect the minimum amount of data for specific purposes • Keep it and use it for the shortest time possible • Use the data only for those legitimate purposes • Provide it to third parties under narrow circumstances
  • 27. COMPANIES OBLIGATIONS (2) • Do not transfer it outside of the EU & EEA, except under specific conditions • Always know what you have, where it is, who is using it and what the basis of consent is • Promptly and transparently respond to the exercise of rights of EU Citizens • (Other requirements such as internal training)
  • 28. PART 4: HOW DOES GDPR AFFECT US COMPANIES?
  • 29. GDPR COVERS ALL EU CITIZENS Covers data on EU citizens, irrespective of location of collection/servers, etc. • If a US company acquires EU citizen data but is not in the EU, could be subject to GDPR
  • 30. GDPR CAN APPLY TO US COMPANIES . . . (Basically) depends on the extent of targeting of, or involvement with, EU citizens • Collects and/or processes EU citizens’ PII as a regular part of its business • E-commerce, payable in Euros and with local language • Global surveys, especially if in a local language • EU citizens get “hit” with cookies then GDPR applies
  • 31. GDPR CAN APPLY TO SUBSIDIARIES • US subsidiaries of EU companies are likely to be subject to GDPR • EU subsidiaries of US companies will definitely be subject to GDPR • Minority interests will likely trigger coverage
  • 32. BASIC “SMELL TEST” HOW MUCH OF YOUR BUSINESS DEPENDS ON EU CITIZENS? • The higher the number—or the higher the percentage of your business—the greater the risk. • The bigger you are the greater the risk. • The more control you have over collection, the greater the risk. • Controlling or processing. • Intentional or unintentional.
  • 33. INCIDENTAL COLLECTION: IN THEORY, YES, BUT . . . Global marketing, per se, that results in such info unlikely to trigger GDPR • Even though the law could permit the EU to chase you
  • 34. BE CAREFUL: THIS IS JUST A GUESS No one really knows how the EU data authorities will respond.
  • 35. IN OTHER WORDS: ARE EU CITIZENS A TARGET MARKET FOR YOU? Then building the data privacy structure implied by the GDPR is probably a good idea.
  • 36. GDPR: IT’S NOT JUST A PRIVACY POLICY It’s more about: • your “data plumbing” than about your privacy policy (privacy notice) • Your control of the data you collect and use, i.e., knowing what it is, the consent basis for it and where it is. • Your responsiveness to EU Citizens’ requests • Your control through contract provisions of your relationships with others in the data plumbing
  • 38. SOME RELIEF . . . JUST DO IT. Some companies are perfectly happy to implement privacy policies and procedures “compliant” with GDPR specifications. It’s best practices. That’s good business.
  • 39. SOME RELIEF . . . • The EU/US Privacy Shield • Model clauses/model contracts
  • 40. THE EU/US PRIVACY SHIELD The “privacy shield” permits companies to fulfill some of the obligations under GDPR and “shield” themselves from (some) risk. But • [the company] “must include robust mechanisms for assuring compliance with the Principles, recourse for individuals who are affected by non-compliance with the Principles, and consequences for the organization when the Principles are not followed.”
  • 41. “MODEL CONTRACTS” AKA BONDING CORPORATE RULES Companies in a “group” or a “joint economic undertaking” can enter into “binding corporate rules” to govern their transatlantic data transfers under GDPR • Good for parent/sub relationships • Must apply with the relevant “data protection authority” at the member state level
  • 42. WHAT TO DO • EU/US Privacy Shield and “Binding Corporate Rules” take time and money and are a little tricky. • Still not necessarily a bad idea. Some rigidity v. some flexibility. • Good for larger firms.
  • 44. THANK YOU GLOBALCAPITAL JAMES C. ROBERTS III | jcr@globalcaplaw.com www.globalcaplaw.com © 2009-2018. Global Capital Law Group PC. All rights reserved.