Skip to content

menu

Data Protection Report logo
HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseData breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

Data transfer

Subscribe to Data transfer via RSS

Pseudonymised data could fall outside data protection law – introducing the “means reasonably likely” assessment

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on September 4, 2025

The Court of Justice of the European Union (CJEU) has delivered its judgment on case C 413/23 P European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB).  The CJEU has confirmed that pseudonymised…

Motherboard Circuit Background. Virus detected over circuit board. Worm, cyber attack, antivirus, firewall alert and danger warning concept. Futuristic PCB. 3D render

Lessons on international transfers to the US to organisations caught by the GDPR

Photo of Jurriaan JansenPhoto of Naomi SchuitemaPhoto of Marcus Evans (UK)Photo of Rosie Nance
By Jurriaan Jansen, Naomi Schuitema, Marcus Evans (UK) & Rosie Nance on September 11, 2024

The Dutch data protection authority, the Autoriteit Persoonsgegevens (AP) announced a fine of €290 million on Uber Technologies Inc. (UTI) and Uber B.V.,(UBV) (together Uber) with press releases in Dutch and English.  The fine relates to the transfer of…

Subscribe to Data Protection Report

Subscribe to this publication
Motherboard Circuit Background. Virus detected over circuit board. Worm, cyber attack, antivirus, firewall alert and danger warning concept. Futuristic PCB. 3D render

Thailand – The Regulation with respect to Cross-border Transfer of Personal Data

Photo of Teerin VanikietiPhoto of Thanthiti Seneewong Na AyudhayaPhoto of Patcharapol Sudsakorn
By Teerin Vanikieti, Thanthiti Seneewong Na Ayudhaya & Patcharapol Sudsakorn on January 16, 2024

On 25 December 2023, the Personal Data Protection Committee (PDPC) published two notifications detailing regulations for cross-border transfers of personal data under Sections 28 and 29 (Notifications) of the Personal Data Protection Act B.E. 2562 (2019)…

China proposes to ease cross border data transfer restrictions

Photo of Anna GamvrosPhoto of Ruby Kwok (HK)
By Anna Gamvros & Ruby Kwok (HK) on October 20, 2023

On 28 September 2023, the Cybersecurity Administration of China (CAC) released the Draft Provisions on Regulating and Promoting Cross Border Data Flow (规范和促进数据跨境流动规定) (Draft Provisions) for public consultation. The Draft Provisions, if passed, will ease the…

European Commission and ASEAN releases Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses

Photo of Marcus Evans (UK)Photo of Anna GamvrosPhoto of Wilson AngPhoto of Jeremy Lua
By Marcus Evans (UK), Anna Gamvros, Wilson Ang & Jeremy Lua on June 26, 2023

Introduction

To enable international businesses to comply with cross-border personal data transfers and the relevant laws across the European Union (EU) and South-East Asia, on 24 May 2023 the European Commission and the Association of Southeast Asian Nations…

Practical steps for businesses to comply with Bill C-27: part 2

Photo of Imran Ahmad (CA)Photo of Shreya GuptaPhoto of Jeremie Wyatt (CA)
By Imran Ahmad (CA), Shreya Gupta & Jeremie Wyatt (CA) on March 7, 2023

In our previous update, we summarized key operational elements that businesses should be aware of under the proposed Consumer Privacy Protection Act (CPPA), and provided practical tips to help businesses comply with these new requirements. As currently drafted, the…

New UK guidance on Transfer Risk Assessments

Photo of Lara White (UK)Photo of Fiona Bundy-Clarke (UK)
By Lara White (UK) & Fiona Bundy-Clarke (UK) on December 8, 2022

On 17 November 2022, the Information Commissioner’s Office (ICO) published an update to its guidance on international transfers (Transfers Guidance).  This included specific guidance about transfer risk assessments or TRAs and a tool for undertaking…

First part of EU/ US Transatlantic Data Protection Framework published today

Photo of Marcus Evans (UK)Photo of Lara White (UK)Photo of Susan Ross (US)
By Marcus Evans (UK), Lara White (UK) & Susan Ross (US) on October 7, 2022

On 7 October 2022, the US White House published the Executive Order on enhancing safeguards for United States signals intelligence activities. This action is the first part of the US legal apparatus required for the EU Commission to find certain…

UK finally publishes revised standard form international data transfer agreements and conversion addendum for the use of revised EU SCCs

Photo of Lara White (UK)Photo of Marcus Evans (UK)
By Lara White (UK) & Marcus Evans (UK) on January 31, 2022

The UK government has finally published the UK’s own standard form international data transfer agreement (UK IDTA) for transferring personal data outside the UK to countries not deemed to have adequate data protection regimes. It has also published…

Where data meets IP – Derivative data in M&A transactions

Photo of Imran Ahmad (CA)Photo of Nikita StepinPhoto of Suzie Suliman (CA)
By Imran Ahmad (CA), Nikita Stepin, Suzie Suliman (CA) & Admin on January 19, 2022

With the growth of the high-tech industry worldwide, it is no surprise that more and more transactions involve the transfer of rights to access or control data and derivative data. In our previous update we discussed protecting business data in…

Post navigation

Older Posts 

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2026, Norton Rose Fulbright LLP. All rights reserved.