GDPR Decision Against Meta Highlights that Privacy Regulators Don’t Understand ‘Necessity’
The €390 million fine that the Irish Data Protection Commission (DPC) levied last week against Meta marks both the latest skirmish in the ongoing regulatory war on the use of data by private firms, as well as a major blow to the ad-driven business model that underlies most online services. More specifically, the DPC was ... GDPR Decision Against Meta Highlights that Privacy Regulators Don’t Understand ‘Necessity’
European Commission Tentatively Finds US Commitments ‘Adequate’: What It Means for Transatlantic Data Flows
Under a draft “adequacy” decision unveiled today by the European Commission, data-privacy and security commitments made by the United States in an October executive order signed by President Joe Biden were found to comport with the EU’s General Data Protection Regulation (GDPR). If adopted, the decision would provide a legal basis for flows of personal ... European Commission Tentatively Finds US Commitments ‘Adequate’: What It Means for Transatlantic Data Flows
After the FTX Crash, What’s Next for Crypto?
For many observers, the collapse of the crypto exchange FTX understandably raises questions about the future of the crypto economy, or even of public blockchains as a technology. The topic is high on the agenda of the U.S. Congress this week, with the House Financial Services Committee set for a Dec. 13 hearing with FTX ... After the FTX Crash, What’s Next for Crypto?
Biden’s Data Flows Order: Does It Comport with EU Law?
European Union officials insist that the executive order President Joe Biden signed Oct. 7 to implement a new U.S.-EU data-privacy framework must address European concerns about U.S. agencies’ surveillance practices. Awaited since March, when U.S. and EU officials reached an agreement in principle on a new framework, the order is intended to replace an earlier ... Biden’s Data Flows Order: Does It Comport with EU Law?
How Not to Use Industrial Policy to Promote Europe’s Digital Sovereignty
The concept of European “digital sovereignty” has been promoted in recent years both by high officials of the European Union and by EU national governments. Indeed, France made strengthening sovereignty one of the goals of its recent presidency in the EU Council. The approach taken thus far both by the EU and by national authorities ... How Not to Use Industrial Policy to Promote Europe’s Digital Sovereignty
Commerce Committee Fails to Correct Major Deficiencies in House Privacy Bill
Having earlier passed through subcommittee, the American Data Privacy and Protection Act (ADPPA) has now been cleared for floor consideration by the U.S. House Energy and Commerce Committee. Before the markup, we noted that the ADPPA mimics some of the worst flaws found in the European Union’s General Data Protection Regulation (GDPR), while creating new ... Commerce Committee Fails to Correct Major Deficiencies in House Privacy Bill
Privacy, Crypto, and EU Financial Surveillance
European Union lawmakers appear close to finalizing a number of legislative proposals that aim to reform the EU’s financial-regulation framework in response to the rise of cryptocurrencies. Prominent within the package are new anti-money laundering and “countering the financing of terrorism” rules (AML/CFT), including an extension of the so-called “travel rule.” The travel rule, which ... Privacy, Crypto, and EU Financial Surveillance
ADPPA Mimics GDPR’s Flaws, and Goes Further Still
Just three weeks after a draft version of the legislation was unveiled by congressional negotiators, the American Data Privacy and Protection Act (ADPPA) is heading to its first legislative markup, set for tomorrow morning before the U.S. House Energy and Commerce Committee’s Consumer Protection and Commerce Subcommittee. Though the bill’s legislative future remains uncertain, particularly ... ADPPA Mimics GDPR’s Flaws, and Goes Further Still
DMA Update: It’s Still a Privacy Danger
The European Union’s Digital Markets Act (DMA) has been finalized in principle, although some legislative details are still being negotiated. Alas, our earlier worries about user privacy still have not been addressed adequately. The key rules to examine are the DMA’s interoperability mandates. The most recent DMA text introduced a potentially very risky new kind ... DMA Update: It’s Still a Privacy Danger
EU’s Compromise AI Legislation Remains Fundamentally Flawed
European Union (EU) legislators are now considering an Artificial Intelligence Act (AIA)—the original draft of which was published by the European Commission in April 2021—that aims to ensure AI systems are safe in a number of uses designated as “high risk.” One of the big problems with the AIA is that, as originally drafted, it ... EU’s Compromise AI Legislation Remains Fundamentally Flawed
Privacy and Security Risks of Interoperability and Sideloading Mandates
There has been a wave of legislative proposals on both sides of the Atlantic that purport to improve consumer choice and the competitiveness of digital markets. In a new working paper published by the Stanford-Vienna Transatlantic Technology Law Forum, I analyzed five such bills: the EU Digital Services Act, the EU Digital Markets Act, and ... Privacy and Security Risks of Interoperability and Sideloading Mandates
The Digital Markets Act Shouldn’t Mandate Radical Interoperability
Despite calls from some NGOs to mandate radical interoperability, the EU’s draft Digital Markets Act (DMA) adopted a more measured approach, requiring full interoperability only in “ancillary” services like identification or payment systems. There remains the possibility, however, that the DMA proposal will be amended to include stronger interoperability mandates, or that such amendments will ... The Digital Markets Act Shouldn’t Mandate Radical Interoperability