The World

Privacy Compliance

One of the fundamental principles for Personal Data Controllers is the unwavering commitment to transparency vis-à-vis data subjects. In their pursuit to address this requirement, Controllers have opted to issue lengthy Privacy Notices, aiming for comprehensive disclosure to relevant data subjects. However, the question arises: Does this approach represent the most optimal method to guarantee […]

Privacy Compliance
Introduction to gdpr

8 November, 2023

KEY TAKEAWAYS: – GDPR is the EU’s current personal data protection regulation and the global standard in the field of data protection; – Predecessors of GDPR include the OECD’s 1980 Privacy Guidelines and the 1995 Directive 95/46/EC ; – GDPR stipulates many concepts and regulations regarding data protection such as the definitions, rights and responsibilities […]

Privacy Compliance

What is the PIPL? The Personal Information Protection Law of the People’s Republic of China is a particular law enacted for the purposes of protecting the rights and interests on personal information, regulating personal information processing activities, and promoting reasonable use of personal information (Art.1). When did the PIPL take effect? The PIPL entered into force […]

Privacy Compliance

In the modern world, information of all forms, including personal data, is a valuable resource that is beginning to show its true worth. In order to protect ordinary people from personal data infringement, many countries in the world have enacted legislation stipulating the rights of the data subject. Among many such rights, there is one […]

Privacy Compliance
[GDPR] the wp29 & edpb?

8 November, 2023

The Article 29 Working Party (WP29) is the predecessor to the European Data Protection Board (EDPB), which was established under the General Data Protection Regulation (GDPR). WP29 was an advisory body composed of representatives from the national data protection authorities of all EU member states, as well as the European Data Protection Supervisor. Its primary […]

Privacy Compliance

Performing a Privacy Impact Assessment (PIA) is an essential process that organizations undertake to ensure that their operations comply with data protection regulations and that they are protecting the privacy rights of individuals. A PIA is required under the GDPR for certain types of processing activities that are likely to result in high risks to […]

Privacy Compliance

Under the General Data Protection Regulation (GDPR), Privacy by Design and Privacy by Default are two key principles that organizations are required to follow to ensure data protection and privacy. Here are the differences between Privacy by Design and Privacy by Default as defined by the GDPR: Definition: Privacy by Design: Privacy by Design, as […]

Privacy Compliance

Designating a data protection officer (DPO) is one of the statutory obligations on the controller and the processor in some particular circumstances according to the EU’s General Data Protection Regulation (GDPR). Here is an overview of GDPR regulations on DPO that enterprises and organisations can refer to, in the context that Decree No.13/2023/ND-CP does not […]

Privacy Compliance

One of the basic principles of personal data processing under the EU’s General Data Protection Regulations (“GDPR”) is the lawfulness principle. This means that the processing of personal data must have a lawful basis. The most common basis that is generally relied upon for personal data processing is the “consent” of the data subject. However, […]

Privacy Compliance

In April 2021, the European Commission proposed the first EU regulatory framework for artificial intelligence (AI). The proposed AI act is the first-ever attempt to enact a horizontal regulation for AI. Now the EU lawmakers are starting negotiations to finalize the new regulations, with substantial amendments to the Commission’s proposal including revising the definition of […]