This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
EDPB requests review of EU-US Data Privacy Framework following US Supreme Court decision on independent agencies
The European Data Protection Board (EDPB) has formally requested the European Commission to assess the implications of the U.S. Supreme Court's Trump v. Slaughter decision on independent agency authority for the EU-U.S. Data Privacy Framework. The EDPB highlights that the effective functioning of independent supervisory authorities in a third country is a key element for assessing adequacy. This request underscores concerns about the U.S. Federal Trade Commission's ability to uphold DPF commitments following the ruling.
A US based company relies on the EU US Data Privacy Framework for transferring personal data from the EU. Following a recent US Supreme Court decision impacting the independence of US regulatory bodies, the EDPB has requested the European Commission to review the Framework's adequacy. What is the most immediate and critical action for the US company's DPO or privacy counsel?
Immediately cease all data transfers from the EU to the US until the review is complete.
Conduct a Transfer Impact Assessment (TIA) for all existing EU US data transfers and identify alternative transfer mechanisms.
Await the European Commission's decision, as the Framework remains valid until officially revoked.
Notify all data subjects in the EU about the potential instability of the data transfer mechanism.
South Korea’s Personal Information Protection Commission (PIPC) fined KT, the country's largest telco, $38m after security vulnerabilities allowed hackers to defraud customers. The investigation revealed that the theft of a femtocell enabled unauthorized access to KT's mobile network and subsequent fraudulent micropayments.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.