Tag Archives: Penalty

Sweden Fined for Delaying Implementation of the Data Retention Directive

On May 30, 2013, the Court of Justice of the European Union held that Sweden failed to fulfill its obligations under EU law when it delayed complying with the Court’s 2010 ruling regarding the country’s implementation of the EU Data Retention Directive 2006/24/EC (the “Data Retention Directive”). The Court ordered Sweden to pay a lump sum of €3,000,000.

Continue reading…

Tags: EU Member States, European Commission, European Union, International, Legislation, Penalty, Sweden, Telecommunications

Estonian Data Protection Authority Issues Annual Report

On May 20, 2013, the Estonian Data Protection Inspectorate issued its Annual Report 2012 (the “Report,” summary available in English). The number of inquiries, complaints and supervision proceedings have remained the same over the last few years. The main topics of complaints include employment relations, CCTV, electronic direct marketing and social media. The Inspectorate stated that its primary goal is to stop violations of the law, not to impose sanctions. According to the Report, the Inspectorate issued orders regarding compliance in 48 cases and imposed fines in 39 cases.

Continue reading…

Tags: Advertisement, Article 29 Working Party, Data Protection Act, Estonia, European Union, International, Marketing, Online Privacy, Penalty, Social Media

Chinese Ministry of Industry and Information Technology Enacts Draft Rules on Personal Information

On April 10, 2013, the Ministry of Industry and Information Technology of the People’s Republic of China (the “MIIT”) enacted two draft rules (“Provisions on the Protection of Personal Information of Telecommunications and Internet Users” and “Provisions on the Registration of Real Identity Information of Telephone Users”) to solicit public comments. The comment period is open until May 15, 2013. Both Drafts include proposals for substantial provisions on the protection of personal information and were enacted according to the Resolution of the Standing Committee of the National People’s Congress Relating to Strengthening the Protection of Information on the Internet (issued by the Standing Committee in December 2012) and some other telecommunications rules.

Continue reading…

Tags: China, Criminal Law, Enforcement, Information Security, International, Marketing, Online Privacy, Penalty, Personally Identifiable Information, Security Breach, Telecommunications

UK ICO Fines Company GBP 90,000 for Nuisance Calls

On March 20, 2012, the UK Information Commissioner’s Office announced that it has issued a monetary penalty of £90,000 against DM Design Bedrooms Ltd. (“DM Design”) for making thousands of unwanted marketing calls.

Continue reading…

Tags: Christopher Graham, Data Controller, Data Protection Act, Do Not Call, Enforcement, European Union, Information Commissioners Office, International, Marketing, Penalty, Text Message, United Kingdom

German Parliament Passes Regulation Affecting Commercial Use of Address Data

On March 1, 2013, the German Federal Council (Bundesrat) passed a new registration law after insisting on a number of important amendments (in German). Among other issues covered in the bill, the new law regulates how businesses can obtain the registered addresses of individuals in Germany from Germany’s public authorities (“official address data”) and use that information for commercial purposes.

Continue reading…

Tags: Data Processor, European Union, Germany, International, Opt-In Consent, Penalty

Singapore’s Personal Data Protection Commission Publishes Consultation Paper

On February 5, 2013, Singapore’s new data protection agency, the Personal Data Protection Commission, published its first consultation paper (the “Paper”) articulating proposals for a data protection regulation. The Paper outlines the Commission’s positions on three key issues: (1) requests for access and correction; (2) transfer of personal data outside of Singapore; and (3) individuals who may act for others under the Personal Data Protection Act (“PDPA”). The PDPA was passed by the Singapore Parliament in October 2012 and became law in January 2013.

Continue reading…

Tags: Binding Corporate Rules, Data Protection Authority, Data Transfer, International, Penalty, Singapore

European Data Privacy Day Expert Panel Provides 30-Year Retrospective on UK Data Protection

On January 28, 2013, the London office of Hunton & Williams marked European Data Privacy Day with the launch of the fourth edition of Data Protection Law & Practice, written by Senior Attorney Rosemary Jay. A panel comprised of the current UK Information Commissioner, Christopher Graham; his three predecessors, Eric Howe CBE, Elizabeth France CBE and Richard Thomas CBE; and the UK Minister of State for Justice, Lord McNally, spoke at the event and provided a retrospective on data protection in the United Kingdom since the Information Commissioner’s Office’s (“ICO’s”) inception in 1984. Continue reading…

Tags: Bridget Treacy, Christopher Graham, Data Controller, Data Protection Act, Data Protection Authority, Enforcement, European Union, Events, Health Privacy, Information Commissioners Office, Information Security, International, Penalty, Richard Thomas, Rosemary Jay, Security Breach, United Kingdom

FTC Issues Staff Report on Mobile Privacy Disclosures and Announces Settlement with Social Networking Service for Mobile App Privacy Violations

On February 1, 2013, the Federal Trade Commission issued a new report entitled Mobile Privacy Disclosures: Building Trust Through Transparency. The report makes recommendations “for the major participants in the mobile ecosystem as they work to improve mobile privacy disclosures,” offering specific recommendations for mobile platforms, app developers, advertising networks and other third parties operating in this space. The FTC’s report also makes mention of the Department of Commerce’s National Telecommunications and Information Administration’s efforts to engage in a multistakeholder process to develop an industry code of conduct for mobile apps.

Continue reading…

Tags: Consent Order, Consumer Protection, COPPA, Department of Commerce, Enforcement, Facebook, Federal Trade Commission, Information Security, Jon Leibowitz, Mobile App, Mobile Device, National Telecommunications and Information Administration, Obama, Online Privacy, Penalty, Privacy Policy, Social Media, Twitter

UK ICO Fines Sony GBP 250,000

On January 24, 2013, the UK Information Commissioner’s Office (“ICO”) served Sony Computer Entertainment Europe Limited (“Sony”) with a monetary penalty of £250,000 resulting from a serious breach of the Data Protection Act 1998. An April 2011 security incident involving the Sony PlayStation Network Platform affected the personal data of millions of customers, including names, addresses, email addresses, dates of birth, account passwords and credit card details.

Continue reading…

Tags: Christopher Graham, Data Protection Act, Enforcement, European Union, Information Commissioners Office, International, Penalty, Security Breach, United Kingdom

Medical Practices Agree to $140,000 Settlement with Massachusetts Attorney General

On January 7, 2013, Massachusetts Attorney General Martha Coakley announced that several Massachusetts medical practices have agreed to a consent judgment and $140,000 payment to settle charges they improperly disposed of medical information. The defendants, which include several pathology practices and a firm that provided medical billing services to those practices, were accused of dumping hard copy medical records at the Georgetown Transfer Station, a waste management facility open to the public. The records allegedly contained the names, Social Security numbers and medical diagnoses of approximately 67,000 individuals. The illegal dumping allegations were publicized in a Boston Globe article after a photographer for the newspaper discovered medical records at the facility while he was disposing of his own trash.

Continue reading…

Tags: Consent Order, Consumer Protection, Enforcement, Health Privacy, HIPAA, Massachusetts, Penalty, Privacy Rule, Protected Health Information, Social Security Number, State Attorneys General, U.S. State Law