Header graphic for print
HL Chronicle of Data Protection Privacy & Information Security News & Trends

Tag Archives: data controller

Posted in Consumer Privacy, International/EU Privacy

Surrender! German Court Strengthens the Position of Data Principals in Insolvency Proceedings

In a recent decision, the Higher Regional Court of Düsseldorf held that data controllers may claim immediate surrender of customer data in the insolvency of marketing agencies and IT service providers in Germany under section 47 of the German Insolvency Statute (decision of 27 September 2012, file number: I-6 241/11; for a German text version of… Continue Reading

Posted in International/EU Privacy

CNIL Cloud Guidelines Address Controller vs. Processor Issues

The French CNIL’s new guidelines on cloud computing revisit the tricky question of whether a cloud provider is a data processor or a data controller under French data protection law. The CNIL’s guidelines contain seven recommendations for cloud customers, and a list of recommended contractual clauses. The CNIL points out that when the cloud provider is located in a non-European country “local government authorities can send requests to the provider to have access to the data.”

Posted in International/EU Privacy

Spain changes the paradigm of international transfers of personal data allowing Spanish data processors to be “exporters” under the Standard Contractual Clauses for the Transfer of Data

The Spanish Data Protection Authority (SDPA) has established new procedures that allow data processors (not data controllers) based in Spain to obtain authorizations for transferring data processed on behalf of their customers (the data controllers) to sub-processors based in Third Countries that are not deemed to have an adequate level of protection for personal data. In addition, data processors can enter into Standard Contractual Clauses with their sub-processors. Previously in Spain, data controllers had to enter into Standard Contractual Clauses with each of their data processors’ sub-processors in Third Countries and data controllers had to obtain authorizations from the SDPA for such transfers.