The US Lessons for the EU Personal Data Breach Notification: Part I - What is Personal Data Breach and Introduction of the US Regulatory Perspective

Warning

This publication doesn't include Faculty of Arts. It includes Faculty of Law. Official publication website can be found on muni.cz.
Authors

KASL František

Year of publication 2020
Type Article in Periodical
Magazine / Source The Lawyer Quarterly
MU Faculty or unit

Faculty of Law

Citation
Web Open access časopisu
Keywords Personal data breach; security breach; notification obligation; US law; GDPR
Description The new obligation to notify personal data breaches under Articles 33 and 34 of the General Data Protection Regulation 2016/679 can be seen as a reflection of the US regulatory approach to security breach incidents, which has an established tradition since the enactment of Security Breach Information Act in California in 2002. The contribution presents in two parts the relevant legal frameworks of the US and the EU, in order to provide a discussion on their similarities and differences. The aim is to identify available intellectual stimuli to the respective academic debate regarding interpretation, application and specification of the EU provisions based on inspiration from the US experience. The Part I introduces the reader to the concept of personal data breach and its relevance in nowadays digital society and then offers and introduction of the relevant US regulatory frameworks.

You are running an old browser version. We recommend updating your browser to its latest version.