Articles

GDPR is effective: Will GDPR guidelines from national authorities be binding?

Stibbe - Will GDPR guidelines from national authorities be binding?

GDPR is effective: Will GDPR guidelines from national authorities be binding?

31.05.2018 EU law

GDPR is now fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. We highlighted a series of 12 common misconceptions regarding the interpretation of the GDPR.

Will GDPR guidelines from national authorities be binding?

Doubts exist as to the binding effects of guidelines issued by the different national authorities that further elaborate the different aspects of the GDPR. This could lead to potentially contradictory instructions for multinational corporate groups that have subsidiaries in different Member States where the corresponding data protection authorities could have issued differing guidelines on the application of a same provision of the GDPR.

In that respect, the interpretation adopted by a national authority on specific provisions of the GDPR will only be binding for those companies (or groups of companies) whose “main establishment” (i.e., the place where decisions on data processing are taken in the European Union) is located in the territory of the country in question.

In any event, and as a general rule under the GDPR, the European Data Protection Committee holds an ultimate power to interpret any provision on a number of subject matters listed in Article 70 (including, for example, those related to profiling, notification of security breaches, international data transfers, or sanctions).

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

16.01.2020 BE law
24 January 2020: Carol Evrard participates in a panel session on Global Compliance at the CPDP conference in Brussels

Speaking slot - Stibbe is a long standing partner of the International Computers, Privacy and Data Protection Conference (CPDP) which takes place in Brussels between 22 and 24 January 2020 This year's theme is “Data protection and Artificial intelligence”. Carol Evrard, associate in our TMT team, participates in a panel organised by TrustArc (a privacy compliance technology company based in San Francisco, California) on "Changing Technology and Laws: Can Accountability be a Key to Global Compliance?"

Read more

15.01.2020 NL law
Consultatiereactie 'Wet plan van aanpak witwassen'

Short Reads - Soeradj Ramsanjhal, Karlijn van den Heuvel, Djoe Kuils, Rogier Raas, Judica Krikke en Muriël Rosing hebben een reactie ingediend op het concept wetsvoorstel ‘Wet plan van aanpak witwassen’. Dit wetsvoorstel is 2 december 2019 in consultatie gegaan en bevat verschillende voorgestelde wijzigingen van de Wet ter voorkoming van witwassen en financieren van terrorisme en de Wet op de economische delicten. 

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring