Blog
EU Regulators are coming directly after non-EU processors for GDPR violations
I’m a non-EU data processor, no EU regulator is coming after me right? Wrong, says French regulator, CNIL, in new decision fining SaaS provider 1 Million EUR! At issue in this case was a non-EU processor that had failed to delete controller data after the termination of the agreement between them, and subsequently suffered a data breach impacting many of the users of the controller’s platform. (Similar to the fact pattern in the recent Spanish AEPD decision)…
By: Fox Rothschild LLP