- LittleLaw
- Posts
- đˇ The cost of a GDPR breach
đˇ The cost of a GDPR breach
TOGETHER WITH...
In todayâs email:
Lorries are getting longer
Interest rates donât want to stop rising
Qualify as a lawyer without any uni debt
Law firms asking their partners for money
Help the Netherlands by watching a livestream of fish
How much you can get if youâre a victim of a GDPR breach
If you take just one thing from this emailâŚ
GDPR is an EU regulation which applies to all 27 EU member countries. But thereâs usually scope for national courts to interpret these themselves meaning that the rules can be applied differently in different countries. Wherever theyâre applied more strictly is usually worse for companies as it becomes harder (read: more expensive) to comply.
EDITOR'S RAMBLE đŁ
I qualified as a lawyer having gone down the âtraditionalâ legal career path of graduating from university and - eventually - getting a training contract.
One big down side of this route is youâre often saddled with a lot of uni debt at the end. Iâve been working for 2.5 years and havenât even made a dent in mine!
This means the âtraditionalâ route isnât a viable option for everyone to take and, as a result, it contributes to the lack of diversity in the legal profession.
That's why I'm excited for today's sponsor, Gowling WLG.
They're offering a scheme that allows you to qualify as a lawyer without the need for a university degree and the accompanying financial burden (more on that below).
It's important to create alternative pathways into legal careers to ensure that the legal profession represents a wider range of perspectives and experiences.
P.S. If youâre from a law firm and are interested in reaching 6,700 aspiring lawyers to spread the word about any schemes you run, drop me an email!
- Idin
FEATURED REPORT đ°
đˇ The cost of a GDPR breach
Whatâs going on here?
The Court of Justice of the European Union (CJEU) - the European Unionâs top court - has decided a case that has a big impact in the world of personal data and the right to compensation under Article 82 General Data Protection Regulation (GDPR) - which pretty much every company should care about.
What was the case about?
The case was about the Austrian postal company called Ăsterreichische Post.
Theyâd collected information on people's political affiliations without telling them and used an algorithm to create profiles for targeted advertising during elections.
But one Austrian citizen who hadn't agreed to this data collection (letâs call him Bob) found out and made a complaint. He said that the political party which the algorithm had attributed to him was insulting and damaging to his reputation.
Bob claimed âŹ1,000 in compensation for ânonmaterial damagesâ (meaning damage which didnât have a financial impact on him - in this case damage to his reputation), but the lower Austrian courts rejected his claim.
It went to the Austrian Supreme Court which then essentially asked the CJEU:
whether any violation of GDPR (however small) should allow someone to claim compensation,
whether you can only claim for serious breaches, and
how courts should determine the amount of compensation for a GDPR claim like this.
Does any violation of GDPR (however small) allow someone to claim compensation?
The CJEU said no - not necessarily.
The GDPR requires three conditions to be met:
an infringement,
damage suffered, and
a causal link between the two.
So an âinfringementâ alone isnât enough to give someone a right to claim compensation (as youâll also need the two other bits).
Can you only claim for serious breaches?
The CJEU said no - they wanted to keep the door open for people to bring claims for non-financial damage that werenât serious (like the person in this case who only suffered damage to his reputation).
The Court thought allowing claims for non-serious breaches would give people the best quality of data protection.
How should compensation for GDPR breaches be calculated by courts?
The GDPR doesn't have any guidelines on how to assess damages, so national courts have been told to use their own rules to figure out how much compensation is payable for GDPR breaches.
As long as those rules follow EU law principles, they're good.
However, the CJEU made it clear that the purpose of Article 82 is to give data subjects full and effective compensation for the harm they've suffered.
Why should law firms care?
Law firms should care because this ruling will affect their clients who deal with their usersâ personal data (which in 2023 is probably every single one of their clients).
Itâs a bit unclear whether companies should be happy or sad as a result of this case.
In a way, itâs good for companies because the decision says that any breach of GDPR doesnât automatically give someone the right to compensation.
BUT because the judgment also leaves the door open for people to claim for nonmaterial breaches (like damage to their reputation) thereâs a chance that people can claim for things they previously couldnât.
Nonetheless, it means companies need to really tighten up on how theyâre dealing with data to make sure theyâre compliant with GDPR - and commercial law firms can advise them in the following ways:
đľď¸ GDPR compliance assessments: Law firms can conduct comprehensive assessments of their clientâs data processing activities
đ Draft GDPR-compliant policies and notices: Lawyers will assist in drafting clear privacy policies and data protection notices
đ¤ Contract review: Commercial lawyer can ensure contracts with third-party data processors are GDPR-compliant
đ¨ Data breach response planning: Data protection lawyers will develop and implement data breach response plans that comply with GDPR requirements
And if a dispute ever does arise against a companyâŚ
âď¸ Legal representation: Litigators can provide legal representation and defence in regulatory investigations and litigation related to GDPR non-compliance.
So, did Bob get his âŹ1,000 in the end?
It doesnât look like he has yet but itâs now up to the Austrian court of appeal to interpret the judgment itself.
Theyâll have to decide whether Bob gets his âŹ1,000 or not.
TOGETHER WITH GOWLING WLG đ¤*
Qualify as a solicitor completely debt free (in fact, you'll get paid) - thatâs a Brum-believable offer
If you're looking to become a qualified lawyer, the Birmingham apprenticeship scheme from Gowling (a global law firm based in the UK and Canada) can get you there.
The scheme offers an alternative route to the traditional path to qualification (you know - uni, debt, SQE, more debt, training contract...). This way, you'll get paid while studying and doing real work for Gowling's clients.
You won't be a guinea pig - the firm's run this scheme since 2015. The first cohort is about to qualify with first-class honours degrees from the University of Law.
You'll also be with others who've gone through it before - successful applicants will join a community of 30 apprentices to support them through the scheme.
Who can apply?
You donât need to have studied any particular subjects - just:
đ§ a sharp mind,
đŞ a can-do attitude, and
đď¸ a willingness to learn.
Join Gowlingâs team of over 1,400 legal professionals working globally and take your first steps towards becoming a qualified lawyer.
* This is sponsored content
A BIT OF FUN đ
It! was! great! to! meet! you! at! the! open! day!
IN OTHER NEWS đ
đ¸ Withers (a global law firm headquartered in London) has asked some of its partners to contribute up to ÂŁ41,000 each to the firm. Supposedly itâs not because of the current economic situation - they made the decision two years ago as part of trying to give their partners more of a stake in the business (lucky them). Withers recently posted their financial results, showing that their profit fell slightly. Maybe they're trying to shore up their finances a bit by getting their partners to chip in.
đ The UK government has given the green light to using longer lorries on the country's roads. They say it'll help businesses be more efficient and cut down on emissions as you can fit 15% more stuff in each lorry. The government reckons that using these longer lorries will result in about ÂŁ1.4 billion of economic benefits. But not everyone is happy - some campaigners are worried that the larger tail swing could be dangerous for pedestrians and cyclists.
đ The Bank of England is expected to raise interest rates for the 12th consecutive time to try to control inflation, which currently stands above 10%. The Bank rate is predicted to go up from 4.25% to 4.5%, the highest level in 14 years. The decision would have an impact on borrowers and savers. Hereâs our summary of the impact of interest rate changes.
AROUND THE WEB đ
đ Emoji: This AI emoji finder gives you the perfect emoji for anything you need (try it by typing in the name of your favourite book).
đ Fishy: This is really cool - the Netherlands is livestreaming this canal and asking the internet to ring the doorbell when you see a large amount of fish so they can open up the dam to let the fish migrate.
đď¸ News: If youâre after apolitical, jargon-free news from around the world, youâre in luck! Join 35,000+ readers who start their day with International Intrigue. 100% free.*
Credit: r/internetisbeautiful
* This is an affiliate link. It's free to join for you and if you sign up through us, we will receive a small commission.
STUFF THAT MIGHT HELP YOU đ
đĽ Community for aspiring lawyers: If you're struggling with motivation for law firm applications, check out FlowHuddle - a supportive online community, hosting remote co-working sessions, expert office hours and in-person meet-ups.
đCommercial awareness journal: Check out this journal that we've created alongside the team from The Lawyer Spot. It gives your a simple three-step structure to improve your commercial awareness in a high-quality physical notebook.
đŁ Advertise with us: If you're looking to reach an engaged audience of over 6,700 aspiring lawyers, drop us an email.
How did you find today's newsletter? |