Regulatory Open Forum

 View Only
  • 1.  EU GDPR and Privacy laws in US

    Posted 15-Mar-2018 17:37

    Hi,

     

    Does anyone have an idea on the  similarities & differences between the  personal data protection policy of EU and the privacy laws of US ? We wish to update our policy , agreements to cover all the clauses.

     

    Thanks & Regards,

     

    Rashmi Pillay
    Regulatory Affairs Associate


    Ellex 

    3-4 Second Avenue

    Mawson Lakes SA, 5095

     

    T + 61 8 7074 8105
    rpillay@ellex.com

    W ellex.com

    .............................................................................
     
    One Powerful Vision.

    Confidentiality: This e-mail is from Ellex Medical Pty Ltd, ABN 35 008 276 060. The contents are confidential and intended only for the named recipient of this e-mail. If the reader of this e-mail is not the intended recipient you are hereby notified that any use, reproduction, disclosure or distribution of the information contained in the e-mail is prohibited. Viruses: Any loss/damage incurred by using this material is not the sender's responsibility. No warranty is made that this material is free from computer virus or other defect. Ellex Medical Pty Ltd entire liability will be limited to resupplying the material. If you have received this e-mail in error, please reply to us immediately and delete the document. 

     



     



  • 2.  RE: EU GDPR and Privacy laws in US

    Posted 16-Mar-2018 05:44
    My interpretation is really quite different. The key differences for companies like mine (a consultancy) will be the (i) extent of data covered (health care data yes, but it goes much further than this all the way through to the use of person-name as opposed to function-name e-mail addresses, (ii) the specific roles defined for certain individuals and assignment of responsibility for data protection, (iii) a move to opt-in with no penalty for not doing (so things like "join our mailing list to get a free whitepaper/special offer" are prohibited practices unless they are also otherwise as readily available). The most difficult issue for many companies maybe understanding when data is transferred outside the EU for processing and the implication of doing this. So in summary, you only have two months, now is the time to contact a lawyer or consultant in your (or your EUAR's) domiciles EU countrybecause there are really stiff financial penalties.

    Good luck!

    Neil

    ------------------------------
    Neil Armstrong FRAPS
    CEO MeddiQuest Limited
    Peterborough
    United Kingdom
    ------------------------------



  • 3.  RE: EU GDPR and Privacy laws in US

    Posted 18-Mar-2018 00:29

    Hi ,

     

    Would really appreciate if somebody could recommend a suitable EU lawyer /consultant for complying to the GDPR.

     

    Thanks & Regards,

     

    Rashmi Pillay
    Regulatory Affairs Associate


    Ellex 

    3-4 Second Avenue

    Mawson Lakes SA, 5095

     

    T + 61 8 7074 8105
    rpillay@ellex.com

    W ellex.com

    .............................................................................
     
    One Powerful Vision.

    Confidentiality: This e-mail is from Ellex Medical Pty Ltd, ABN 35 008 276 060. The contents are confidential and intended only for the named recipient of this e-mail. If the reader of this e-mail is not the intended recipient you are hereby notified that any use, reproduction, disclosure or distribution of the information contained in the e-mail is prohibited. Viruses: Any loss/damage incurred by using this material is not the sender's responsibility. No warranty is made that this material is free from computer virus or other defect. Ellex Medical Pty Ltd entire liability will be limited to resupplying the material. If you have received this e-mail in error, please reply to us immediately and delete the document. 

     



     






  • 4.  RE: EU GDPR and Privacy laws in US

    Posted 19-Mar-2018 01:51
    Rashmi,

    I agree with the other comments that this is a big topic, and there is no shortage of lawyers and privacy professionals offering services to help companies comply with GDPR.   I think I saw one person reference DLA Piper, which is a well-known international law firm.   

    However, like the new medical device and IVD rule changes in EU, the first issue is to provide scope to the question.   For example, if your goal is to have an EU company ensure compliance with GDPR, then I would recommend an EU law firm or privacy consultancy, and not a US-based entity.

    If you are looking for basic materials on the subject, the EU has an excellent page: Home Page of EU GDPR 

    The International Assoc. of Privacy Professionals also has a good summary, here

    I'd be happy to contact friends in EU to help you find an appropriate privacy lawyer/law firm if that is what you need.


    Roger

    ------------------------------
    Roger Cepeda, JD, MBA, RAC
    MedTech Law LLC
    roger@medtech.law
    Mobile: 847-421-8361
    ------------------------------



  • 5.  RE: EU GDPR and Privacy laws in US

    Posted 19-Mar-2018 07:53
    Hello Rashmi,

    Erik Vollebregt at www.medicaldeviceslegal.com is well versed in this, with many presentations, posts, blogs.

    I would recommend starting there.

    Good luck.. I have to connect one of my clients with someone too, so if not him, would be interested to see other suggestions.

    Best regards,

    Ginger Cantor, MBA, RAC
    Centaur Consulting LLC centaurconsultingllc@gmail.com
    (+1) 715-307-1850





  • 6.  RE: EU GDPR and Privacy laws in US

    Posted 16-Mar-2018 07:45
    Hello Rashmi

    This is a huge topic. Unless someone here is a privacy lawyer, and wants to share only top level synopsis here, I would really advise you to consult with a privacy expert. The stakes are too high from company and patient/user perspective to try to use this forum.

    Just my opinion.

    Best regards,

    Ginger Cantor, MBA, RAC
    Centaur Consulting LLC centaurconsultingllc@gmail.com
     (+1) 715-307-1850





  • 7.  RE: EU GDPR and Privacy laws in US

    Posted 16-Mar-2018 09:23
    I'm not sure if looking at similarities and differences is the right approach to ensuring compliance with GDPR.
    For one, US has a completely different approach to privacy protection, in that there isn't a single law or regulation. If you're processing health data then HIPAA/HITECH are probably the most relevant, but not the only regulations and they only cover protected health information. GDPR on the other hand covers all types of personal information.
    If you already comply with HIPAA then there are a number of processes and controls that will apply to GDPR, such as security of processing, governance, staff training, etc.

    This site may be helpful with a general comparison, but as other suggested, you should get assistance from a consultant or a privacy lawyer.
    https://www.dlapiperdataprotection.com/index.html?c=GB&c2=US&t=security

    ------------------------------
    Michael Zagorski RAC
    Pittsburgh PA
    ------------------------------