Recapitalisation measures added to the Serbian state aid framework for COVID-19 crisis
Sticky Post

Recapitalisation measures added to the Serbian state aid framework for COVID-19 crisis

Since the beginning of the COVID-19 crisis, the Government of Serbia has adopted several state aid measures aimed at helping the economic entities preserve jobs and liquidity. In this respect, the Government took the lead from the European Commission and its measures adopted within the scope of the Temporary Framework to support the economy in […]

Germany: Data leakage does not automatically justify compensation claim
Sticky Post

Germany: Data leakage does not automatically justify compensation claim

On 18 September 2020 Regional Court of Frankfurt am Main rendered an interesting judgement which holds, in the main, that data leakage does not on its own evidence controller’s breach of the GDPR and warrant payment of non-material damages. More is required for a plaintiff to succeed in his or her claim. Background A Belgian […]

Garante: Employers, deactivate e-mail account of the departing employees
Sticky Post

Garante: Employers, deactivate e-mail account of the departing employees

If employers want to be compliant with GDPR, what should they do with employee’s corporate e-mail account after termination of his employment? Italian supervisory authority’s decision of 2 July 2020, against Mapei S.p.A. (“Mapei“), gives us answers to this question. Background A former employee of Mapei lodged a complaint before Italian supervisory authority (“Garante“) in […]

Processing agreements: Copy-pasting from GDPR art. 28 does not suffice
Sticky Post

Processing agreements: Copy-pasting from GDPR Art. 28 does not suffice

Last September, the European Data Protection Board (“EDPB“) issued its Guidelines 07/2020 on the concepts of controller and processor in the GDPR. The guidelines were subject to public consultation until 19 October. As it can be inferred from the title, the document gives criteria for the correct interpretation of some key concepts used in the […]

Nowak: Opinions are personal data; access is to data, not documents
Sticky Post

Nowak: Opinions are personal data; access is to data, not documents

The Court of Appeal of Ireland adopted on 1 July 2020 a judgement in a dispute between Peter Nowak and the Irish Data Protection Commissioner, as respondent (“DPC“), at the end of a years-long judicial saga. The case, taken in its entirety, offers interesting insight into two important questions: can written opinions and assessments made […]

Serbian competition authority opens a new gun jumping case
Sticky Post

Serbian competition authority opens a new gun jumping case

The Serbian Commission for Protection of Competition launched its fourth investigation in September 2020. The latest one will look into whether Zdravstvena ustanova Apoteka Janković, a privately owned chain of pharmacies (“ZUA Janković“), breached merger control rules by not notifying the acquisition of control over the pharmaceutical business of state-owned chain of pharmacies Zdravstvena ustanova […]

IFLR1000 rankings
Sticky Post

IFLR1000 rankings

We are grateful to our clients for the work that has landed us once again into Tier 1 for Corporate and Finance in both Serbia and Montenegro in the latest IFLR1000 directory. We are satisfied with our Tier 2 ranking in Bosnia and Herzegovina in this practice area. We will work harder to improve the […]

M&A trends in Serbia in light of COVID-19
Sticky Post

M&A trends in Serbia in light of COVID-19

BDK’s senior partner Vladimir Dašić spoke at FINIZ round table on trends in mergers and acquisitions in Serbia in light of the pending COVID-19 crisis. He stressed that the crisis had a significant negative impact on the economies of the region. Serbia declared the state of emergency in spring which significantly disturbed economic activity. However, […]

Auto Draft 10
Sticky Post

CNIL imposes a fine on a French online shoe retailer

The French Data Protection Authority (CNIL) issued on 28 July 2020 a fine of €250,000 against Spartoo, a French company which specializes in selling shoes online. The decision offers rich insights into the failures of a data controller to fulfil the GDPR requirements concerning data minimization, data retention, privacy notices, and security of processing. The […]