{"id":4797,"date":"2018-11-23T11:00:31","date_gmt":"2018-11-23T11:00:31","guid":{"rendered":"https:\/\/www.infolaw.co.uk\/newsletter\/?p=4797"},"modified":"2021-01-10T12:58:38","modified_gmt":"2021-01-10T12:58:38","slug":"gdpr-dust-settling","status":"publish","type":"post","link":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/","title":{"rendered":"GDPR \u2013 the dust is settling"},"content":{"rendered":"<p>The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created \u2013 is in place and life goes on. As the dust left by the dramatic coming into effect of the GDPR settles, we are beginning to see what the GDPR means in practical terms. Many questions remain unanswered and many aspects of the law will take years \u2013 if not decades \u2013 to be fully interpreted and understood. However, among the numerous issues covered by the GDPR, some areas are emerging as the key strategic questions to address and becoming the focus of attention at an operational level.<\/p>\n<h3>Is enforcement happening?<\/h3>\n<p>One GDPR-related question appears to overshadow all the others: when will enforcement happen and how strict and heavyweight will it be? So much has been said in recent times about the infamous 4 per cent of the worldwide annual turnover as a measure for fines that, in a morbid kind of way, the expectations are sky-high. This has the effect of disrupting not only the approach to compliance \u2013 which is too often tainted by efforts to simply avoid negative consequences \u2013 but also the understanding of the reasons for regulatory action. The primary role of regulators is to ensure compliance and they have plenty of tools at their disposal to achieve that. Enforcement will undoubtedly happen and as enforcement actions take place, we will be able to calibrate what is seen as a big deal.<\/p>\n<p>In the meantime, it is possible to predict what worries the regulators. Both the guidance issued and the current regulatory action point in a clear direction. As the <a href=\"https:\/\/ico.org.uk\/media\/about-the-ico\/documents\/2259467\/regulatory-action-policy.pdf\">UK Information Commissioner\u2019s Office has stated<\/a>, breaches of the law involving novel or invasive technology, or a high degree of intrusion into the privacy of individuals can expect to attract regulatory attention at the upper end of the scale. Similarly, the Irish Data Protection Commission has indicated that it will be targeting those engaged in intensive online tracking and profiling, as well as companies which use emerging technologies or which are intensively engaged in automated decision making.<\/p>\n<p>All of this seems to suggest that any technological development that is particularly aimed at exploiting the value of personal data at a large scale is likely to be closely scrutinised. This is helpful to know as there are tools in the GDPR, such as data protection by design and by default, and data protection impact assessments that are ideally placed to identify and address the privacy risks resulting from new technologies and data uses. So a clear message to take on board is that whilst we have yet to see a spectacular enforcement action, it is essential to be alert to the regulators\u2019 priorities and consider at the outset the implications of sophisticated data uses for privacy.<\/p>\n<h3>Power to the people<\/h3>\n<p>One of the greatest \u2013 and perhaps most surprising \u2013 achievements of the GDPR has been its ability to bring privacy and data protection into the mainstream. At pubs, at supermarkets, at schools, in the real world \u2026 people talk about the GDPR. It\u2019s slightly surreal. That has in part led to an unexpectedly high increase in the exercise of data subjects\u2019 rights. Time will tell if the volume of requests experienced so far will decrease, increase or remain constant, but dealing with all types of data subjects\u2019 requests currently demands a far more dedicated approach than ever before. Dealing with data subjects\u2019 rights is not easy because most of these rights are not absolute rights. They cannot be ignored but they often involve careful thinking about the limits to be applied, the rights of others and the practicalities of honouring those rights. As with many other European data protection matters, having a process in place is key and following it is essential.<\/p>\n<p>Implementing a process to handle requests from individuals who wish to exercise their data protection rights starts with mapping out the decision-making that goes into it. The GDPR establishes a number of rights \u2013 some longstanding ones, like the right of access, rectification or deletion, and some new ones, like data portability \u2013 but in every case, the steps to take tend to follow a similar pattern:<\/p>\n<ul>\n<li>identification of the individual;<\/li>\n<li>rigorous management of timeframes;<\/li>\n<li>appropriate use of parameters and exemptions permitted by law; and<\/li>\n<li>effective engagement with the individual to meet their expectations.<\/li>\n<\/ul>\n<p>Honouring data subjects\u2019 rights should not be business-crippling. It should be part and parcel of operating in the digital economy and it will certainly pay off to approach this in a planned and organised manner.<\/p>\n<h3>International data transfers are back<\/h3>\n<p>Speaking of putting processes in place, there is an issue that was somewhat put to one side in the crazy days of pre-GDPR panic and is coming back as a major concern: international data transfers. It should be pretty obvious by now that global data flows are essential to the digital economy. It\u2019s how the internet works and the bread and butter of today\u2019s digital world, from cloud computing and mobile communications to e-commerce and social media. However, European data protection law has retained its traditional hard core approach of restricting data transfers to non-EU countries and this continues to be a visible area of concern.<\/p>\n<p>Transfers of personal data to the US in particular are under constant scrutiny. For starters, after nearly two years in operation, the criticism that the EU\u2013US Privacy Shield receives from all sides is still relentless. Fairly or unfairly, the abrupt end of the original Safe Harbor framework that led to the creation of the Privacy Shield still casts a shadow over its robustness. The fact that the <a href=\"http:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20180628IPR06836\/suspend-eu-us-data-exchange-deal-unless-us-complies-by-1-september-say-meps\">European Parliament has called on the European Commission to suspend the Privacy Shield<\/a> is indeed worrying and a sign that even if the Commission still defends the framework as a valid one, regulators are likely to remain wary.<\/p>\n<p>Even more preoccupying is the <a href=\"https:\/\/www.irishtimes.com\/business\/technology\/high-court-sets-out-11-questions-for-ecj-on-eu-us-data-transfers-1.3459549\">referral by the High Court of Ireland<\/a> to the Court of Justice of the European Union (CJEU) of a number of critical questions about the validity of the European Commission\u2019s Standard Contractual Clauses (SCC) for transfers. The SCC are by far the most relied-upon mechanism to legitimise international data transfers, so the fact that the CJEU has been tasked with determining the validity of the existing model clauses is a serious concern.<\/p>\n<p>Against this background, partly by design, partly by elimination, Binding Corporate Rules (BCR) have emerged as the go-to solution for any organisation seeking a robust yet flexible approach to legitimising global data flows. BCR top the list of options available in the GDPR for this purpose, and regulators appear sensitive to this situation. It is probably not a coincidence that one of the first actions of the newly created European Data Protection Board (EDPB) has been to <a href=\"https:\/\/edpb.europa.eu\/sites\/edpb\/files\/files\/news\/endorsement_of_wp29_documents_en_0.pdf\">reiterate the regulators\u2019 most recent guidance on BCR<\/a>. In a nutshell, with the coming into effect of the GDPR, the EU regulators are clearly endorsing the role of BCR as the main enabling tool for lawful data transfers worldwide.<\/p>\n<h3>e-Privacy as an added complexity<\/h3>\n<p>Looking ahead, high on the list of most troubling issues is the relationship between the GDPR and the evolving EU e-privacy framework. The level of unease is particularly noticeable around the interaction between the requirement for a lawful ground for processing and the strict obligation to obtain consent for the use of tracking technologies. Can internet profiling rely on \u201clegitimate interests\u201d? Is my \u201ccookie wall\u201d approach compatible with freely given consent? Will the forthcoming e-privacy regulation change anything and, if so, when? These are difficult questions because the answers have tangible practical implications.<\/p>\n<p>Something that is certain is that from a European public policy perspective, e-privacy is an additional necessity to what the GDPR already provides, not an alternative. That means that we should be prepared to continue to operate with this two-tier approach for the foreseeable future, whilst acknowledging that the law in this area is almost as dynamic as the technological developments.<\/p>\n<p><em>Eduardo Ustaran is co-director of the Privacy and Cybersecurity practice of <a href=\"http:\/\/hoganlovells.com\">Hogan Lovells<\/a> and an internationally recognised expert in privacy and data protection law. <\/em><em>Email <a href=\"mailto:eduardo.ustaran@hoganlovells.com\">eduardo.ustaran@hoganlovells.com<\/a>. Twitter @<a href=\"https:\/\/twitter.com\/EUstaran\">EUstaran<\/a>.<\/em><\/p>\n<p><em>Image: GDPR and ePrivacy <a href=\"http:\/\/www.Convert.com\/GDPR\/\">cc by Convert<\/a> <a href=\"https:\/\/www.flickr.com\/photos\/160103778@N03\/40039030284\/\">on Flickr<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created \u2013 is in place and life goes on. As the dust left by the dramatic coming into effect of the GDPR settles, we are beginning to see what the GDPR [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":4800,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[],"class_list":["post-4797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\r\n<title>GDPR \u2013 the dust is settling - Internet for Lawyers Newsletter<\/title>\r\n<meta name=\"description\" content=\"The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created\" \/>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_GB\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"GDPR \u2013 the dust is settling - Internet for Lawyers Newsletter\" \/>\r\n<meta property=\"og:description\" content=\"The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/\" \/>\r\n<meta property=\"og:site_name\" content=\"Internet for Lawyers Newsletter\" \/>\r\n<meta property=\"article:published_time\" content=\"2018-11-23T11:00:31+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2021-01-10T12:58:38+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg\" \/>\r\n\t<meta property=\"og:image:width\" content=\"640\" \/>\r\n\t<meta property=\"og:image:height\" content=\"400\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\r\n<meta name=\"author\" content=\"Eduardo Ustaran\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:creator\" content=\"@nickholmes\" \/>\r\n<meta name=\"twitter:site\" content=\"@nickholmes\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Eduardo Ustaran\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/\",\"url\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/\",\"name\":\"GDPR \u2013 the dust is settling - Internet for Lawyers Newsletter\",\"isPartOf\":{\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg\",\"datePublished\":\"2018-11-23T11:00:31+00:00\",\"dateModified\":\"2021-01-10T12:58:38+00:00\",\"author\":{\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/#\/schema\/person\/404f6d488d10c16d7ff8e0ed61b72189\"},\"description\":\"The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created\",\"breadcrumb\":{\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#primaryimage\",\"url\":\"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg\",\"contentUrl\":\"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg\",\"width\":640,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.infolaw.co.uk\/newsletter\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR \u2013 the dust is settling\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/#website\",\"url\":\"https:\/\/www.infolaw.co.uk\/newsletter\/\",\"name\":\"Internet for Lawyers Newsletter\",\"description\":\"Edited by Nick Holmes\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.infolaw.co.uk\/newsletter\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/#\/schema\/person\/404f6d488d10c16d7ff8e0ed61b72189\",\"name\":\"Eduardo Ustaran\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.infolaw.co.uk\/newsletter\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/1ef91770d99a0f1fa392d42d3218e9158c1b68366c13435e0adf5845d570b0fb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/1ef91770d99a0f1fa392d42d3218e9158c1b68366c13435e0adf5845d570b0fb?s=96&d=mm&r=g\",\"caption\":\"Eduardo Ustaran\"},\"description\":\"Eduardo Ustaran is co-director of the Privacy and Cybersecurity practice of Hogan Lovells and an internationally recognised expert in privacy and data protection law. Email eduardo.ustaran@hoganlovells.com. Twitter @EUstaran\",\"url\":\"https:\/\/www.infolaw.co.uk\/newsletter\/author\/eduardoustaran\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR \u2013 the dust is settling - Internet for Lawyers Newsletter","description":"The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/","og_locale":"en_GB","og_type":"article","og_title":"GDPR \u2013 the dust is settling - Internet for Lawyers Newsletter","og_description":"The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created","og_url":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/","og_site_name":"Internet for Lawyers Newsletter","article_published_time":"2018-11-23T11:00:31+00:00","article_modified_time":"2021-01-10T12:58:38+00:00","og_image":[{"width":640,"height":400,"url":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg","type":"image\/jpeg"}],"author":"Eduardo Ustaran","twitter_card":"summary_large_image","twitter_creator":"@nickholmes","twitter_site":"@nickholmes","twitter_misc":{"Written by":"Eduardo Ustaran","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/","url":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/","name":"GDPR \u2013 the dust is settling - Internet for Lawyers Newsletter","isPartOf":{"@id":"https:\/\/www.infolaw.co.uk\/newsletter\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#primaryimage"},"image":{"@id":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg","datePublished":"2018-11-23T11:00:31+00:00","dateModified":"2021-01-10T12:58:38+00:00","author":{"@id":"https:\/\/www.infolaw.co.uk\/newsletter\/#\/schema\/person\/404f6d488d10c16d7ff8e0ed61b72189"},"description":"The panic has receded. The frantic drafting has slowed down. The GDPR \u2013 widely regarded as the most ambitious data protection legal framework ever created","breadcrumb":{"@id":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#primaryimage","url":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg","contentUrl":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-content\/uploads\/2018\/11\/GDPR-by-Dennis-van-der-Heijden.jpg","width":640,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/www.infolaw.co.uk\/newsletter\/2018\/11\/gdpr-dust-settling\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infolaw.co.uk\/newsletter\/"},{"@type":"ListItem","position":2,"name":"GDPR \u2013 the dust is settling"}]},{"@type":"WebSite","@id":"https:\/\/www.infolaw.co.uk\/newsletter\/#website","url":"https:\/\/www.infolaw.co.uk\/newsletter\/","name":"Internet for Lawyers Newsletter","description":"Edited by Nick Holmes","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infolaw.co.uk\/newsletter\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.infolaw.co.uk\/newsletter\/#\/schema\/person\/404f6d488d10c16d7ff8e0ed61b72189","name":"Eduardo Ustaran","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.infolaw.co.uk\/newsletter\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/1ef91770d99a0f1fa392d42d3218e9158c1b68366c13435e0adf5845d570b0fb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1ef91770d99a0f1fa392d42d3218e9158c1b68366c13435e0adf5845d570b0fb?s=96&d=mm&r=g","caption":"Eduardo Ustaran"},"description":"Eduardo Ustaran is co-director of the Privacy and Cybersecurity practice of Hogan Lovells and an internationally recognised expert in privacy and data protection law. Email eduardo.ustaran@hoganlovells.com. Twitter @EUstaran","url":"https:\/\/www.infolaw.co.uk\/newsletter\/author\/eduardoustaran\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/posts\/4797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/comments?post=4797"}],"version-history":[{"count":3,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/posts\/4797\/revisions"}],"predecessor-version":[{"id":5762,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/posts\/4797\/revisions\/5762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/media\/4800"}],"wp:attachment":[{"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/media?parent=4797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/categories?post=4797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infolaw.co.uk\/newsletter\/wp-json\/wp\/v2\/tags?post=4797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}