This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
Our top-eleven European dataprotection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.
Our top-five European dataprotection developments from February are: European Commission publishes guidelines on prohibited AI practices : The EU Commission has published non-binding guidance on the EU AI Acts prohibited use cases. The ban entered into force on 2 February 2025. Spanish Telecomm Provider Fined 1.2
privacy legislation, is now addressing these technologies with a new set of proposed rules by the California Privacy Protection Agency (CPPA). The European Unions General DataProtection Regulation (GDPR) , particularly Article 22 , addresses similar concerns by regulating decisions made solely through automated processing.
Our top-five European dataprotection developments from August are: Uber fined for personal data transfer: The Dutch DataProtection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., without sufficient safeguards.
UK High Court dismisses most of the Dixons data breach claim What happened : The UK High Court dismissed various claims against DSG Retail Limited (“DSG”), the owner of Currys PC World and Dixons Travel, relating to a 2017 – 2018data breach where hackers accessed personal data in the company’s systems.
million fine against Austrian Post for channelling electronic dataprotection-related inquiries to a web form and not offering an additional email address, irrespective of the data subject option to also use non-electronic postal mail or customer service. These developments, and more, covered below.
Key takeaways this April include: UK children’s dataprotection focus continues: Businesses may wish to review policies and procedures for dealing with children’s data in light of recent UK ICO fines and guidance, especially to ensure that terms of use are adequately enforced. UK ICO fines TikTok £12.7
In this post, we look back at the 2020 European dataprotection landscape and five trends that help companies understand not only where we are, but where dataprotection enforcement, litigation, and practice may be headed. million against Marriott for its 2018data breach When you dig deeper though, two key points emerge.
Dataprotection & AI: In particular: (i) the French CNIL published its first set of guidance on GDPR compliance when developing AI tools; and (ii) the UK ICO issued a preliminary enforcement notice against Snap over its AI chatbot, alleging that Snap had not adequately assessed the privacy risks posed to child users of the tool.
EDPB “Consent or pay” models: Businesses operating large online platforms should consider the European DataProtection Board’s recent opinion indicating that “consent or pay” models are unlikely to be GDPR-compliant.
GDPR one-stop-shop: Businesses wishing to take advantage of the GDPR one-stop-shop system should take note of a new digest, published by the European DataProtection Board, which analyses the decisions made by so-called Lead Supervisory Authorities in this context.
Key takeaways from March include: CNIL data security practice guide: The French DPA published an update of its data security practice guide for dataprotection officers, chief information security officers, computer scientists and legal experts. 33(2) GDPR relating to the same personal data breach.
“If you don’t see me in half a decade, just wait a little longer” – India’s dataprotection bill ( circa 2018 ) On 9 th August, the Digital Personal DataProtection Bill, 2023 was finally passed in the Parliament. The finish line – the new data bill What stood out?
New dataprotection laws, increasing regulation, greater risk of cyber attacks: The challenges for entrepreneurs are becoming ever greater. On September 1, a new dataprotection law (revDSG) has come into force in Switzerland. However, compliance can be largely automated through artificial intelligence.
On 3 October 2023, the UK Information Commissioner’s Office (“ ICO ”) finalized its Employment practices and dataprotection − Monitoring workers guidance (“ Guidance ”) to account for new types of work, including work from home, and the use of more sophisticated technologies for monitoring.
However, data controllers and processers should be aware that the UK’s Information Commissioner’s Office (“ICO”) can also carry out dawn raids as part of investigations into compliance with dataprotection laws. unlawfully obtaining personal data). Train key staff on protocols and procedures for dawn raids.
These requirements cover a wide range of issues that are frequently debated in relation to the governance of generative AI globally, such as dataprotection, non-discrimination, bias and the quality of training data. This blog post identifies a few highlights of the draft Measures.
If you can remember as far back as December 2021, we published a blog post announcing that the European DataProtection Board (EDPB) published draft guidelines on the interplay between the territorial scope of the GDPR and the international transfer requirements.
EU authorities have understandably declined to put forward a single list of mandatory data security controls that apply to all companies subject to the GDPR. million fine imposed by the UK Information Commissioner’s Office (“ICO”) against Ticketmaster for alleged data security failings that exposed customer payment card data.
This blog post delves into the legal considerations that contribute to the success of e-commerce in different African countries and recommends suitable entry points for businesses entering the e-commerce market. and Trade, Consumer Protection , [link] [10] Kenya Info and Commc’n Act (1998), [link] Consumer Prot. 15] Ultimately, U.S.
As anyone following the fallout from the Court of Justice of the European Union’s decision in Schrems II will know, the GDPR restricts the transfer of personal data to “third countries”, including the U.S., This requires firms to share only personal data that is truly necessary for the stated purpose of the data request.
In this blog post, we outline the current and forthcoming EU legislation on the international transfer of non-personal data. This blog post was drafted with the contribution of Diane Valat. ) X (Recent Council versions remove this obligation.) We are happy to answer any questions you may have on this topic.
The penalty resolves charges that Pearson misled investors related to a 2018data breach. According to the SEC’s Order , on March 21, 2019, Pearson learned that millions of rows of data had been accessed and downloaded by a threat actor exploiting an unpatched security vulnerability. securities issuer.
Check out our blog post on understanding HIPAA compliance for more information. GDPR : To help address global needs for enhanced data security, in 2018, Europe introduced a unified dataprotection law, the General DataProtection Regulations (GDPR). So, it may be a good idea to learn more about GDPR.
Entities transferring personal data outside the European Economic Area on the basis of standard contractual clauses that are no longer in force (where the transfer began before 27 September 2021) should conclude agreements based on new clauses by 27 December 2022.
The recent publication of the SEC’s 2021 Division of Examination Priorities (the “2021 Priorities”) presents an opportunity to look back at the cybersecurity work of the SEC in 2020 and speculate about the SEC’s examination and enforcement priorities for dataprotection in the coming year for RIAs.
Mr Lloyd alleged that Google breached its duties as a data controller under the DataProtection Act 1998 (“DPA”) when it implemented the ‘Safari Workaround’. Google was initially successful before the first instance judge in 2018. This was reversed by the Court of Appeal in 2019.
So if you’re a new entrant and you want to go into competition with those companies, one way to sort of lower the barriers to entry would be that you get access to those data. And, of course, due to our very strict dataprotection rules, you will not get access to the data without sort of consent of the end users.
So if you’re a new entrant and you want to go into competition with those companies, one way to sort of lower the barriers to entry would be that you get access to those data. And, of course, due to our very strict dataprotection rules, you will not get access to the data without sort of consent of the end users.
14] Concerns, interest, and public outcries over data security have been increasing. [15] 15] Increased awareness of companies profiting from lax data security systems and personal information, along with high-profile data breaches, has heightened concerns about cybersecurity in the private sector. [16] Agency: Blog (Mar.
As cyber threats continue to grow, and consumers gain more privacy rights over their personal data, businesses need robust data minimization programs that can significantly reduce the amount of sensitive data they collect and maintain. The UK DataProtection Act of 2018 has a similar provision.
FTC Commissioner Rohit Chopra remarked in a statement that Commissioners have previously voted to allow dataprotection law violators to retain algorithms and technologies that derive much of their value from ill-gotten data and that the Everalbum settlement marked an “an important course correction.”
European DataProtection Roundup – September 2022 Key takeaways this September include: Google Analytics : Continue to assess carefully the use of Google Analytics. What to do : The Danish DataProtection Agency referred entities to the CNIL’s detailed guidance on making Google Analytics GDPR-compliant.
up to 45 when including the European Economic Area and the 16 German state dataprotection authorities). In 2018, the U.S. The outcome could have a significant impact on businesses’ potential liability for GDPR infringements and the viability of mass claims. authorised the U.S.
“AI models can learn and remember specific data points, meaning that, if they are open source, users’ sensitive personal information – like financial data – could be included in the code.” [15] 15] As such, AI can inadvertently leak users’ private data. [16] 15] As such, AI can inadvertently leak users’ private data. [16]
On March 2, 2023, the White House Office of the National Cyber Director (“ONCD”) released the Biden Administration’s (the “Administration”) long-awaited National Cybersecurity Strategy (the “Strategy”), the first since the Trump Administration’s strategy was issued in September 2018. To subscribe to our DataBlog, click here.
Another lengthy blog post rounding up cases from the past few months involving CSAM or commercial sex and Section 230/FOSTA. May 6, 2025) Prior blog posts ( 1 , 2 ). Users can store iCloud files using “Advanced DataProtection,” which encrypts the files such that Apple can’t access them.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content