article thumbnail

Dutch SA Sanctions Credit Card Company for Failure to Perform Data Protection Impact Assessment

Inside Privacy

In December 2023, the Dutch SA fined a credit card company €150,000 for failure to perform a proper data protection impact assessment (“DPIA”) in accordance with Art. 35 GDPR for its “identification and verification process”. The DPO was also not sufficiently involved in the assessment.

article thumbnail

Spanish Data Protection Authority Issues Guidance on Data Spaces

Inside Privacy

The last section of the paper discusses how various GDPR requirements apply in the context of data spaces – for example, obligations to: (i) appoint a data protection officer; (ii) conduct a data protection impact assessment; (iii) implement risk management processes, safeguards, and security measures for data sharing; (iv) ensure data governance and (..)

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Decoding India’s Data Protection Law

Ikigai Law

India’s Digital Personal Data Protection Bill 2023 was introduced in Parliament on 3 August 2023. Once passed, the law will govern how businesses collect and use individuals’ data. What data is covered? Personal data, i.e., data about an individual that can identify them. What else should fiduciaries do? (a)

article thumbnail

UK ICO Updates Guidance on Artificial Intelligence and Data Protection

Inside Privacy

On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and data protection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. Additionally, the ICO have added a new annex on data protection fairness considerations across the AI lifecycle.

article thumbnail

Fintech and the Data Protection Bill

Ikigai Law

No piece of legislation has taken more punches than our elusive data protection law. The data law is nearly here! The Digital Personal Data Protection Bill, 2023 was introduced in Parliament on 3 August 2023. Say you are a payment aggregator or a KYC service provider or an AI-based data analytics service provider.

article thumbnail

European Data Protection Roundup – August 2023

Debevoise Data Blog

The AEPD held that a DPO cannot hold a position that leads them to determine the purposes and means of data processing. The scale and data protection risks associated with such technologies has been further complicated recently by their increasing integration with artificial intelligence systems.

article thumbnail

FCC Announces Creation of Privacy and Data Protection Task Force

Inside Privacy

Last week, FCC Chairwoman Jessica Rosenworcel announced the creation of a new Privacy and Data Protection Task Force (the “Task Force”) to demonstrate the agency’s commitment to protecting consumer data and ensuring that the telecommunications industry remains secure from threat actors.