Remove 2022 Remove Compliance Remove Data protection
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU.

article thumbnail

UK ICO Updates Guidance on Artificial Intelligence and Data Protection

Inside Privacy

On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and data protection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. Additionally, the ICO have added a new annex on data protection fairness considerations across the AI lifecycle.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

The French CNIL Reminds Two Medical Research Organizations of their Data Protection Obligations

Inside Privacy

Following a report, the French supervisory authority (“CNIL”) audited two organizations carrying out medical research in early 2022 to check their compliance with these requirements. Despite being found in breach of the French data protection rules, none of the audited organizations were fined.

article thumbnail

European Data Protection Roundup – December 2022 and January 2023

Debevoise Data Blog

On 29 December 2022, the CNIL fined TikTok UK and Ireland as joint controllers €5 million for failing to: offer users the ability to refuse cookies as easily as accepting them (several clicks were required to refuse all cookies, as opposed to just one to accept them); and inform users in a sufficiently precise manner about cookie purposes.

article thumbnail

European Data Protection Roundup – August 2024

Debevoise Data Blog

Our top-five European data protection developments from August are: Uber fined for personal data transfer: The Dutch Data Protection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., without sufficient safeguards. ICO proposes £6.09

article thumbnail

European Data Protection Roundup – November

Debevoise Data Blog

Digital Operation Resilience Act is imminent What happened : On 28 November 2022, the European Union finalised the EU Digital Operational Resilience Act (“DORA”). Management will also face new overarching and specific obligations to approve, oversee and manage DORA-related compliance frameworks. These developments are covered below.

article thumbnail

European Data Protection Roundup – May 2023

Debevoise Data Blog

Third country data transfers : Businesses that transfer personal data outside of the EEA may want to review their transfer mechanisms in light of new guidance on the EU and South East Asia SCCs, and the DPC’s record-breaking €1.2 82 (see our May 2021 , August 2021 , and October 2022 blog posts for previous developments).