Remove 2022 Remove Data protection Remove e-records
article thumbnail

European Data Protection Roundup – December 2022 and January 2023

Debevoise Data Blog

On 29 December 2022, the CNIL fined TikTok UK and Ireland as joint controllers €5 million for failing to: offer users the ability to refuse cookies as easily as accepting them (several clicks were required to refuse all cookies, as opposed to just one to accept them); and inform users in a sufficiently precise manner about cookie purposes.

article thumbnail

European Data Protection Roundup – May 2023

Debevoise Data Blog

Third country data transfers : Businesses that transfer personal data outside of the EEA may want to review their transfer mechanisms in light of new guidance on the EU and South East Asia SCCs, and the DPC’s record-breaking €1.2 82 (see our May 2021 , August 2021 , and October 2022 blog posts for previous developments).

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

UK Data Protection and Digital Information Bill: Key Proposed Changes

Debevoise Data Blog

On 18 July 2022, the UK government published the Data Protection and Digital Information Bill (the “Bill”), which proposes reforms to the UK’s data protection and e-privacy landscape in-line with the National Data Strategy.

article thumbnail

European Data Protection Roundup – December 2023

Debevoise Data Blog

Sensitive personal data: The CJEU has clarified that the processing of special category personal data, such as health data, requires a legal basis under both GDPR Art. 6, meaning that businesses may wish to review their records of processing activities to ensure that both are reflected. 9 and GDPR Art. 6 and Art.

article thumbnail

European Data Protection Roundup – June & July 2023

Debevoise Data Blog

. : Business may want to revisit their cross-border data transfer arrangements following the new adequacy decision for the EU-U.S. Data Privacy Framework, assess whether they are eligible to self-certify and, if they are, whether it makes sense to. Data Privacy Framework (the “DPF”). Data Privacy Framework (the “DPF”).

article thumbnail

GDPR vs. Meta Platforms: is it time to change the business model?

Legal IT Group

According to the Better Regulation Delivery Office, several years ago, the e-commerce market in Ukraine alone was worth about UAH 50 billion a year. Everyone with an account has authorized Meta Platforms to record all their activities on the site. But this is just the tip of the iceberg.

article thumbnail

The EU AI Act – Navigating the EU’s Legislative Labyrinth

Debevoise Data Blog

The specific detail of these requirements is yet to be agreed but could include heightened data governance standards, monitoring and record-keeping rules, heightened standards for cybersecurity and transparency, as well as human oversight obligations. To subscribe to the Data Blog, please click here. Limited risk systems.