This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
Our top-eleven European dataprotection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. This includes products such as software, webcams and smart TVs.
Those who process personal data of EU residents should comply with the requirements of the General DataProtection Regulation or GDPR. Non-compliance with GDPR may result in hefty fines and reputational losses. However, it is not enough to just formally have such policies in place.
Therefore, individual states took matters into their own hands and passed local laws to protect the privacy of their residents. The California Privacy Rights Act ( CPRA ) amends the CCPA and came into force (for the most part) on January 01, 2023.
Every day, more and more companies face the problem of personal dataprotection. As companies are increasingly scrutinised for proper dataprotection, it’s worth paying close attention to the latest best practices to avoid dealing with the potential negative consequences of a data breach.
In December 2023, the Dutch SA fined a credit card company €150,000 for failure to perform a proper dataprotection impact assessment (“DPIA”) in accordance with Art. 35 GDPR for its “identification and verification process”. The DPO was also not sufficiently involved in the assessment.
On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and dataprotection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. AI has been a strategic priority for the ICO for several years.
On 3 October 2023, the UK Information Commissioner’s Office organised its annual DataProtection Practioner’s Conference 2023 (DPPC 2023). Here are the takeaways from the DPPC 2023 (the event sessions available here ). Cyber security risks remain significant, the most common of them being phishing attacks.
On 19 June 2023, the Information Commissioner’s Office (ICO) has released new Guidance on Privacy-Enhancing Technologies (PETs) for DataProtectionCompliance. Understanding PETs PETs are software and hardware systems that can help minimize use of personal data use while maximizing information security.
The AEPD held that a DPO cannot hold a position that leads them to determine the purposes and means of data processing. The scale and dataprotection risks associated with such technologies has been further complicated recently by their increasing integration with artificial intelligence systems.
Following a report, the French supervisory authority (“CNIL”) audited two organizations carrying out medical research in early 2022 to check their compliance with these requirements. Despite being found in breach of the French dataprotection rules, none of the audited organizations were fined.
UK ICO updates guidance to clarify requirements for fairness in AI What happened : The UK ICO has updated its existing Guidance on AI and dataprotection following requests from industry to clarify requirements for fairness in AI. Norwegian DataProtection Authority fines medical device company c.$240,000
Our summary of the Digital Personal DataProtection Bill, 2023 The Digital Personal DataProtection Bill, 2023 ( 2023 Bill ) was tabled in Parliament on 3 August 2023. It is the fifth – and likely final – iteration of India’s efforts to formulate a personal dataprotection law.
Dataprotection & AI: In particular: (i) the French CNIL published its first set of guidance on GDPR compliance when developing AI tools; and (ii) the UK ICO issued a preliminary enforcement notice against Snap over its AI chatbot, alleging that Snap had not adequately assessed the privacy risks posed to child users of the tool.
Since the entry into force of the General DataProtection Regulation (GDPR), many companies processing the data of Europeans have faced the task of achieving the much desired GDPR-compliance. Why do we need this?
Key takeaways this April include: UK children’s dataprotection focus continues: Businesses may wish to review policies and procedures for dealing with children’s data in light of recent UK ICO fines and guidance, especially to ensure that terms of use are adequately enforced.
Third country data transfers : Businesses that transfer personal data outside of the EEA may want to review their transfer mechanisms in light of new guidance on the EU and South East Asia SCCs, and the DPC’s record-breaking €1.2 billion fine against Meta. These developments, and more, covered below. (1)
For example, the Garante notes the need to incorporate dataprotection by design and by default principles within any AI systems used in the healthcare space. In particular, the paper recommends the use of internal data access controls, regular auditing of data security measures, and the use of dataprotection impact assessments.
Introduction In our previous articles , we have already drawn your attention to the Brazilian dataprotection legislation which is quite similar to the General DataProtection Regulation (GDPR). Also, the ANPD has shared a new form which should be used for sending security incident reports by a data controller.
Key takeaways from September include: UK-US data bridge: From 12 October 2023, UK businesses will be able to transfer personal data to certain US organisations certified under a UK-specific extension to the EU-U.S. data bridge from 12 October 2023. These developments, and more, covered below. For the wider UK-U.S.-EU
When calculating the fine, the CNIL cited the large scale of the data processing and the high proportion of minors (38% were between 13 and 17) as aggravating factors. The fines follow non-compliance notices CNIL served to 60 organisations that did not allow users to refuse cookies as easily as to accept them.
India’s Digital Personal DataProtection Bill 2023 was introduced in Parliament on 3 August 2023. Once passed, the law will govern how businesses collect and use individuals’ data. What data is covered? Personal data, i.e., data about an individual that can identify them.
Privacy and DataProtection , a leading UK journal on practical dataprotectioncompliance issues, has featured in its latest edition an article by Robert Maddox and Stephanie Thomas on the hallmarks of effective dataprotection by design and default under the EU and UK GDPR.
It originally appeared in the July 2023 Edition of FinTales, our monthly fintech newsletter. No piece of legislation has taken more punches than our elusive dataprotection law. The data law is nearly here! The Digital Personal DataProtection Bill, 2023 was introduced in Parliament on 3 August 2023.
On 21 June 2023, at the close of a roundtable meeting of the G7 DataProtection and Privacy Authorities, regulators from the United States, France, Germany, Italy, United Kingdom, Canada and Japan published a joint “Statement on Generative AI” (“Statement”) (available here ).
First of all, the data can be transferred based on the adequacy decision or subject to appropriate safeguards. Among these safeguards, in particular, are binding corporate rules, standard dataprotection clauses, code of conduct, and certification mechanism. What about the US? In such cases, appropriate safeguards are used.
With this regard, it is essential to know about the privacy legislation of this country since, nowadays, most internet businesses process the personal data of their clients, and they should do it in compliance with dataprotection laws. What to expect in 2024? The “personal information” definition is amended.
EDPB “Consent or pay” models: Businesses operating large online platforms should consider the European DataProtection Board’s recent opinion indicating that “consent or pay” models are unlikely to be GDPR-compliant.
Our top-five European dataprotection developments from August are: Uber fined for personal data transfer: The Dutch DataProtection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., without sufficient safeguards.
EDPB’s new work programme prioritises new technologies and cooperation amongst supervisory authorities What happened : The EDPB adopted its work programme for 2023/24. The recipient entity may be able to rely on legitimate interests in certain circumstances. Facilitating harmonisation amongst national supervisory authorities.
Management will also face new overarching and specific obligations to approve, oversee and manage DORA-related compliance frameworks. The ban follows recent public sector scandals involving the use of facial recognition technology.
. : Business may want to revisit their cross-border data transfer arrangements following the new adequacy decision for the EU-U.S. Data Privacy Framework, assess whether they are eligible to self-certify and, if they are, whether it makes sense to. Data Privacy Framework (the “DPF”). These developments, and more, covered below.
On 8 March 2023, the UK government presented a new version of the UK DataProtection and Digital Information Bill No.2. As with the previous bill, the new bill aims to alleviate the burden of compliance with the UK GDPR and its implementing UK DataProtection Act (2018) for organisations in the UK.
In 2023 the real technological “boom” happened — products based on artificial intelligence flooded the market. Regardless of the proven practical benefits of AI in different fields, its use has some risks for users’ privacy and dataprotection. 25 GDPR (dataprotection by design and by default). Violation of Art.
2022 was another busy year in privacy and dataprotection. Regulations surrounding privacy and data continue to develop at a rapid pace. As a result, 2023 could be an exciting and a busy year for privacy and data. Andreas Splittgerber , Munich – “2023 will be a landmark year for AI regulations in Europe.
They are also reminded of their obligation to maintain appropriate technical and organisational measures in relation to their data processing, and may wish to review their compliance with these measures. It remains to be seen whether dataprotect authorities will provide guidance on how to interpret the “draw strongly” condition.
Key takeaways from March include: CNIL data security practice guide: The French DPA published an update of its data security practice guide for dataprotection officers, chief information security officers, computer scientists and legal experts. To subscribe to the Data Blog, please click here.
The Amendments became effective on September 1, 2022, save for certain provisions that will become effective on March 1, 2023. The penalties for non-compliance are relatively modest in comparison to those in the European Union and the United Kingdom. The United States and China are not among the Permitted Jurisdictions at this time.
On February 22, 2023, the European DataProtection Board (“EDPB”) released its Work Program for 2023-2024 (“the Program”), outlining the key priority areas for the next two years. The Program is divided into four pillars, which largely reflect the priorities already set out in its Strategy 2021-2023.
As we approach the end of the year, here are the Top 10 Privacy posts on the Debevoise Data Blog in 2023 by page views. At the December 8, 2023 board meeting , the CPPA voted to advance the recently updated proposed cybersecurity audit regulations to formal rulemaking. Similar trends exist in the EU.
Therefore, a logical question arises: what should an employer know about the use of personnel monitoring tools in order not to violate the requirements of personal dataprotection legislation? Justifying the need for monitoring The General DataProtection Regulation (GDPR) does not prohibit surveillance of employees in the workplace.
In 2023, it’s crucial for big & small law firms to adapt to law tech. Compliance Finally, legal tech can help firms ensure compliance with legal and regulatory requirements. For example, tools for managing data privacy and security can help firms to comply with dataprotection laws.
Digital Markets Act: Developments since its proposal Following the European Commission’s initial proposal of the Digital Markets Act (DMA) in December 2020, its adoption by the European Parliament in March 2022 and the entry into force on November 1, 2022, the DMA will finally apply from May 2, 2023.
million active attorneys in the United States as of 2023. Prioritize Compliance and Security Innovation should never come at the expense of compliance and security. Our platform is specifically designed to support legal practices and is equipped with the latest security features that prioritize dataprotection and compliance.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content