This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
Our top-eleven European dataprotection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. This includes products such as software, webcams and smart TVs.
Therefore, individual states took matters into their own hands and passed local laws to protect the privacy of their residents. The California Privacy Rights Act ( CPRA ) amends the CCPA and came into force (for the most part) on January 01, 2023.
Every day, more and more companies face the problem of personal dataprotection. As companies are increasingly scrutinised for proper dataprotection, it’s worth paying close attention to the latest best practices to avoid dealing with the potential negative consequences of a data breach.
state to mandate that attorneys take continuing legal education courses in cybersecurity, privacy and dataprotection. New York has become the first U.S. The order creates two types of cybersecurity training, one focused on ethics and the other on practice.
Those who process personal data of EU residents should comply with the requirements of the General DataProtection Regulation or GDPR. In this article, we will explain what companies that have already entered or are entering the EU market in 2023 should pay attention to. What to prepare for in 2023?
In December 2023, the Dutch SA fined a credit card company €150,000 for failure to perform a proper dataprotection impact assessment (“DPIA”) in accordance with Art. 35 GDPR for its “identification and verification process”. The DPO was also not sufficiently involved in the assessment.
Last week, FCC Chairwoman Jessica Rosenworcel announced the creation of a new Privacy and DataProtection Task Force (the “Task Force”) to demonstrate the agency’s commitment to protecting consumer data and ensuring that the telecommunications industry remains secure from threat actors.
On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and dataprotection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. AI has been a strategic priority for the ICO for several years.
On 3 October 2023, the UK Information Commissioner’s Office organised its annual DataProtection Practioner’s Conference 2023 (DPPC 2023). Here are the takeaways from the DPPC 2023 (the event sessions available here ). Cyber security risks remain significant, the most common of them being phishing attacks.
They are responsible for overseeing an organizations dataprotection measures, risk management strategies, overall security infrastructure, among other critical responsibilities. Tasked with overseeing a firms cybersecurity posture, CISOs stand on the front lines of a corporations digital defense.
A detailed clause-wise analysis of the Digital Personal dataProtection Bill 2023 On 7 August 2023, the Lok Sabha passed the Digital Personal DataProtection Bill, 2023. It will soon be introduced in the Rajya Sabha and likely become a law in a couple of days. Read the analysis here.
The AEPD held that a DPO cannot hold a position that leads them to determine the purposes and means of data processing. The scale and dataprotection risks associated with such technologies has been further complicated recently by their increasing integration with artificial intelligence systems.
UK ICO updates guidance to clarify requirements for fairness in AI What happened : The UK ICO has updated its existing Guidance on AI and dataprotection following requests from industry to clarify requirements for fairness in AI. Norwegian DataProtection Authority fines medical device company c.$240,000
Our summary of the Digital Personal DataProtection Bill, 2023 The Digital Personal DataProtection Bill, 2023 ( 2023 Bill ) was tabled in Parliament on 3 August 2023. It is the fifth – and likely final – iteration of India’s efforts to formulate a personal dataprotection law.
Key takeaways this April include: UK children’s dataprotection focus continues: Businesses may wish to review policies and procedures for dealing with children’s data in light of recent UK ICO fines and guidance, especially to ensure that terms of use are adequately enforced.
Dataprotection & AI: In particular: (i) the French CNIL published its first set of guidance on GDPR compliance when developing AI tools; and (ii) the UK ICO issued a preliminary enforcement notice against Snap over its AI chatbot, alleging that Snap had not adequately assessed the privacy risks posed to child users of the tool.
On March 13, 2023, the CNIL published a statement announcing that it reminded these two organizations of their legal obligations under the French dataprotection framework. Despite being found in breach of the French dataprotection rules, none of the audited organizations were fined.
Key takeaways from September include: UK-US data bridge: From 12 October 2023, UK businesses will be able to transfer personal data to certain US organisations certified under a UK-specific extension to the EU-U.S. data bridge from 12 October 2023. These developments, and more, covered below. For the wider UK-U.S.-EU
The Summer 2023 Edition of the quarterly IT & DataProtection Newsletter by Reed Smith Germany has just been released: English version German version This edition covers the following topics: New adequacy decision for EU-U.S. We also included an overview over the 2023 annual reports of the German dataprotection authorities.
As we covered here , last October, the CNIL fined Clearview AI €20 million for various dataprotection violations, including “intrusive and massive” data processing without consent or a valid legitimate interest. Nonetheless, businesses that transfer personal data to the U.S. These developments, and more, covered below.
For example, the Garante notes the need to incorporate dataprotection by design and by default principles within any AI systems used in the healthcare space. In particular, the paper recommends the use of internal data access controls, regular auditing of data security measures, and the use of dataprotection impact assessments.
India’s Digital Personal DataProtection Bill 2023 was introduced in Parliament on 3 August 2023. Once passed, the law will govern how businesses collect and use individuals’ data. What data is covered? Personal data, i.e., data about an individual that can identify them.
The Best Law Firm Websites Contest of 2023 saw entrants from all over the world and practice areas. This year, sites spanned DataProtection, Mergers & Acquisitions, Family Law, and Personal Injury, and more. Below are the top ten websites of 2023. We thank each and every one of the entrants.
It originally appeared in the July 2023 Edition of FinTales, our monthly fintech newsletter. No piece of legislation has taken more punches than our elusive dataprotection law. The data law is nearly here! The Digital Personal DataProtection Bill, 2023 was introduced in Parliament on 3 August 2023.
EDPB’s cookie banner task force report highlights user-friendly design choices What happened : In January 2023, the EDPB adopted a final report on the Cookie Banner Task Force’s work. Both investigations concerned the lawful basis relied on for the processing of user data to deliver personalised advertising.
Our top-five European dataprotection developments from August are: Uber fined for personal data transfer: The Dutch DataProtection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., without sufficient safeguards.
Our top five European dataprotection developments from June are: Non-material damage under GDPR: The CJEU clarified the scope of compensation for non-material damage in the context of identity theft and data subjects’ fear that their personal data had been exposed. To subscribe to the Data Blog, please click here.
EDPB “Consent or pay” models: Businesses operating large online platforms should consider the European DataProtection Board’s recent opinion indicating that “consent or pay” models are unlikely to be GDPR-compliant.
On 21 June 2023, at the close of a roundtable meeting of the G7 DataProtection and Privacy Authorities, regulators from the United States, France, Germany, Italy, United Kingdom, Canada and Japan published a joint “Statement on Generative AI” (“Statement”) (available here ).
Privacy and DataProtection , a leading UK journal on practical dataprotection compliance issues, has featured in its latest edition an article by Robert Maddox and Stephanie Thomas on the hallmarks of effective dataprotection by design and default under the EU and UK GDPR.
EDPB’s new work programme prioritises new technologies and cooperation amongst supervisory authorities What happened : The EDPB adopted its work programme for 2023/24. The recipient entity may be able to rely on legitimate interests in certain circumstances. Facilitating harmonisation amongst national supervisory authorities.
Four highlights from this week : Artificial Intelligence: Key Practices to Help Ensure Accountability in Federal Use; Don't get scammed by fake ChatGPT apps: Here's what to look out for; Apple Employees Forbidden From Using ChatGPT; and How to Enable Advanced DataProtection on iOS, and Why You Should.
On 19 June 2023, the Information Commissioner’s Office (ICO) has released new Guidance on Privacy-Enhancing Technologies (PETs) for DataProtection Compliance. Understanding PETs PETs are software and hardware systems that can help minimize use of personal data use while maximizing information security.
They raise various questions under regulatory and dataprotection and data security laws. The DiGA Regulation imposes specific dataprotection and data security requirements on health apps (in addition to safety, functionality, quality and interoperability requirements). 26 of the GDPR.
In 2023 the real technological “boom” happened — products based on artificial intelligence flooded the market. Regardless of the proven practical benefits of AI in different fields, its use has some risks for users’ privacy and dataprotection. 25 GDPR (dataprotection by design and by default). Violation of Art.
. : Business may want to revisit their cross-border data transfer arrangements following the new adequacy decision for the EU-U.S. Data Privacy Framework, assess whether they are eligible to self-certify and, if they are, whether it makes sense to. Data Privacy Framework (the “DPF”). These developments, and more, covered below.
On 8 March 2023, the UK government presented a new version of the UK DataProtection and Digital Information Bill No.2. As with the previous bill, the new bill aims to alleviate the burden of compliance with the UK GDPR and its implementing UK DataProtection Act (2018) for organisations in the UK.
Italy bans private use of facial recognition technology What happened : On 14 November 2022, the Italian Garante announced that the use of existing and new facial recognition systems that use biometric data is prohibited until a new law is passed, and at least until the end of 2023.
2022 was another busy year in privacy and dataprotection. Regulations surrounding privacy and data continue to develop at a rapid pace. As a result, 2023 could be an exciting and a busy year for privacy and data. Andreas Splittgerber , Munich – “2023 will be a landmark year for AI regulations in Europe.
They are also reminded of their obligation to maintain appropriate technical and organisational measures in relation to their data processing, and may wish to review their compliance with these measures. It remains to be seen whether dataprotect authorities will provide guidance on how to interpret the “draw strongly” condition.
Introduction In our previous articles , we have already drawn your attention to the Brazilian dataprotection legislation which is quite similar to the General DataProtection Regulation (GDPR). Also, the ANPD has shared a new form which should be used for sending security incident reports by a data controller.
Key takeaways from March include: CNIL data security practice guide: The French DPA published an update of its data security practice guide for dataprotection officers, chief information security officers, computer scientists and legal experts. To subscribe to the Data Blog, please click here.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content