Remove Blog Remove Court Remove Data protection
article thumbnail

EU General Court Clarifies When Pseudonymized Data is Considered Personal Data

Inside Privacy

On April 26, 2023, the General Court of the European Union issued its judgment in Case T-557/20, SRB v EDPS. The Court held that pseudonymized data transmitted to a data recipient will not be considered personal data if the data recipient does not have the means to re-identify the data subjects.

Court 137
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Minnesota’s Attempt to Copy California’s Constitutionally Defective Age Appropriate Design Code is an Utter Fail (Guest Blog Post)

Eric Goldman

by guest blogger Jess Miers, Legal Advocacy Counsel at Chamber of Progress [Eric’s intro: last year I blogged about Minnesota’s flirtation with mandatory age verification. Among their targets were the Data Protection Impact Assessment requirements, which NetChoice argued amounted to prior restraint and compelled speech.

article thumbnail

The European Union’s Digital Services Act: In Force from This Saturday, February 17, 2024, Including for U.S. Intermediaries (Guest Blog Post)

Eric Goldman

Marketa Trimble [Eric’s introductory note: I briefly addressed the DSA in this blog post , along with the attached meme. The DSA will require much agency and court interpretation to give legal certainty to intermediaries and the recipients of their services. by guest blogger Prof.

article thumbnail

European Data Protection Roundup – July 2024

Debevoise Data Blog

Building on prior European guidance , the French and Irish DPAs published guidance on the deployment of generative AI, large language models and data protection. To that end, the EDPB proposed designating DPAs as the “national competent authorities” under the AI Act to create a single point of contact.

article thumbnail

European Data Protection Roundup – August

Debevoise Data Blog

UK DPA launches data transfer consultation What happened : The ICO launched a consultation covering its international data transfer guidance, draft transfer risk assessment tool (“TRA”) and draft international data transfer agreement (“ IDTA ”). These developments, and more, covered below.

article thumbnail

European Data Protection Roundup – March 2021

Debevoise Data Blog

million for vendor oversight failings, unlawful cross-border transfers What happened : The AEPD, the Spanish data protection authority (“DPA”), fined Vodafone Spain €8.15 4 million was for allegedly deficient oversight of Vodafone’s data processors. See our blog post here for further tips on managing the latest landscape.