Remove Blog Remove Court Remove Data protection
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

article thumbnail

European Data Protection Roundup – February 2025

Debevoise Data Blog

Our top-five European data protection developments from February are: European Commission publishes guidelines on prohibited AI practices : The EU Commission has published non-binding guidance on the EU AI Acts prohibited use cases. The ban entered into force on 2 February 2025. Spanish Telecomm Provider Fined 1.2

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

AI Gets Personal: CCPA vs. GDPR on Automated Decision-Making

Berkley Technology Law Journal

privacy legislation, is now addressing these technologies with a new set of proposed rules by the California Privacy Protection Agency (CPPA). The European Unions General Data Protection Regulation (GDPR) , particularly Article 22 , addresses similar concerns by regulating decisions made solely through automated processing.

article thumbnail

EU General Court Clarifies When Pseudonymized Data is Considered Personal Data

Inside Privacy

On April 26, 2023, the General Court of the European Union issued its judgment in Case T-557/20, SRB v EDPS. The Court held that pseudonymized data transmitted to a data recipient will not be considered personal data if the data recipient does not have the means to re-identify the data subjects.

Court 137
article thumbnail

The Security ‘Scapegoat?’: When Liability Comes Knocking, CISOs Answer the Call

Berkley Technology Law Journal

They are responsible for overseeing an organizations data protection measures, risk management strategies, overall security infrastructure, among other critical responsibilities. District Court for the Southern District of New York suggests that CISOs might be outside of point-blank range.

article thumbnail

European Data Protection Roundup – July 2024

Debevoise Data Blog

Building on prior European guidance , the French and Irish DPAs published guidance on the deployment of generative AI, large language models and data protection. To that end, the EDPB proposed designating DPAs as the “national competent authorities” under the AI Act to create a single point of contact.

article thumbnail

European Data Protection Roundup – August

Debevoise Data Blog

UK DPA launches data transfer consultation What happened : The ICO launched a consultation covering its international data transfer guidance, draft transfer risk assessment tool (“TRA”) and draft international data transfer agreement (“ IDTA ”). These developments, and more, covered below.