article thumbnail

Dutch SA Sanctions Credit Card Company for Failure to Perform Data Protection Impact Assessment

Inside Privacy

In December 2023, the Dutch SA fined a credit card company €150,000 for failure to perform a proper data protection impact assessment (“DPIA”) in accordance with Art. 35 GDPR for its “identification and verification process”. The DPO was also not sufficiently involved in the assessment.

article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Spanish Data Protection Authority Issues Guidance on Data Spaces

Inside Privacy

In May 2023, the Spanish Supervisory Authority (“SA”) issued a detailed guidance paper on GDPR compliance in the context of data spaces.

article thumbnail

UK ICO Updates Guidance on Artificial Intelligence and Data Protection

Inside Privacy

On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and data protection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. Additionally, the ICO have added a new annex on data protection fairness considerations across the AI lifecycle.

article thumbnail

Cyber Security Compliance for Legal Businesses: What You Need to Know

MatterSuite

Therefore, it is crucial for legal businesses to implement robust cyber security for law firm compliance measures to protect themselves and their clients. What is Cyber Security Compliance? Compliance requirements are usually set by government and regulatory bodies, as well as industry associations.

article thumbnail

Guidance on Privacy-Enhancing Technologies for Data Protection Compliance: Key Considerations for Organizations

Technology Law Dispatch

On 19 June 2023, the Information Commissioner’s Office (ICO) has released new Guidance on Privacy-Enhancing Technologies (PETs) for Data Protection Compliance. Understanding PETs PETs are software and hardware systems that can help minimize use of personal data use while maximizing information security.

article thumbnail

Automated Compliance: German start-up Secjur expands into Switzerland

Legal Tech Blog

New data protection laws, increasing regulation, greater risk of cyber attacks: The challenges for entrepreneurs are becoming ever greater. However, compliance can be largely automated through artificial intelligence. On September 1, a new data protection law (revDSG) has come into force in Switzerland.