article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

article thumbnail

European Data Protection Roundup – February 2025

Debevoise Data Blog

Our top-five European data protection developments from February are: European Commission publishes guidelines on prohibited AI practices : The EU Commission has published non-binding guidance on the EU AI Acts prohibited use cases. Spanish Telecomm Provider Fined 1.2

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Case T-557/20: the importance and impact on data protection

Legal IT Group

Every day, more and more companies face the problem of personal data protection. As companies are increasingly scrutinised for proper data protection, it’s worth paying close attention to the latest best practices to avoid dealing with the potential negative consequences of a data breach.

article thumbnail

Personal data protection: why a Data Transfer Impact Assessment should be part of your GDPR compliance

Legal IT Group

International data transfers in GDPR compliance are complex, as data are transferred to third countries outside the European Union (EU) or the European Economic Area (EEA). Suppose you are interested in personal data protection issues. What should the DTIA note for transferring personal data from the EU to Ukraine?

article thumbnail

AI Gets Personal: CCPA vs. GDPR on Automated Decision-Making

Berkley Technology Law Journal

privacy legislation, is now addressing these technologies with a new set of proposed rules by the California Privacy Protection Agency (CPPA). The European Unions General Data Protection Regulation (GDPR) , particularly Article 22 , addresses similar concerns by regulating decisions made solely through automated processing.

article thumbnail

The Security ‘Scapegoat?’: When Liability Comes Knocking, CISOs Answer the Call

Berkley Technology Law Journal

They are responsible for overseeing an organizations data protection measures, risk management strategies, overall security infrastructure, among other critical responsibilities. District Court for the Southern District of New York suggests that CISOs might be outside of point-blank range.

article thumbnail

EU General Court Clarifies When Pseudonymized Data is Considered Personal Data

Inside Privacy

On April 26, 2023, the General Court of the European Union issued its judgment in Case T-557/20, SRB v EDPS. The Court held that pseudonymized data transmitted to a data recipient will not be considered personal data if the data recipient does not have the means to re-identify the data subjects.

Court 137