This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
Our top-five European dataprotection developments from February are: European Commission publishes guidelines on prohibited AI practices : The EU Commission has published non-binding guidance on the EU AI Acts prohibited use cases. Spanish Telecomm Provider Fined 1.2
Our top-eleven European dataprotection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. These developments are covered below.
By understanding this purpose, digital marketers can make informed design decisions. The Core Purpose: Conversion The primary purpose of a website is to share information online. Are you aiming to: Generate Leads: Capture potential clients’ information through forms, contact requests, or email sign-ups.
In that case, you also need to be aware of whether the dataprotection rules are not violated. Source: Drones and DataProtection What should companies/people who use drones do to be in compliance with privacy regulations? Once again, it depends on the type of drone and the purpose you use it for.
Our top five European dataprotection developments from January are: UK ransomware reporting proposals. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. DeepSeek was given 20 days to provide the requested information. UK ICO acts on cookie compliance. These developments are covered below.
For example, in 2020, the DataProtection Authority of Hamburg imposed a 35.3 In particular, specific details about the lives of some employees of H&M (illnesses, medical diagnoses, religious beliefs, and family problems) were comprehensively recorded and stored as information on a network drive. 6 (1) (a) of GDPR Art.
Every day, more and more companies face the problem of personal dataprotection. As companies are increasingly scrutinised for proper dataprotection, it’s worth paying close attention to the latest best practices to avoid dealing with the potential negative consequences of a data breach.
Therefore, individual states took matters into their own hands and passed local laws to protect the privacy of their residents. In this article, we will review who needs to know the new rules of the US legislation, when exactly they will come into force and what obligations these laws provide.
state to mandate that attorneys take continuing legal education courses in cybersecurity, privacy and dataprotection. New York has become the first U.S. The order creates two types of cybersecurity training, one focused on ethics and the other on practice.
Not only are law firms storing more data, but since the pandemic has forced us all to become increasingly mobile, keeping clients’ sensitive information safe is even more challenging. 11 Tips for Effective Law Firm DataProtection As a law firm, protecting your clients' sensitive information should be at the top of your priority list.
On 29 March 2023, the UK Information Commissioner’s Office (“ICO”) published updated Guidance on AI and dataprotection (the “Guidance”) following “requests from UK industry to clarify requirements for fairness in AI”. AI has been a strategic priority for the ICO for several years.
On 3 October 2023, the UK Information Commissioner’s Office organised its annual DataProtection Practioner’s Conference 2023 (DPPC 2023). This year its focus was on Cybersecurity – a topic that concerns organisations across the board. Here are the takeaways from the DPPC 2023 (the event sessions available here ).
On March 13, 2023, the CNIL published a statement announcing that it reminded these two organizations of their legal obligations under the French dataprotection framework. Another requirement is that patients participating in the research must receive all the information mandated by Art.
Candidate, 2025 No one wants to be left holding the bag after a break-in, but for chief information security officers (CISOs), the risk of liability is ever-present. Tasked with overseeing a firms cybersecurity posture, CISOs stand on the front lines of a corporations digital defense.
But in Latin America, no, perhaps there are, in some jurisdictions, regulations related to dataprotection, but that's not necessarily what we are referring to. All that technology offers to the new generations, they have access to information. If I'm not wrong, the latest was Peru. Nowadays, it is much easier.”
Representative actions: In light of the CJEU ruling that a violation of the controller’s information obligations can be subject to a representative action, businesses should consider the potentially increased risk of litigation following GDPR breach allegations and how to respond.
EDPB “Consent or pay” models: Businesses operating large online platforms should consider the European DataProtection Board’s recent opinion indicating that “consent or pay” models are unlikely to be GDPR-compliant.
India’s Digital Personal DataProtection Bill 2023 was introduced in Parliament on 3 August 2023. Once passed, the law will govern how businesses collect and use individuals’ data. What data is covered? Personal data, i.e., data about an individual that can identify them. What else should fiduciaries do? (a)
Our top-five European dataprotection developments from August are: Uber fined for personal data transfer: The Dutch DataProtection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., without sufficient safeguards. ICO proposes £6.09
Our top five European dataprotection developments from May are: UK guidance on ransom payments: The UK NCSC and various insurance industry bodies co-published guidance on key considerations for ransomware payments. 22, then there must be sufficient human-involvement in that processing for it to be GDPR-compliant.
Our top five European dataprotection developments from June are: Non-material damage under GDPR: The CJEU clarified the scope of compensation for non-material damage in the context of identity theft and data subjects’ fear that their personal data had been exposed. These developments, and more, are covered below.
Definition of personal data 1.2. Rights of data subjects 1.4. Privacy concepts and roles Technologies, most impacting on privacy and dataprotection 2.1. Social media advertising, based on personal data 2.2. PRIVACY PROTECTION IN THE MODERN WORLD 1.1. Such an identifier is personal data.
Dataprotection & AI: In particular: (i) the French CNIL published its first set of guidance on GDPR compliance when developing AI tools; and (ii) the UK ICO issued a preliminary enforcement notice against Snap over its AI chatbot, alleging that Snap had not adequately assessed the privacy risks posed to child users of the tool.
The controller was also fined €9,000 for not having the proper contact information for the DPO in its privacy policy, and for using cookies without user consent. These developments, and more, covered below.
Key takeaways from March include: CNIL data security practice guide: The French DPA published an update of its data security practice guide for dataprotection officers, chief information security officers, computer scientists and legal experts. These developments, and more, are covered below.
A detailed clause-wise analysis of the Digital Personal dataProtection Bill 2023 On 7 August 2023, the Lok Sabha passed the Digital Personal DataProtection Bill, 2023. It will soon be introduced in the Rajya Sabha and likely become a law in a couple of days. Read the analysis here.
Key takeaways this April include: UK children’s dataprotection focus continues: Businesses may wish to review policies and procedures for dealing with children’s data in light of recent UK ICO fines and guidance, especially to ensure that terms of use are adequately enforced.
On 19 June 2023, the Information Commissioner’s Office (ICO) has released new Guidance on Privacy-Enhancing Technologies (PETs) for DataProtection Compliance. Understanding PETs PETs are software and hardware systems that can help minimize use of personal data use while maximizing information security.
GDPR one-stop-shop: Businesses wishing to take advantage of the GDPR one-stop-shop system should take note of a new digest, published by the European DataProtection Board, which analyses the decisions made by so-called Lead Supervisory Authorities in this context.
Introduction In our previous articles , we have already drawn your attention to the Brazilian dataprotection legislation which is quite similar to the General DataProtection Regulation (GDPR). Also, the ANPD has shared a new form which should be used for sending security incident reports by a data controller.
For example, the Garante notes the need to incorporate dataprotection by design and by default principles within any AI systems used in the healthcare space. In particular, the paper recommends the use of internal data access controls, regular auditing of data security measures, and the use of dataprotection impact assessments.
A dataprotection officer ( DPO ) is a specialist who helps companies ensure compliance with international dataprotection laws. In a nutshell, the DPO is a key person who helps the company in all business processes to ensure compliance with the dataprotection law.
They raise various questions under regulatory and dataprotection and data security laws. The DiGA Regulation imposes specific dataprotection and data security requirements on health apps (in addition to safety, functionality, quality and interoperability requirements). 26 of the GDPR.
Even though the lack of privacy measures will have the same data leakage, IoT developers still shall take all appropriate actions to protect the personal data of its users. Internet of Things and General DataProtection Regulation. Is it applicable? For sure, yes. Lets look separately at each of the major aspect.
As we covered here , last October, the CNIL fined Clearview AI €20 million for various dataprotection violations, including “intrusive and massive” data processing without consent or a valid legitimate interest. Nonetheless, businesses that transfer personal data to the U.S. These developments, and more, covered below.
On 21 June 2023, at the close of a roundtable meeting of the G7 DataProtection and Privacy Authorities, regulators from the United States, France, Germany, Italy, United Kingdom, Canada and Japan published a joint “Statement on Generative AI” (“Statement”) (available here ).
Following a number of complaints, the European DataProtection Supervisor (‘EDPS’) decided that the SRB shared pseudonymized personal data with the consulting firm without informing the affected individuals of this sharing. Before sharing the responses, SRB replaced the name of each respondent with a code.
UK ICO updates guidance to clarify requirements for fairness in AI What happened : The UK ICO has updated its existing Guidance on AI and dataprotection following requests from industry to clarify requirements for fairness in AI. Norwegian DataProtection Authority fines medical device company c.$240,000
The Summer 2023 Edition of the quarterly IT & DataProtection Newsletter by Reed Smith Germany has just been released: English version German version This edition covers the following topics: New adequacy decision for EU-U.S. data transfers CJEU: Requirements for GDPR damage claims CJEU: Lawfulness of processing in case of Art.
On 3 October 2023, the UK Information Commissioner’s Office (“ ICO ”) finalized its Employment practices and dataprotection − Monitoring workers guidance (“ Guidance ”) to account for new types of work, including work from home, and the use of more sophisticated technologies for monitoring.
However, the personalized advertising ecosystem relies heavily on the personal data of users, raising questions about dataprotection and privacy requirements. So, what should businesses take into account to comply with dataprotection requirements?
ChatGPT (Generative Pre-trained Transformer) — is a chatbot based on AI, developed by the US laboratory OpenAI, which gives information and answers to users’ requests. Regardless of the proven practical benefits of AI in different fields, its use has some risks for users’ privacy and dataprotection. Violation of Art.
Countries like Italy initially blocked ChatGPT's use, later reinstating it with promises of increased transparency and dataprotection. The Ibero-American DataProtection Network (RIPDP) warns of the risks associated with using AI services like those developed by OpenAI, L.L.C.,
What to do : A UK business that wishes to transfer personal data to the US under the data bridge should go to the DPF List , search for the US organisation in question, and confirm they are signed up to the “UK Extension”. data transfers. Two areas that have been stressed previously in the dataprotection compliance context.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content