Latest Posts › Cybersecurity

Share:

New Zealand Privacy Commissioner: Companies Need To Be Fully Transparent About Data Processing

Click to accept – not always good enough, says the New Zealand Privacy Commissioner. Companies need to be fully transparent about their data processing practices and take steps to ensure that this is conveyed to the...more

How To Count To 30: UK ICO Sets Timeline For Responding To Data Subject Requests

Following a decision from the Court of Justice of the EU, the UK Information Commissioner’s Office changed its guidance on how to calculate the GDPR 30-day time limit for data subject requests....more

US Senators Raise Concerns About EdTech Data Privacy

“U.S. Senators Dick Durbin (D-IL), Ed Markey (D-MA), and Richard Blumenthal (D-CT) Friday, August 16, 2019, sent letters to numerous education technology (EdTech) companies inquiring about data collection practices on...more

CISO White Paper On CCPA Compliance Guides Cybersecurity Leaders In Retail And Hospitality

CISO members of the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) published a white paper to help cybersecurity leaders in retail and hospitality prepare for compliance with the California Consumer...more

Romanian Data Protection Authority Fines Company For Inadequate Notice Of Video Surveillance

Privacy notices are required under the European Union’s General Data Protection Regulation even if your data processing is video surveillance/CCTV. The Romanian Data Protection Authority issued a fine against a company...more

Life, Libra And The Pursuit Of Data Protection

The UK Information Commissioner’s Office (ICO) has joined data protection authorities from around the world in calling for more openness about the proposed Libra digital currency and infrastructure....more

Bahrain’s New Data Privacy Law Took Effect On August 1

Under the Bahrain Personal Data Protection Law (PDPL), which came into effect on August 1, 2019, organizations need to obtain consent from customers in order to collect, process, store and use their personal information for...more

German Court: Internal Recorded Statements And Notes Are Personal Data And Must Be Disclosed

The Higher Regional Court of Cologne Germany has held that internal recorded statements, conversation notes or telephone notes constitute personal data and copies of them must be disclosed in response to a data access...more

Hellenic Data Protection Authority Issues Opinion On Employee Data

The Hellenic DPA has issued an opinion regarding the appropriate legal basis for processing employee data under GDPR: Consent should be used as the legal basis only where the other legal bases do not apply....more

EU Court Of Justice Issues Long-Awaited Decision On Facebook Likes In Fashion ID Matter

A Facebook “like” is actually more like “in a [Joint Controller] relationship” status, says the Court of Justice of the EU in a long awaited decision in the Fashion ID matter. At issue: The legal framework surrounding...more

French Regulator Fines Auto Insurance Company For Failing To Prevent Web Crawling

Web crawling and data protection: CNIL has issued a 180,000 EUR fine against a provider of automobile insurance policies for failure to adequately protect data in violation of GDPR, specifically citing disallowing web...more

European Commission Releases Its Assessment Of GDPR Year One

The European Commission has published a report looking at the impact of the EU data protection rules, and how implementation can be improved further....more

FTC Commissioner Rohit Chopra Issues Dissent On Facebook Settlement

“The decision to impose documentation requirements, rather than bright line rules, represents a significant departure from how the government traditionally aims to protect the public. It is akin to if federal regulators,...more

FTC Issues Landmark $5 Billion Fine Against Facebook

Big Picture Takeaways: Facebook faces many detailed requirements for internal and external governance and oversight with extensive reporting requirements...more

Italian Data Protection Authority Levies Warning Against Company Loyalty Program Promo

Italian Data protection Authority, Garante privacy, ordered a company that did not acquire granular consent for marketing from members of its loyalty programs to: (i) stop processing personal data for marketing purposes...more

Which Cookies Are ‘Strictly Necessary?’ The UK’s Information Commissioner’s Office Provides Guidance

Strict is for cookie, that’s good enough for me. The United Kingdom’s Information Commissioner’s Office highlights “strictly necessary” cookies: Strictly necessary cookies are cookies which are essential, not just nice...more

CNIL, ICO Offer Differing Approaches To Analytics Cookies

Analytics cookies in the crossfire. Different approaches set forth in the CNIL Guidance and in the ICO cookie guidance. CNIL – Set list of terms to qualify for an exemption from the need to obtain consent....more

Dutch Hospital Fined Under GDPR For Medical Records Access Lapses

The Dutch Data Protection Authority has levied a fine of 460,000 euros on Haga Hospital for insufficient security following an investigation revealing that dozens of hospital staff had unnecessarily checked the medical...more

EDPB Opinion Provides Guidance On Controller-Processor Agreements Under GDPR

The European Data Protection Board (EDPB) has issued an opinion on the standard contractual clauses proposed by the Denmark Data Protection Authority that contains important takeaways for drafting and negotiating of all...more

EDPB Opinion Details Lead Supervisory Authority In The Event A Main Establishment Changes Locations

The European Data Protection Board has issued an opinion on lead supervisory authority in the event of a change of location of the main establishment of an organization....more

Why Every M&A Deal Should Include Data Privacy Due Diligence

Milk, meat, fruits, breads … and data protection. These are the new food groups for your M&A deal. Just 24 hours after the notice of intent to fine British Airways 183 Million GBP, the UK ICO issued an intent to fine...more

British Airways Facing Major Fine Under GDPR For Data Breach

If you wait for them, the big General Data Protection Regulation (GDPR) fines will come. UK Data protection authority, ICO, announced its intent to fine British Airways 183 million GBP (1.5 percent of annual revenue) for a...more

FTC Reaches Consent Order With Sole Proprietor Over Failure To Protect Personal Information

The FTC has entered into a consent order with a sole proprietor for a failure to implement reasonable protections of personal information....more

Tips For Verifying Individual Requests For Data Access Or Deletion Under CCPA And GDPR

How do you verify the identity of an individual requesting access to their data or that data be deleted? The Dutch Data Protection Authority, Autoriteitpersoonsgegevens, offers guidance which can be helpful and instructive...more

Furniture Store Fined Under GDPR For Failing To Delete Personal Data

If you retain personal data indefinitely, or have not given thought to your retention schedule – now may be the time to take another look. The Danish Data Protection Authority has fined a furniture store 200,000 EUR for...more

221 Results
 / 
View per page
Page: of 9

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide