Latest Posts › Data Protection Authority

Share:

What Did Ireland’s Data Protection Commissioner Say at IAPP’s Data Protection Congress?

Helen Dixon, Ireland’s Data Protection Commissioner, gave the keynote speech during the closing session of the International Association of Privacy Professionals’ Data Protection Congress in Brussels. Here are a few of...more

The Data Protection/Digital Identity Dilemma: ICO Weighs In On UK Proposal

The Information Commissioner’s position paper on the UK government’s proposal for a trusted digital identity system provides insight into the interplay between data protection and digital identity. Key Points- •Given...more

Italy’s Data Protection Authority Publishes FAQs On CCTV

Garante, the Italian data protection authority, has issued FAQ's on CCTV surveillance and data protection. Highlighting the European Data Protection Board's (EDPB) guidelines on the topic, here are some takeaways: Area of...more

Irish Data Commissioner Discusses Schrems II, Enforcement And Consent

“I worry that we are caught in a DPA (Data Protection Authority) beauty contest of who issues the bigger fine,” said Ireland Data Protection Commissioner Helen Dixon in her keynote for Daniel Solove’s Privacy+Security Academy...more

Swiss Privacy Regulator Rules U.S.-Swiss Privacy Shield Not Adequate

On the heels of the Court of Justice of the European Union’s decision in Schrems II, Switzerland’s Federal Data Protection and Information Commissioner (FDPIC) has determined that the U.S.-Swiss Privacy Shield does not meet...more

Italy: COVID-19 Pandemic Is Not Carte Blanche For Invasive Data Processing

According to Italian Data Protection Authority Garante Per La Protezione Dei Dati Personale, The COVID-19 emergency does not automatically, and in itself, represent a sufficient legal basis for particularly invasive data...more

Bailiwick Of Guernsey Contributes Its Two Cents On Schrems II

•The Bailiwick of Guernsey’s Office of Data Protection Authority has stated its position on #SchremsII: You must invest resources into ensuring appropriate safeguards are in place. •Identify if you have been relying on the...more

Spanish Data Protection Authority: Protect Personal Data Without Hindering Pandemic Response

Coronavirus and GDPR , the Spanish AEPD weighs in: •Data protection should not be used to hinder or limit the effectiveness of the measures taken by authorities in the fight against the pandemic. •Consent may not be...more

Dutch Privacy Regulator Fines Tennis Association For Selling Personal Data Without Proper Consent

Tell me, don’t sell me, the GDPR version. The Dutch Data Protection Authority (AP) has imposed a fine of 525,000 euros on tennis association KNLTB for selling personal data without proper consent....more

Belgian Data Protection Authority Releases Enforcement Priorities

The Belgian data protection authority has published for public consultation its priorities for 2019-2025....more

CNIL, France’s Data Protection Authority, Releases Strategic Road Map

In a statement of its priorities over the next year, French data privacy regulator CNIL emphasizes the importance of a balanced approach to data protection regulation....more

Dutch Cookie Check Reveals Half Of Websites Failed To Meet Permission Requirements

How compliant is that cookie in the window? The Dutch Data Protection Authority (AP) carried out a check on approximately 175 websites of web shops, municipalities and media, among other things, to determine whether they...more

Polish Data Protection Authority Fines Website For Overly Complicated Consent Withdrawal Process

The Polish data protection authority has fined ClickQuickNow €47,126.97 for violating the General Data Protection Regulation (GDPR) by requiring too difficult a process for revoking consent....more

Danish Data Protection Authority: Auto-Complete Not Prohibited By GDPR

The auto-complete function is not prohibited by GDPR, says the Danish data protection authority. The search function suggested certain search suggestions automatically including the complainant’s name....more

Sweden OKs Use Of Facial Recognition Technology By Police To ID Suspects

According to the NewEurope newspaper, “Sweden’s data protection authority has approved the use of facial recognition technology by the police, to help identify criminal suspects.”...more

Dutch Data Protection Authority Offers Its Take On ‘Legitimate Interest” Data Processing Authority

The Dutch DPA has issued guidance on the use of “legitimate interest” as a legal basis for processing data under GDPR. Key takeaways on what constitutes “legitimate”: The interest needs to be pursuant to a written or...more

Polish Regulator Fines Public Authority For Multiple GDPR Violations

The Polish data protection authority has fined a public authority 40,000 Euros for violations of GDPR including: Failure to execute Article 28 data processing agreements with its service providers....more

Latin American And Spanish DPAs Issue Joint Statement On Data Processing And Artificial Intelligence

Latin American Data Protection Authorities and the Spanish Data Protection Authority have issued a joint statement on data processing and Artificial Intelligence....more

Key Commercial Takeaways From The European Commission’s Third Annual Report On EU-U.S. Privacy Shield

The European Commission expects the U.S. Department of Commerce (DoC) to request from companies evidence of the privacy provisions of the relevant contracts with third parties to assess compliance with the onward transfer...more

Spanish DPA Fines Airline For Cookie Compliance Failures

On the heels of the Planet49 decision, the Spanish data protection authority AEPD has fined Vueling Airlines €30,000 (reduced to €18,000 for payment in full) for failure to provide a compliant cookie disclosure/consent under...more

Picture Picture On The Wall: Danish DPA Takes New Position On The GDPR Legal Basis For Posting Online Photos

The Danish Data Protection Authority has changed its position regarding the legal basis for posting pictures online under the General Data Protection Regulation (GDPR). Rather than a distinction between "situational" and...more

Belgian DPA: Requiring Customers to Allow Their ID Cards To Be Scanned To Receive Loyalty Cards Violates GDPR

Asking to read an electronic ID card as a condition for the provision of a service (issuing a rewards/loyalty card) is disproportionate and in violation of GDPR, says the Belgian data protection authority. The company was...more

Who Is Responsible Under GDPR For Putting A Data Processing Agreement In Place?

Who is responsible for putting a GDPR Article 28 Data Processing Agreement in place? Dutch Data Protection Authority, Autoreitpersoonsgegevens, says: BOTH the data controller and the data processor....more

Hamburg DPA Releases Guidelines For Google Voice Assistant

The Hamburg Data Protection Authority (DPA) laid out guidelines for Google regarding its voice assistant that may reveal what DPAs may be expecting for compliance with GDPR (and some parts may be applicable for CCPA too)...more

Romanian Data Protection Authority Fines Company For Inadequate Notice Of Video Surveillance

Privacy notices are required under the European Union’s General Data Protection Regulation even if your data processing is video surveillance/CCTV. The Romanian Data Protection Authority issued a fine against a company...more

50 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide