Latest Posts › Data Protection

Share:

How To Count To 30: UK ICO Sets Timeline For Responding To Data Subject Requests

Following a decision from the Court of Justice of the EU, the UK Information Commissioner’s Office changed its guidance on how to calculate the GDPR 30-day time limit for data subject requests....more

US Senators Raise Concerns About EdTech Data Privacy

“U.S. Senators Dick Durbin (D-IL), Ed Markey (D-MA), and Richard Blumenthal (D-CT) Friday, August 16, 2019, sent letters to numerous education technology (EdTech) companies inquiring about data collection practices on...more

CISO White Paper On CCPA Compliance Guides Cybersecurity Leaders In Retail And Hospitality

CISO members of the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) published a white paper to help cybersecurity leaders in retail and hospitality prepare for compliance with the California Consumer...more

Romanian Data Protection Authority Fines Company For Inadequate Notice Of Video Surveillance

Privacy notices are required under the European Union’s General Data Protection Regulation even if your data processing is video surveillance/CCTV. The Romanian Data Protection Authority issued a fine against a company...more

Life, Libra And The Pursuit Of Data Protection

The UK Information Commissioner’s Office (ICO) has joined data protection authorities from around the world in calling for more openness about the proposed Libra digital currency and infrastructure....more

Bahrain’s New Data Privacy Law Took Effect On August 1

Under the Bahrain Personal Data Protection Law (PDPL), which came into effect on August 1, 2019, organizations need to obtain consent from customers in order to collect, process, store and use their personal information for...more

German Court: Internal Recorded Statements And Notes Are Personal Data And Must Be Disclosed

The Higher Regional Court of Cologne Germany has held that internal recorded statements, conversation notes or telephone notes constitute personal data and copies of them must be disclosed in response to a data access...more

Belgian Data Protection Authority Weighs In On DPOs Deleting Data Subjects’ Personal Data

The Belgian Data Protection Authority holds that a Data Protection Officer (DPO) may not himself/herself delete personal information of a data subject. Doing so constitutes a violation of the General Data Protection...more

Hellenic Data Protection Authority Issues Opinion On Employee Data

The Hellenic DPA has issued an opinion regarding the appropriate legal basis for processing employee data under GDPR: Consent should be used as the legal basis only where the other legal bases do not apply....more

European Commission Seeking To Fine Spain And Greece For Failing To Transpose Data Protection Rules Into National Law

Tardiness with transposing data protection laws comes with a hefty fine. The European Commission is asking the Court of Justice of the European Union to impose financial sanctions on Greece and Spain for failing to...more

French Regulator Fines Auto Insurance Company For Failing To Prevent Web Crawling

Web crawling and data protection: CNIL has issued a 180,000 EUR fine against a provider of automobile insurance policies for failure to adequately protect data in violation of GDPR, specifically citing disallowing web...more

European Commission Releases Its Assessment Of GDPR Year One

The European Commission has published a report looking at the impact of the EU data protection rules, and how implementation can be improved further....more

FTC Commissioner Rohit Chopra Issues Dissent On Facebook Settlement

“The decision to impose documentation requirements, rather than bright line rules, represents a significant departure from how the government traditionally aims to protect the public. It is akin to if federal regulators,...more

UK Data Protection Agency Issues New Guidelines for Data Sharing

The United Kingdom’s Information Commissioners Office (ICO) has issued, for public consultation, draft guidelines for data sharing that—once adopted —will govern all controller-to-controller data sharing agreements which are...more

FTC Issues Landmark $5 Billion Fine Against Facebook

Big Picture Takeaways: Facebook faces many detailed requirements for internal and external governance and oversight with extensive reporting requirements...more

Italian Data Protection Authority Levies Warning Against Company Loyalty Program Promo

Italian Data protection Authority, Garante privacy, ordered a company that did not acquire granular consent for marketing from members of its loyalty programs to: (i) stop processing personal data for marketing purposes...more

French Privacy Regulator Releases Long-Awaited Rules For Use Of Cookies

The French privacy regulator CNIL has released guidance on how to comply with the European Union’s General Data Protection Regulation (GDPR) when using cookies and other web tracking technologies that are an integral part of...more

EDPB’s 2018 Annual Report Sheds Light On Future Guidance

The European Data Protection Board (EDPB) publishes it’s first annual report and reveals a road map for guidance to come. In 2019 and 2020, the EDPB aims to focus on data subjects’ rights, the concept of the controller and...more

Sharing Data? Key Questions To Ask According To The ICO’s Draft Guidelines

Questions to ask when sharing data between two data controllers (from the ICO Data Sharing Code of Conduct): What is the sharing meant to achieve?...more

ICO Data Sharing Code: Controller-Controller Data Sharing Agreement Checklist

Checklist for drafting your controller-controller data sharing agreement (from the ICO Data Sharing Code of Conduct now out for public consultation): What is the purpose of the data sharing initiative?...more

Dutch Hospital Fined Under GDPR For Medical Records Access Lapses

The Dutch Data Protection Authority has levied a fine of 460,000 euros on Haga Hospital for insufficient security following an investigation revealing that dozens of hospital staff had unnecessarily checked the medical...more

Conducting Video Surveillance? The EDPB Is Watching You. Here’s What It’s Looking For

The European Data Protection Board has issued guidance on the use of video surveillance. Key takeaways: The monitoring purposes of cameras should be documented in writing....more

ICO Issues Draft Guidelines For Data Sharing

The UK Information Commissioner’s Office has issued a data sharing code of conduct for public consultation. Key takeaways: When considering sharing data, assess your overall compliance with the data protection...more

EDPB Opinion Provides Guidance On Controller-Processor Agreements Under GDPR

The European Data Protection Board (EDPB) has issued an opinion on the standard contractual clauses proposed by the Denmark Data Protection Authority that contains important takeaways for drafting and negotiating of all...more

EDPB Opinion Details Lead Supervisory Authority In The Event A Main Establishment Changes Locations

The European Data Protection Board has issued an opinion on lead supervisory authority in the event of a change of location of the main establishment of an organization....more

314 Results
 / 
View per page
Page: of 13

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide