Latest Posts › EU

Share:

Could We Ditch the EU AI Act?

Is the EU AI Act a Jenga piece that can easily be removed from the regulatory tower? Here are some key points from the “AI Regulation – a critical comment” workshop at the Alpine Privacy Days Conference, courtesy of Florent...more

What Is an AI System? The EU Offers a Formula

The European Commission recently issued a formula for identifying Artificial Intelligence Systems: Machine-based system- Designed to operate with varying levels of autonomy- •Some degree of independence of actions from...more

Do App Permissions Satisfy Requirements for Valid Consent for the Purpose of GDPR?

App permissions do not satisfy the requirements for valid consent for the purpose of GDPR because they lack sufficient detail and granularity, according to the Commission Nationale de l’Informatique et des Libertés (CNIL)....more

How Anonymous Is Your AI Model?

There is more to learn from the European Data Protection Board’s recent opinion on AI models. I previously reviewed the EDPB’s take on what the consequences could be for the unlawful processing of personal data in the...more

How Legitimate Is Your Interest When It Comes To Developing AI Models?

The European Data Protection Board’s recent opinion on AI models can be useful in several ways. Last week, I covered EDPB’s take on what the consequences could be for the unlawful processing of personal data in the...more

What Happens If an AI Model Is Developed With Unlawfully Processed Personal Data

The European Data Protection Board recently issued an opinion on AI models, shedding light on what the consequences could be for the unlawful processing of personal data in the development phase of an AI model on the...more

Cookie Banners Shouldn’t Be Confusing and Other Life Lessons

The Commission Nationale de l’Informatique et des Libertés in France recently took action against misleading cookie banners as subverting true consent. This is not a new issue, though, with the Federal Trade Commission, the...more

GDPR Question: What Do You Do With a US Court Order?

So you have a court order from a U.S. court seeking data? In the words of Shania Twain, “That don’t impress me much!” The European Data Protection Board recently issued an opinion on cross border transfers pursuant to Art 48...more

Employees Are People Too — And Not Just in California

I recently had the pleasure of speaking with the Atlantic County Bar Association. Here are some of the key takeaways from my presentation: Employees are “consumers” under the California Consumer Privacy Act. It requires:...more

Uber’s 290 Million Euro Fine: What You Need to Know

What can U.S.-based and multi-national companies learn from the 290 million euro fine Autoriteit Persoonsgegevens, the Dutch Data Protection Authority, issued against Uber in connection with the processing of Dutch driver...more

The Colorado Artificial Intelligence Act: What You Need to Know

Colorado recently enacted its Artificial Intelligence law, launching a new era of state AI laws. What do you need to know? •The bill is effective February 1, 2026 and enforceable by the Attorney General. •This is a...more

A Helpful Guide on Data Processing Consent

The Office of the Data Protection Authority of the Bailiwick of Guernsey has issued concise guide on the definition of consent. This is helpful not only for GDPR, but also for understanding and implementing consent under the...more

Are Test Answers Personal Data?

Are test questions and answers personal data that needs to be provided pursuant to an access request? A German court recently weighed in, providing some good insight regarding both GDPR and U.S. state data privacy laws....more

A Cookie Is Not Just a Cookie: EDPB Issues Draft Guidelines on Art 5(3) ePrivacy Directive

A cookie is not just a cookie, according to the European Data Protection Board. It’s also similar technologies, and access and Internet of Things (IOT). Here are some key takeaways you need to know from the EDPB’s draft...more

U.S. Attorney Generals Take on AI

In a letter to the National Telecommunications and Information Administration, attorneys generals from 21 states, the District of Columbia and the U.S. Virgin Islands recently weighed in on Artificial Intelligence...more

Ireland’s Data Protection Commission and Meta: What You Need to Know

Ireland’s Data Protection Commission has fined Meta Ireland 1.2 billion EUR. While you have probably heard about that, there is much, much more to this case and the larger Schrems II cross border saga. Here is what you...more

Ireland’s Data Protection Commission, Meta and Art 49 Derogations: An Overview

Ireland’s Data Protection Commission has fined Meta €1.2 billion. What, however, did the commission say in the case about using Art 49 derogations for transfers to the U.S.? An overview: I will discuss the Meta decision...more

GDPR After 5 Years: Where Does the Regulation Stand?

The GDPR journey has not been wonderful. NOYB has 800 cases out and the enforcement process is difficult because procedural law is different in different countries....more

EDPB Issues Opinion on the EU-US Data Privacy Framework: Key Takeaways

The European Data Protection Board (EDPB) has issued a long-awaited opinion on the EU-US Data Privacy Framework. Here are some key takeaways: The scope of the exemptions to the adherence to the principles, including on the...more

What Should Companies Do Following the Draft US Adequacy Decision?

The United States is adequate, at least according to a draft opinion on the EU-U.S. Data Privacy Framework. Here is a look at what the opinion says, and what U.S. companies involved in EU-U.S. transfers should be doing now....more

What Did the EDPS Have to Say About FTC Rulemaking on Commercial Surveillance?

The European Data Protection Supervisor (EDPS) has submitted comments to FTC Rulemaking on commercial surveillance. Here are some key takeaways. IOT devices: •It is important that data from the Internet of Things are...more

Make Sure You Have a Good Data Retention Plan. You Need It.

You need a data retention plan. No really. And not just in the European Union. In California too. Commission Nationale de l’Informatique et des Libertés (CNIL) has fined messaging platform Discord 800,000 EUR for (non...more

Caveat Employer? In the EU and California, Employers Must Beware!

Employers should have in place a process to delete former employees’ information – including public facing information and photos – to meet their retention limitation requirements, according to the Belgian Data Protection...more

Is Everything Sensitive Data?

After the recent Court of Justice of the European Union decision on sensitive inferences that can be drawn from the name of your spouse, it is fair to ask: Is everything sensitive data (special category data)?...more

Data Protection Professionals Like it Hot: 7 Hot Topics and Trends in Data Privacy Today

Please take note! 1.SchremsII and cross border transfers: Risk based, wherefore art thou? With the Google Analytics, Google Fonts, Amazon AWS, Google Workspace other cases, the SchremsII and DPA guidance is piling up....more

146 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide