News & Analysis as of

Data Protection Authority

Stikeman Elliott LLP

Recent Biometrics Decisions from Québec’s Data Protection Authority: Five Key Takeaways

Stikeman Elliott LLP on

Two recent decisions by Québec’s data protection authority, the Commission d’accès à l’information (the “CAI”), should serve as cautionary tales for any business contemplating the deployment of biometric information...more

Alston & Bird

Belgian Data Protection Authority Issues Updated Guidance on Direct Marketing Rules

Alston & Bird on

On March 10, 2025, the Belgian Data Protection Authority (BDPA) updated its 2020 guidance on the processing of personal data for direct marketing purposes (see the updated guidance here in French and in Dutch)....more

Sheppard Mullin Richter & Hampton LLP

Don’t Forget the EU: Italy Issued First GenAI Fine of €15 Million Alleging GDPR Violations 

At the end of 2024 the Italian Data Protection Authority issued a 15 million euro fine in the first generative AI-related case brought under GDPR. According to Garante (the Italian authority), OpenAI trained ChatGPT with...more

Clark Hill PLC

Right To Know - January 2025, Vol. 25

Clark Hill PLC on

Cyber, Privacy, and Technology Report - Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed....more

MoFo Tech

Strengthened AI Oversight in the Netherlands

MoFo Tech on

EU countries will need to designate supervisory authorities (SAs) for the EU AI Act by August 2025. Contrary to GDPR, for example, a single country is allowed to appoint multiple AI SAs. Furthermore, an SA could be appointed...more

Ballard Spahr LLP

Netflix Fined by Dutch Regulator for Privacy Violations

Ballard Spahr LLP on

The Dutch Data Protection Authority (the “Dutch DPA”) issued a €4.75 million (approximately $5 million USD) fine on Netflix in connection with a data access investigation that started in 2019. The investigation arose out of...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

Mexico’s Federal Government Initiates Process to Eliminate Autonomous Data Privacy Authority

Mexico’s new government has initiated the process for eliminating autonomous institutes, including the National Institute for Transparency, Access to Information and Protection of Personal Data (INAI)....more

K&L Gates LLP

Navigating the Intersection of Data Scraping and Artificial Intelligence–A Global Data Protection Authorities Take

K&L Gates LLP on

In alignment with the ongoing concerns from several European data protection authorities publishing guidelines on data scrapping (i.e., the Dutch DPA, the Italian DPA and the UK Information Commissioner’s Office), the Global...more

DLA Piper

VIETNAM, MALAYSIA AND INDONESIA: What You Need to Know About the New SE Asia Data Protection Laws

DLA Piper on

It’s the turn of South-East Asian countries to update their data protection laws. Here is our summary of the proposed new data protection laws in Vietnam, Malaysia and Indonesia. Organisations are advised to update their data...more

Goodwin

Irish Data Protection Commission fines LinkedIn Ireland EUR 310 million for GDPR violations

Goodwin on

On October 24, 2024, the Irish Data Protection Commission (DPC) issued a press release announcing its EUR 310 million fine of LinkedIn over the platform’s use of member personal data in breach of the EU’s General Data...more

Ius Laboris

Using Fingerprints for Time Recording May Violate GDPR

Ius Laboris on

In a recent decision, the Litigation Chamber of the Belgian Data Protection Authority (DPA) indicated that it is unlikely that valid consent to the processing of biometric data can be given in the context of an employment...more

A&O Shearman

EU and UK Data Protection Regulatory Trends so far in 2024: a focus on international data transfers

A&O Shearman on

This series of blogs rounds up some of the key data protection regulatory trends we have seen during 2024, focused on the EU and UK. 2024 has seen behavioural advertising and cookies continue to dominate the agenda of...more

Pillsbury - Consumer Protection Dispatch

GDPR Enforcement: Lessons from Recent Data Privacy Penalties

Recent decisions by the French data protection authority (CNIL) have highlighted the importance of GDPR compliance, particularly in the areas of data retention, consent for processing sensitive personal data, and marketing...more

Alston & Bird

EDPB Adopts Opinion on the Use of Processors and Sub-processors

Alston & Bird on

On October 7, 2024, the European Data Protection Board (“EDPB”) adopted an opinion on obligations following from the use of processors and sub-processors (the “Opinion”). The EDPB is the body that seeks to ensure harmonised...more

Goodwin

Navigating New CNIL Sanctions: What You Need to Know

Goodwin on

The Commission Nationale de l’Informatique et des Libertés (CNIL) is an independent French administrative regulatory body whose mission is to ensure that the collection, storage, and use of personal data comply with data...more

DLA Piper

EU: CJEU Confirms That Legitimate Interests Can Cover Purely Commercial Interests

DLA Piper on

Introduction - The subject of “legitimate interests” and in particular whether they can be “purely commercial” has been a topic of front and center stage debate in the Netherlands for some time. The Dutch data protection...more

Robinson+Cole Data Privacy + Security Insider

CPPA’s Cooperation with International Data Protection Authorities

Across Europe and other countries, there are numerous data protection authorities with differing goals and enforcement powers. Until 2020, when the California Privacy Rights Act (which amended the California Consumer Privacy...more

Hogan Lovells

CJEU clears the air, Dutch DPA’s interpretation of legitimate interests is too strict

Hogan Lovells on

On 4 October 2024, the Court of Justice of the European Union (CJEU) published its long-awaited judgement in case C-621/22 (KNLTB), which clarifies that purely commercial interests may not be categorically excluded from...more

Fisher Phillips

Brazil’s New International Data Transfer Rules Could Impact Your Multinational Business: What You Need to Know and Your 6-Step...

Fisher Phillips on

New rules just took effect in Brazil regulating international data transfers, and employers doing business in the country must take note. Covered data processing agents – such as companies in Brazil that transfer data to...more

Fisher Phillips

Netherlands Imposes Record-Breaking Data Privacy Fine on Uber: 4 Key Steps Companies Can Take to Ensure Compliance

Fisher Phillips on

Dutch data privacy officials recently imposed a staggering penalty on Uber – €290 million ($324 million) – for allegedly breaching the European Union’s comprehensive data privacy and security law. This groundbreaking fine is...more

DLA Piper

UK: Data Protection Authority Issues Reprimand to Gambling Operator for Unlawfully Processing Personal Data

DLA Piper on

On 16 September 2024, the UK’s data protection authority, the Information Commissioner’s Office (ICO), issued a reprimand against Sky Betting and Gaming (SkyBet) for unlawfully processing people’s data through advertising...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

Supply Chain Attacks in the UK: Reducing Risk and Preparing for Upcoming Legal Changes

Effective information security is no longer just dependent on an organisation’s own internal cybersecurity controls. The UK Information Commissioner’s Office (ICO) highlights that third-party service providers are processing...more

Alston & Bird

Belgian Data Protection Authority Publishes Guidance on the Interplay between the GDPR and the AI Act

Alston & Bird on

On 19 September 2024, the Belgian Data Protection Authority (DPA) issued new Guidance on the interplay between the recently adopted EU Regulation on Artificial Intelligence (the AI Act) and the General Data Protection...more

Hogan Lovells

Dutch DPA’s fine decision suspended by Dutch court amidst “(commercial) legitimate interest-controversy”

Hogan Lovells on

Once again, a Dutch district court has recalled a decision of the Dutch Data Protection Authority (Dutch DPA) for its too strict interpretation that purely commercial interests cannot be legitimate interests under Article...more

Barnea Jaffa Lande & Co.

Board of Director’s responsibility for data security in a company

The Israeli Privacy Protection Authority recently published a binding directive addressing the board of director’s responsibilities for the fulfillment of a company’s obligations prescribed in the Privacy Protection...more

815 Results
 / 
View per page
Page: of 33

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide