Loading

Zandilli Lucien

Author: Zandilli Lucien

Transparency obligations under the EU AI Act

Under the EU AI Act, what are transparency obligations imposed upon organisations, and what requirements and implications do these obligations carry?   The EU AI Act aims to regulate the development and use of AI in the EU. One of the key elements of the proposed Act is the requirement for transparency. This means that

Biometric identification and the EU AI Act

How does the EU AI Act address biometric identification, and how do its provisions compare to those of the GDPR regarding biometric data?   Biometric identification encompasses a variety of methods for verifying an individual’s identity. It can be utilized for various purposes, such as user authentication (e.g., unlocking smartphones) or verification at border crossings

High risk AI and the EU AI Act

What AI systems fall under the “high-risk” category and what requirements do they need to comply with under the EU AI Act?    The European Union Artificial Intelligence (AI) Act, officially approved by the Council of Ministers through a voting process in May 2024, is a landmark piece of legislation that will have a profound

General-purpose AI and Systemic risk in the EU AI Act

As Europe continues to embrace the potential of general-purpose AI, it is essential that a calculated approach is taken to address the systemic risks associated with the technology.    General-purpose Artificial Intelligence (GPAI) models are ones that have a wide range of possible uses, both intended and unintended by the developers. They can be used

The new EU AI Regulation: What is it and to whom does it apply?

After final approval by the Council of the EU on May 21, 2024, the EU AI Act is set to go into effect. What does this Regulation entail, and to whom does it apply?   The EU AI Act is a legal framework that aims to regulate the development, deployment, and use of Artificial Intelligence

Right to be forgotten: how unfit data deletion protocol resulted in a fine from Dutch DPA

A company was fined by the Dutch Data Protection Agency for failure to delete data after receiving such requests, thereby violating individuals’ right to be forgotten under the GDPR.   The Dutch Data Protection Authority (DPA) has imposed a fine of 6,000 euros on a recruitment company. The company was fined for failing to delete

Data Protection and AI chatbots: Advice from the ICO

Following an investigation into the technology company Snap Inc, the ICO has published data protection advice with the use of AI chatbots.   Lately, it has become increasingly common for businesses and organisations to offer the option of an AI chatbot for website visitors and app users. Whether it be a social media chatbot, or

Guidance on the Use of Wi-Fi Tracking Technology

The AEPD has published guidance on the use of wi-fi technology in compliance with the GDPR.    In a collaborative effort to address the growing concerns surrounding Wi-Fi tracking technology, the Spanish Data Protection Agency (AEPD), in conjunction with the Catalan Data Protection Authority, the Basque Data Protection Authority, and the Transparency and Data Protection

Combat the threat of cyber attacks: A call to action from the ICO

The ICO has called on organisations to take action to combat the threat of cyber attacks, providing guidance based on 2023 data breach reports.    In light of the escalating risk of cyber threats, The Information Commissioner’s Office (ICO) is urging all organisations to strengthen their cyber security measures and safeguard the personal data under

Web Scraping is almost always unlawful under the GDPR

Under the GDPR, web scraping is almost always unlawful, except for in very few exceptional cases.    The automatic collection and storage of information from the Internet is referred to as web scraping. Through this process, a computer program automatically extracts data from the internet, for example by scanning social media platforms. Scraping involves the