Loading

Zandilli Lucien

Author: Zandilli Lucien
Page 19

Data subject right of access: Guidelines by the EDPB

The EDPB recently released guidelines on data subject right of access in the context of the GDPR.   The right of access aims to provide individuals with sufficient, transparent and easily accessible information about the processing of their personal data. This is expected to add greater ease to the process of data subjects exercising their

Declaration on digital rights and principles proposed by the European Commission

The Commission has proposed a declaration of rights and principles to the European Parliament and Council that is intended to guide digital transformation in the EU.   The European Commission has prepared a draft declaration on digital rights and principles with the aim of providing a clear reference point on the kind of digital transformation

Explore alternatives to Google Analytics: advice from the Norwegian DPA

With multiple European authorities ruling against the use of this service, the Norwegian DPA suggests that companies explore alternatives to Google Analytics.    In a recent blog, we covered why the use of Google Analytics (and Stripe) by the European Parliament was considered a violation of the Court of Justice’s (CJEU) “Schrems II” ruling on

Fine imposed by Italian DPA for aggressive telemarketing

Fine imposed by Italian DPA on Enel Energia, amounting to €26.5 million for aggressive telemarketing.   The Italian DPA has imposed a fine of €26.5 million on Enel Energia for aggressive telemarketing according to this recent report. After hundreds of reports and complaints about unwanted promotional calls to customers from Enel Energia, Garante, the Italian

How subcontractors can reuse data: CNIL outlines specific conditions

How subcontractors can reuse data: this is possible only under specific conditions, which CNIL has outlined with specific context.   Under the GDPR, there are several conditions which need to be met in order for subcontractors to reuse data provided to them by the data controller. French regulator; CNIL has outlined the context under which

EDPS reprimands European Parliament for use of Google Analytics

Illegal EU-US data transfers by the European Parliament lead to sanction from EDPS    Due to a complaint made approximately one year prior, the European Parliament has been sanctioned by the EDPS over illegal EU-US data transfers, among other violations. On a COVID-19 testing site, the use of Google Analytics and Stripe (both US companies)

Employee right of access: how does it work?

The CNIL of France has released an article explaining the employee right of access under the EU GDPR.   Article 15 of the GDPR gives individuals the right to request a copy of any of their personal data from a data controller. This also applies when the data controller is the individual’s employer. CNIL has

International Data Protection Committee established by Danish DPA

An international data protection committee has been established by the Danish DPA to protect Danish interests regarding international data protection.   The Danish DPA has established a special committee with the aim of giving the Authority’s stakeholders more and better insight into the international data protection work done by the Data Inspectorate. It will also

The UK’s new Information Commissioner; John Edwards

The UK’s new Information Commissioner; John Edwards was recently appointed for a five year term starting January 3rd.    John Edwards formally began his five year stint as the UK’s new Information Commissioner on Monday, January 3rd 2022, according to this statement released by the UK Government. Edwards ushers in the new year beginning this

CLEARVIEW AI ordered to delete photos by French DPA; CNIL

CLEARVIEW AI, ordered to delete photos by the French DPA after investigation revealed unlawful collection and processing of photos from the Internet.   CLEARVIEW AI, and the facial recognition software the company produces were first reported to the CNIL in May of 2020. This led to an investigation which uncovered two GDPR infractions; the unlawful