Loading

Category: Data Protection

The AEPD releases guidance on biometric data and GDPR

The AEPD has released guidance on biometric data to help controllers to securely process this data pursuant to the GDPR. Biometric data may have a significant degree of intrusiveness on the privacy of individuals and, if not properly processed, it may also involve high risks to their rights and freedoms. According to the AEPD, elements

Unlawfully obtaining personal data results in the prosecution of former Health Advisor

A former Health Advisor pleaded guilty to, and was prosecuted for unlawfully obtaining personal data, and was ordered to compensate his victims.    A former Health Advisor has been prosecuted for obtaining the personal data of service users, particularly patients of South Warwickshire NHS Foundation Trust. He was found guilty of accessing the medical records

Final decision on Meta Platforms delayed by Irish DPC

The Irish DPC has been forced to delay its final decision on Meta Platforms’ use of SCCs for international data transfers.    Despite several threats from the company Meta Platforms to shut down Facebook and Instagram in Europe due to concerns over the use of Standard Contractual Clauses (SCCs) for cross-border data transfers, this may

The risks associated with geolocation data: an assessment by LINC, CNIL

The “Laboratoire d’Innovation Numerique de la CNIL” or LINC in France has been assessing the risks associated with geolocation data.    France’s digital innovation laboratory, known as “Laboratoire d’Innovation Numerique de la CNIL ” or  LINC secured a geolocation database from a data broker which was supposedly anonymized. The purpose of this was to test

Fine imposed on Volkswagen by German Data Protection Commissioner for multiple GDPR violations

A recent fine imposed on Volkswagen by a German Data Protection Commissioner, for multiple GDPR violations amounted to €1.1 million.   The State Commissioner for Data Protection in the German state of Lower Saxony (LfD Lower Saxony) has imposed a fine of €1.1 million on Volkswagen Aktiengesellschaft in accordance with GDPR Article 83. The fine

Facebook cookie injunction has been dropped

CNIL has recently lifted an injunction placed on Facebook last December, regarding the company’s use of cookies.     Last December, CNIL ordered Facebook Ireland Limited to allow the use of facebook.com by users in France, in a manner that allows these users to refuse having cookies deposited on their device, just as easily as they

Inadequate security measures lead to a fine from the Danish DPA

The Danish Data Protection Authority has fined a law firm after a data breach, due to their inadequate security measures.    A law firm in Denmark has been fined over €67,000 for failing to implement basic security measures when establishing remote access to the company’s IT systems. These systems facilitated access to personal data of

Fine of €20 million from the Greek DPA

Clearview AI has recently been hit with a fine of €20 million for violating the principles of lawfulness and transparency.    A civil non-profit organisation, “Homo Digitalis” lodged a complaint against Clearview AI Inc., a facial recognition company which developed its database by scraping individuals’ images from across the web. This was lodged on behalf

Cybersecurity guide published by CNIL of France

The CNIL, in collaboration with the French government, has recently published a cybersecurity guide for French municipalities.    In recent times, cybersecurity has posed major difficulties for several communities in France. As a result, a study was conducted by Cybermalveillance.gouv.fr, a government-sponsored cybersecurity initiative, toward the end of 2021. This study was focused on communities

Data subjects’ consent is required for personalised ads – Italian SA warns TikTok

The Italian supervisory authority issues a formal warning after TikTok makes changes to its privacy policy and fails to get data subjects’ consent.    TikTok has recently made changes to its privacy policy stating that users aged above 18 would receive ‘personalised’ ads. From July 13th, users over 18 would receive ads based on profiling