Loading

Category: Data Protection

WP29 Guidelines on adequacy of data protection by third countries

According to the GDPR provisions, the transfer of personal data to countries outside the EU or international organisations is permitted only under the requirement that their legal framework satisfies an adequate level of data protection. Our Blog Editor Vasiliki Antoniadou explains WP29 Guidelines on adequacy of data protection by third countries under GDPR. The existence

GDPR consent explained by WP29

GDPR consent requirements, one of the most difficult GDPR areas for businesses to comply with, have been further explained by Article 29 Working Party. This is our choice of highlights from the new GDPR Consent Guidelines. Imbalance of power does not in all cases preclude valid GDPR consent Although cases of consent by employee to

Our client Salve on their fertility app – and health data privacy

The team of brilliant founders Charlie, Elin and Alex explain how Salve app is changing fertility treatments and why is patient health data privacy an important aspect of it. 1. How did the idea for the Salve app emerge? A close friend works in fertility and told me how broken communication was between the clinic

GDPR Data Protection by Design and by Default – in practice

GDPR data protection by design and by default is not an additional layer of data security but rather a test of the company’s commitment to protect personal data not just from third parties but also from its own commercial interests, management and employees. GDPR privacy by design and by default provision builds on the idea

GDPR right to be forgotten as seen by online personalities

GDPR right to be forgotten will soon enable EU citizens to request online search engines and social media to erase their past online activity and even chase third parties who have replicated it. We explore how GDPR right to be forgotten is seen through the eyes of three people running their successful personal online businesses.

GDPR profiling and automated decision making WP29 Guidelines

Our blog editor Vasiliki Antoniadou explains the latest Article 29 Working Party GDPR profiling guidelines in relation to automated decision making – and how they might affect your business. The technological evolution and specifically the development of big data analytics, IoT and artificial intelligence permit automated processing of personal data in order to evaluate certain

GDPR Data Breach Notification WP29 Guidelines

GDPR data breach notification obligation requires the adoption of appropriate technical and organisational measures in order to ensure the safeguarding of personal data during processing. Since the assessment of the risk degree is not always unequivocal, the Article 29 Data Protection Working Party (WP29) has recently adopted GDPR data breach Guidelines. When unauthorised or unlawful processing

Felicia Yap on iDiaries and our online memory delusions

In Felicia Yap’s speculative world of ‘Yesterday’ , people’s short-term memories are finite – so everyone records their daily experiences on electronic diaries. The Guardian’s Rising Star for Fiction 2017 chats to Aphaia Blog about our online memory delusions. The EU law, including General Data Protection Regulation ( GDPR ) , grants individuals the ‘Right to be Forgotten’ ,

GDPR after Brexit

Our blog editor Vasiliki Antoniadou explores the exchange of position papers between the UK and the European Commission regarding the data protection and GDPR after Brexit . As the time for the withdrawal of the United Kingdom from the European Union approaches, the necessary and time consuming negotiation processes in the legislative field commence. Considering that the

GDPR to do list this autumn

GDPR starts to apply less than a year from now – which seems like a reason enough to panic for many data-driven organisations who have so far not addressed the transition to GDPR. But instead of panicking, it may be better to have a look at our autumn GDPR to do list. 1. Map your