Loading

Category: GDPR

Page 4

Fine imposed on Volkswagen by German Data Protection Commissioner for multiple GDPR violations

A recent fine imposed on Volkswagen by a German Data Protection Commissioner, for multiple GDPR violations amounted to €1.1 million.   The State Commissioner for Data Protection in the German state of Lower Saxony (LfD Lower Saxony) has imposed a fine of €1.1 million on Volkswagen Aktiengesellschaft in accordance with GDPR Article 83. The fine

Inadequate security measures lead to a fine from the Danish DPA

The Danish Data Protection Authority has fined a law firm after a data breach, due to their inadequate security measures.    A law firm in Denmark has been fined over €67,000 for failing to implement basic security measures when establishing remote access to the company’s IT systems. These systems facilitated access to personal data of

Data subjects’ consent is required for personalised ads – Italian SA warns TikTok

The Italian supervisory authority issues a formal warning after TikTok makes changes to its privacy policy and fails to get data subjects’ consent.    TikTok has recently made changes to its privacy policy stating that users aged above 18 would receive ‘personalised’ ads. From July 13th, users over 18 would receive ads based on profiling

CNIL imposes €1 million fine for several infractions related to data subject’s rights and transparency obligations

€1 million fine imposed by CNIL on an energy company for several GDPR violations related to data subject’s rights and transparency obligations.    After receiving several complaints regarding the difficulties encountered by users in having their requests for access to their data and opposition to receiving calls for the purposes of direct marketing fulfilled by

Legal basis is required for audio surveillance, according to the Polish SA

The Polish SA says a legal basis is required for audio surveillance and has fined the Warsaw Centre for Intoxicated Persons for a lack thereof.   The Polish Supervisory Authority was recently informed that between 2016 and 2021, the Warsaw Centre for Intoxicated Persons recorded sound through its surveillance system, without a legal basis to

Digital Markets Act and Digital Services Act officially approved in the EU

The digital markets act and digital services act have officially been approved in the EU and are being implemented.   EU lawmakers recently approved the Digital Markets Act (DMA), and Digital Services Act (DSA), which will help control unfair advantage by tech giants such as Google, Amazon, Apple, Facebook and Microsoft.  Companies may now face

GDPR-CARPA certification mechanism adopted by CNPD

Luxembourg adopted the GDPR-CARPA verification mechanism  becoming the first country to introduce a certification mechanism under the GDPR.   The National Data Protection Commission of Luxembourg (CNPD) adopted its GDPR-CARPA (Certified Assurance-Report based Processing Activities) certification mechanism last month. This will be known as the first certification mechanism under the GDPR to be adopted on

Data sharing for charities: guidance from CNIL

CNIL recently published guidance relating to data sharing for charities for the purposes of prospecting.   CNIL recently published guidance relating to data sharing for charities for the purposes of prospecting. According to CNIL, these guidelines are geared towards any association or foundation appealing to the generosity of the public to receive donations, which wishes

Google Analytics custom features do not make transfers legal, according to CNIL

CNIL has announced that even with the use of Google Analytics custom features, transfers are still not legal.    CNIL recently announced that even with the use of Google Analytics custom features, transfers are still not legal in the absence of a transfer deal between Europe and the US. This announcement was added in the

The concept of “data exporter” clarified by the Danish DPA

In the light of the Schrems II judgment by the CJEU, questions relating to the concept of “data exporter” have been clarified by the Danish DPA.     Since the CJEU’s Schrems II judgment, the Danish Data Protection Agency has received an increasing number of questions relating to the transfer of personal data to third countries.