Loading

Category: GDPR

Page 6

Protection of health data: new section on AEPD website

The AEPD has launched a new section on its website containing information and resources specific to the protection of health data.   The Spanish Agency for Data Protection (AEPD) recently published a new web space in the Areas of Interest section on its website, to facilitate consultation and disseminate information on the processing of health

Recorded telephone conversations for the establishment of a contract

CNIL has published guidance on the establishment of contacts via recorded telephone conversations.    In the establishment of a contract, it is sometimes necessary to record a telephone conversation as proof of the formation of the contract. Under the law, this is permitted where necessary. Therefore, in order for an organisation  to lawfully record telephone

Medical data breach leads to major fine from CNIL

Earlier this month, the CNIL imposed a fine of €1.5 million after a medical data breach affecting nearly 500,000 people revealed a company’s security flaws.   Early last year, a major data breach affecting nearly 500,000 people was reported. The breach involved information including users’ surnames, first names , social security numbers, names of their

New cookie consent popup launched by Google following CNIL fine

Google is rolling out a new cookie consent pop up, after receiving a fine from the CNIL under the EU GDPR.   Google recently shared a preview of its new cookie consent popup. This new popup will initially be available on YouTube in France. However Google has expressed that it plans to roll out the

Record fine imposed by the Dutch DPA

A record fine was imposed on the Tax and Customs Administration by the Dutch DPA for multiple GDPR violations.    The Dutch Data Protection Authority has imposed a fine of 3.7 million euros on the Tax and Customs Administration due to years of unlawful processing of personal data in their Fraud Signalling Facility. According to

Danish bank fined for failure to delete the data it no longer needed

The Danish SA has proposed a fine, and had Danske bank reported to police officials, after the bank reportedly neglected to have data deleted.    The Danish Supervisory Authority has filed a police report against Danske Bank and proposed a fine on the bank, of €1.3 million, according to this report from the EDPB. This

Fine from the Dutch DPA for requesting ID for erasure requests

A Company received a fine from the Dutch DPA for the collection of excessive data.    The Dutch Data Protection Authority has imposed a fine of €525,000 on DPG Media according to this EDPB report. The media company was fined for requesting a copy of subjects’ identification to confirm their identity before honoring their right

New agreement on EU-US data transfers

For companies which depend on cross border data transfers, some needed relief may come in the form of a new agreement on EU-US data transfers.  The European Union and the U.S. recently announced that they had reached an agreement  “in principle” on a new framework for cross-border data transfers. This is expected to bring some

Clearview AI fined and ordered to remove data

Clearview AI fined by the Italian SA after various GDPR violations, and ordered to remove data and appoint an EU representative.   The company Clearview AI, has been fined by yet another EU watchdog, according to this report from the EDPB. The Italian SA has also ordered the company to delete the data of Italians

Record fine by Hellenic DPA

Unlawful data processing and a personal data breach has led to a record fine by Hellenic DPA on two telecommunications companies.   An investigation into a personal data breach has resulted in two companies being hit with fines for €6 million and €3.25 million respectively. COSMOTE and OTE were fined for various GDPR  violations after