Loading

Tag: Compliance

Tag: Compliance

Using AI in recruitment: Recommendations for business owners

The ICO has published recommendations for business owners on using AI in recruitment processes lawfully and ethically.   Artificial intelligence (AI) is transforming recruitment by saving time and improving efficiency for businesses of various sizes and across industries. Businesses are using AI tools to source potential candidates, summarize CVs, as well as score applicants. However,

Cyber Resilience Act: EU Council and Parliament Approve New Cybersecurity Standards for Digital Products

EU Council and EU Parliament enhance cybersecurity for digital products with the Cyber Resilience Act, ensuring connected devices are secure before entering the market.   The European Union has taken a major step forward in enhancing cybersecurity for digital products with the adoption of the Cyber Resilience Act by the EU Council and EU Parliament.

Legitimate interest as a legal basis: Guidance from the EDPB

Controllers must ensure necessary, proportionate, processing which respects the rights of data subjects, ensuring GDPR compliance.   When processing personal data under the General Data Protection Regulation (GDPR), controllers must ensure that their actions are lawful. Specifically, if relying on Article 6(1)(f) of the GDPR, the processing must be based on a legitimate interest. This

Tech giants push for lighter AI regulations in Europe

Tech giants push for lighter AI regulations in Europe amid concerns over fines and transparency.   In a pivotal final effort, the world’s largest technology companies are urging the European Union (EU) to take a more lenient stance on regulating artificial intelligence (AI). Firms like Amazon, Google, and Meta are currently facing the looming possibility

European Commission Initiates Proceedings to Ensure Apple’s Compliance with Digital Markets Act

The European Commission has initiated proceedings to ensure Apple complies with the Digital Markets Act by providing free interoperability to third-party developers for its iOS and iPadOS platforms.   The European Commission has launched two specification proceedings to ensure that Apple meets its obligations under the Digital Markets Act (DMA). As a “gatekeeper” under the

Hong Kong’s AI model framework: the Personal Data (Privacy) Ordinance

The Hong Kong PCPD’s AI Model Framework provides guidelines for organisations using AI systems that process personal data, emphasising compliance with the PDPO.   On June 11, 2024, the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD) unveiled its Artificial Intelligence Model Personal Data Protection Framework (Model Framework). This framework serves as

The use of AI chatbots may lead to data breaches

The Dutch DPA urges businesses to be vigilant as the use of AI chatbots by employees may lead to data breaches.    Recently, the Dutch Data Protection Authority (AP) received multiple allegations of data breaches resulting from employees sharing the personal information of patients or consumers with an artificial intelligence (AI) chatbot. Companies that provide

Enforcement notices issued to two public organisations

The UK ICO has issued enforcement notices to two public bodies under the Freedom of Information Act of 2000, ordering them to address a backlog of requests from the public.    The Information Commissioner’s Office (ICO) recently took action against two public service organisations for their ongoing failures to meet fundamental Freedom of Information Act

Unlawful use of data results in significant fine for canvassing company

Unlawful use of data results in significant fine for canvassing company A company was fined by CNIL for unlawfully using data obtained from a data broker for commercial prospecting purposes.    On April 4, 2024, the French data protection authority, CNIL, imposed a significant fine of 525,000 euros on the company HUBSIDE.STORE. The fine was

Compliance for tech and retail businesses: A guide to data protection regulations

Operating a tech or retail business which requires the collection of personal information from individuals within the EU or UK requires careful consideration of compliance regulations. This is a guide to data protection regulations in the EU and UK.    Data protection is of particular  concern for businesses, especially those operating in the technology and