Loading

Tag: Compliance

Tag: Compliance

Coolblue was fined €40,000 for violating GDPR by unlawfully processing personal data via cookies

Coolblue was fined €40,000 by the Dutch DPA for unlawfully processing personal data via cookies, by failing to obtain explicit consent.   The Dutch Data Protection Authority (AP) recently imposed a €40,000 fine on Coolblue for unlawfully processing personal data via cookies in 2020. The violation stemmed from Coolblue’s failure to obtain explicit consent from

Draft Measures for the Certification of the Protection of Personal Information Exported Abroad published by China’s CAC

The Cyberspace Administration of China (CAC) released the draft Measures for Cross-Border Data Transfer which clarify Personal Information Protection Certification.   On January 3, 2025, the Cyberspace Administration of China (CAC) released a draft document titled “Measures for the Certification of the Protection of Personal Information Exported Abroad” (hereinafter, draft measures). These measures, comprising 20

A year of Data Protection Law: 2024 review

Throughout this year, the EU and the UK have experienced several notable developments in data protection. In this article, we will highlight some of the key milestones of 2024.   The year began with an ever relevant reminder, advising UK organisations on the transfer of personal data to the US under the UK GDPR, stressing

A Polish catering company was fined €54,600 for a data breach after an employee lost a flash drive with sensitive data.

A Polish catering company was fined €54,600 for failing to protect personal data after an employee lost a flash drive containing sensitive information, revealing vulnerabilities in the company’s data security. The Polish Data Protection Authority (UODO) recently fined Res-Gastro M. Gaweł Sp. k., a catering company in Kolbuszowa, Poland, €54,600 for failing to implement adequate

Using AI in recruitment: Recommendations for business owners

The ICO has published recommendations for business owners on using AI in recruitment processes lawfully and ethically.   Artificial intelligence (AI) is transforming recruitment by saving time and improving efficiency for businesses of various sizes and across industries. Businesses are using AI tools to source potential candidates, summarize CVs, as well as score applicants. However,

Cyber Resilience Act: EU Council and Parliament Approve New Cybersecurity Standards for Digital Products

EU Council and EU Parliament enhance cybersecurity for digital products with the Cyber Resilience Act, ensuring connected devices are secure before entering the market.   The European Union has taken a major step forward in enhancing cybersecurity for digital products with the adoption of the Cyber Resilience Act by the EU Council and EU Parliament.

Legitimate interest as a legal basis: Guidance from the EDPB

Controllers must ensure necessary, proportionate, processing which respects the rights of data subjects, ensuring GDPR compliance.   When processing personal data under the General Data Protection Regulation (GDPR), controllers must ensure that their actions are lawful. Specifically, if relying on Article 6(1)(f) of the GDPR, the processing must be based on a legitimate interest. This

Tech giants push for lighter AI regulations in Europe

Tech giants push for lighter AI regulations in Europe amid concerns over fines and transparency.   In a pivotal final effort, the world’s largest technology companies are urging the European Union (EU) to take a more lenient stance on regulating artificial intelligence (AI). Firms like Amazon, Google, and Meta are currently facing the looming possibility

European Commission Initiates Proceedings to Ensure Apple’s Compliance with Digital Markets Act

The European Commission has initiated proceedings to ensure Apple complies with the Digital Markets Act by providing free interoperability to third-party developers for its iOS and iPadOS platforms.   The European Commission has launched two specification proceedings to ensure that Apple meets its obligations under the Digital Markets Act (DMA). As a “gatekeeper” under the

Hong Kong’s AI model framework: the Personal Data (Privacy) Ordinance

The Hong Kong PCPD’s AI Model Framework provides guidelines for organisations using AI systems that process personal data, emphasising compliance with the PDPO.   On June 11, 2024, the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD) unveiled its Artificial Intelligence Model Personal Data Protection Framework (Model Framework). This framework serves as