Loading

Tag: Data Protection

Tag: Data Protection
Page 14

GDPR-CARPA certification mechanism adopted by CNPD

Luxembourg adopted the GDPR-CARPA verification mechanism  becoming the first country to introduce a certification mechanism under the GDPR.   The National Data Protection Commission of Luxembourg (CNPD) adopted its GDPR-CARPA (Certified Assurance-Report based Processing Activities) certification mechanism last month. This will be known as the first certification mechanism under the GDPR to be adopted on

Data sharing for charities: guidance from CNIL

CNIL recently published guidance relating to data sharing for charities for the purposes of prospecting.   CNIL recently published guidance relating to data sharing for charities for the purposes of prospecting. According to CNIL, these guidelines are geared towards any association or foundation appealing to the generosity of the public to receive donations, which wishes

Google Analytics custom features do not make transfers legal, according to CNIL

CNIL has announced that even with the use of Google Analytics custom features, transfers are still not legal.    CNIL recently announced that even with the use of Google Analytics custom features, transfers are still not legal in the absence of a transfer deal between Europe and the US. This announcement was added in the

The concept of “data exporter” clarified by the Danish DPA

In the light of the Schrems II judgment by the CJEU, questions relating to the concept of “data exporter” have been clarified by the Danish DPA.     Since the CJEU’s Schrems II judgment, the Danish Data Protection Agency has received an increasing number of questions relating to the transfer of personal data to third countries.

New data strategy introduced in the UK

New data strategy introduced in the UK to drive innovation and improve efficiency in the health sector.    The UK recently announced a new data strategy for health data, which focuses on 7 principles to harness the data-driven power and innovation exhibited during the pandemic, and use it to improve the future of healthcare. These

Dark patterns in social media platform interfaces

Dark Patterns are defined by the European Data Protection Board (EDPB), as “interfaces and user experiences implemented on social media platforms that lead users into making unintended, unwilling and potentially harmful decisions regarding the processing of their personal data”. These dark patterns seek to influence user behaviour on those platforms, hindering their ability to make conscious

Bank fined by Hungarian SA for unlawful data processing

Budapest Bank fined by Hungarian SA, for unlawful data processing as the controller’s use of AI systems lacked transparency.    Budapest Bank was recently fined by the Hungarian SA due to the fact that the data controller (Budapest Bank) performs automated analyses of customers’ satisfaction using AI on customer service phone calls. This data processing

Clearview fined by the ICO for unlawful data collection and processing

Clearview AI Inc was fined over £7.5 million, and ordered to delete photos and data of UK residents from its database.    The ICO has fined Clearview AI Inc £7,552,800 for using the images of people, including those in the UK, that were scraped from the web and social media profiles to create their global

Uber fined by Italian DPA for lack of transparency

A major privacy violation has landed Uber companies fined by Italian DPA, Garante, €2 million and €120,000 respectively.    A privacy violation affecting over 1.5 million individuals has landed Uber two fines of 2 million and 120 thousand euros each, from Italian DPA Garante, according to this report. The company, Uber BV has a European

Google was fined by the AEPD and ordered to come into compliance after Lumen Project data transfers

Google was fined by the AEPD and ordered to come into compliance after  GDPR violations relating to Lumen Project data transfers.    The AEPD has issued a decision in the case against Google LLC, which states that the company has committed two very serious GDPR violations. The Spanish Data Protection Agency decided to impose a