Tag: personal data

Tag: personal data

Toyota Bank Polska fined €132,000 for GDPR breaches including failure to ensure the independence of its DPO and lack of documented profiling practices

Poland’s data protection authority has fined Toyota Bank Polska €132,000 for failing to ensure the independence of its DPO and neglecting to document profiling practices and conduct a DPIA. On 18 December 2024, the Polish Data Protection Authority (UODO) imposed an administrative fine of €132,000 on Toyota Bank Polska S.A. for violations of key GDPR

CNIL concludes public consultation on draft recommendation for location data from connected vehicles

CNIL concludes public consultation regarding a proposed recommendation to provide guidance on GDPR compliance for the processing of location data from connected vehicles. The French data protection authority, CNIL, recently closed its public consultation on a draft recommendation addressing the use of location data generated by connected vehicles. Launched on March 25, 2025, the consultation

$1.375 Billion Google Settlement Highlights Growing Scrutiny of Unlawful Data Practices

A $1.375 billion Google settlement highlights the growing legal focus on unlawful geolocation tracking, incognito data collection, and biometric surveillance by tech companies. A recently announced $1.375 billion settlement between Google and the State of Texas marks a major development in the ongoing scrutiny of how Big Tech companies handle users’ personal data. The resolution,

Dutch DPA Calls for Stronger Business Oversight of Algorithms and AI Use

The Dutch Data Protection Authority identifies significant gaps in business awareness and control over algorithmic personal data processing. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) has identified a significant gap in the Dutch business community’s preparedness for dealing with algorithms and AI systems that process personal data. According to a survey of 1,600

EDPB Guidelines on Blockchain and GDPR Compliance: Key Considerations for Data Controllers

The EDPB has issued draft guidelines to clarify how the GDPR applies to blockchain technologies. The European Data Protection Board (EDPB) has issued draft Guidelines to provide clarity on the application of the GDPR to blockchain-based processing operations. While blockchain technologies offer benefits in transparency, decentralisation, and resilience, their technical characteristics pose considerable challenges to

ICO’s 2025 Anonymisation Guidance: Turning Personal Data into a Privacy Asset

Explore how the ICO’s March 2025 guidance helps organisations use anonymisation to unlock data value while meeting UK GDPR compliance and strengthening accountability. As the prevalence of data-driven innovation increases, organisations must ensure that this data is being handled with the necessary level of responsibility, which for some data means that anonymisation is necessary. On

Pseudonymisation guidelines adopted by the EDPB, along with steps to enhance collaboration with competition authorities

The EDPB released new guidelines on pseudonymisation and a position paper on data protection and competition law to strengthen GDPR compliance. In January 2025, the European Data Protection Board (EDPB) made a significant regulatory announcement during its plenary meeting, by adopting new pseudonymisation guidelines, as well as issuing a position paper on the interplay between

The ICO provides tips on data protection

Prioritizing data protection for your business in 2025: ICO provides tips As you undertake business operations this year, there’s one crucial element that shouldn’t be overlooked—data protection. Getting data protection right from the start will not only ensure compliance with data privacy laws but also help you build trust with customers, suppliers, and partners alike.

CNIL imposed a fine of €240,000 on KASPR for multiple GDPR violations

CNIL of France has imposed a fine of €240,000 on KASPR for multiple GDPR violations linked to the unlawful collection and retention of personal data.  KASPR, a company offering a Chrome extension to extract professional contact details from LinkedIn and other online sources, has faced regulatory action for its practices. Through its database of approximately

Coolblue was fined €40,000 for violating GDPR by unlawfully processing personal data via cookies

Coolblue was fined €40,000 by the Dutch DPA for unlawfully processing personal data via cookies, by failing to obtain explicit consent.   The Dutch Data Protection Authority (AP) recently imposed a €40,000 fine on Coolblue for unlawfully processing personal data via cookies in 2020. The violation stemmed from Coolblue’s failure to obtain explicit consent from