A recent decision by Hungary’s Data Protection Authority (NAIH) offers a deceptively modest outcome, a €5,000 fine, but sends a much stronger signal on the evolving expectations around data minimization
Continue Reading Data Minimization Under Scrutiny: Hungarian DPA Decision Signals Risk for U.S. EmployersGDPR
GDPR Processing Begins at the Data Request: What a Spanish Supreme Court Decision Signals for U.S. Privacy Compliance
Data processing begins even before the data is received. A recent ruling of the Supreme Court of Spain clarifies the scope of GDPR obligations and the implications extend to the…
Continue Reading GDPR Processing Begins at the Data Request: What a Spanish Supreme Court Decision Signals for U.S. Privacy ComplianceEU Regulators are coming directly after non-EU processors for GDPR violations
I’m a non-EU data processor, no EU regulator is coming after me right? Wrong, says French regulator, CNIL, in new decision fining SaaS provider 1 Million EUR!
At issue in…
Continue Reading EU Regulators are coming directly after non-EU processors for GDPR violations“Smile, You’re on Camera”: Meets GDPR and U.S. Privacy Law in the retail context
A Bavarian court held that a store’s private security guard lawfully used a body-worn camera under Article 6(1)(f) GDPR to protect property, maintain order, and ensure staff safety, in a…
Continue Reading “Smile, You’re on Camera”: Meets GDPR and U.S. Privacy Law in the retail context12 Myths About Automated Decision-Making Systems, per the EDPS
The European Data Protection Supervisor (EDPS) recently issued a TechDispatch on Automated Decision Making.
Here is what you need to know:
Part 1: 12 Myths About Automated Decision-Making (ADM) Systems…
Continue Reading 12 Myths About Automated Decision-Making Systems, per the EDPSDo App Permissions Satisfy Requirements for Valid Consent for the Purpose of GDPR?
App permissions do not satisfy the requirements for valid consent for the purpose of GDPR because they lack sufficient detail and granularity, according to the Commission Nationale de l’Informatique et…
Continue Reading Do App Permissions Satisfy Requirements for Valid Consent for the Purpose of GDPR?How Anonymous Is Your AI Model?
There is more to learn from the European Data Protection Board’s recent opinion on AI models.
I previously reviewed the EDPB’s take on what the consequences could be for the…
Continue Reading How Anonymous Is Your AI Model?California’s CPPA Partners with France’s CNIL to Safeguard Personal Information
Is California going to start policing CCPA violations like the French police GDPR violations?
The California Privacy Protection Agency (CPPA) and France’s Commission Nationale de l’Informatique et des Libertés (CNIL)…
Continue Reading California’s CPPA Partners with France’s CNIL to Safeguard Personal InformationThe Elements of Profiling
- This is the analysis of information about/regarding a person.
- The definition is
Don’t Expect to Easily Claim ‘Disproportionate’ Effort When Responding to US Data Access Requests
U.S. companies thinking about falling back on “disproportionate” effort for access requests under the new U.S. privacy laws because they require compiling too many documents should think again.
The Berlin…