Latest Posts › General Data Protection Regulation (GDPR)

Share:

German Court Rules Company Can Disclose Shareholder Information To Other Shareholders

GDPR does not prohibit a company from disclosing to one company shareholder, information identifying other shareholders in the same company, says the Higher Regional Court of Munich. The legal basis under GDPR is that the...more

Belgian DPA: Requiring Customers to Allow Their ID Cards To Be Scanned To Receive Loyalty Cards Violates GDPR

Asking to read an electronic ID card as a condition for the provision of a service (issuing a rewards/loyalty card) is disproportionate and in violation of GDPR, says the Belgian data protection authority. The company was...more

Handling Confidential Internal Documents When Faced With A GDPR Data Subject Access Request

Do I have to disclose documents with confidential internal correspondence, and comments from my staff as part of a GDPR data subject access request? The Court of The Hague says “Yes, you do.”...more

Who Is Responsible Under GDPR For Putting A Data Processing Agreement In Place?

Who is responsible for putting a GDPR Article 28 Data Processing Agreement in place? Dutch Data Protection Authority, Autoreitpersoonsgegevens, says: BOTH the data controller and the data processor....more

German Court Rules Sweepstakes Participation Conditioned On Receiving Ads Amounts To Consent Under GDPR

If you condition participation in a sweepstakes on receiving advertising on a particular topic from the provider of the sweepstakes or from other third parties — this is still valid consent under GDPR, says the Higher...more

How To Count To 30: UK ICO Sets Timeline For Responding To Data Subject Requests

Following a decision from the Court of Justice of the EU, the UK Information Commissioner’s Office changed its guidance on how to calculate the GDPR 30-day time limit for data subject requests....more

Romanian Data Protection Authority Fines Company For Inadequate Notice Of Video Surveillance

Privacy notices are required under the European Union’s General Data Protection Regulation even if your data processing is video surveillance/CCTV. The Romanian Data Protection Authority issued a fine against a company...more

Belgian Data Protection Authority Weighs In On DPOs Deleting Data Subjects’ Personal Data

The Belgian Data Protection Authority holds that a Data Protection Officer (DPO) may not himself/herself delete personal information of a data subject. Doing so constitutes a violation of the General Data Protection...more

Hellenic Data Protection Authority Issues Opinion On Employee Data

The Hellenic DPA has issued an opinion regarding the appropriate legal basis for processing employee data under GDPR: Consent should be used as the legal basis only where the other legal bases do not apply....more

European Commission Seeking To Fine Spain And Greece For Failing To Transpose Data Protection Rules Into National Law

Tardiness with transposing data protection laws comes with a hefty fine. The European Commission is asking the Court of Justice of the European Union to impose financial sanctions on Greece and Spain for failing to...more

French Regulator Fines Auto Insurance Company For Failing To Prevent Web Crawling

Web crawling and data protection: CNIL has issued a 180,000 EUR fine against a provider of automobile insurance policies for failure to adequately protect data in violation of GDPR, specifically citing disallowing web...more

European Commission Releases Its Assessment Of GDPR Year One

The European Commission has published a report looking at the impact of the EU data protection rules, and how implementation can be improved further....more

UK Data Protection Agency Issues New Guidelines for Data Sharing

The United Kingdom’s Information Commissioners Office (ICO) has issued, for public consultation, draft guidelines for data sharing that—once adopted —will govern all controller-to-controller data sharing agreements which are...more

French Privacy Regulator Releases Long-Awaited Rules For Use Of Cookies

The French privacy regulator CNIL has released guidance on how to comply with the European Union’s General Data Protection Regulation (GDPR) when using cookies and other web tracking technologies that are an integral part of...more

Dutch Hospital Fined Under GDPR For Medical Records Access Lapses

The Dutch Data Protection Authority has levied a fine of 460,000 euros on Haga Hospital for insufficient security following an investigation revealing that dozens of hospital staff had unnecessarily checked the medical...more

Conducting Video Surveillance? The EDPB Is Watching You. Here’s What It’s Looking For

The European Data Protection Board has issued guidance on the use of video surveillance. Key takeaways: The monitoring purposes of cameras should be documented in writing....more

ICO Issues Draft Guidelines For Data Sharing

The UK Information Commissioner’s Office has issued a data sharing code of conduct for public consultation. Key takeaways: When considering sharing data, assess your overall compliance with the data protection...more

EDPB Opinion Provides Guidance On Controller-Processor Agreements Under GDPR

The European Data Protection Board (EDPB) has issued an opinion on the standard contractual clauses proposed by the Denmark Data Protection Authority that contains important takeaways for drafting and negotiating of all...more

European Data Protection Board Covers Wide Range Of Issues At 12th Plenary Session

The European Data Protection Board’s addressed some interesting issues during its 12th Plenary Session on July 9 and 10: Guidelines on how the GDPR applies to the processing of personal data when using video devices....more

Why Every M&A Deal Should Include Data Privacy Due Diligence

Milk, meat, fruits, breads … and data protection. These are the new food groups for your M&A deal. Just 24 hours after the notice of intent to fine British Airways 183 Million GBP, the UK ICO issued an intent to fine...more

British Airways Facing Major Fine Under GDPR For Data Breach

If you wait for them, the big General Data Protection Regulation (GDPR) fines will come. UK Data protection authority, ICO, announced its intent to fine British Airways 183 million GBP (1.5 percent of annual revenue) for a...more

Tips For Verifying Individual Requests For Data Access Or Deletion Under CCPA And GDPR

How do you verify the identity of an individual requesting access to their data or that data be deleted? The Dutch Data Protection Authority, Autoriteitpersoonsgegevens, offers guidance which can be helpful and instructive...more

Furniture Store Fined Under GDPR For Failing To Delete Personal Data

If you retain personal data indefinitely, or have not given thought to your retention schedule – now may be the time to take another look. The Danish Data Protection Authority has fined a furniture store 200,000 EUR for...more

UK Information Commissioner’s Office Reports On Data Privacy Concerns With Adtech/Real Time Bidding

The UK’s ICO has issued a report on data protection in the adtech process of real time bidding (RTB). RTB relies on the potential advertiser seeing information about you....more

Questions In Swedish DPA’s Spotify Data Access Request Inquiry Can Aid GDPR, CCPA Compliance Efforts

The Swedish Data Protection Authority has initiated an inquiry into how song streaming provider Spotify handles data access requests....more

232 Results
 / 
View per page
Page: of 10

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide