CEDPO Conference: DMA-GDPR Guidelines and consistency

GDPR & DMA at CEDPO: Another great discussion (and a mini bit of sparring too) with Gwendal Le Grand, together with Borja Martínez Corral and our moderator Natascha Gerlach. Readers know how often I get to write critically about the European Data Protection Board, and my first thoughts on their DMA-GDPR Guidelines drafted together with […]

Read Analysis →

SRB judgment and EU-U.S. transfers: CEDPO reflections

Nothing like a last minute extra – just stepped in to moderate a great discussion with the excellent Herke Kranenborg and Yann Padova after their two co-speakers were unfortunately prevented from attending the CEDPO Conference (no, it wasn’t meant to be a “manel”). Great exchanges on the pragmatism and complications of the SRB judgment of […]

Read Analysis →

Analyzing the critical agenda items for the EDPB forum on AI models

Going through the European Data Protection Board’s list of key topics for its stakeholder event on 5 November on AI models (thanks EDPB for confirming my participation!), I hope all attendees will have had the chance to carefully read the following materials (in their entirety): – My in-depth article on the two key topics, i.e. […]

Read Analysis →

Essential guidance for navigating adtech, identifiers, and GDPR enforcement

If you are (interested) in AdTech, privacy-enhancing technologies, GDPR enforcement, identifiers, etc., you’ll want to attend this IAPP workshop on 19 November 2024: “AdTech and Privacy: Prospects and Pitfalls” (half-day intensive workshop, 9 to 12.30 CET). Led by Dr. Sachiko Scheuing (FEDMA / Acxiom), featuring Elena Turtureanu (Adform), Nathalie Laneret (Criteo), Matthias Matthiesen (TripleLift), Enrico […]

Read Analysis →

DMA-GDPR Guidelines: why non-gatekeepers should take notice

Not a gatekeeper? No matter – the DMA-GDPR Guidelines of the EDPB & European Commission are important: the EDPB’s input aims to ensure consistency in the interpretation of the GDPR. I’ll go through all 55 pages before next week’s great CEDPO panel with the EDPB’s own Gwendal Le Grand, Borja Martínez Corral and our moderator […]

Read Analysis →

Pseudonymisation and cyber attacks: addressing article 4(1) GDPR

SRB: Do potential cyber attacks matter when assessing whether pseudonymisation is sufficient to make personal data cease to be “personal” from the perspective of a recipient? Short answer: no, they shouldn’t. Why is that? In my extensive analysis of the SRB judgment and its practical implications ( https://lnkd.in/e2eNmGUP ), I did not write much about […]

Read Analysis →

Why everyday computer interactions shouldn’t trigger ePrivacy consent rules

Several posters seem to agree with the EDPB’s new ePrivacy Guidelines. “Of course every computer interaction is covered”. I disagree, but let’s imagine they are right. Isn’t it still problematic that *almost nothing is exempt from consent* nowadays in the eyes of most EDPB members? First, the basics. Under Art. 5(3) of the ePrivacy Directive […]

Read Analysis →

A side-by-side comparison of the draft versus final ePrivacy guidelines

So, here’s the comparison between the EDPB’s new ePrivacy Guidelines and the version that was up for public consultation end of 2023. As you can see, not much has changed. The fundamental issues that affected the previous version (competence, overbroad interpretation that doesn’t match the actual meaning of words or the intention of the legislator, […]

Read Analysis →

Multidisciplinary approaches to AI Act compliance

AI Act compliance is complex, so it’s good when tools can help you along the way. It was a privilege to develop such a tool for one client. There are plenty of amazing resources available to help organisations, such as (to name just a couple) a great tool by David Rosenthal of Visscher, fantastic infographics […]

Read Analysis →

How to register for the upcoming EDPB stakeholder event on AI models

Here’s the registration form for the EDPB’s stakeholder event on AI models: https://lnkd.in/enBa5dHq 500-character limit for an explanation of why your organisation should take part More on this in my in-depth article on AI models and GDPR: https://lnkd.in/eYXabSfs data protection privacy

Read Analysis →