AI models and the notion of “personal data”: a relativistic approach

While I disagree with his conclusions, do read the post of Damien Desfontaines re the BfDI’s public consultation on personal data in AI models. Pity that it ends on 31 August, with the EU Court of Justice’s SRB judgment coming out on 4 September. I hope the BfDI takes a relativistic approach to the notion […]

Read Analysis →

ICO online advertising consultation: the case for PETs and flexibility

One month into the summer consultation process (thanks EU Commission & others!), a few thoughts on the ICO’s online advertising consultation. There is still one month to respond to the “call for views” from the UK Information Commissioner’s Office (soon “Information Commission”) regarding its approach to regulating online advertising: https://lnkd.in/evScibNJ I cannot stress enough the […]

Read Analysis →

Can businesses demand physical ID cards for GDPR identification checks?

A recent Amsterdam District Court judgment on whether ID cards can be requested for data subject identification raises interesting points re GDPR and data minimisation – and how controllers can reach a satisfactory level of identification. Context: – A controller (C) had 2 processes for verifying the identity of data subjects making a request: (i) […]

Read Analysis →

Why businesses cannot afford to dismiss the corporate risk of deepfakes

Scarily powerful – don’t dismiss the risk of deep fakes for your company. With now tools like Deep Live Cam (“real time face swap and one-click video deepfake with only a single image”) making the rounds, it is imperative for you to educate *everyone* in your organisation about good reflexes regarding both cybersecurity and AI. […]

Read Analysis →

Google Tag Manager and the consent trap: a call for nuance

A months-old German court decision on Google Tag Manager has resurfaced here, with many claiming the GDPR applies to every use of GTM or similar tools. A bit of nuance may be useful: – First, that claim that the use of IP addresses and other identifiers = always processing of personal data? Let’s first wait […]

Read Analysis →

Digital Fairness Act: balancing consumer protection and innovation

So the Digital Fairness Act consultation process begins, with lofty yet potentially flawed goals. The Commissions wishes to notably: – “[prevent] traders from using dark patterns and other unfair techniques that pressure, deceive and manipulate consumers online – “[address] problematic personalisation practices, including situations where consumer vulnerabilities are targeted for the purposes of personalised advertising […]

Read Analysis →

Is the CrowdStrike IT outage truly a personal data breach under the GDPR?

My takeaways from the 100+ comment discussion following my post on whether the Crowdstrike incident is a “personal data breach” under the GDPR: 1. There are clearly two camps on this. I didn’t expect this level of opposition between two visions of what is a personal data breach. 2. One camp adheres to the views […]

Read Analysis →

The Hamburg DPA aligns on tracking tokens and behavioral identification

Glad to see the Hamburg DPA going in a similar direction as what I was suggesting in the post below: tokens should not be viewed as personal data. Even at the level of the output, “the mere presence of plausible personal information in LLM output is not conclusive evidence that personal data has been memorized, […]

Read Analysis →

Good & bad in judgment on Meta AI training & personal data (legitimate interests, sensitive data) + new French & German guidance

Does training of AI systems involve the processing of personal data, and is it permitted under the GDPR? These were the two fundamental questions that I have already looked into in two previous articles: On the date of that second article, the Cologne Higher Regional Court (the Oberlandesgericht Köln – the Cologne HRC) delivered a […]

Read Analysis →

ePrivacy precedent: critiquing the CJEU’s interpretation of spam

One to watch. Based on the summary of the hearing, this looks like a continuation of the CNIL’s Orange decision and of the CJEU’s SwTL v eprimo case – if so, I fear we are going down a path of bad legal precedent after bad legal precedent. As I have previously commented, the eprimo judgment […]

Read Analysis →