The EU General Court reiterates the relative nature of personal data definitions

Personal data is a relative concept, EU General Court stresses in a new judgment – “it is necessary to put oneself in [the relevant organisation’s] position in order to determine whether the information transmitted to it relates to �identifiable persons�. The judgment reaffirms the conditional findings of the CJEU in its Breyer judgment (which found […]

Read Analysis →

Comparing ICO and EDPB guidance on pseudonymisation

My reading right now – the ICO recognising (unlike the EDPB) the relative nature of personal data and the moving scale of identifiability. This guidance on Pseudonymisation & Anonymisation looks more promising than what the EDPB had published! Link: https://lnkd.in/eN7DacRV GDPR privacy data protection

Read Analysis →

EDPB accountability: are Guidelines and Opinions challengeable?

Are Guidelines of the European Data Protection Board “challengeable acts”, and could you attack them before the General Court of the EU? What about Art. 64 GDPR Opinions of the EDPB? The Advocate General’s Opinion in the WhatsApp v EDPB case (re EDPB Binding Decisions) suggests that the answer could be “yes” regarding those Art. […]

Read Analysis →

Challenging AG Szpunar: flaws in the “Inteligo Media” Opinion

Not convinced by the reasoning of CJEU Advocate General Szpunar in the Inteligo Media case on the notion of “direct marketing”. Why? (i) The reasoning on Art. 13(2) of the ePrivacy Directive (ePD) seems flawed. The AG suggests that “Article 13(2) [ePD] deals comprehensively with the question of consent” (para. 50) and that its lex specialis […]

Read Analysis →

EDPB accountability: could Binding Decisions be challenged?

A step towards EDPB accountability? Advocate General sides with WhatsApp in CJEU case on whether EDPB binding decisions can be challenged directly. Sure, it’s “just” an AG Opinion, but it’s well researched and argued. What it says: 1. What is a challengeable act? The AG says that some circumstances are *irrelevant* to assessing whether an […]

Read Analysis →

Market Court overturns DPA decision on abuse of rights

NOYB-instigated Belgian DPA decision overturned on appeal for abuse of data subject rights. Key excerpt below, but paragraphs 29-38 of the judgment of the Market Court will be of interest to anyone facing data protection / GDPR complaints that are coordinated by litigating organisations – though the same reasoning may not be accepted in all […]

Read Analysis →

NIS2 compliance: 7 strategic takeaways for global business

7 points after giving another in-depth presentation to global businesses on the path to NIS2 compliance (with a flavour of DORA and GDPR): (i) Having a broad enough team (“multidisciplinary” / “multi-stakeholder” / however you wish to call it) is not easy for many organisations, irrespective of their size (this is nothing new, but it […]

Read Analysis →

EDPB Pseudonymisation Guidelines: urgent need for review

Readers will know that some of the EDPB’s positions in its pseudonymisation guidelines are unconvincing or absolutist by nature. Now, IAB Europe and other associations in the digital ecosystem have submitted their feedback on these guidelines, and the feedback shows the acute need for a review of those guidelines. This response is well worth the […]

Read Analysis →

Belgian DPA’s direct marketing recommendation: critical analysis

Belgian DPA’s direct marketing recommendation: great first attempt, but questionable positions included. First thoughts: [The BDPA has published a new direct marketing recommendation (replacing one of 5 years ago), and it’s a very good document. A public consultation is open until 10 May, and I hope some comments will deal with its shortcomings.] – Claim […]

Read Analysis →

Key lessons from Italy’s temporary ban on OpenAI and ChatGPT processing

The news from Italy and its temporary limitation of the processing by OpenAI of personaldata of Italian residents (re chatgpt and more) begs a few questions: 1) Did they just order that without prior contact? 2) Did they consider the OpenAI “privacy policy” – which I can see easily on the login/sign-up screen – was […]

Read Analysis →