Missed the discussion? Catch up on the intersection of GDPR, AI, and ePrivacy

For anyone who missed it… Data protection GDPR AI ePrivacy

Read Analysis →

Speaking with Max Schrems on the future of user consent networks

1.000 registered – and counting. The “Future of User Consent” webinar of 24 Sept., where I am speaking alongside Max Schrems of noyb.eu, Romain Gauthier of Didomi and Willy Mikalef of Bird & Bird looks set to have a broad range of attendees. On the agenda are some of the top data protection, GDPR, ePrivacy […]

Read Analysis →

Live observations from the CJEU hearing on complex data processing frameworks

Really interesting hearing this morning at the CJEU, with a few pointed questions from the judges. Always a privilege to present legal and technical explanations to the Court of Justice! gdpr data protection

Read Analysis →

Moderating the executive regulatory panel on global data strategies at RAID

Panel I’m moderating at RAID: EDPB Chair Anu Talus, Luxembourg CNPD President Tine A. Larsen, Deputy Head of Data Protection Unit at the Commission’s DG Justice Karolina Mojzesowicz, MEP Brando Benifei and Gibson Dunn Partner Ahmed Baladi. Topic: “Making Tech Legislation Work in Practice Time: noon CET on Tuesday 24 September Key topics: – What […]

Read Analysis →

Why the Belgian DPA rejection of a noyb complaint is a must-read

The Belgian DPA’s newest rejection of a NOYB complaint for reasons of fictional mandates (yes, again) is a must-read for both complainants (or complainant organisations) and controllers/processors who receive complaints from representative organisations. Summary: “The method by which the complaint at the initiative of the representative seeks to raise a general predetermined practice, by addressing […]

Read Analysis →

The Belgian DPA cracks down on dark patterns and missing reject buttons

No “reject all” button? Different colours in a cookie banner? Belgian DPA orders a change, based on “dark pattern” allegations and lack of freely given consent. Readers know I have my doubts on this, due because “in the physical world” we are led to make choices all the time based on product colours (some of […]

Read Analysis →

New contract necessity questions for corporate processing referred to the CJEU

In today’s EU Official Journal, new questions submitted to the CJEU: What is “necessary” for performance of a contract under the GDPR, and can customary business practices be taken into account in this assessment? In languages such as French where gender traditionally has an influence on many words in a sentence and also on how […]

Read Analysis →

Key themes and systemic challenges within the BDPA Litigation Chamber

[Slide upload:] On Monday, at the invitation of the Belgian DPA’s Litigation Chamber, I spoke about key themes of the Litigation Chamber’s decisions over the past 5 years and about both the positive improvements in maturity of those decisions and the challenges resulting from the lack of appeals against certain decisions (leading to the creation […]

Read Analysis →

Why classifying GDPR fines as criminal penalties impacts your insurance coverage

Another important CJEU judgment! Whether GDPR administrative fines are “criminal penalties” or not is a relevant issue for both insurability and indemnification clauses (e.g. “Y agrees to indemnify and hold Z harmless for data protection violations”). Today’s CJEU’s judgment in case C-27/22 strengthens the position of those who raised concerns regarding GDPR fine insurance and […]

Read Analysis →

Moving past the generative AI hype to focus on real governance and liability

Yes, GenerativeAI is what people are talking about. Yes, it presents specific risks (notably re disinformation). But from an aigovernance and liability perspective, the risks associated with predictive/discriminative AI are just as relevant. In her speech today re the State of the European Union, Ursula von der Leyen said that we should “not underestimate the […]

Read Analysis →