Is your DPO overworked? Why missing authority requests risks a heavy fine

Is your DPO overworked? Do certain requests from authorities fall through the cracks? You could be in breach of the GDPR, says the Belgian DPA in its newest decision. In this particular case, a DPO was working three days per week, and was the only person to have access to a particular e-mail address to […]

Read Analysis →

How modern corporate lawyers balance roles as AI advisors and technical users

Lawyers can both be AI advisors (legal implications) and users of machine learning / generativeai / applied statistics / … systems. Tomorrow we will be helping members of the Flemish Bar Association understand some of the key things to look out for and reflexes to have – both for themselves and for their own clients. […]

Read Analysis →

A practical checklist for vendor and supplier risk management under NIS2

Practical checklist: good practices for vendor/supplier risk management inspired by GDPR, NIS2, Data Governance Act and DORA. The underlying question: what good practices do these EU laws highlight and transform into legal obligations in certain cases, and how can we combine them? This checklist is *not* a comprehensive list of best practices, but it should […]

Read Analysis →

Why the public debate around high-risk AI safety is ignoring structural privacy

Suddenly general audiences in the EU are hearing about AI legislation in the news, and high-risk systems present a risk to… privacy (really, that’s the only angle being put forward in some news outlets). As if the GDPR didn’t contain anything that can be (and is) used to manage the data protection aspects of AI […]

Read Analysis →

Webinar recording: contextual versus behavioral ads and consent or pay

Consent or Pay” again – this time a recorded webinar! Behavioural vs contextual ads, freedom to conduct a business, flaws in the EDPB’s approach, lots of ground covered in this webinar! With Eva Jarbekk, Miko?aj Barczentewicz and Rob Corbet GDPR data protection ePrivacy privacy

Read Analysis →

What is next after three intense speaker panels at CPDP2024 in Brussels?

What a week! So what’s next? After 3 speaker slots at CPDP2024 (featuring some of the most heated exchanges of the entire conference), one webinar, and loads of really good discussions on the biggest data protection topics (“Pay or OK”, “Advertising, data protection and AI”, “balancing of fundamental rights: protection of personal data vs/with freedom […]

Read Analysis →

How a systemic lack of appeals is emboldening European data authorities

Data protection “case law” suffers from a lack of appeals, which emboldens authorities to reuse a questionable position and make it seem like the law. Case in point? Today the Belgian DPA published yet another decision with a warning about keeping a mailbox active after a person has left a company, this time for just […]

Read Analysis →

Daring to question the absolute primacy of personal data protection rights

?? Let’s dare to question the primacy of the right to the protection of personal data, and see what comes of it. A little pragmatism, perhaps, given that data protection is not absolute? Here’s my summary for the “too long; didn’t read” crowd: (but really, read the whole article!) – GDPR compliance is the justification […]

Read Analysis →

Op-Ed: Who dares question the primacy of data protection?

Let the name-calling begin. Companies looking to leverage data are now told that it is just like they are responsible for oil spills, cancer and drug cartel violence. As a lawyer working for some of the companies facing these absurd comparisons, I thought I would tackle another controversial stance now: just how absolute (or relative) […]

Read Analysis →

Can individuals legally waive their data subject rights under the GDPR?

Very interesting (and non-dogmatic) outcome here of a question on the extent to which a person can waive data subject rights. Self-determination and the non-absolute nature of data protection rights are topics that will very likely give rise to more discussion in the future! gdpr data protection privacy Thanks Dr. Carlo Piltz for highlighting it!

Read Analysis →