The corporate obsession with appointing an executive Chief AI Officer

You’re a Chief AI Officer! And you! And you too!” – Recently, requiring AI officers has become all the rage. (Funnily enough, there were Chief Internet Officers at one point, and there may still be vestiges of the role of Chief Blockchain Officer in some places) In the US, the White House Office of Management […]

Read Analysis →

Is the European Commission fundamentally misunderstanding contextual ads?

Did I get this right? Thierry Breton at the European Commission is suggesting that a specific form of advertising (“contextual” – i.e. ads based on limited data) is required by the DMA, as an alternative to another (profile-based advertising), and that a “consent or pay” approach might not be permitted (the Commission apparently has “serious […]

Read Analysis →

The cybersecurity intersection: when lawyers wear hoodies and CISOs read laws

Laws with cybersecurity requirements: time for the lawyer to wear a hoodie and for the CISO to put on a lawyer’s gown. [because we all know that’s how the other profession dresses 100% of the time] For years I have been stressing the need for cybersecurity and legal teams to work as one – and […]

Read Analysis →

Spotting a critical translation shift in an Advocate General opinion on privacy

Stunned to notice, while re-reading an important Opinion by an Advocate General to advise a client, that when he says “According to the case-law of the Court of Justice [of the European Union]”, he is actually quoting non-binding regulatory opinions (not from the CJEU) and only one CJEU judgment that doesn’t even come close to […]

Read Analysis →

What you may have missed in the CJEU appellate judgment on the OLAF case

With the IAB Europe judgment and some others, you may have missed the CJEU’s appellate judgment in the OLAF case on the EUI GDPR – which (also) deals with the concept of “personal data”. Here is my take: First, the EUI GDPR – Regulation 2018/1725 – is extremely similar to the GDPR itself, also as […]

Read Analysis →

The immediate operational impact of the CJEU IAB Europe and TCF judgment

Want to know what is the impact of today’s IAB Europe / TCF judgment for your business? (A couple of adtech / martech players have already reached out for advice, so I figure it may be a question many have) If you can’t find the answer to your specific situation in the IAB Europe FAQ […]

Read Analysis →

Is IAB Europe a joint controller? Unpacking the CJEU answer to question two

Summary + thoughts on the CJEU’s answer to the 2nd question (“is IAB Europe (joint) controller?”) in the�IAB Europe�& TCF case (C-604/22). [Again, I may be biased] – 55: Broad definition of “controller” in order to ensure an effective and complete protection of data subjects (C-210/16) 57: A natural or legal person who influence “for […]

Read Analysis →

Is the TC String personal data? Analyzing the CJEU answer to question one

Summary + thoughts on the CJEU’s answer to the 1st question (“is the TC String personal data?”) in the IAB Europe & TCF case (C-604/22). [I may be biased] – 33: CJEU data protection Directive case law is “in principle” also relevant for the GDPR, “given that this directive was withdrawn by and replaced by […]

Read Analysis →

Why means of identification and actual influence shape joint controllership after Breyer

Breyer seemingly confirmed (means of identification are crucial), facts matter re establishment of joint controllership (it depends on whether there is actual influence and an own purpose), and joint controllership doesn’t necessarily extend to further processing (such as advertising) – we will be looking at the CJEU’s newest judgment (C-604/22 – IAB Europe / TCF […]

Read Analysis →

Why server connection telemetry isn’t automatically personal data under the GDPR

Another adtech discussion showing that not all information gleaned through server connections is personal data under the GDPR (or even the CCPA’s broad “personal information” concept). [Nor is it / should it be automatically covered by ePrivacy rules] In this case, it was about which data points are actually being used, by whom and who […]

Read Analysis →