Why simply viewing client data on a mobile app isn’t a transfer under the GDPR

I’m seeing significant misinterpretations of the CJEU’s newest GDPR judgment. The CJEU *did not say* today that simply seeing information on a mobile app is processing of personal data. Instead, it said that *the process by which a COVID certificate is scanned by a device and then interpreted to reveal a green checkmark or a […]

Read Analysis →

When data protection failures lead to prison sentences instead of standard fines

Fines aren’t the only possible sanction in case of an infringement of data protection rules – prison is also a possibility in certain countries. That’s exactly the outcome of a case in France, where a former head of HR received a six-month (suspended) prison sentence yesterday. In that case, the person in question had created […]

Read Analysis →

Why claims of 100% GDPR compliance for AI software are a myth

100% GDPR compliant” claims seem to have made a big comeback with the flurry of GenerativeAI tools being released*. As a reminder, claiming that a software solution is GDPR compliant is a marketing trick at best and misleading at worst. First, if you’re not sure what the sources are on which a particular AI system […]

Read Analysis →

Suspicion alone is not a valid reason to file a complaint with the Belgian DPA

I’m not sure X/Y’s data protection practices are compliant” is not a justification for filing a complaint, says the Belgian DPA in a new decision, reminding data subjects that they should exercise their rights before a complaint or at least be able to show that an alleged non-compliance by a controller or processor somehow affects […]

Read Analysis →

The Belgian Market Court protects document confidentiality against complainants

Important comment by the Belgian Market Court in a new judgment, here on confidentiality of controller/processor documents vis-�-vis a complainant: “the general principle regarding the prohibition of the abuse of rights prevents a complainant [�] from using the complaint to obtain information that it would not be able to obtain lawfully by other means”. The […]

Read Analysis →

Why the EU-US Data Privacy Framework isn’t a complete global transfer fix

Great news about the EU-U.S. adequacy decision! But let’s remember that many organisations want a solution for global transfers, not just for the United States. While the EU-U.S. adequacy decision helps a lot, it is only part of the solution that organisations need. Let’s look at some of the other components. Another part of the […]

Read Analysis →

An expanded look at the contract legal ground after the landmark CJEU Meta ruling

After some initial thoughts on Tuesday, here is a slightly expanded analysis of the “contract” legal ground assessment by the CJEU in its new Meta judgment (C-252/21). Once again, I hope this ruling will not be misapplied in practice – and that controllers who build personalisation into a service for valid reasons are not forced […]

Read Analysis →

How the CJEU defines the objectively indispensable threshold for contract performance

Objectively indispensable”, that’s how the CJEU describes the threshold for processing of personaldata to be necessary for performance (or conclusion) of a contract under Art. 6(1)(b) GDPR. In its new Meta judgment (case 252/21), the Court of Justice examined many points of law, but it may be useful to other organisations to look at paragraphs […]

Read Analysis →

What the formal launch of TCF 2.2 means for publishers and adtech vendors

15 months, countless meetings with publishers, audience measurement providers, adtech players, personalized content companies, … With TCF 2.2 launched, time to reflect on the enormous privilege I had of being involved (and prominently so) in so many stages of the development of new iterations to such an important standard for the online ecosystem. My role […]

Read Analysis →

Utilizing the new ENISA report to build a comprehensive security strategy for AI

Looking for good practices re AI security? The new ENISA report can help. It shows the need for a broad strategy that takes into account various risks (including legal ones) regarding not just your machine-learning algorithm or other tool but also the data sources themselves and the expected output. Bias, for instance, is not a […]

Read Analysis →