Navigating the leaked GDPR and Data Act Omnibus document

GDPR & Data Act Digital Omnibus: this is *NOT* the final version we expect the Commission to publish in two weeks (already made public by some outlets such as Contexte). But this way anyone keen on reading in more detail the points I summarised and commented in my previous post on the GDPR aspects (see […]

Read Analysis →

Detailed breakdown of key changes in the GDPR Omnibus draft

Key points from (& thoughts on) draft GDPR Digital Omnibus: First, Art. 4(1) GDPR would be completed with an SRB-like statement (great news), plus a mitigation of abusive interpretation of the Scania judgment (also great news). Art. 4(15) on “data concerning health” would also finally be more specific, avoiding some of the more awkward and […]

Read Analysis →

Unpacking the economic future of the GDPR at the EDPB stakeholder event

Some thoughts on today’s EDPB “Pay or Consent” stakeholder event – in practice one about the future of GDPR enforcement, consent, adtech and even the future of the Internet: – At times, things got heated in our breakout room between two camps, typically privacy rights campaigners + contextual ad solution providers on the one hand […]

Read Analysis →

Overview and preliminary thoughts on the GDPR Omnibus draft

That draft GDPR Digital Omnibus is quite worth the read. Once the story gets out, I’ll be posting a summary of all the changes and some preliminary thoughts – but it’s a promising blend of data protection case law (+ mitigations of excessive interpretations that might be made of certain judgments), ePrivacy improvements and AI […]

Read Analysis →

AI literacy: moving beyond general training to system-specific awareness

The AI literacy point is very interesting. AI literacy is one of those odd obligations: on paper, it makes sense, but in practice it’s sadly often been used to offer training on AI usage principles without knowing which AI systems are actually (going to be) used. I’m keener on ensuring that any person using an […]

Read Analysis →

Is a corporate ransomware attack legally classified as force majeure?

How can you reinforce your cyber resilience? Is a ransomware attack “force majeure” preventing contractual performance? Who is responsible and liable for cybersecurity (failures) in a company? I had the pleasure of taking part in a panel discussion organised by the Belgian Federation of Enterprises (VBO FEB) in which I was asked to speak on […]

Read Analysis →

Distinguishing data abuse from the necessity of regulatory reform

The uncovering of a dataset with information on the movements and even domicile of European Commission officials is an important reminder that, as with every other technology or data point, location data can be abused. Since the news broke out, I have seen several seizing upon it to say that data brokers are inherently illegal […]

Read Analysis →

Getty v Stability AI: implications for personal data and model training

These excerpts from the Getty v Stability judgment will be interesting for data protection professionals to look at, not just copyright professionals: – Judge: “Stable Diffusion does not itself store the data on which it was trained” [para. 552 of the judgment] – Expert report: “Rather than storing their training data, diffusion models learn the […]

Read Analysis →

A final reminder to voice your company’s concerns on the new ePrivacy guidelines

Just one month to go for comments on the EDPB’s new ePrivacy guidelines, so here’s a reminder of why you *should* respond if your company has digital activities: – The new EDPB guidelines concern the scope of Art. 5(3) of the ePrivacy Directive, which was never only about cookies but about the storing of information […]

Read Analysis →

The Belgian DPA restricts permanent video surveillance of corporate employees

New Belgian Data Protection Authority decision on video surveillance: don’t do permanent surveillance of employees. Questions remain, but without more background (name of the stores, history of theft within the stores etc.) it’s difficult to assess whether the BDPA was right in its assessment. The decision mentions the fact that cameras were deployed in 6 […]

Read Analysis →