Scope: DataGovernance

Can't find what you're looking for? Try the search bar!

A curious settlement by the Belgian DPA over minor structural violations

Amusing settlement decision by the Belgian DPA published yesterday: 500 EUR & 250 EUR respectively, plus adaptations to policies and procedures, so that when people book a table in a given restaurant by phone their data isn’t included automatically in a third-party table booking system and then used to send commercial e-mails. The lesson? If […]

Read Analysis →

How GDPR principles are serving as the blueprint for non-personal data laws

On this fifth GDPR anniversary, remember that data protection principles are increasingly serving as inspiration for legal obligations regarding the use of “non-personal”/”corporate” data. What was good business practice is becoming a statutory obligation. So double-check that you have everything you *should* have, because soon you will be *required* to have it. Not that privacy […]

Read Analysis →

Cross-border compliance trends from my recent case law briefing

Yesterday, I had the pleasure of giving a 5h presentation on the latest case law on the GDPR and other data protection legislation at various levels (Belgium, other EU countries, the Court of Justice and the European Court of Human Rights) to Data Protection Officers from a broad range of organisations and companies. The past […]

Read Analysis →

How to build effective AI governance structures on top of your existing GDPR framework

Very good piece by Kristin Johnston on aigovernance and in particular how to start the process. One recommendation – building AI governance on top of existing privacy processes – is very relevant but you have to be careful about how you implement it. The key challenge is making sure it can be sufficiently distinct as […]

Read Analysis →

How modern corporate lawyers balance roles as AI advisors and technical users

Lawyers can both be AI advisors (legal implications) and users of machine learning / generativeai / applied statistics / … systems. Tomorrow we will be helping members of the Flemish Bar Association understand some of the key things to look out for and reflexes to have – both for themselves and for their own clients. […]

Read Analysis →

Let’s discuss third-party risk management and data governance in Brussels

Are you keen to have a discussion about datagovernance and third-party risk management (AI, cybersecurity, ESG), and will you be in Brussels (or come to Brussels) early March 2024? We are holding a complimentary event on 8 March for businesses and trade associations, with breakout sessions on these topics, as well as (in parallel) sessions […]

Read Analysis →

When data protection failures lead to prison sentences instead of standard fines

Fines aren’t the only possible sanction in case of an infringement of data protection rules – prison is also a possibility in certain countries. That’s exactly the outcome of a case in France, where a former head of HR received a six-month (suspended) prison sentence yesterday. In that case, the person in question had created […]

Read Analysis →

Practical strategies for aligning data governance with upcoming EU tech laws

Good reflexes regarding datagovernance and aigovernance, what to expect from the upcoming legislation and how to prepare, those were some of the topics discussed during our panel on the EU draft AIAct and the DataAct at the Flanders AI Forum 2023. A few additional thoughts: “Data/AI isn�t our core business�? Every business involves data & […]

Read Analysis →