Scope: dataprotection

Can't find what you're looking for? Try the search bar!

Essential guidance for navigating adtech, identifiers, and GDPR enforcement

If you are (interested) in AdTech, privacy-enhancing technologies, GDPR enforcement, identifiers, etc., you’ll want to attend this IAPP workshop on 19 November 2024: “AdTech and Privacy: Prospects and Pitfalls” (half-day intensive workshop, 9 to 12.30 CET). Led by Dr. Sachiko Scheuing (FEDMA / Acxiom), featuring Elena Turtureanu (Adform), Nathalie Laneret (Criteo), Matthias Matthiesen (TripleLift), Enrico […]

Read Analysis →

Why everyday computer interactions shouldn’t trigger ePrivacy consent rules

Several posters seem to agree with the EDPB’s new ePrivacy Guidelines. “Of course every computer interaction is covered”. I disagree, but let’s imagine they are right. Isn’t it still problematic that *almost nothing is exempt from consent* nowadays in the eyes of most EDPB members? First, the basics. Under Art. 5(3) of the ePrivacy Directive […]

Read Analysis →

A side-by-side comparison of the draft versus final ePrivacy guidelines

So, here’s the comparison between the EDPB’s new ePrivacy Guidelines and the version that was up for public consultation end of 2023. As you can see, not much has changed. The fundamental issues that affected the previous version (competence, overbroad interpretation that doesn’t match the actual meaning of words or the intention of the legislator, […]

Read Analysis →

How to register for the upcoming EDPB stakeholder event on AI models

Here’s the registration form for the EDPB’s stakeholder event on AI models: https://lnkd.in/enBa5dHq 500-character limit for an explanation of why your organisation should take part More on this in my in-depth article on AI models and GDPR: https://lnkd.in/eYXabSfs data protection privacy

Read Analysis →

Does training an AI model actually constitute processing personal data?

How the GDPR interacts with AI models: my in-depth look at whether AI model training even involves the processing of “personal data”, and which legal grounds might be most appropriate even if we do consider that personal data is involved. With the European Data Protection Board’s “stakeholder” event registration opening tomorrow in relation to its […]

Read Analysis →

Inside the RAID panel debate with the EDPB Chair and national DPAs

Fun day! After moderating a RAID panel with as panelists EDPB Chair Anu Talus, Luxembourg CNPD President Tine A. Larsen, Deputy Head of Data Protection Unit at the Commission’s DG Justice Karolina Mojzesowicz, MEP Brando Benifei and Gibson Dunn Partner Ahmed Baladi, I then was a speaker in a debate alongside Max Schrems of noyb.eu, […]

Read Analysis →

The Belgian DPA rules that both controllers and processors are liable for missing DPAs

New Belgian Data Protection Authority decision: – Both the controller *and* the processor can be liable for not having a data processing agreement (DPA) in place – If you sign a DPA with “retroactivity clause” (i.e. foreseeing an earlier effective date than the signature date), that retroactivity clause does not have any effect from a […]

Read Analysis →

The Belgian DPA issues a 100k EUR fine for ignoring an access request

Belgian DPA: 100k EUR fine for a controller for not responding during 14 months to a data subject access request. [Decision of 23 August 2024; fine:

Read Analysis →

Can businesses demand physical ID cards for GDPR identification checks?

A recent Amsterdam District Court judgment on whether ID cards can be requested for data subject identification raises interesting points re GDPR and data minimisation – and how controllers can reach a satisfactory level of identification. Context: – A controller (C) had 2 processes for verifying the identity of data subjects making a request: (i) […]

Read Analysis →

Why businesses cannot afford to dismiss the corporate risk of deepfakes

Scarily powerful – don’t dismiss the risk of deep fakes for your company. With now tools like Deep Live Cam (“real time face swap and one-click video deepfake with only a single image”) making the rounds, it is imperative for you to educate *everyone* in your organisation about good reflexes regarding both cybersecurity and AI. […]

Read Analysis →