Scope: dataprotection

Can't find what you're looking for? Try the search bar!

IAB Europe submits its formal data protection letter to the EDPB

IAB Europe’s letter to the EDPB on “Pay or Consent” is out – with considerations relating to the GDPR and broader data protection rules, fundamental rights, personal data as “consideration” for a contract (co-signatories: Alliance Digitale, IAB Italia & IAB Spain) Key points: – �The assessment of �Consent or Pay� models must remain coherent with […]

Read Analysis →

What the bpost enforcement decision reveals about legitimate interests and DPO roles

Three points of interest (also beyond Belgium) taken from the Belgian data protection authority’s new decision regarding bpost (postal services): – Legitimate interests can be a valid legal ground for direct marketing (this is already well known throughout the European Union, but it’s worth repeating, considering the opposite view that the Dutch Autoriteit Persoonsgegevens continues […]

Read Analysis →

European Parliament members challenge Meta over its pay or OK strategy

PayOrOkay [I’ll surely get shot for writing this:] 39 members of the European Parliament write to Meta to say that the right to privacy is “no” [I assume “not”] “something you should have to purchase” and that “[s]tudies” [citation needed] “suggest that contextual advertising is nearly as profitable as surveillance-based advertising”. Honestly, I preferred the […]

Read Analysis →

The Belgian DPA issues key findings on data models and compatible research

New BDPA decision on data models + “research” as a compatible purpose. Two key questions: (i) If a data model is *no longer* based on a data subject’s data after an objection, can that data subject still file a complaint before a data protection authority? “Yes as long as that person can demonstrate an interest”, […]

Read Analysis →

What the upcoming AI Act actually means for everyday enterprise structures

While everyone is shouting “it’s for realz now”*, what will the AIAct actually mean for most organisations? Awareness (“AI literacy”) obligations and obligations to ensure that people know (i) if they are interacting with an AI system or (ii) whether they are subject to an AI system – and safeguards to ensure that no high-risk […]

Read Analysis →

Cross-border compliance trends from my recent case law briefing

Yesterday, I had the pleasure of giving a 5h presentation on the latest case law on the GDPR and other data protection legislation at various levels (Belgium, other EU countries, the Court of Justice and the European Court of Human Rights) to Data Protection Officers from a broad range of organisations and companies. The past […]

Read Analysis →

Spotting the irony when privacy critics use dark patterns and trick wording

Wasn’t FOMO manipulation / “trick wording” a darkpattern? Why then do some critics thereof use them? Genuinely curious. Not all do so, far from it (and some of the most prominent ones are very good at *avoiding* such techniques), but it seems that some enjoy labelling everything as “Breaking” (even information that is more than […]

Read Analysis →

The common misconceptions around contextual versus targeted advertising

Contextual ads > targeted ads”? Often this approach refers to one Dutch broadcaster’s (misinterpreted) story and mistaken assumptions that “contextual” means “no data”. Now for the opposite story from Belgium: the news website Tweakers tried an allegedly “tracking-free” contextual ad system since May 2022 but announced yesterday it was not economically viable and would be […]

Read Analysis →

The Belgian DPA rules that noyb lacks a structural legal interest in a key complaint

Belgian DPA drops a bomb on a complaint filed by noyb.eu: in Belgium at least, says the BDPA, in order for noyb to have a legal interest in filing a complaint on behalf of data subjects, those data subjects cannot have been working for noyb at the time. The case in question concerned cookies and […]

Read Analysis →

Finland’s Traficom openly disputes the EDPB interpretation of ePrivacy scope

Now this says a lot: Traficom, the Finnish ePrivacy regulator, has disputed the EDPB’s interpretation of the scope of Art. 5(3) of the ePrivacy Directive in comments it submitted on the EDPB’s proposed ePrivacy Guidelines (in the words of Traficom, they have “some reservations” about “some aspects of the opinion that may lead to an […]

Read Analysis →