Scope: dataprotection

Can't find what you're looking for? Try the search bar!

Why European authorities are wrong to demand cookie consent for contextual ads

Controversial op-ed of the day: Why do many EU-based authorities say that advertising cookies etc. require consent (yes, behavioural *and* contextual advertising)? How could those views evolve? Can digitaladvertising not be seen as strictly necessary for provision of the service explicitly requested by a user? � Here are some (personal) thoughts on these issues, with […]

Read Analysis →

Essential community comments on the far-reaching scope of ePrivacy rules

For anyone with an interest in ePrivacy, onlineadvertising, digital businesses or even computing in general, I highly recommend reading the comments that we had the privilege of working on with IAB Europe and national associations in relation to the EDPB’s proposed ePrivacy guidelines. Link to the IAB Europe press release: https://lnkd.in/ediZ4Cxq And here are comments […]

Read Analysis →

Is the security data stored by a CAPTCHA strictly necessary under ePrivacy?

So… is the information “stored” and “accessed” through use of a CAPTCHA strictly necessary to the provision of the service explicitly requested by a user, namely the service of being able to submit a form? From the perspective of common interpretations of data protection authorities also in charge of ePrivacy enforcement, you would expect “no”, […]

Read Analysis →

Analyzing paragraph 100 of the Belgian DPA decision on a major data broker

Lots to digest in the Belgian Data Protection Authority’s latest decision, regarding a large data broker. One of the most important parts is its paragraph 100, which inadvertently raises the question of whether non-compliance with a data source’s terms of use or licence agreement can render a processing unlawful. The context: the data broker included […]

Read Analysis →

Inconsistencies your business should address before the ePrivacy consultation closes

Last few days to comment on the game-changing ePrivacy guidelines of the EDPB. One issue examined for some clients is the inconsistency between the expanded scope of that provision (a rule regarding cookies and similar (active) information storage & access technologies, but now also covering nearly any interaction with a computing device *and* the passive […]

Read Analysis →

New questions referred to the CJEU on the right to be forgotten

Here is an English version of the questions referred yesterday to the CJEU on the right to erasure or “right to be forgotten” in a case about a request for removal from a baptism register – an interesting balance of fundamental rights. The case, an appeal against a decision by the Belgian Data Protection Authority […]

Read Analysis →

The upcoming EDPB vote on AI models that everyone is watching

Anyone who has been following the “AI models & personal data” discussion can probably guess which vote of an Art. 64(2) GDPR Opinion will be on the agenda on that day. Want to know more? Read up on the topic here: https://lnkd.in/eVE4NSwd data protection

Read Analysis →

Does a settlement with a complainant actually stop a DPA investigation?

In case of a complaint before a supervisory authority, will a settlement to withdraw the complaint stop an investigation? The Belgian Data Protection Authority examined the issue in its newest decision: 1. Context and procedure: A data subject complaints before the BDPA because a (large) search engine provider (as controller) has rejected a delisting/erasure request […]

Read Analysis →

Why the French CNIL fine against Orange for email ads is a misstep

The new French fine against Orange for notably displaying ads among a list of e-mails is a misstep, in my view. It builds upon a rare legal misstep of the CJEU, a case in which the highest EU judges introduced subjectivity in an ePrivacy provision that was built around objective criteria. I am speaking about […]

Read Analysis →

Can a nightclub force app downloads under the guise of consent or pay?

Now for a different “Consent or Pay” anecdote (not mine though!): a night club tells those trying to get in that they need to download an app and scan a code after registering. It later turns out the alternative was to pay 10�. Is this “Pay or OK” in relation to non-digital services? The context […]

Read Analysis →