CNIL published guidelines on data protection in the health sector

In June 2018, the CNIL, Commission Nationale Informatique & Libertes, published guidelines for the protection of personal data in the health sector. In particular, the French Data Protection Authority (DPA) provides professionals in the health sector with tips to comply with the EU Privacy Regulation 2016/679, GDPR: limit the information collected to what is necessary for the treatment of patients; keep a record of treatments; delete patient data after the maximum retention period Read more [...]

Irish DPA prepared a list of processing operations that require DPIA open for public consultation

In June 2018 the Irish Data Protection Commission (DPC) published a draft list of processing operations for which it is mandatory to conduct a data protection impact assessment (DPIA). The list is intended to encompass both national and cross-border data processing under Article 35 of the General Data Protection Regulation (GDPR). With a view to finalizing the proposed list for submission to the EDPB for approval, the DPC is issuing its draft DPIA list for public consultation. Stakeholder shall Read more [...]

Another step toward an EU online market place without discrimination based on customers’ location: Regulation (EU) 2018/302

On March 22, 2018, the new EU rules against unjustified geo-blocking (Regulation (EU) 2018/302) entered into force and will be applicable starting December 3, 2018. The Regulation aims at abolish discrimination based on nationality and residence. Sellers will have to stop denying access to websites from one Member States to the other, preventing purchases of residents of another Member State or asking to pay with a debit or credit card from a certain country. EU citizens should finally Read more [...]

Privacy complaint in Italy shall be field according to GDPR; local rules surpassed

On May 31, 2018, the Garante per la Protezione dei Dati Personali, Italy’s Data Protection Authority (DPA) issued a decision explaining that until a legislative decree that harmonizes domestic law with the GDPR will come into force, the current complaint procedure shall be considered incompatible with the Regulations. The DPA refers to Article 77, GDPR, conferring data subjects the right to lodge a complaint with a supervisory authority. The DPA made available a page instructing on how Read more [...]

EPrivacy Regulation? Acknowledgment by the EU Council that further work needs to be done in next presidency

At the beginning of June the EU Council discussed its position on the ePrivacy Regulation to update privacy rules for electronic communications. It appears like no real progress was registered at the Council meeting and that further work is needed under the next presidency (June to December 2018). The ePrivacy Regulation aims at ensuring a high level of protection of private life, communications and personal data in the electronic communications sector, to create a “level playing field for providers Read more [...]