Users’ guidance on DPIA under the GDPR published by EU Data Protection Authorities

EU Data Protection Authorities released useful Data Protection Impact Assessment tools (DPIAS) Belgium: the Commission for the Protection of Privacy, Commissie voor de bescherming van de persoonlijke levenssfeer (CBPL) issued a Recommandation d'initiative concernant l'analyse d'impact relative à la protection des données (n° 01/2018) Cyprus: the Office of the Commissioner for Personal Data Protection, Γραφείου Επιτρόπου Προστασίας Δεδομένων Προσωπικού Read more [...]

Facebook “moves” processing of data of non EU users from Ireland to the US

According to Reuters, Facebook is modifying its terms and conditions so that the data of around one and a half billion of its users will be processed by Facebook USA rather than Facebook Ireland. As of today, the data of the users of Africa, Asia, Oceania and Latin America are processed by Facebook Ireland, thus falling under the umbrella of the applicable EU data protection laws. Despite not being European, the processing of data of the users from these countries would have fallen straight Read more [...]

Italian DPA fines political party for privacy policy violation

In March 2018, the Garante per la Protezione dei Dati Personali, Italy’s Data Protection Authority, issued a fine of Euros 32,000 against the Rousseau association, controller of the processing of data of the website users of the Italian political party “5-Star” (Cinque Stelle). Federprivacy reports. After a data breach, the Italian DPA started investigating whether the websites had a compliant data privacy policy. Among other security issues, the DPA discovered the controller did not Read more [...]

Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679

On February 6, 2018, Working Party 29 (WP29) adopted the Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 (wp251rev.01). Advances in the capabilities of big data analytics, as well as the widespread availability of personal data on the internet and from Internet of Things (IoT) devices can allow aspects of an individual’s interests to be analyzed and predicted. Regulation 2016/679, the s.c. General Data Protection Regulation (GDPR) addresses Read more [...]

Guidelines on data breach notification

On February 6, 2018, Working Party 29 (WP29) adopted the Guidelines on Personal data breach notification under Regulation 2016/679, wp250rev.01 Regulation 2016/679, the s.c. General Data Protection Regulation (GDPR) introduces the requirement for a personal data breach  to be notified to the competent national supervisory authority (or in the case of a cross-border breach, to the lead authority) and, in certain cases, to communicate the breach to the individuals whose personal data have been Read more [...]