Latest Posts › Personal Data

Share:

German Court: Internal Recorded Statements And Notes Are Personal Data And Must Be Disclosed

The Higher Regional Court of Cologne Germany has held that internal recorded statements, conversation notes or telephone notes constitute personal data and copies of them must be disclosed in response to a data access...more

Belgian Data Protection Authority Weighs In On DPOs Deleting Data Subjects’ Personal Data

The Belgian Data Protection Authority holds that a Data Protection Officer (DPO) may not himself/herself delete personal information of a data subject. Doing so constitutes a violation of the General Data Protection...more

Hellenic Data Protection Authority Issues Opinion On Employee Data

The Hellenic DPA has issued an opinion regarding the appropriate legal basis for processing employee data under GDPR: Consent should be used as the legal basis only where the other legal bases do not apply....more

EU Court Of Justice Issues Long-Awaited Decision On Facebook Likes In Fashion ID Matter

A Facebook “like” is actually more like “in a [Joint Controller] relationship” status, says the Court of Justice of the EU in a long awaited decision in the Fashion ID matter. At issue: The legal framework surrounding...more

European Commission Releases Its Assessment Of GDPR Year One

The European Commission has published a report looking at the impact of the EU data protection rules, and how implementation can be improved further....more

FTC Commissioner Rohit Chopra Issues Dissent On Facebook Settlement

“The decision to impose documentation requirements, rather than bright line rules, represents a significant departure from how the government traditionally aims to protect the public. It is akin to if federal regulators,...more

FTC Issues Landmark $5 Billion Fine Against Facebook

Big Picture Takeaways: Facebook faces many detailed requirements for internal and external governance and oversight with extensive reporting requirements...more

Danish DPA Issues Guidelines For Transmitting Personal Data Via SMS

The Danish Data Protection Authority has issued guidance on the transmission of personal data via text messages (SMS). Key takeaways: Sending personal data by SMS is risky as it entails transmission in clear text, over...more

EDPB Opinion Provides Guidance On Controller-Processor Agreements Under GDPR

The European Data Protection Board (EDPB) has issued an opinion on the standard contractual clauses proposed by the Denmark Data Protection Authority that contains important takeaways for drafting and negotiating of all...more

Furniture Store Fined Under GDPR For Failing To Delete Personal Data

If you retain personal data indefinitely, or have not given thought to your retention schedule – now may be the time to take another look. The Danish Data Protection Authority has fined a furniture store 200,000 EUR for...more

FTC, Car Dealership Management Software Company Reach Settlement Over Storage Of Personal Information In Cleartext

The Federal Trade Commission (FTC) has entered into a settlement with a provider of management software for car dealerships that held personal information, including SSN’s and payroll information, in cleartext, holding its...more

Case Study, France: Examining Adequate/Reasonable Protections For Personal Information

Spotlight on adequate/reasonable protections to personal information – Part 1 – France. CNIL fined a real estate company 400,000 EUR for failure to implement adequate protections to personal data in violation of GDPR....more

European Commission Issues Its Take On GDPR At One

“The game-changing rules [of GDPR] have not only made Europe fit for the digital age, they have also become a global reference point,” say Andrus Ansip, Vice-President for the Digital Single Market and Vera Jourová,...more

CNIL Issues Data Protection Kit For Developers

The French Data protection authority, CNIL, has issued a “Developer Kit” setting forth best practices for data protection. Key takeaways: Before using a development tool, especially for personal data, read the...more

Lithuanian Data Protection Inspectorate Levies Fine For GDPR Data Management Violations

The Lithuanian data protection inspectorate issued a 61,500 EUR fine against a payment services provider for violations of the data minimization, adequate security measures and data breach reporting requirements of GDPR....more

Does The California Consumer Privacy Act Apply To Me?

The California Consumer Privacy Act (CCPA), a broad-based law protecting information that identifies California residents, was passed in June 2018 and will take effect in 2020. Dubbed “GDPR Lite,” to denote its similarities...more

Dutch Data Protection Authority Issues Advisory On Medical Records Under GDPR

“The right to be forgotten does not apply in principle to medical records. However, as a patient, you may ask your health care provider to remove data from your medical record,” according to the Dutch Data Protection...more

Dutch DPA Makes Data Protection Policy Recommendations

The Dutch Data Protection Authority makes six recommendations on drafting your data protection policy, based on its audits of privacy policies of blood banks, IVF clinics and political parties. A good data protection policy...more

French Data Protection Authority Reports 32 Percent Increase In Complaints In 2018

The French Data Protection Agency CNIL recieved 11,077 complaints in 2018, up 32.5 percent compared to 2017. Other highlights from the CNIL 2018 report- CNIL carried out 310 investigations in 2018, of which 204 were...more

European Commission Provides Update On Interplay Between Clinical Trials Regulation And GDPR

“Where the sponsor processes personal data of data subjects in the EU, including in the context of managing the clinical trial, GDPR is fully applicable, including the obligation to designate a representative in the...more

Highlights Of 2018 GDPR Enforcement

How has GDPR enforcement played out in the past year? The Dutch Data Protection Authority (Autoriteitpersoonsgegevens, or AP) recently published a report on its 2018 activities....more

Drivers File Right Of Access Claim Against Uber Over Failure To Disclose Driving Data

GDPR right of access applies in the work context too. Four Uber drivers from London, Nottingham and Glasgow claim Uber has breached their rights by failing to disclose personal data the firm holds on them in breach of the...more

European Data Protection Board Issues Opinion On Interplay Between GDPR And ePrivacy Directive

EDPB on the ePrivacy Directive and GDPR: In situations where the ePrivacy Directive renders more specific the rules of the GDPR, the provisions of the ePrivacy Directive take precedence over the provisions of the GDPR....more

UK Data Protection Authority Advises Doctors On Patient Requests For Access To Health Information

Data subject access rights and your medical practice: The UK Information Commissioner’s Office (ICO) issues advice. Medical practices have reported a significant rise in subject access requests (SARs) since the GDPR came...more

That’s Not In The GDPR: Myth-Busters From The Irish Data Protection Commission

GDPR does NOT: prohibit a hairdresser from telling a customer what hair color they used on their hair - prevent the fire department from telling a property management company whether there had been a fire in one of its...more

129 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide