News & Analysis as of

Data Protection Authority Personal Data Enforcement Actions

Sheppard Mullin Richter & Hampton LLP

Don’t Forget the EU: Italy Issued First GenAI Fine of €15 Million Alleging GDPR Violations 

At the end of 2024 the Italian Data Protection Authority issued a 15 million euro fine in the first generative AI-related case brought under GDPR. According to Garante (the Italian authority), OpenAI trained ChatGPT with...more

Clark Hill PLC

Right To Know - January 2025, Vol. 25

Clark Hill PLC on

Cyber, Privacy, and Technology Report - Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed....more

Ballard Spahr LLP

Netflix Fined by Dutch Regulator for Privacy Violations

Ballard Spahr LLP on

The Dutch Data Protection Authority (the “Dutch DPA”) issued a €4.75 million (approximately $5 million USD) fine on Netflix in connection with a data access investigation that started in 2019. The investigation arose out of...more

Pillsbury - Consumer Protection Dispatch

GDPR Enforcement: Lessons from Recent Data Privacy Penalties

Recent decisions by the French data protection authority (CNIL) have highlighted the importance of GDPR compliance, particularly in the areas of data retention, consent for processing sensitive personal data, and marketing...more

Goodwin

Navigating New CNIL Sanctions: What You Need to Know

Goodwin on

The Commission Nationale de l’Informatique et des Libertés (CNIL) is an independent French administrative regulatory body whose mission is to ensure that the collection, storage, and use of personal data comply with data...more

Ius Laboris

Massive fine for Uber of EUR 290 million

Ius Laboris on

On 26 August the Dutch Data Protection Authority (DPA) fined Uber EUR 290 million for a breach of the General Data Protection Regulation (GDPR). Following a number of complaints from French Uber drivers, the DPA found that...more

Latham & Watkins LLP

ستة أشهر حتى سريان النظام: خطوات الامتثال الرئيسية لنظام حماية البيانات في المملكة العربية السعودية

Latham & Watkins LLP on

يُعد نظام حماية البيانات الشخصية (النظام) أول نظام شامل لحماية البيانات في المملكة العربية السعودية. من المتوقع أن تبدأ الهيئة السعودية للبيانات والذكاء الاصطناعي (الهيئة) في الإنفاذ الكامل للنظام اعتبارًا من 14 سبتمبر 2024،...more

Mayer Brown

ANPD Applies First Sanctions of 2024

Mayer Brown on

The Brazilian Data Protection Authority (Autoridade Nacional de Proteção de Dados, “ANPD”), applied its first two sanctions of 2024 against two Brazilian governmental institutions. It is worth noting that, as both are public...more

WilmerHale

EDPB Adopts Guidelines on Calculation of GDPR Fines and on Facial Recognition Technology in Law Enforcement

WilmerHale on

On May 16, 2022, the European Data Protection Board (EDPB), the independent body of data protection supervisors that promotes consistent data protection rules and application thereof throughout the European Union (EU),...more

Robinson+Cole Data Privacy + Security Insider

Irish DPA Hits WhatsApp with $266M Fine for Alleged GDPR Violations

When GDPR became effective three years ago, companies took notice of the fines and penalties attached to violations of the stringent privacy law—4 percent of global annual sales....more

K&L Gates LLP

German Supervisory Authority Initiates Post-Schrems II Enforcement Against EU Companies Using U.S. Service Providers

K&L Gates LLP on

The Bavarian Data Protection Authority recently prohibited a European company from using U.S. newsletter provider Mailchimp in a first-of-its-kind decision. Since the Schrems II decision of the Court of Justice of the...more

BakerHostetler

International Data Protection Update – First Quarter 2021

BakerHostetler on

This quarterly update highlights some of the international data protection issues that have caught our attention, and the attention of our clients, in the past three months....more

Hogan Lovells

Spanish DPA shakes the privacy status quo in Spain – highest fines yet on personal data

Hogan Lovells on

The Spanish Data Protection Agency (“Spanish DPA”) decided to start 2021 the same way it ended 2020: by imposing the highest fines to date (EUR 5,000,000 and 6,000,000) to two large Spanish financial entities. ...more

Epiq

Comply or Get Fined: 2020 GDPR Fines are the Highest on Record

Epiq on

The European Union’s (EU) General Data Protection Regulation (GDPR) has been in effect since May 2018. The law’s goal of protecting EU citizens’ personal information and privacy seems to be coming into fruition. In the past,...more

Barnea Jaffa Lande & Co.

H&M Fined EUR 35 Million for Violating Employee Privacy in Germany

Barnea Jaffa Lande & Co. on

In early October, the Data Protection Authority in Hamburg, Germany announced that the clothing retailer H&M committed severe violations of its employees’ privacy. Because of these European General Data Protection Regulations...more

Spirit Legal

35 million reasons to take privacy seriously: German data protection authority hits fashion store owner H&M with second-highest...

Spirit Legal on

It was announced today that the Hamburg data protection authority (DPA) has imposed a fine of a whopping €35,258,707.95 on the fashion retailer H&M Hennes & Mauritz Online Shop A.B. & Co. KG, which is based in Hamburg....more

Latham & Watkins LLP

French Data Protection Authority Hands Down First Sanction as Lead Authority

Latham & Watkins LLP on

The CNIL has imposed a €250,000 fine on an online retailer for GDPR infringements in cooperation with other EU supervisory authorities. Founded in 2006 and headquartered in France, Spartoo SAS (Spartoo) is one of the...more

White & Case LLP

GDPR Guide to National Implementation: Cyprus - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed. ——— (b) Relevant legislation includes: ...more

White & Case LLP

GDPR Guide to National Implementation: Bulgaria - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? Old legislation has been updated. ———...more

White & Case LLP

GDPR Guide to National Implementation: Belgium - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed. ———...more

White & Case LLP

GDPR Guide to National Implementation: Austria - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? Old legislation has been updated. ——— (b) Relevant legislation...more

Hogan Lovells

The ICO Updates Its Data Sharing Code of Practice

Hogan Lovells on

On 9 July 2019 the UK data protection authority (ICO) updated its Data Sharing Code of Practice (first published in 2011) (Code). On the same day, the ICO also announced its intention to fine Marriott International just over...more

White & Case LLP

Regulator prohibits use of transaction data for marketing purposes

White & Case LLP on

The Dutch Data Protection Authority has written to the Dutch Banking Association to state that processing customers' transaction data for direct marketing purposes may not be in compliance with the General Data Protection...more

White & Case LLP

UK ICO issues major fines and criticises lack of data protection due diligence in corporate acquisitions

White & Case LLP on

The UK Information Commissioner's Office announced more than £280 million of fines last week, in connection with data protection breaches. It singled out the perceived failure of buyers to conduct proper data protection due...more

Akin Gump Strauss Hauer & Feld LLP

A Year of GDPR: Five Recommendations to Help Limit Regulatory Scrutiny

A year ago, on May 25, 2018, the European Union’s General Data Protection Regulation (GDPR) came into force. With its extraterritorial scope and detailed requirements, the GDPR aimed to change the approach to personal data...more

42 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide