Data Protection Bulletins
The Council of Europe Convention on AI
Following two years of work – a fairly limited time frame for an international treaty – the Convention on Artificial Intelligence (“AI”), the first legally binding international treaty on AI, was approved on May 17, 2024, at the annual meeting of the Council of Europe’s
Data retention periods
In the bulletin of May 9, 2024, we recalled that retention is a processing operation and that personal data should be retained for a limited time, indeed, for the minimum amount of time necessary to fulfill the stated purpose. In this round, we focus on
Amendments to the Italian Privacy Code
The decree-law for the implementation of the National Recovery and Resilience Plan (so-called “PNRR Decree” Decree No. 19 of March 2, 2024, converted with amendments by Law No. 56/2024), provided in Article 44.1-bis, the amendment of Articles 2-sexies and 110 of the Privacy Code. Both
Data retention
In this article, we address one of the thorniest aspects of the data protection discipline: data retention and, in particular, the limitation of the time of retention of personal data. It is not so much the principle itself that is complex – according to which
Pay or Consent
The European Data Protection Board (EDPB) on April 17 issued its long-awaited Opinion 08/2024 on the GDPR compliance of the “pay or consent” mode of using personal data for behavioral advertising, which has long been used by operators of major online platforms and online media
Liability in the GDPR
With today’s episode on liability, we complete our legal analysis on the triad of adequacy, accountability and liability with regard to data protection law. Adequacy Adequacy – as stated in the January 25, 2024 Bulletin – is the element on which the level of compliance
Facial recognition for time and attendance: lawfulness and GDPR compliance
The Italian Data Protection Authority’s newsletter number 520 of March 28, 2024 reports the issuance of five decisions by the authority against as many companies involving the implementation and operation of a facial recognition system to detect workplace attendance by employees at waste disposal sites.
Accountability in the GDPR
The application perimeter of the accountability principle is not that of merely demonstrating what, if anything, the data controller claims in terms of GDPR compliance; in fact, accountability consists of a twofold obligation: Comply with the general principles (“The controller shall be responsible for, and
Code of Conduct for Employment Agencies
In the February 29, 2024 bulletin, news was given of the completion of the Code of Conduct for Employment Agenciesby dwelling on the legal bases identified for typical processing of personnel data, as these can provide useful guidance to any employer attempting to compile its
CJEU on processing and personal data
Three CJEU pronouncements have clarified some important aspects of the general concepts of “processing” and “personal data.” Some of the Court’s considerations are of general relevance; others must be contextualized to the case before the Luxembourg judges. The rulings were all delivered on March 7,
EDPB opinion on the main establishment
The topic of Opinion 04/2024, issued by the European Data Protection Board (EDPB) on February 13, 2024, is the notion of a data controller’s main establishment in the Union under Article 4(16)(a) of the GDPR. It was the French supervisory authority (CNIL) that requested the
ENEL Energia and procedural time limits
In a press release dated Feb. 29, 2024, the Italian Data Protection Authority announced the issuance of its own sanction measure of more than 79 million euros against Enel Energia for telemarketing processing violations (web doc no. 9988710). The value of the fine is the
Legal bases for personnel data processing
In its February 14, 2024 newsletter, the Italian Data Protection Authority informs of the approval of the code of conduct for employment agencies. As specified in the press release, “the code defines good practices for the correct processing of data carried out in the context
Guidance document on metadata of employees’ emails
* The Authority in a subsequent decision suspended the legal effects of the guidance document and initiated a public consultation to be concluded within 30 days. There has been an uproar over the Italian Data Protection Authority’s guidance document disclosed in the Feb. 6, 2024,
Coordinated Enforcement Action
In January 2024, the EDPB published the report on the designation and position of DPOs as a result of the Coordinated Enforcement Action (“CEA”) conducted in 2023, as part of the Coordinated Enforcement Framework (“CEF”) convened in 2022. Previously, the same committee conducted the first
Interactions between the Data Act and personal data protection
As is well known, the purpose of the Data Act – specified in Recital (4) thereof – is to “to lay down a harmonised framework specifying who is entitled to use product data or related service data, under which conditions and on what basis.” Recital
Italian Data Protection Authority’s decisions on Local Health Authorities
The January 24, 2024, newsletter of the Italian data protection authority reports the news of three decisions with related fine orders against three Local Health Authorities in the Friuli-Venezia Giulia region. The merits of the disputes are identical and concern a statistical stratification treatment of
Adequacy in the GDPR
The term “adequacy” and other words with the same root are found 113 times in the Italian text of the GDPR. Adequacy is synonymous with “proportionality” i.e., being in proper relation to the element of comparison. Adequacy in the GDPR is not a feature present
GDPR damage compensation
A number of decisions of the EU Court of Justice provide further interpretive clarification on the compensation of damages arising from processing of personal data under Article 82 of the GDPR. Article 82 of the GDPR Article 82(1) of the GDPR reads as follows: «Any
Data Act
The Official Journal of the European Union has published the long-awaited data regulation “Data Act”. After the Data Governance Act, the Data Act is the second most significant regulatory intervention of a horizontal nature i.e., applicable to any sector, of the EU Data Strategy promoted
The right to be forgotten for former cancer patients
On Dec. 18, 2023, the Italian official gazette published Law No. 193/2023, which introduces the right to be forgotten for former cancer patients into Italy’s legal system. Thus comes to a successful conclusion a parliamentary initiative promoted by multiple sources, already in the past legislature, and
Cryptography
In a press release dated Dec. 12, 2023, the Italian Data Protection Authority announced the adoption of guidelines on cryptographic functions, created with the Agency for National Cybersecurity (ACN), in particular, on password retention. The guidelines were adopted by a decision of the Authority dated
Behavioral advertising and urgent binding decision
The European Data Protection Board (EDPB) has made public the urgent binding decision adopted on October 27, 2023 (UBD) ordering the adoption of definitive actions against Meta IE in relation to its processing of personal data for behavioral advertising purposes, indicating as legal bases the
Privacy access of the heirs
The Italian Data Protection Authority’s newsletter of Nov. 27, 2023, gives notice of the Oct. 26 decision (web doc. no. 9954881), interpretative about the exercise of the right of access by heirs to the data of deceased individuals. However, the Authorithy’s intervention, which appropriately traces
Controls on artificial intelligence -2
We resume our analysis of the implications that the development of artificial intelligence (“AI”) tools generates in the personal data protection area, continuing along the lines outlined in the previous bulletin of November 16, 2023. The acquisition of a dataset by the developer, in order
ePrivacy Scope of Application
On November 14, 2023, the EDPB published Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive. As usual, the guidelines are subject to public consultation for a period ending December 28, 2023. Probably, this action was necessary as a result of difficulties in
Controls on artificial intelligence
Artificial intelligence (AI) tools are the focus of general attention, both for the countless opportunities they offer and for the impacts they can cause on individuals and the community. At different levels, binding rules or recommendations and guidelines have been proposed or have already been
Data breach: operational implications
Criminals have been known to take advantage of favorable conditions; nature, with its elementary but timeless rules, teaches us that the predatory animal relies on two characteristics: dexterity and vulnerability. The same is true, outside the metaphor, for cybercriminals. During the Covid pandemic, a circumstance
Whistleblowing: GDPR Setting – 3
Legislative Decree No. 24 of 2023, implementing EU Directive 2019/1937, introduced in the Italian legal system a horizontal discipline of whistleblowing no longer markedly split between the public sphere – regulated within the Consolidated Text for Public Bodies (Legislative Decree No. 165/2001, Art. 54-bis) –
Worker geolocation and the right of access
The Italian Data Protection Authority’s decision of September 14, 2023 (web doc. no. 9936174) deals with the right of access under the Data Protection Regulation. The aspects that have been touched upon are not new but offer an opportunity to better contextualize the different profiles
The algorithm examined by the Supreme Court
In a recent decision, the Supreme Court has ruled on the issue of lawfulness regarding judgments on the substance of cases involving artificial intelligence tools. This ruling – in the opinion of the author – highlights how the jurisprudential approach in this area has not
CJEU decisions on data protection
Over the past year (October 2022-October 2023), the Court of Justice of the EU (CJEU) has issued interpretative decisions on several provisions of the GDPR, ePrivacy, and Directive 2016/680. The CJEU’s pronouncements help in a correct reading of regulatory requirements, shedding light on aspects that
Whistleblowing: the Italian National Anti-corruption Authority’s Guidelines and GDPR Setting -2
Italian Legislative Decree No. 24/2023 – implementing Directive (EU) 2019/1937 – on whistleblowing and the resulting Anti-Corruption Authority’s guidelines (ANAC) for procedures for the submission and management of external reports, first and foremost, regulate the phenomenon of reports of potential wrongdoing that workers and collaborators
EU data strategy and termination of the parliamentary term
In this legislative period, 2019-2024, the European Union has been marked by considerable dynamism in the development of legislative acts directly or indirectly related to the EU data strategy. The panorama of EU legislation in this area is broad and includes acts that have been
Duration of the consent to data processing
Two recent decisions of the Italian Data Protection Authority, against Comparafacile (web doc. no. 9921112) and Tiscali (web doc. no. 9920942), offer the cue to resume the systematic analysis of consent as a legal basis for data processing, in general, and for processing for marketing
DPO and conflict of interests
The data protection officer (DPO) plays an important supervisory role with regard to compliance with legal requirements and policies on the subject that may have been adopted by the entity that appointed him or her, whether the data controller or the processor. The subject of
Whistleblowing: the Italian National Anti-corruption Authority’s Guidelines and the GDPR setting – 1
Regulatory framework Directive (EU) 2019/1937 obliges member states to adopt in their legal systems specific guiding principles for horizontal regulation of the phenomenon of whistleblowing, reporting or public disclosure of situations that are against the law, of which employees become aware in their employment environment.
Data Privacy Framework
The new EU-US agreement on the transfer to the United States of personal data of EU subjects – known as the Data Privacy Framework (“DPF”) – was the subject of an adequacy decision by the EU Commission on July 10, 2023. With this act of
Personal data for marketing purposes and others -2
We resume and complete the analysis of the Italian Data Protection Authorithy’s decisions announced in the June 28, 2023 newsletter (web doc no. 9903191) full of insights not only in the marketing field but also as an opportunity to reiterate or clarify general rules applicable
Right of access according to the CJEU – 2
We resume our analysis of some preliminary rulings of the CJEU on the right of access, published in the first half of 2023; specifically, issued: In the Crif case, C-487/21, of May 4, 2023 on the right of access, the term of “copy” and the
Personal data for marketing purposes and others -1
In its newsletter of June 28, 2023 (web doc. no. 9903191) the Italian Supervisory Authority’s mentioned a number of decisions adopted by the Authority that are rich in insights not only in the area of marketing but also as an opportunity to reiterate or specify general rules
Right of access according to the CJEU – 1
The GDPR grants data subjects specific rights to ensure that they have control over the use of their personal data in Articles 15 to 22. These rights, which are given to the data subject thanks to the provisions contained in the regulation, should be kept
Does the violation of the ROPA cause unlawful processing?
The Court of Justice of the EU (CJEU) on May 4, 2023 issued its decision on the preliminary ruling subject of Case C-60/22, UZ v. Bundesrepublik Deutschland. The questions submitted to the CJEU concerned the following aspects of the GDPR: Whether the lack of maintaining
EDPB: calculation of administrative fines under the GDPR
On 24 May 2023, the EDPB released the updated version of Guidelines 04/2022 – on the calculation methods of administrative fines – which incorporates some of the suggestions from the public consultation. In addition to changes of a purely formal nature, the major change concerns
Considerations on artificial intelligence
Artificial intelligence has assumed such relevance in the global debate that not a day goes by without a multiplicity of articles and interviews, scientific reports, and interventions by authorities and public institutions. It is difficult to disentangle oneself from this flood of information and even
The processing of health data in the workplace
On May 25, 2023, the Advocate General submitted his conclusions regarding Case C-667/21 on the reference for a preliminary ruling submitted to the CJEU by the German Federal Labour Court. Many of the conclusions are in the groove of previous pronouncements of the same Court
When pseudonyms are not personal data -2
We resume our analysis of the European General Court decision of April 26, 2023 on the dispute that occurred between a European agency ( the Single Resolution Board – SRB) and the EDPS concerning the appeal of a decision of the European Supervisor against the
Jehovah’s Witnesses Litigation between the CJEU and the ECtHR
On May 9, 2023, the Chamber of the European Court of Human Rights (ECtHR) issued a decision in Case No. 31172/19 that could put an end to a more than decade-long litigation involving, on the one hand, the Jehovah’s Witnesses community and, on the other
When pseudonyms are not personal data
The European General Court, a constituent court of the Court of Justice of the European Union, ruled on April 26, 2023 on a dispute between a European agency (Single Resolution Board – SRB) and the EDPS concerning the appeal of a decision of the European
Privacy rights and legal bases
The European Data Protection Board (EDPB) has released a GDPR compliance guide for small and medium-sized enterprises. In it, the table of the scope of application of privacy rights in relation to the legal bases of personal data processing is worth highlighting for summary clarity.
The Italian Supreme Court on the consequences of phishing on online bank access codes
In its March 13, 2023, No. 7214 decision, the Italian Supreme Court ruled conclusively on a banking dispute that involved a financial institution and some of its account holders regarding liability for abusive access to a bank account by unauthorized third parties resulting in the
Code of conduct for telemarketing and teleselling – 2
The code of conduct (“cdc”) for telemarketing and teleselling approved by the Italian Data Protection Authority with Decision No. 70 of March 9, 2023 (Web Doc. No. 9868813) awaits, for its entry into force, the accreditation of the Monitoring Body by the authority and, thereafter,
Data sources: focus on the public sector
Profiling, automated decisions, algorithms and artificial intelligence presuppose the availability of large amounts of data, personal and non-personal. The main question in this technological phase, therefore, is finding the sources of data from which to draw, sources that are reliable, accurate, and readily available. European
Code of conduct for telemarketing and teleselling – 1
The final draft of the code of conduct for telemarketing and teleselling activities – after July 21, 2022- was submitted for public consultation and, thereafter, submitted to the Italian Data Protection Authority (Garante) for approval, who approved it with Order No. 70 of March 9,
EDPB one-stop-shop case digest on right to object and right to erasure
On February 20, 2023, the EDPB released the One-Stop-Shop case digest on right to object and right to erasure, by Professor Mantelero, i.e., a compendium of evidence from decisions taken under the One-Stop-Shop mechanism and published on the corresponding EDPB Registry. Consultation of the Registry
European investigation on DPO designation and position
On March 15, 2023, the European Data Protection Board launched the second coordinated enforcement action, following the previous one in 2022, on the designation and position of the DPOs within the organization of companies and entities. It is intended to ascertain, through the dissemination and filling out
Whether both Art. 9 and Art. 6 of the GDPR should be complied with when it comes to sensitive data
Days ago a friend asked me for a confirmation that for the lawfulness of the processing of special categories of personal data – but the issue also concerns the “judicial” data of Article 10 – it was indeed necessary to identify also a specific legal
Burden of proof in the exercise of privacy rights
The principle of accountability requires the controller to demonstrate its compliance with the requirements of the GDPR, establishing a general reversal of the burden of proof. This conclusion is especially true in controller-supervisory authority relationships and, to a lesser extent, in controller-data subject interactions. There
Contrived or fraudulent schemes in personal data protection
Following public consultation, on February 14, 2023, the EDPB released version 2 of Guidelines 03/2022 on deceptive design patterns in social media platform interfaces. As usual, few changes have occurred since version 1, starting with the title where the term “dark patterns” has been preferred
Proof of consent: data processing and retention
A decision by the Danish Data Protection Authority on operations carried out by a data broker for marketing purposes has addressed innovative aspects of interest. In summary, the decision answered the following questions: If a data broker acquires personal data for its own marketing purposes
GDPR evolution through the EU Data Strategy – 3
There are several provisions of the DGA, DMA, DSA, and the proposed EHDS that intersect those of the GDPR realizing on various issues a composite discipline from multiple sources. In this round, we will focus on the news concerning: Minors Risk assessment Profiling Forbidden data
Whistleblowing
Directive (EU) 2019/1937 on whistleblowing – that is, on reporting by individuals regarding violations that have come to their attention in the work environment – introduces a uniform and harmonized regulation across different sectors. The directive had to be transposed by member states by Dec.
GDPR evolution through the EU Data Strategy – 2
There are several provisions of the DGA, DMA, DSA, and the proposed EHDS and AI Act regulations that intersect those of the GDPR realizing on various issues a composite discipline from multiple sources. In this round, we will focus on the news concerning the: Exercise
ISO 31700 Privacy by design
The International Organization for Standardization (ISO) has announced that it will adopt “Privacy by design”-or data protection by design-as the ISO 31700 standard on February 7, 2023. Compliance assessment Initially, ISO 31700 will not be a standard that can be used to certify compliance with
Data sharing
Artificial intelligence (“AI”), machine learning (“ML”), and the metaverse are all characterized by the need to require a significant amount of data: a phenomenon called big data. More precisely, AI, ML and metaverse are applications or application environments that require, as an essential condition of
Automated monitoring of employees
The control of labor activity by automated means is one of those legal profiles that most differentiates the approaches of European law from that of the United States. In the U.S., wanting to simplify, prevalence is given to the managerial power of the entrepreneur and
GDPR evolution through the EU Data Strategy -1
There are several provisions of DGA, DMA, DSA and the proposed EHDS that intersect those of the GDPR coming to realize on various issues a composite discipline from multiple sources. In this round, we will focus on the news concerning the EU representative, data brokering, data
Takeaways from Clubhouse measure
The Italian Data Protection Authority (Garante) has fined Clubhouse two million euros. The measure is full of useful guidance for the operational implementation of GDPR obligations. We provide below a summary of those that seemed most relevant. Characteristics of the controller and the service Clubhouse
GDPR evolution through the EU Data Strategy
On November 24, 2022, was held the webinar “UK and EU between data economy and protection of rights: conflicts and opportunities” organized by Officine Dati. The UK is discussing the reform of the UKGDPR, the transposition of the post-Brexit EU regulation into national law. The
Marketing takeaways from the Douglas measure
On October 20, 2022, the Italian supervisory authority issued a 1.4 million euro fine for personal data processing for marketing purposes that did not comply with the GDPR regulation in multiple respects. This articulated measure provides some useful operational rules for the industry that are
Fundamental rights and freedoms – 3
In previous bulletins we noted how, for EU law, not only the right to personal data protection is a fundamental right but also we observed the importance of additional fundamental rights for the data protection discipline (see bulletin of 6/10/2022). Then, we examined the legal
More than $400 million from Google for the use of location data
News of the agreement signed by Google and the Pennsylvania Attorney General to close an investigation by the Attorneys General of 40 US states into the company’s practices on the use of users’ location data, which were deemed deceptive and unfair, has caused a stir.
Update on the EU digital strategy
The EU data strategy has many points of contact with the data protection framework and the GDPR. In addition to the GDPR and the ePrivacy Directive, which is still being updated as the ePrivacy Regulation, as well as the Police Directive (dir. (EU) 2016/680) and
Cross-border data processing and lead authority
The flow of personal data to third countries (i.e., non-EU/EEA) has been regulated by Directive 95/46/EC in order to prevent the transfer from thwarting the safeguards and rights that EU law provides for the protection of data subjects. The GDPR, in addition to this scenario,
EDPB: Guidelines 9/2022 on data breach
The European Data Protection Board (EDPB) released on October 10, 2022, guidelines 09/2022 on the obligation to notify the supervisory authority of a data breach, submitting them to a “targeted” public consultation. These guidelines take over and replace the previous wp250 rev.01 on the same
Executive Order for EU-US data flows
On October 7, 2022, President Biden signed an executive order (Executive Order on Enhancing Safeguards for United States Signals Intelligence Activities – “EO”) regarding new safeguards under the U.S.-EU political agreement for the transfer of personal data and, in particular, for possible data access by
Fundamental Rights and Freedoms – 2
The GDPR aims to protect the fundamental rights of the individual, in particular, the right to protection of personal data. Respect for fundamental rights is the essential condition for the lawfulness of processing for compliance with the principle of lawfulness enshrined in Article 5(1)(a). Rights and
When suffering a data breach can turn into a crime
In the United States, a Chief Security Officer (CSO) was found guilty of a pair of crimes for concealing from the Federal Trade Commission that his company had suffered a data breach by hackers. The hackers had subsequently been paid a ransom so that they
Fundamental rights and freedoms
The data protection framework, protects individuals through their fundamental rights and freedoms, in particular the right to protection of personal data concerning them.The right to the protection of personal data, in addition to the nature of a fundamental right as such, also plays a facilitating function
Why Instagram was fined
The publication of the EDPB’s binding decision on the settlement of the dispute that arose between the Irish authority – as lead authority (LSA) – and a number of other concerned supervisory authorities (CSAs), together with the publication of the revised LSA decision issued in accordance
Employee’s data transparency – 2
Legislative Decree No. 104/2022 – which transposed in Italy Directive 2019/1152 on the subject of information obligations with regard to the employee – introduced a new provision (Article 1-bis) not covered by the European Directive and which requires the Italian employer to provide its employee
€405 million fine to Instagram
Ireland’s supervisory authority (Data Protection Commission “DPC”) on September 2, 2022 fined social media platform Instagram – of the Facebook group, now called Meta – €405 million for GDPR infringements. This is the largest fine imposed by this authority and the second ever imposed by
Employee’s data transparency -1
Over the summer, the Italian Official Gazette of July 29, 2022 published Legislative Decree No. 104/2022, which implements into Italian law Directive (EU) 2019/1152 on transparent and predictable working conditions. Directive 2019/1152 extends the information obligations that public and private employers were already required to
The Italian “Do-not-call” and marketing consent
We are back on the topic of the Italian “Do-not-call” Register reform, finalizing its analysis in this round. With the publication in the official gazette of the: Presidential Decree of January 27, 2022, No. 26 on the functioning of the reformed Register and Decree dated
Calculation of administrative fines under the GDPR -4
The European Data Protection Board (EDPB) has released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The Guidelines divide the logical process of determining administrative fines into steps: the first, consisting of identifying
Data Governance Act -3
Let’s resume our analysis of the EU Regulation known as the Data Governance Act, examining the data intermediation and data altruism services and the implications with the data protection regulation. We have already addressed some points of the DGA in the June 23, 2022 and
Calculation of administrative fines under the GDPR -3
The European Data Protection Board (EDPB) has released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The Guidelines divide the logical process of determining administrative fines into steps: the first, consisting of identifying
Data Governance Act -2
We resume our analysis of the EU Regulation known as the Data Governance Act, examining the re-use of data held by public sector bodies and its implications with data protection regulations. The first part of this analysis was published in the bulletin of June 23,
Calculation of administrative fines under the GDPR -2
The European Data Protection Board (EDPB) has released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The Guidelines divide the logical process of determining administrative fines into steps: the first, consisting of identifying
Data Governance Act “DGA”
The EU Commission’s proposal for a data governance regulation was published in November 2020 and completed its process, becoming a European law (EU Regulation 2022/868) with its publication in the Official Journal of the European Union on June 3, 2022. The figure below outlines the
Calculation of administrative fines under the GDPR -1
The European Data Protection Board (EDPB) released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The General Regulation made significant changes in the area of administrative fines that Directive 95/46/EC, on the other
FAQ for standard contractual clauses
On May 25, 2022, the European Commission published a set of questions and answers on the two sets of standard contractual clauses: (1) one for the use between controllers and processors (Art. 28 GDPR) and (2) one for the transfer of personal data to countries
European health data space
As part of the European data strategy, the EU Commission has released the first proposal for a European data space in a specific area, focusing on health data, in particular on electronic health data. These are the main objectives of this proposal: Enable more transparency,
EDPB Annual Report 2021
Around May-June of each year the supervisory authorities release their annual report for their activities carried out in the previous year: this has already been done by the CNIL (press version), among others, and likewise by the EDPB, while the Italian Garante’s report is expected soon.
“Privacy” access as a power of control
More and more, legislators, both supranational and national, are recognizing a right of access for individuals to information held by third parties that affects them in some way or that is functional to the exercise of their rights under the law. The GDPR is no
Complaints against GDPR violations
The several complaints lodged with national supervisory authorities, by international non-profits such as NoyB, La Quadrature du Net, Privacy International and others, are a practical example of the provisions of Article 80(1) of the GDPR, which allows data subjects to exercise their remedies recognized by
Data sharing
The data economy is based on “data sharing”, that is, the sharing of data with third parties. The EU strategy on the data economy, aimed at stimulating its development and eliminating the barriers that stand in its way, has promoted a series of legislative acts,
The Italian “Do-not-call” – 2
Let’s resume our analysis of the reform of the Italian “Do-not-call” Register (Registro Pubblico delle Opposizioni), completed with the publication in the Official Gazette of the implementing regulation (Presidential Decree no. 26/2022), replacing the previous Presidential Decree no. 178/2010. In the meantime, the Ministry of
One Stop Shop
The EDPB has released the Guidelines 02/2022 on the application of Article 60 of the GDPR, i.e., the procedural modalities of the cooperation mechanism, known as the “one-stop-shop.” The document, at first glance, would appear to be aimed primarily at supervisory authorities, but offers useful
The Italian “Do-not-call” – 1
The official gazette of March 29, 2022 (no. 74) – the editorial body that publishes with official value the regulations of the Italian Republic – has published the long-awaited regulation of the Italian “Do Not Call” Register (Registro Pubblico delle Opposizioni). The Italian Do-not-call Register
EU – U.S. data flows: political agreement
On the sidelines of the European and global level meetings held in Brussels, the joint press conference of the President of the United States and the President of the EU Commission on March 25, 2022, broke the news that an agreement “in principle” had been
Clearview Case – Takeaways
The business of the American company – consisting in the web scraping of images of internet users, in the matching with metadata identifying the subjects and in the comparison with photos provided by the customers of the application in order to obtain their identification – has been
Artificial Intelligence in the GDPR
EU Data Strategy The proposal for an Artificial Intelligence Regulation is part of the broader EU data strategy that has already produced a large number of regulations aimed at creating a single European data market: the Data Governance Act and the Data Act, which aim
Exercise of Rights
The EDPB Guidelines 01/2022 on the “privacy” right of access contain indications that can be also applied generally with regard to the exercise of other GDPR rights. In this roundup, for example, we will discuss two aspects that are common to the exercise of any right under the regulation: the matter of
Data Act
The European Commission has published the long-awaited proposal for a regulation on data law (“Data Act“). This is, after the Data Governance Act, the second most important regulatory measure crossing all sectors of the EU Data Strategy (see Bulletin of 22/7, 9/9, 11/11 and 23/12/2021). EU Data Strategy
Data Barter
If it is true that data – and “personal” data in particular – are the lifeblood of the digital economy, it is equally true that their availability is essential for the performance of any type of activity, whether of a commercial or non-profit nature. Entering
Belgian Authority vs. IAB Europe
A complex investigation into the GDPR compliance of the Transparent and Consent Framework platform of the IAB Europe federation, which brings together stakeholders in the field of behavioral advertising, has come to an end with a €250,000 sanctioning decision adopted by the Belgian authority. Measure of the
EDPB Guidelines on the Right of access
The European Data Protection Board has released Guidelines 01/2022 on the right of access subjecting them, as is customary, to public consultation; any comments should be sent by March 11, 2022. The guidelines contain an explanatory flow chart, which we will use to better describe
CNIL vs. Google
The disputes between the French supervisory authority and the Californian company are still going on for alleged violations of European regulations on the protection of personal data and privacy in electronic communications. On December 31, 2021, the CNIL fined for a total of 150 million
Sanction for telemarketing and more
The Italian authority intervened once again regarding telemarketing activities that did not comply with the applicable regulations, imposing one of the largest fines of 26.5 million euros. The measure – which also regarded violations of a different nature – was issued at the end of
Grindr sanctioning measure
The case in which the Norwegian supervisory authority (Datatilsynet) sanctioned the American company Grindr LLC, supplying the mobile application Grindr, the world’s largest social networking app for the LGBTQ community, offers elements to be considered both from the point of view of the strategy for
Defensive employees’ monitoring: from the Italian legal cases
If the employer has the right to check the worker’s performance, the latter does not lose confidentiality margins for the sole fact of working in the company. European Court of Human Rights According to the European Court of Human Rights (ECtHR), the protection of
Advertiser privacy roles
In the context of the implementation of advertising campaigns, in reference to the topic of the identification of subjective privacy roles, we’ll discuss the specific role assumed by the advertiser. The latter, hired by the client, implements the campaign using personal data in his exclusive
Data Governance Act – 2
One of the main regulations in the EU data strategy is the proposed Data Governance Act. In the bulletin of November 11th, we described its general aspects; in this one, we will focus on its relative impacts on the discipline dictated by the GDPR, in
Data on criminal convictions and offences
Data relating to criminal convictions and offenses receive heightened protection under the GDPR because of the sensitivity of the information they cover and the high impact they can have on the rights and freedoms of data subjects. According to the CJEU, this type of information
Connected vehicles
On March 9, 2021, the European Data Protection Board (EDPB), following the public consultation phase, adopted the final version (v.2.0) of Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications. Considering the wide context of reference, the topic
EU Data Strategy – 3
The European Union’s data strategy takes shape through an articulated complex of regulatory acts, some already enacted and others in the course of completing the legislative process among the European institutions. EU Regulations for data sharing Once the data protection regime has been
Targeted advertising to social media users
On April 13, 2021, the European Data Protection Board (EPDB) adopted the final version (v. 2.0) of the 8/2020 Guidelines on targeting of social media users following the conclusion of the public consultation phase. Subsequently, on July 7, 2021, the same EDPB released a new
Lead Generation
Let’s take a closer look at “lead generation”, that is, the preliminary step of advertising campaigns consisting of promotional solicitation aimed at collecting the names of customers who express their general interest in the particular product or service to be promoted. Solicitations of leads
DGA -1
In the European strategy for data, an important step is the proposal for a regulation known as the Data Governance Act or DGA. It complements other initiatives that aim to achieve developmental conditions for the data economy while respecting the platform of safeguards and measures
Responsibilities of a EU Representative
In the event that an organization under the jurisdiction of a country outside the EU/EEA processes personal data that falls within the scope of the GDPR and does not have its own establishment in the EU, it must designate, in writing, a Representative established in
Social engineering
The expression “social engineering”, in the domain of information security, usually groups together all those cases of artifices and deceptions aimed at manipulating the human predisposition to trust. In fact, unlike to what might appear at first sight, the human being is inclined to have
A. I. between expectations and doubts – second part
Anticipated by the work of the High-Level Expert Group on AI (Ethics Guidelines for Trustworthy AI of April 2019 and Policy and Investment Recommendations for Trustworthy AI of June 2019) and the EU Commission’s own White Paper on AI (19/2/2020), the proposed Artificial Intelligence Act
Additional measures in personal data transfers
On June 18, 2021, the European Committee released the updated version (v.2.0) of Recommendations 1/2020 on additional measures to be adopted in the event that those provided by Article 46 of the GDPR to legitimize data transfers to third countries, are not sufficient following the
Green pass: Interactions with the related processing of personal data -2
The discipline of the use of the green pass, as indicated by the Legislative Decree 52/2021 and 127/2021 and as reiterated by the regulation 2021/953, inevitably involves the processing of personal data so, within these areas, you must make sure to comply with both disciplines.
Green Pass, green Privacy
The Covid pandemic has forced us to a difficult exercise of new balances between fundamental rights and freedoms, some synergistic – such as public and private health as well as protection of personal data – others where there was more evidence of a backward step
Relationship between domestic and European law
Often, even in the course of this Covid-19 pandemic, we have witnessed uncertainties on the part of the legislators of individual EU member states in identifying ways to intervene in issues and rights already governed by European law. Especially in the field of personal data
EU Representative
The appointment of the EU Representative is required if the company in question is subject to the law of a country which is not a member of the European Union and only under certain circumstances and conditions. Summary How to determine if
EU Data Strategy – 2
We resume our analysis of the European data strategy and the main purpose of promoting the development of a “data driven” economy of the union. In the Alert of July 22nd, 2021, we highlighted the strategic value of “data” and examined the ranking of the
Code of Conduct on commercial information
After two years since its approval on June 12, 2019 (see Editorial of 6/27/2019), on May 27, 2021, the “Code of Conduct prepared by the National Association between Business Information and Credit Management Companies (Ancic)” (“Code on commercial information”) came into force in Italy through
Standard clauses between controllers and processors – 2
The Legal Information Service will be paused for the month of August and will recommence with the bulletin of September 2nd. We complete the analysis of the EU Commissione 2021/915 decision which adopts the standard clauses between data controllers and data processors, considering their structure
EU data strategy – 1
The European Commission, with the publication of the “European data strategy” document of 2020, launched the five-year strategic plan for the creation of the European Common Data Space and the Data-based digital economy. The plan starts from the observation that the two major “players” of
Cookies: new guidelines of the Italian Garante
The Privacy Garante – following the public consultation completed in 2020 – has released the new guidelines on cookies that update those of 2014 following the changes made by the GDPR. Although they come out in the middle of the negotiation of the trilogue between
The EU Commission has adopted the new SCCs – 2
Let’s go back to examining the new standard clauses adopted by the EU Commission aimed at legitimizing the transfer of personal data to third countries (see Alert of 10/6/2021). The transfer of personal data to a third country (i.e. neither belonging to the EU nor
The Council of State on the Italian Antitrust v. Facebook – 2
The sentence of 29 March 2021 of the Italian Council of State (in Italian) – which concluded the first group of the charges made by the Antitrust (“AGCM”) to Facebook for the unfair commercial practices carried out in relation to the use of the personal
Data breach: notification forms
There is an aphorism in the world of information security that says “do not ask yourself if you will ever have a data breach, but rather when it will be your turn”. In the domain of personal data protection, data security is a principle of
The Italian Council of State on the Antitrust v. Facebook – 1
The first round of the Italian antitrust (“AGCM”) litigation case against Facebook, started on 6 April 2018 to challenge alleged unfair commercial practices implemented by the social provider in the use of personal data of its users / consumers, has come to a conclusion. The
Italian Antitrust against Facebook
The second round in the confrontation between the AGCM and Facebook also came to an end with the imposition of a new overall fine of € 7 million against Facebook Ireland Ltd. and Facebook Inc. jointly and severally. The story shows how the current business
Cookie “banner”, “barrier” and “wall”
The EU Commission’s proposal for the new ePrivacy regulation did not explicitly refer to the circumstances that practice has identified with the terms “cookie banner”, “cookie barrier” and “cookie wall”. The version of Parliament approved by the LIBE commission provides for the prohibition of “cookie
Advertising and Data Protection
Individual advertising or “direct” promotion, in a broad sense, is that promotional operations that address the advertising message directly to the potential customer (therefore also called “direct marketing”); this aspect distinguishes it from general advertising which, on the other hand, is aimed at a general
International data flows: the new SCCs
Within a few days, answers were given, albeit not definitive, to the stringent expectations that followed the decision of the CJEU on the Schrems II case. The decision of the Court, as is known, invalidated the Privacy Shield agreement and considered the standard or “SCC”
ENISA Threat scenario
The EU Cyber Security Agency (ENISA) has published the 2019-2020 threat scenario. This is the eighth edition but also the first since the entry into force of the Cybersecurity Act which strengthened the role and competences of the agency by giving it a permanent mandate.
ICO reduces the fine on British Airways
Following a major security incident that caused the breach of sensitive personal data of over 400,000 individuals (passengers), the British Information Commissioner (“ICO”) the 08/07/2019 communicated to the airline the intention to sanction it for the significant sum of 183.39 million pounds (€ 204M) for
Brazilian privacy law
After an initial postponement in February 2020, on 26th of August the Brazilian Senate approved the entry into force of the Brazilian law on the protection of personal data “Lei Geral de Proteção de Dados Pessoais” (LGPD) with effect from 15 August 2020, ie two
Data Subject Requests
Learning from previous cases The provisions of the national supervisory authorities, together with the guidelines and opinions of the EDPB, if read in watermark allow us to obtain important information on how to operate in organizations in order to respond adequately to the principle of
Schrems II
On 16 July 2020, the Court of Justice of the European Union issued the expected decision on the preliminary ruling in the case known as Schrems II (C-311/18) which deemed the Privacy Shield instrument invalid, with immediate effect and clarified some aspects regarding the scope
The 6 rules for personal data breach
Last week’s Alert pointed out hacker opportunism taking advantage of emergencies, as recorded in these Coronavirus times. There are many profiles of increased vulnerability in this situation: work outside the corporate context, where the level of protection – physical and logical – is certainly higher