Data Protection Bulletins

The Council of Europe Convention on AI

Following two years of work – a fairly limited time frame for an international treaty – the Convention on Artificial Intelligence (“AI”), the first legally binding international treaty on AI, was approved on May 17, 2024, at the annual meeting of the Council of Europe’s

Read more »

Data retention periods

In the bulletin of May 9, 2024, we recalled that retention is a processing operation and that personal data should be retained for a limited time, indeed, for the minimum amount of time necessary to fulfill the stated purpose. In this round, we focus on

Read more »

Amendments to the Italian Privacy Code

The decree-law for the implementation of the National Recovery and Resilience Plan (so-called “PNRR Decree” Decree No. 19 of March 2, 2024, converted with amendments by Law No. 56/2024), provided in Article 44.1-bis, the amendment of Articles 2-sexies and 110 of the Privacy Code. Both

Read more »

Data retention

In this article, we address one of the thorniest aspects of the data protection discipline: data retention and, in particular, the limitation of the time of retention of personal data. It is not so much the principle itself that is complex – according to which

Read more »

Pay or Consent

The European Data Protection Board (EDPB) on April 17 issued its long-awaited Opinion 08/2024 on the GDPR compliance of the “pay or consent” mode of using personal data for behavioral advertising, which has long been used by operators of major online platforms and online media

Read more »

Liability in the GDPR

With today’s episode on liability, we complete our legal analysis on the triad of adequacy, accountability and liability with regard to data protection law. Adequacy Adequacy – as stated in the January 25, 2024 Bulletin – is the element on which the level of compliance

Read more »

Accountability in the GDPR

The application perimeter of the accountability principle is not that of merely demonstrating what, if anything, the data controller claims in terms of GDPR compliance; in fact, accountability consists of a twofold obligation: Comply with the general principles (“The controller shall be responsible for, and

Read more »

Code of Conduct for Employment Agencies

In the February 29, 2024 bulletin, news was given of the completion of the Code of Conduct for Employment Agenciesby dwelling on the legal bases identified for typical processing of personnel data, as these can provide useful guidance to any employer attempting to compile its

Read more »

CJEU on processing and personal data

Three CJEU pronouncements have clarified some important aspects of the general concepts of “processing” and “personal data.” Some of the Court’s considerations are of general relevance; others must be contextualized to the case before the Luxembourg judges. The rulings were all delivered on March 7,

Read more »

EDPB opinion on the main establishment

The topic of Opinion 04/2024, issued by the European Data Protection Board (EDPB) on February 13, 2024, is the notion of a data controller’s main establishment in the Union under Article 4(16)(a) of the GDPR. It was the French supervisory authority (CNIL) that requested the

Read more »

ENEL Energia and procedural time limits

In a press release dated Feb. 29, 2024, the Italian Data Protection Authority  announced the issuance of its own sanction measure of more than 79 million euros against Enel Energia for telemarketing processing violations (web doc no. 9988710). The value of the fine is the

Read more »

Legal bases for personnel data processing

In its February 14, 2024 newsletter, the Italian Data Protection Authority informs of the approval of the code of conduct for employment agencies. As specified in the press release, “the code defines good practices for the correct processing of data carried out in the context

Read more »

Guidance document on metadata of employees’ emails

* The Authority in a subsequent decision suspended the legal effects of the guidance document and initiated a public consultation to be concluded within 30 days. There has been an uproar over the Italian Data Protection Authority’s guidance document disclosed in the Feb. 6, 2024,

Read more »

Coordinated Enforcement Action

In January 2024, the EDPB published the report on the designation and position of DPOs as a result of the Coordinated Enforcement Action (“CEA”) conducted in 2023, as part of the Coordinated Enforcement Framework (“CEF”) convened in 2022. Previously, the same committee conducted the first

Read more »

Adequacy in the GDPR

The term “adequacy” and other words with the same root are found 113 times in the Italian text of the GDPR. Adequacy is synonymous with “proportionality” i.e., being in proper relation to the element of comparison. Adequacy in the GDPR is not a feature present

Read more »

GDPR damage compensation

A number of decisions of the EU Court of Justice provide further interpretive clarification on the compensation of damages arising from processing of personal data under Article 82 of the GDPR. Article 82 of the GDPR Article 82(1) of the GDPR reads as follows: «Any

Read more »

Data Act

The Official Journal of the European Union has published the long-awaited data regulation “Data Act”. After the Data Governance Act, the Data Act is the second most significant regulatory intervention of a horizontal nature i.e., applicable to any sector, of the EU Data Strategy promoted

Read more »

The right to be forgotten for former cancer patients

On Dec. 18, 2023, the Italian official gazette published Law No. 193/2023, which introduces the right to be forgotten for former cancer patients into Italy’s legal system. Thus comes to a successful conclusion a parliamentary initiative promoted by multiple sources, already in the past legislature, and

Read more »

Cryptography

In a press release dated Dec. 12, 2023, the Italian Data Protection Authority announced the adoption of guidelines on cryptographic functions, created with the Agency for National Cybersecurity (ACN), in particular, on password retention. The guidelines were adopted by a decision of the Authority dated

Read more »

Behavioral advertising and urgent binding decision

The European Data Protection Board (EDPB) has made public the urgent binding decision adopted on October 27, 2023 (UBD) ordering the adoption of definitive actions against Meta IE in relation to its processing of personal data for behavioral advertising purposes, indicating as legal bases the

Read more »

Privacy access of the heirs

The Italian Data Protection Authority’s newsletter of Nov. 27, 2023, gives notice of the Oct. 26 decision (web doc. no. 9954881), interpretative about the exercise of the right of access by heirs to the data of deceased individuals.  However, the Authorithy’s intervention, which appropriately traces

Read more »

Controls on artificial intelligence -2

We resume our analysis of the implications that the development of artificial intelligence (“AI”) tools generates in the personal data protection area, continuing along the lines outlined in the previous bulletin of November 16, 2023. The acquisition of a dataset by the developer, in order

Read more »

ePrivacy Scope of Application

On November 14, 2023, the EDPB published Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive. As usual, the guidelines are subject to public consultation for a period ending December 28, 2023. Probably, this action was necessary as a result of difficulties in

Read more »

Controls on artificial intelligence

Artificial intelligence (AI) tools are the focus of general attention, both for the countless opportunities they offer and for the impacts they can cause on individuals and the community. At different levels, binding rules or recommendations and guidelines have been proposed or have already been

Read more »

Data breach: operational implications

Criminals have been known to take advantage of favorable conditions; nature, with its elementary but timeless rules, teaches us that the predatory animal relies on two characteristics: dexterity and vulnerability. The same is true, outside the metaphor, for cybercriminals. During the Covid pandemic, a circumstance

Read more »

Whistleblowing: GDPR Setting – 3

Legislative Decree No. 24 of 2023, implementing EU Directive 2019/1937, introduced in the Italian legal system a horizontal discipline of whistleblowing no longer markedly split between the public sphere – regulated within the Consolidated Text for Public Bodies (Legislative Decree No. 165/2001, Art. 54-bis) –

Read more »

Worker geolocation and the right of access

The Italian Data Protection Authority’s decision of September 14, 2023 (web doc. no. 9936174) deals with the right of access under the Data Protection Regulation. The aspects that have been touched upon are not new but offer an opportunity to better contextualize the different profiles

Read more »

The algorithm examined by the Supreme Court

In a recent decision, the Supreme Court has ruled on the issue of lawfulness regarding judgments on the substance of cases involving artificial intelligence tools. This ruling – in the opinion of the author – highlights how the jurisprudential approach in this area has not

Read more »

CJEU decisions on data protection

Over the past year (October 2022-October 2023), the Court of Justice of the EU (CJEU) has issued interpretative decisions on several provisions of the GDPR, ePrivacy, and Directive 2016/680. The CJEU’s pronouncements help in a correct reading of regulatory requirements, shedding light on aspects that

Read more »

EU data strategy and termination of the parliamentary term

In this legislative period, 2019-2024, the European Union has been marked by considerable dynamism in the development of legislative acts directly or indirectly related to the EU data strategy.  The panorama of EU legislation in this area is broad and includes acts that have been

Read more »

Duration of the consent to data processing

Two recent decisions of the Italian Data Protection Authority, against Comparafacile (web doc. no. 9921112) and Tiscali (web doc. no. 9920942), offer the cue to resume the systematic analysis of consent as a legal basis for data processing, in general, and for processing for marketing

Read more »

DPO and conflict of interests

The data protection officer (DPO) plays an important supervisory role with regard to compliance with legal requirements and policies on the subject that may have been adopted by the entity that appointed him or her, whether the data controller or the processor. The subject of

Read more »

Data Privacy Framework

The new EU-US agreement on the transfer to the United States of personal data of EU subjects – known as the Data Privacy Framework (“DPF”) – was the subject of an adequacy decision by the EU Commission on July 10, 2023. With this act of

Read more »

Personal data for marketing purposes and others -2

We resume and complete the analysis of the Italian Data Protection Authorithy’s decisions announced in the June 28, 2023 newsletter (web doc no. 9903191) full of insights not only in the marketing field but also as an opportunity to reiterate or clarify general rules applicable

Read more »

Right of access according to the CJEU – 2

We resume our analysis of some preliminary rulings of the CJEU on the right of access, published in the first half of 2023; specifically, issued: In the Crif case, C-487/21, of May 4, 2023 on the right of access, the term of “copy” and the

Read more »

Personal data for marketing purposes and others -1

In its newsletter of June 28, 2023 (web doc. no. 9903191)  the Italian Supervisory Authority’s mentioned a number of decisions adopted by the Authority that are rich in insights not only in the area of marketing but also as an opportunity to reiterate or specify general rules

Read more »

Right of access according to the CJEU – 1

The GDPR grants data subjects specific rights to ensure that they have control over the use of their personal data in Articles 15 to 22. These rights, which are given to the data subject thanks to the provisions contained in the regulation, should be kept

Read more »

EDPB: calculation of administrative fines under the GDPR

On 24 May 2023, the EDPB released the updated version of Guidelines 04/2022 – on the calculation methods of administrative fines – which incorporates some of the suggestions from the public consultation. In addition to changes of a purely formal nature, the major change concerns

Read more »

Considerations on artificial intelligence

Artificial intelligence has assumed such relevance in the global debate that not a day goes by without a multiplicity of articles and interviews, scientific reports, and interventions by authorities and public institutions. It is difficult to disentangle oneself from this flood of information and even

Read more »

The processing of health data in the workplace

On May 25, 2023, the Advocate General submitted his conclusions regarding Case C-667/21 on the reference for a preliminary ruling submitted to the CJEU by the German Federal Labour Court. Many of the conclusions are in the groove of previous pronouncements of the same Court

Read more »

When pseudonyms are not personal data -2

We resume our analysis of the European General Court decision of April 26, 2023 on the dispute that occurred between a European agency ( the Single Resolution Board – SRB) and the EDPS concerning the appeal of a decision of the European Supervisor against the

Read more »

When pseudonyms are not personal data

The European General Court, a constituent court of the Court of Justice of the European Union, ruled on April 26, 2023 on a dispute between a European agency (Single Resolution Board – SRB) and the EDPS concerning the appeal of a decision of the European

Read more »

Privacy rights and legal bases

The European Data Protection Board (EDPB) has released a GDPR compliance guide for small and medium-sized enterprises. In it, the table of the scope of application of privacy rights in relation to the legal bases of personal data processing is worth highlighting for summary clarity. 

Read more »

Code of conduct for telemarketing and teleselling – 2

The code of conduct (“cdc”) for telemarketing and teleselling approved by the Italian Data Protection Authority with Decision No. 70 of March 9, 2023 (Web Doc. No. 9868813) awaits, for its entry into force, the accreditation of the Monitoring Body by the authority and, thereafter,

Read more »

Data sources: focus on the public sector

Profiling, automated decisions, algorithms and artificial intelligence presuppose the availability of large amounts of data, personal and non-personal. The main question in this technological phase, therefore, is finding the sources of data from which to draw, sources that are reliable, accurate, and readily available. European

Read more »

Code of conduct for telemarketing and teleselling – 1

The final draft of the code of conduct for telemarketing and teleselling activities – after July 21, 2022- was submitted for public consultation and, thereafter, submitted to the Italian Data Protection Authority (Garante) for approval, who approved it with Order No. 70 of March 9,

Read more »

European investigation on DPO designation and position

On March 15, 2023, the European Data Protection Board launched the second coordinated enforcement action, following the previous one in 2022, on the designation and position of the DPOs within the organization of companies and entities. It is intended to ascertain, through the dissemination and filling out

Read more »

Burden of proof in the exercise of privacy rights

The principle of accountability requires the controller to demonstrate its compliance with the requirements of the GDPR, establishing a general reversal of the burden of proof. This conclusion is especially true in controller-supervisory authority relationships and, to a lesser extent, in controller-data subject interactions. There

Read more »

Contrived or fraudulent schemes in personal data protection

Following public consultation, on February 14, 2023, the EDPB released version 2 of Guidelines 03/2022 on deceptive design patterns in social media platform interfaces. As usual, few changes have occurred since version 1, starting with the title where the term “dark patterns” has been preferred

Read more »

Proof of consent: data processing and retention

A decision by the Danish Data Protection Authority on operations carried out by a data broker for marketing purposes has addressed innovative aspects of interest. In summary, the decision answered the following questions: If a data broker acquires personal data for its own marketing purposes

Read more »

GDPR evolution through the EU Data Strategy – 3

There are several provisions of the DGA, DMA, DSA, and the proposed EHDS that intersect those of the GDPR realizing on various issues a composite discipline from multiple sources. In this round, we will focus on the news concerning: Minors   Risk assessment   Profiling   Forbidden data

Read more »

Whistleblowing

Directive (EU) 2019/1937 on whistleblowing – that is, on reporting by individuals regarding violations that have come to their attention in the work environment – introduces a uniform and harmonized regulation across different sectors.  The directive had to be transposed by member states by Dec.

Read more »

GDPR evolution through the EU Data Strategy – 2

There are several provisions of the DGA, DMA, DSA, and the proposed EHDS and AI Act regulations that intersect those of the GDPR realizing on various issues a composite discipline from multiple sources.  In this round, we will focus on the news concerning the: Exercise

Read more »

ISO 31700 Privacy by design

The International Organization for Standardization (ISO) has announced that it will adopt “Privacy by design”-or data protection by design-as the ISO 31700 standard on February 7, 2023. Compliance assessment Initially, ISO 31700 will not be a standard that can be used to certify compliance with

Read more »

Data sharing

Artificial intelligence (“AI”), machine learning (“ML”), and the metaverse are all characterized by the need to require a significant amount of data: a phenomenon called big data. More precisely, AI, ML and metaverse are applications or application environments that require, as an essential condition of

Read more »

Automated monitoring of employees

The control of labor activity by automated means is one of those legal profiles that most differentiates the approaches of European law from that of the United States. In the U.S., wanting to simplify, prevalence is given to the managerial power of the entrepreneur and

Read more »

GDPR evolution through the EU Data Strategy -1

There are several provisions of DGA, DMA, DSA and the proposed EHDS that intersect those of the GDPR coming to realize on various issues a composite discipline from multiple sources.   In this round, we will focus on the news concerning the EU representative, data brokering, data

Read more »

Takeaways from Clubhouse measure

The Italian Data Protection Authority (Garante) has fined Clubhouse two million euros. The measure is full of useful guidance for the operational implementation of GDPR obligations. We provide below a summary of those that seemed most relevant. Characteristics of the controller and the service Clubhouse

Read more »

GDPR evolution through the EU Data Strategy

On November 24, 2022, was held the webinar “UK and EU between data economy and protection of rights: conflicts and opportunities” organized by Officine Dati. The UK is discussing the reform of the UKGDPR, the transposition of the post-Brexit EU regulation into national law. The

Read more »

Marketing takeaways from the Douglas measure

On October 20, 2022, the Italian supervisory authority issued a 1.4 million euro fine for personal data processing for marketing purposes that did not comply with the GDPR regulation in multiple respects.    This articulated measure provides some useful operational rules for the industry that are

Read more »

Fundamental rights and freedoms – 3

In previous bulletins we noted how, for EU law, not only the right to personal data protection is a fundamental right but also we observed the importance of additional fundamental rights for the data protection discipline (see bulletin of 6/10/2022). Then, we examined the legal

Read more »

Update on the EU digital strategy

The EU data strategy has many points of contact with the data protection framework and the GDPR. In addition to the GDPR and the ePrivacy Directive, which is still being updated as the ePrivacy Regulation, as well as the Police Directive (dir. (EU) 2016/680) and

Read more »

Cross-border data processing and lead authority

The flow of personal data to third countries (i.e., non-EU/EEA) has been regulated by Directive 95/46/EC in order to prevent the transfer from thwarting the safeguards and rights that EU law provides for the protection of data subjects. The GDPR, in addition to this scenario,

Read more »

EDPB: Guidelines 9/2022 on data breach

The European Data Protection Board (EDPB) released on October 10, 2022, guidelines 09/2022 on the obligation to notify the supervisory authority of a data breach, submitting them to a “targeted” public consultation. These guidelines take over and replace the previous wp250 rev.01 on the same

Read more »

Executive Order for EU-US data flows

On October 7, 2022, President Biden signed an executive order (Executive Order on Enhancing Safeguards for United States Signals Intelligence Activities – “EO”) regarding new safeguards under the U.S.-EU political agreement for the transfer of personal data and, in particular, for possible data access by

Read more »

Fundamental Rights and Freedoms – 2

The GDPR aims to protect the fundamental rights of the individual, in particular, the right to protection of personal data. Respect for fundamental rights is the essential condition for the lawfulness of processing for compliance with the principle of lawfulness enshrined in Article 5(1)(a).  Rights and

Read more »

When suffering a data breach can turn into a crime

In the United States, a Chief Security Officer (CSO) was found guilty of a pair of crimes for concealing from the Federal Trade Commission that his company had suffered a data breach by hackers.  The hackers had subsequently been paid a ransom so that they

Read more »

Fundamental rights and freedoms

The data protection framework, protects individuals through their fundamental rights and freedoms, in particular the right to protection of personal data concerning them.The right to the protection of personal data, in addition to the nature of a fundamental right as such, also plays a facilitating function

Read more »

Why Instagram was fined

The publication of the EDPB’s binding decision on the settlement of the dispute that arose between the Irish authority – as lead authority (LSA) – and a number of other concerned supervisory authorities (CSAs), together with the publication of the revised LSA decision issued in accordance

Read more »

Employee’s data transparency – 2

Legislative Decree No. 104/2022 – which transposed in Italy Directive 2019/1152 on the subject of information obligations with regard to the employee – introduced a new provision (Article 1-bis) not covered by the European Directive and which requires the Italian employer to provide its employee

Read more »

€405 million fine to Instagram

Ireland’s supervisory authority (Data Protection Commission “DPC”) on September 2, 2022 fined social media platform Instagram – of the Facebook group, now called Meta – €405 million for GDPR infringements. This is the largest fine imposed by this authority and the second ever imposed by

Read more »

Employee’s data transparency -1

Over the summer, the Italian Official Gazette of July 29, 2022 published Legislative Decree No. 104/2022, which implements into Italian law Directive (EU) 2019/1152 on transparent and predictable working conditions. Directive 2019/1152 extends the information obligations that public and private employers were already required to

Read more »

The Italian “Do-not-call” and marketing consent

We are back on the topic of the Italian “Do-not-call” Register reform, finalizing its analysis in this round. With the publication in the official gazette of the:  Presidential Decree  of January 27, 2022, No. 26 on the functioning of the reformed Register and  Decree dated

Read more »

Calculation of administrative fines under the GDPR -4

The European Data Protection Board (EDPB) has released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The Guidelines divide the logical process of determining administrative fines into steps: the first, consisting of identifying

Read more »

Data Governance Act -3

Let’s resume our analysis of the EU Regulation known as the Data Governance Act, examining the data intermediation and data altruism services and the implications with the data protection regulation. We have already addressed some points of the DGA in the June 23, 2022 and

Read more »

Calculation of administrative fines under the GDPR -3

The European Data Protection Board (EDPB) has released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The Guidelines divide the logical process of determining administrative fines into steps: the first, consisting of identifying

Read more »

Data Governance Act -2

We resume our analysis of the EU Regulation known as the Data Governance Act, examining the re-use of data held by public sector bodies and its implications with data protection regulations. The first part of this analysis was published in the bulletin of  June 23,

Read more »

Calculation of administrative fines under the GDPR -2

The European Data Protection Board (EDPB) has released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022.  The Guidelines divide the logical process of determining administrative fines into steps: the first, consisting of identifying

Read more »

Data Governance Act “DGA”

The EU Commission’s proposal for a data governance regulation was published in November 2020 and completed its process, becoming a European law (EU Regulation 2022/868) with its publication in the Official Journal of the European Union on June 3, 2022. The figure below outlines the

Read more »

Calculation of administrative fines under the GDPR -1

The European Data Protection Board (EDPB) released Guidelines 04/2022 on the calculation of administrative fines under the GDPR, submitting them for public consultation until June 27, 2022. The General Regulation made significant changes in the area of administrative fines that Directive 95/46/EC, on the other

Read more »

FAQ for standard contractual clauses

On May 25, 2022, the European Commission published a set of questions and answers on the two sets of standard contractual clauses: (1) one for the use between controllers and processors (Art. 28 GDPR) and (2) one for the transfer of personal data to countries

Read more »

European health data space

As part of the European data strategy, the EU Commission has released the first proposal for a European data space in a specific area, focusing on health data, in particular on electronic health data. These are the main objectives of this proposal: Enable more transparency,

Read more »

EDPB Annual Report 2021

Around May-June of each year the supervisory authorities release their annual report for their activities carried out in the previous year: this has already been done by the CNIL (press version), among others, and likewise by the EDPB, while the Italian Garante’s report is expected soon.

Read more »

“Privacy” access as a power of control

More and more, legislators, both supranational and national, are recognizing a right of access for individuals to information held by third parties that affects them in some way or that is functional to the exercise of their rights under the law. The GDPR is no

Read more »

Complaints against GDPR violations

The several complaints lodged with national supervisory authorities, by international non-profits such as NoyB, La Quadrature du Net, Privacy International and others, are a practical example of the provisions of Article 80(1) of the GDPR, which allows data subjects to exercise their remedies recognized by

Read more »

Data sharing

The data economy is based on “data sharing”, that is, the sharing of data with third parties. The EU strategy on the data economy, aimed at stimulating its development and eliminating the barriers that stand in its way, has promoted a series of legislative acts,

Read more »

The Italian “Do-not-call” – 2

Let’s resume our analysis of the reform of the Italian “Do-not-call” Register (Registro Pubblico delle Opposizioni), completed with the publication in the Official Gazette of the implementing regulation (Presidential Decree no. 26/2022), replacing the previous Presidential Decree no. 178/2010. In the meantime, the Ministry of

Read more »

One Stop Shop

The EDPB has released the Guidelines 02/2022 on the application of Article 60 of the GDPR, i.e., the procedural modalities of the cooperation mechanism, known as the “one-stop-shop.” The document, at first glance, would appear to be aimed primarily at supervisory authorities, but offers useful

Read more »

The Italian “Do-not-call” – 1

The official gazette of March 29, 2022 (no. 74) – the editorial body that publishes with official value the regulations of the Italian Republic – has published the long-awaited regulation of the Italian “Do Not Call” Register (Registro Pubblico delle Opposizioni). The Italian Do-not-call Register

Read more »

EU – U.S. data flows: political agreement

On the sidelines of the European and global level meetings held in Brussels, the joint press conference of the President of the United States and the President of the EU Commission on March 25, 2022, broke the news that an agreement “in principle” had been

Read more »

Clearview Case – Takeaways

The business of the American company – consisting in the web scraping of images of internet users, in the matching with metadata identifying the subjects and in the comparison with photos provided by the customers of the application in order to obtain their identification – has been

Read more »

Artificial Intelligence in the GDPR

EU Data Strategy The proposal for an Artificial Intelligence Regulation is part of the broader EU data strategy that has already produced a large number of regulations aimed at creating a single European data market:    the Data Governance Act and the Data Act, which aim

Read more »

Exercise of Rights

The EDPB Guidelines 01/2022 on the “privacy” right of access contain indications that can be also applied generally with regard to the exercise of other GDPR rights. In this roundup, for example, we will discuss two aspects that are common to the exercise of any right under the regulation: the matter of

Read more »

Data Act

The European Commission has published the long-awaited proposal for a regulation on data law (“Data Act“). This is, after the Data Governance Act, the second most important regulatory measure crossing all sectors of the EU Data Strategy (see Bulletin of 22/7, 9/9, 11/11 and 23/12/2021).   EU Data Strategy

Read more »

Data Barter

If it is true that data – and “personal” data in particular – are the lifeblood of the digital economy, it is equally true that their availability is essential for the performance of any type of activity, whether of a commercial or non-profit nature. Entering

Read more »

Belgian Authority vs. IAB Europe

A complex investigation into the GDPR compliance of the Transparent and Consent Framework platform of the IAB Europe federation, which brings together stakeholders in the field of behavioral advertising, has come to an end with a €250,000 sanctioning decision adopted by the Belgian authority. Measure of the

Read more »

EDPB Guidelines on the Right of access

The European Data Protection Board has released Guidelines 01/2022 on the right of access subjecting them, as is customary, to public consultation; any comments should be sent by March 11, 2022. The guidelines contain an explanatory flow chart, which we will use to better describe

Read more »

CNIL vs. Google

The disputes between the French supervisory authority and the Californian company are still going on for alleged violations of European regulations on the protection of personal data and privacy in electronic communications. On December 31, 2021, the CNIL fined for a total of 150 million

Read more »

Sanction for telemarketing and more

The Italian authority intervened once again regarding telemarketing activities that did not comply with the applicable regulations, imposing one of the largest fines of 26.5 million euros. The measure – which also regarded violations of a different nature – was issued at the end of

Read more »

Grindr sanctioning measure

The case in which the Norwegian supervisory authority (Datatilsynet) sanctioned the American company Grindr LLC, supplying the mobile application Grindr, the world’s largest social networking app for the LGBTQ community, offers elements to be considered both from the point of view of the strategy for

Read more »

Advertiser privacy roles

In the context of the implementation of advertising campaigns, in reference to the topic of the identification of subjective privacy roles, we’ll discuss the specific role assumed by the advertiser. The latter, hired by the client, implements the campaign using personal data in his exclusive

Read more »

Data Governance Act – 2

One of the main regulations in the EU data strategy is the proposed Data Governance Act. In the bulletin of November 11th, we described its general aspects; in this one, we will focus on its relative impacts on the discipline dictated by the GDPR, in

Read more »

Data on criminal convictions and offences

Data relating to criminal convictions and offenses receive heightened protection under the GDPR because of the sensitivity of the information they cover and the high impact they can have on the rights and freedoms of data subjects. According to the CJEU, this type of information

Read more »

Connected vehicles

On March 9, 2021, the European Data Protection Board (EDPB), following the public consultation phase, adopted the final version (v.2.0) of Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications. Considering the wide context of reference, the topic

Read more »

EU Data Strategy – 3

The European Union’s data strategy takes shape through an articulated complex of regulatory acts, some already enacted and others in the course of completing the legislative process among the European institutions.   EU Regulations for data sharing   Once the data protection regime has been

Read more »

Targeted advertising to social media users

On April 13, 2021, the European Data Protection Board (EPDB) adopted the final version (v. 2.0) of the 8/2020 Guidelines on targeting of social media users following the conclusion of the public consultation phase.  Subsequently, on July 7, 2021, the same EDPB released a new

Read more »

Lead Generation

Let’s take a closer look at “lead generation”, that is, the preliminary step of advertising campaigns consisting of promotional solicitation aimed at collecting the names of customers who express their general interest in the particular product or service to be promoted.   Solicitations of leads

Read more »

DGA -1

In the European strategy for data, an important step is the proposal for a regulation known as the Data Governance Act or DGA. It complements other initiatives that aim to achieve developmental conditions for the data economy while respecting the platform of safeguards and measures

Read more »

Responsibilities of a EU Representative

In the event that an organization under the jurisdiction of a country outside the EU/EEA processes personal data that falls within the scope of the GDPR and does not have its own establishment in the EU, it must designate, in writing, a Representative established in

Read more »

Social engineering

The expression “social engineering”, in the domain of information security, usually groups together all those cases of artifices and deceptions aimed at manipulating the human predisposition to trust. In fact, unlike to what might appear at first sight, the human being is inclined to have

Read more »

A. I. between expectations and doubts – second part

Anticipated by the work of the High-Level Expert Group on AI (Ethics Guidelines for Trustworthy AI of April 2019 and Policy and Investment Recommendations for Trustworthy AI of June 2019) and the EU Commission’s own White Paper on AI (19/2/2020), the proposed Artificial Intelligence Act

Read more »

Additional measures in personal data transfers

On June 18, 2021, the European Committee released the updated version (v.2.0) of Recommendations 1/2020 on additional measures to be adopted in the event that those provided by Article 46 of the GDPR to legitimize data transfers to third countries, are not sufficient following the

Read more »

Green Pass, green Privacy

The Covid pandemic has forced us to a difficult exercise of new balances between fundamental rights and freedoms, some synergistic – such as public and private health as well as protection of personal data – others where there was more evidence of a backward step

Read more »

Relationship between domestic and European law

Often, even in the course of this Covid-19 pandemic, we have witnessed uncertainties on the part of the legislators of individual EU member states in identifying ways to intervene in issues and rights already governed by European law. Especially in the field of personal data

Read more »

EU Representative

The appointment of the EU Representative is required if the company in question is subject to the law of a country which is not a member of the European Union and only under certain circumstances and conditions.   Summary     How to determine if

Read more »

EU Data Strategy – 2

We resume our analysis of the European data strategy and the main purpose of promoting the development of a “data driven” economy of the union.  In the Alert of July 22nd, 2021, we highlighted the strategic value of “data” and examined the ranking of the

Read more »

Code of Conduct on commercial information

After two years since its approval on June 12, 2019 (see Editorial of 6/27/2019), on May 27, 2021, the “Code of Conduct prepared by the National Association between Business Information and Credit Management Companies (Ancic)” (“Code on commercial information”) came into force in Italy through

Read more »

Standard clauses between controllers and processors – 2

The Legal Information Service will be paused for the month of August and will recommence with the bulletin of September 2nd. We complete the analysis of the EU Commissione 2021/915 decision which adopts the standard clauses between data controllers and data processors, considering their structure

Read more »

EU data strategy – 1

The European Commission, with the publication of the “European data strategy” document of 2020, launched the five-year strategic plan for the creation of the European Common Data Space and the Data-based digital economy. The plan starts from the observation that the two major “players” of

Read more »

Cookies: new guidelines of the Italian Garante

The Privacy Garante – following the public consultation completed in 2020 – has released the new guidelines on cookies that update those of 2014 following the changes made by the GDPR. Although they come out in the middle of the negotiation of the trilogue between

Read more »

The EU Commission has adopted the new SCCs – 2

Let’s go back to examining the new standard clauses adopted by the EU Commission aimed at legitimizing the transfer of personal data to third countries (see Alert of 10/6/2021). The transfer of personal data to a third country (i.e. neither belonging to the EU nor

Read more »

Data breach: notification forms

There is an aphorism in the world of information security that says “do not ask yourself if you will ever have a data breach, but rather when it will be your turn”. In the domain of personal data protection, data security is a principle of

Read more »

Italian Antitrust against Facebook

The second round in the confrontation between the AGCM and Facebook also came to an end with the imposition of a new overall fine of € 7 million against Facebook Ireland Ltd. and Facebook Inc. jointly and severally. The story shows how the current business

Read more »

Cookie “banner”, “barrier” and “wall”

The EU Commission’s proposal for the new ePrivacy regulation did not explicitly refer to the circumstances that practice has identified with the terms “cookie banner”, “cookie barrier” and “cookie wall”.  The version of Parliament approved by the LIBE commission provides for the prohibition of “cookie

Read more »

Advertising and Data Protection

Individual advertising or “direct” promotion, in a broad sense, is that promotional operations that address the advertising message directly to the potential customer (therefore also called “direct marketing”); this aspect distinguishes it from general advertising which, on the other hand, is aimed at a general

Read more »

International data flows: the new SCCs

Within a few days, answers were given, albeit not definitive, to the stringent expectations that followed the decision of the CJEU on the Schrems II case.  The decision of the Court, as is known, invalidated the Privacy Shield agreement and considered the standard or “SCC”

Read more »

ENISA Threat scenario

The EU Cyber Security Agency (ENISA) has published the 2019-2020 threat scenario. This is the eighth edition but also the first since the entry into force of the Cybersecurity Act which strengthened the role and competences of the agency by giving it a permanent mandate.

Read more »

ICO reduces the fine on British Airways

Following a major security incident that caused the breach of sensitive personal data of over 400,000 individuals (passengers), the British Information Commissioner (“ICO”) the 08/07/2019 communicated to the airline the intention to sanction it for the significant sum of 183.39 million pounds (€ 204M) for

Read more »

Brazilian privacy law

After an initial postponement in February 2020, on 26th of August the Brazilian Senate approved the entry into force of the Brazilian law on the protection of personal data “Lei Geral de Proteção de Dados Pessoais” (LGPD) with effect from 15 August 2020, ie two

Read more »

Data Subject Requests

Learning from previous cases The provisions of the national supervisory authorities, together with the guidelines and opinions of the EDPB, if read in watermark allow us to obtain important information on how to operate in organizations in order to respond adequately to the principle of

Read more »

Schrems II

On 16 July 2020, the Court of Justice of the European Union issued the expected decision on the preliminary ruling in the case known as Schrems II (C-311/18) which deemed the Privacy Shield instrument invalid, with immediate effect and clarified some aspects regarding the scope

Read more »

The 6 rules for personal data breach

Last week’s Alert pointed out hacker opportunism taking advantage of emergencies, as recorded in these Coronavirus times. There are many profiles of increased vulnerability in this situation: work outside the corporate context, where the level of protection – physical and logical – is certainly higher

Read more »