Assessment of Inadequate Handling of Data Access Requests Across Europe

On the eve of Data Protection Day 2025, an insightful study by the European Data Protection Board (EDPB) has revealed significant issues in how organizations handle access requests. As data protection professionals and privacy experts, it is crucial to understand the implications of these findings, which highlighted the frequent mishandling of such requests across various […]

Implementing Data Subjects Rights in AI Systems: A Data Protection Professional’s Guide

In the evolving landscape of data protection, the General Data Protection Regulation (GDPR) empowers individuals with numerous rights regarding their personal data. For data protection professionals, ensuring effective implementation of these rights, particularly in AI systems, is crucial. This post offers insights into challenges and methodologies that can enhance compliance with data subjects rights, specifically […]

Enhancing the Right of Access: Findings from the 2024 Coordinated Enforcement Action

As data protection professionals and privacy experts, it is paramount to understand the recent developments surrounding the implementation of the right of access under GDPR. The European Data Protection Board (EDPB) has undertaken a Coordinated Enforcement Framework (CEF) initiative to assess compliance among data controllers regarding access requests, with conclusions expected to shape future best […]

Exploring Pseudonymisation under the GDPR: A Data Protection Strategy – request for input (consultation)

Data protection professionals are always in search of robust strategies to enhance privacy and security. The General Data Protection Regulation GDPR introduces and emphasizes pseudonymisation as a critical measure. As experts in the field, understanding the nuances, benefits, and implementation of pseudonymisation is vital to fulfilling data protection obligations effectively. Understanding Pseudonymisation Pseudonymisation is recognized […]

Data Breach at Volkswagen: A Privacy Wake-Up Call for Vehicle Data Management

The recent data breach at Volkswagen involving the exposure of sensitive information from around 800,000 electric vehicles has thrust vehicle privacy into the spotlight. As data protection professionals, it is vital to scrutinize the implications of such events, especially in the context of automated data collection and its impact on privacy rights. This incident involved […]

Data Protection Toolkit for Schools: Navigating Compliance Challenges

The Data Protection Commission (DPC) has recently unveiled a significant resource aimed at aiding educational institutions in navigating the complexities of data protection compliance. The new “Data Protection Toolkit for Schools” is specifically designed to address the nuanced data protection challenges faced by schools when handling the personal data of children. This initiative, emerging from […]

Commission’s Data Sharing Practices with the US Challenged

Recent developments in data protection have seen the General Court ruling against the European Commission, highlighting the intricacies of data transfer regulations and their implications for EU institutions. In a landmark case, the General Court ordered the Commission to compensate an EU citizen for the unauthorized transfer of his personal data to the United States […]

Mobile Applications: Enhancing Privacy Protection through CNIL’s Recommendations

As data protection professionals, the increasing use of mobile applications by French citizens, as shown by 2023 data, cannot be overlooked. The average download of 30 apps and usage of over three hours a day raises significant concerns about data confidentiality and security. The Commission Nationale de lInformatique et des Libertés CNIL recently published recommendations […]

Sanctions on Unlawful Telemarketing and Data Breach Responses by Privacy Authority

The Italian Data Protection Authority, Garante Privacy, continues to be rigorous in its enforcement actions against non-compliance issues within data protection. Recently, the authority imposed a significant fine of 678,897 euros on Illumia Spa, a utility provider, for unlawful promotional practices that breached personal data regulations. This enforcement is part of the ongoing crackdown on […]

AI in Recruitment: Striking a Balance Between Innovation and Privacy

As artificial intelligence continues to transform recruitment, it offers significant benefits while presenting substantial challenges to data protection. The Information Commissioner’s Office (ICO) diligently conducted audits of AI-powered recruitment tools to ensure compliance with UK data protection law, uncovering critical insights for data protection professionals and privacy experts. Key Areas for Improvement: 1. Data Accuracy […]