Reevaluating Microsoft 365 Copilot Due to Privacy Concerns

Recent findings underline the importance of skepticism among privacy professionals concerning the adoption of new technologies. The case in point is Microsoft 365 Copilot, which poses significant privacy risks that educational and research institutions are advised to consider. Critical Privacy Concerns Microsoft 365 Copilot is under scrutiny following a Data Protection Impact Assessment (DPIA) carried […]

Navigating Google’s Fingerprinting Policy Shift: Implications for Data Protection

On 16 February 2025, Google will change its policy to allow the use of fingerprinting in its advertising products. As data protection professionals, we must understand the profound implications of this move for user privacy and compliance with regulatory frameworks. Understanding Fingerprinting: Fingerprinting involves collecting various data points from a device’s hardware and software to […]

Enhancing Data Subjects’ Rights: The Bayerisches Landesamt für Datenschutzaufsicht’s Worldcoin Investigation Outcome

The Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) has recently concluded its investigation into the biometric data processing practices of Worldcoin, an international digital verification service and cryptocurrency project. This inquiry, focusing on strengthening the rights of data subjects, emphasizes the enforcement of European fundamental rights standards amidst a complex technological and legal landscape. Investigation Highlights: – […]

Enhancing Personal Data Breach Management: Insights from the EDPS Campaign

In a landmark campaign to mark its 20th Anniversary, the European Data Protection Supervisor (EDPS) launched an initiative in 2024 designed to bolster the awareness and management of personal data breaches among European Union Institutions, Agencies, and Bodies (EUIs). This endeavor aimed to fortify compliance with Regulation 2018/1725, enhancing the safeguarding of personal data across […]

Netflix Fined for Inadequate Customer Information Disclosure

Data protection experts will find the recent penalty imposed on Netflix by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens (AP), both a cautionary tale and a lessons-rich case. The streaming giant faced a 4.75 million euro fine after an investigation revealed significant shortcomings in the information it provided customers regarding the usage of their personal […]

Orange Fined €50 Million for Unlawful Email Advertisements

In a significant enforcement action, the French Data Protection Authority (CNIL) levied a €50 million fine against Orange, France’s leading telecommunications operator. The penalty arises from the company’s unauthorized insertion of advertisements within user email inboxes, a clear breach of privacy regulations under the French Data Protection Act and the Post and Electronic Communications Code. […]

Clearview Fined for Illegal Data Collection: Implications for Data Protection Practices

Data protection specialists are acutely aware of the regulatory environment surrounding the collection and use of biometric data. In a significant development, the Dutch Data Protection Authority, Autoriteit Persoonsgegevens (AP), has imposed a substantial fine on Clearview AI amounting to 30.5 million euros, alongside potential additional penalties over 5 million euros, for their inappropriate use […]

Assessing Compliance: The European Commission’s Use of Microsoft 365 Under Scrutiny by EDPS

The European Data Protection Supervisor (EDPS) is keenly examining the European Commission’s adherence to data protection compliance concerning their deployment of Microsoft 365. This measure forms part of a larger effort to ensure that personal data processed by EU institutions adhere to the stringent protections established within Regulation (EU) 2018/1725. Key Insights: – EDPS Compliance […]

Evaluating the ICO’s Public Sector Approach: Strategic Insights

Data protection professionals will find the ICO’s recent strategic review of its public sector approach both enlightening and essential to understanding the evolving landscape of data regulation. John Edwards, UK Information Commissioner, has outlined a proactive and dynamic engagement strategy with public sector bodies, aimed at enhancing data protection compliance while minimizing the punitive financial […]

Email Monitoring in Italy: Navigating Stricter Rules Under the Italian DPA

Data protection professionals and privacy experts in Italy are facing significant challenges with the latest decision by the Italian Data Protection Authority (DPA) regarding email monitoring. The decision underscores the complexities surrounding email management under Italian data protection law, highlighting the increased scrutiny on employers’ compliance with GDPR standards. Key Insights: – Updated Guidelines: On […]