Blog

Data protection digest 1 – 15 Nov 2024: digital product liability, emerging genomics, surveillance databases

EU Product Liability The new Product Liability Directive has been published in the Official Journal of the European Union and will take effect in 20 days. The new law extends the definition of “product” to digital manufacturing files and software, (not excluding AI manufacturers in the future). Also, online platforms can be held liable for […]

Meet Stewart Haynes: former Information Commissioner and TechGDPR Senior Consultant

Stewart Haynes, a former Information Commissioner, has joined the TechGDPR team as a senior consultant. Stewart excels in complex regulatory reporting and remediation scenarios, helping clients approach these critical areas with clarity and precision. His guidance is invaluable for companies building or refining their privacy programs, preparing for potential regulatory interventions, or managing high-risk incidents. […]

Data protection digest 17 – 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI

Non-for-Profit Updated privacy guidance for not-for-profit has been released by the Office of the Australian Information Commissioner. It includes a discussion on what to consider when engaging third-party providers, such as for fundraising, or software vendors. For instance, when entering into arrangements with third parties, your non-for-profit should take reasonable steps to ensure that the third […]

Embracing the GDPR as a non-EU company

6 years after becoming enforceable, the GDPR has not died out in popularity as a conversation topic among board members. While is remains the elephant in the room for many a stakeholder, non-EU companies who have embraced its application and requirements are finding it much easier to remain contenders on the European market. This article […]

Data protection digest 2 – 16 Oct 2024: knowing your processors and sub-processors, automated driving, election technologies

Reliance on processors and sub-processors The EDPB has issued an opinion on the interpretation of certain duties of controllers relying on processors and sub-processors, arising from Art. 28 of the GDPR, as well as the wording of controller-processor contracts. In particular, controllers should have information on the identity of all processors and sub-processors etc. readily […]

Ethical AI: How Data Officers Craft Policies for Fairness, Accountability, and Transparency

The use of artificial intelligence (AI) nowadays is pervasive and many organizations are attempting to develop their version of AI. The EU AI Act was recently passed in August 2024 after years of discussion between the European Commission and Parliament, and now it regulates the use and development of AI systems in the EU. The […]

Beyond Compliance: Elevating AI Ethics with a Data Officer’s Expertise

Introduction The ethical development and usage of artificial intelligence (AI) is essential to ensure fairness, transparency, and justice, as AI systems increasingly impact society and individuals. There are various frameworks and principles that organizations can use to mitigate risks such as bias, discrimination, and privacy violations. Appointing a Data Officer provides a strategic advantage by […]

Data protection digest 17 Sep – 1 Oct 2024: EU Data Act as an illustration of the GDPR ‘prevail’ principle

How does the EU Data Act interact with the GDPR? The Data Act will become applicable in the EU starting on 12 September 2025. In the runup, the European Commission has published an FAQ on the new legislation. Together with the Data Governance Act, it enables a fair distribution of value by establishing clear rules […]

The Future of Responsible AI: The Essential Role of a Data Officer

EU Digital Compliance Landscape After long discussions and a feedback process, we finally have the AI Act. The AI Act covers major concerns such as the ethical use of AI, AI governance, and risk management for AI systems. The future of responsible AI now has a clear legal path. It is hard to capture all […]

Data protection digest 2 – 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR

In this digest we look at the perception of the term privacy in the digital era, data protection measures when concluding “asset deals”, the new SCCs initiative for international transfers from the EU, the probability method and data accuracy, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. […]

Do you need support on data protection, privacy or GDPR? TechGDPR can help.

Request your free consultation