The Data Act As of 12 September, the Data Act has become directly applicable in the EU. It offers harmonised rules on fair access to and use of data. The new rules cover manufacturers, users, data holders, data recipients, public sector bodies, and data processing services. It is designed to empower users, both consumers and […]
Blog
Data protection digest 18-31 Aug 2025: Greater simplification of GDPR, ‘personalisation’ in AI systems
An informal discussion is underway for the greater simplification of the GDPR The Danish EU Presidency is promoting GDPR reform to increase competitiveness by introducing SME-friendly amendments, such as restricting data rights in low-risk situations, rationalising DPIAs, and requiring prior mediation procedures before lodging complaints, the eutechloop.com article states. These are in line with the […]
Data protection digest 2-17 Aug 2025: “Data protection says what should be done, information security says how we do it” – Estonian regulator
How is data protection related to information security? The goal of information security is to protect an organisation’s business processes. This means responsibility for the security of the entire operating system and the ability to resist any activities that threaten the availability, authenticity, integrity, and confidentiality of data processed in the system or the services […]
Data protection digest 18 Jul – 1 Aug 2025: DPO as a value creator and return on investment for companies
The DPO as a value for a company The French data protection regulator CNIL has studied the economic benefits of the presence of a Data Protection Officer within companies. Statistical analysis shows that it is often profitable, especially for companies taking a positive approach to GDPR compliance. The two most represented sectors were research, IT […]
GDPR Compliance for AI: Managing Cross-Border Data Transfers
Artificial intelligence (AI) is based on large and varied datasets to train models and enhance functionality. Though AI often works across borders, data protection regulations such as the EU General Data Protection Regulation (GDPR) impose stringent controls on transferring personal data abroad. The question is evident: how do businesses employ global AI systems and continue […]
Data protection digest 3-17 July 2025: AI-generated voice and visuals’ potential to violate people’s rights and freedoms
A recent Guardian article caused a stir when it reported that an AI-generated band got 1m plays on Spotify in the past couple of weeks. Only after releasing two albums, the group called “The Velvet Sundown” admitted their music, images and backstory were created by AI. The story has triggered a debate on authenticity and […]
Respecting Data Subject Rights in AI: A Practical Guide for Businesses
Nowadays, data subject rights must be considered as artificial intelligence (AI) revolutionizes industries. However, with this advancement, data privacy and data protection both become major concerns for both businesses and consumers. With AI tools enabling greater collection and use of personal data, making it more critical than ever for organizations to respect the rights of […]
Data protection digest 17 Jun – 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment
Risk Assessment Personal data protection should be the cornerstone of risk assessments for organisations. The Polish regulator UODO came to this conclusion after investigating a ransom attack in a children’s clinical hospital in Białystok. Access to IT systems was blocked, which resulted in a breach of confidentiality and availability of personal data of approximately 2,000 […]
How to build trustworthy AI from the ground up with Privacy by Design?
We now live in a time where technologies such as artificial intelligence are increasingly woven into the fabric of existence. AI is invisibly present performing an array of functions such as showing recommendations, fraud detection, disease prediction, and traffic navigation. However, concern about privacy is growing along with the benefits of these technologies. Questions like […]
Data protection digest 2-16 June 2025: Data controller, processor, how to properly identify your GDPR role
GDPR role, how to determine? The French privacy regulator CNIL reviews the criteria and practical consequences of determining the GDPR role of data controllers and processors. The qualification does not always depend on a contractual choice but on the facts: who decides what, and who executes what, concerning personal data. The controller is the natural […]
- 1
- 2
- 3
- …
- 20
- Next Page »