惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
Jina AI
Jina AI
小众软件
小众软件
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Martin Fowler
Martin Fowler
P
Proofpoint News Feed
MyScale Blog
MyScale Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Data Protection & Privacy News (issue #10...
Aert Hulsebos · 2023-04-13 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • The first review of the Japan-EU mutual adequacy arrangement was successfully concluded between the Personal Information Protection Commission of Japan and the European Commission. This follows the “equivalent” recognition of both Japan’s and EU’s data protection systems back in 2019. Read here →
  • The EDPB has published updated guidelines 9/2022 on personal data breach notification under the GDPR. The guidelines “clarify notification requirements for personal data breaches at non-EU establishments” and require that member states supervisory authorities are notified of such breaches when affected data subjects reside in a particular member state. Access here →
  • The IAB Tech Lab and the IAB Legal Affairs Council have announced the launch of a new Privacy Implementation & Accountability Task Force (PIAT) which will serve to address industry challenges. Reported here →
  • New Zealand’s Deputy Privacy Commissioner has urged businesses to keep their data retention policy in check and to retain only necessary information, since several recent cyberattacks have fed off excessive data retention. Press release here →
  • Brazil’s Autoridade Nacional de Proteção de Dados (ANPD) has published a 15 part Q&A in relation to data protection impact assessments (DPIAs). Whilst outlining the proper procedures to be undertaken, the document addresses basic inquiries that entities should follow when performing DPIAs. Read here → (in Portuguese)

2) Notable Case Law

  • In its most recent ruling, Austria’s DSB has declared that the Austrian Newspaper Der Standard’s cookie banner is not GDPR or e-Privacy Directive compliant, since it does not afford the user the “granularity of consent principle.” The choice presented by the pay or okay system does not effectively allow the users to consent freely, as their choices include either agreeing to having all of their data processed or paying as an alternative. Reported here →
  • The UK’s ICO has fined TikTok £12.7M for the unlawful use of children’s data, in particular children under the age of thirteen years, which held an account contrary to the terms of service. Such accounts were set up without parental consent, and the ICO found that TikTok “did not do enough to ensure who was behind such accounts. These breaches together with TikTok’s inactivity to remove such accounts led to the fine. Read about the decision →
  • Canada’s Office of the Privacy Commissioner has launched an investigation into ChatGPT’s operator OpenAI, L.L.C., in “response to a complaint alleging the collection, use, and disclosure of personal information without consent.” The investigation is currently ongoing, and no further information is available at this stage. The Authority’s announcement can be found here →
  • Further to a complaint submitted by an individual wherein it was alleged that Banco Bilbao Vizcaya Argentaria S.A (BBVA) processed the individual’s personal data without any legal basis and moreover also failed to address the individual’s data access request, the Agencia Española de Protección de Datos (AEPD) fined BBVA €140,000 for violating Articles 6(1) and 15 of the GDPR. The AEPD however reduced the fine twice over by 20% to €84,000 since BBVA acknowledged its liability and proceeded to settle the fine within 10 days from issuance of the AEPD’s decision. Read here → (in Spanish)

3) New and Upcoming Legislation

US law updates:

  • Arkansas: Senate Bill 396 on protection of minors has passed the House of Representatives and has been delivered to the Governor.
  • Tennessee: Senate Bill 73 for the enactment of an Information Protection Act has been recommended for passage by the Senate Commerce & Labor Committee.
  • Texas: House Bill 4 for the regulation of the Texas Data Privacy and Security Act was passed by the House of Representatives.
  • California: Senate Bill 721 on the establishment of an Interagency AI Working Group has been re-referred to Senate Committee after already having been withdrawn last month.
  • Washington: House Bill 1155 concerning the collection, sharing and selling of consumer health data was passed by the Senate.

4) Strong Impact Tech

  • The UK’s National Cyber Security Centre (‘NCSC’) and the Information Commissioner’s Office (ICO) have addressed several cyber risk concerns emanating from large language models such as ChatGPT. Both the NCSC and ICO have issued a series of Q&As which serve to enable the public to better comprehend the function and composition of these technologies as well as associated privacy risks.
  • The Swiss Federal Data Protection and Information Commission (FDIPC) has issued a statement concerning the use of ChatGPT and AI-supported apps. Whilst applauding the benefits of using such apps, the FDIPC also highlighted the risks associated with the processing of personal data by such technology. The FDPIC also stated that it is in contact with Italy’s Garante further to the temporary ban issued last month. Reported here →

Other key information from the past weeks

  • ChatGPT’s processing of Italian users’ data has been halted by the Italian Garante.
  • The UK Government has launched an AI white paper “to guide the use of artificial intelligence in the UK, to drive responsible innovation and maintain public trust in this revolutionary technology.”
  • France has ratified the modification to the Council of Europe Convention 108+ which concerns the protection of the automatic processing of individuals’ personal data.

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com