惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
博客园_首页
美团技术团队
M
MIT News - Artificial intelligence
人人都是产品经理
人人都是产品经理
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
J
Java Code Geeks
T
Tailwind CSS Blog
Jina AI
Jina AI
量子位
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
爱范儿
爱范儿
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
宝玉的分享
宝玉的分享
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Data Protection & Privacy News (issue #72...
Aert Hulsebos · 2022-09-01 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • NOYB filed a complaint with the French Data Protection Authority (CNIL) against Google. NOYB claims that the tech giant has consistently disregarded the Court of Justice of the European Union’s (CJEU) decision regarding direct marketing emails and used Gmail to send spam. Want to learn more about NOYB’s cookie complaints and what to do? See our new article here →
  • Small businesses can now follow a six-step guide from the UK DPA (Information Commissioner’s Office or ICO) on handling their data protection complaints. Read the six-step guide here on our blog →
  • On August 24, 2022, the Office of the Attorney General (OAG) updated its list of 13 enforcement case examples under the California Consumer Privacy Act (CCPA). The OAG stated that it typically does not disclose information about its investigations but that the cases represent instances in which the OAG allegedly provided notice of non-compliance, and each company responded by taking action. See here for the case example →
  • The Turkish DPA (KVKK) produced a proposed set of guidelines for processing genetic data. In the Law on the Protection of Personal Data, the KVKK classifies genetic information as “sensitive personal data.” Reported here → (In Turkish)

2) Notable Case Law

  • Sephora will have to pay $1.2 million in fines for violating the California Consumer Privacy Act by selling users’ personal information and failing to comply with opt-out requests. According to California Attorney General, in exchange for benefits like targeted advertising and discounted analytics, Sephora made its users’ personal information available to third-party trackers without telling them it was doing so. Reported here on our blog →
  • Meta settled a claim that it unlawfully acquired location data from users even when those individuals had their devices’ location services switched off. To resolve allegations that Facebook broke California law and its privacy notice, Meta will pay $37.5 million. See here for more →
  • Snapchat have agreed to settle a lawsuit for $35 million, which claimed the business had broken the Illinois Biometric Information Privacy Act (BIPA). Snapchat’s filters failed BIPA by secretly gathering and storing users’ biometric data. Read more on our blog →
  • On August 23, 2022, the National Consumer Secretariat (Senacon) of the Brazilian Ministry of Justice and Public Security (MJSP) issued a decision fining Facebook BRL 6.6 million (about €1,290,000) for disclosing Brazilians’ personal data without their consent. Read more here → (in Portuguese)

3) New and Upcoming Legislation

  • The latest draft for the proposed Data Act was provided by the Czech Presidency of the Council of the European Union. The most recent text modifies the terms under which public agencies may request access to privately held data. The plan exempts most institutions from legal obligations and adds clauses that permit government agencies to utilize private firm data in exceptional circumstances. Reported here →
  • On its third reading, the California Senate revised Assembly Bill 2273, the California Age-Appropriate Design Code. The most recent modifications include extending the time to correct violations from 45 to 90 days and extending the deadline for submitting data protection impact assessments from two to three days. The bill is now back on the Senate’s schedule for second reading due to the revisions, and final approval from the Assembly is now necessary. Access the bill here →

4) Strong Impact Tech

  • LastPass, a password management provider, suffered from a security breach two weeks ago, giving hackers access to the company’s source code and confidential technical data. We’ve reported this story on our blog →
  • Oracle is accused of operating a “worldwide surveillance machine” and violating the fundamental privacy rights of hundreds of millions of people in a class action lawsuit filed last week in the Northern District of California. In addition to five causes of action ranging from state data protection laws to the federal wiretap act, the lawsuit contends that Oracle’s collection and sale of personal data violated the state constitution of California. Read more here →
  • Apple has released an update to address security holes that it claims hackers may have “actively exploited” in its iPhone, iPad, and Mac devices. The new software “provides important security updates and is recommended for all users,” the tech company claimed. Industry experts have speculated that the hole could allow hackers to take total control of vulnerable devices. iPhone 6s and after, iPad Pro, iPad Air 2 and later, and iPad 5th generation and later may all access the update. Reported here →

Other key information from the past weeks

  • The Italian Data Protection Authority (Garante Privacy) imposed a fine of €70,000 on UniCredit S.p.A. for violating Articles 12 and 15 of the General Data Protection Regulation (GDPR) following the receipt of a complaint submitted by an individual.
  • The European Data Protection Board (EDPB) published a binding decision under Article 65(1)(a) of the General Data Protection Regulation (GDPR)
  • Twitch, a video game streaming platform owned by Amazon, has admitted to a significant data breach. According to Twitch, a hacker breached the service’s servers.

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com