惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
博客园_首页
M
MIT News - Artificial intelligence
雷峰网
雷峰网
GbyAI
GbyAI
博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
S
SegmentFault 最新的问题
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
V
Visual Studio Blog
月光博客
月光博客
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
腾讯CDC
云风的 BLOG
云风的 BLOG
美团技术团队
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
有赞技术团队
有赞技术团队

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Data Protection & Privacy News (issue #89...
Aert Hulsebos · 2022-12-29 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • Last week, the French Authority published a post on its website to inform that as of 27 December 2022, exporters and importers of data will no longer be able to use the European Commission’s old standard contractual clauses and will have to use the updated clauses in 2021 or use another transfer tools. Read here → (in French)
  • The UK Data Protection Authority published the UK government’s assessment of the Republic of Korea’s adequacy in processing personal data. Therefore, the adequacy decision between the UK and the Republic of Korea came into force on 19 December 2022. Access here →

2) Notable Case Law

  • The French Authority imposed a 60 million euro fine on Microsoft Ireland Operations Limited for failing to put in place a mechanism to reject cookies as easily as accepting them. It was found that when a user visited the website, cookies were deposited on their computer without consent and used for advertising purposes. In addition, the company will have to obtain the consent of the data subjects within three months, if they fail to do so, the company will be required to pay a penalty for each day of delay. Read about the decision on our Blog →
  • On 15 December, the Spanish Data Protection Authority issued a decision in response to one of the complaints filed by NOYB concerning the use of Google Analytics. The Authoritys summary can be found here → (in Spanish)
  • Epic Games, developer of the popular video game Fortnite, was sentenced to pay a penalty of 275 million dollars for violating the law on children’s privacy, changing the default privacy settings, and $245 million in refunds for tricking users into making unwanted purchases. Reported here →

3) New and Upcoming Legislation

  • The EU Directive 2022/2555, called NIS2, was published today in the Official Journal of the European Union and will enter into force in 20 days. At its core, NIS2 establishes stricter cybersecurity requirements for risk management, reporting obligations, and information sharing. The requirements cover incident response, supply chain security, encryption, and vulnerability disclosure, among others. Read here →
  • After three years, the review of the Australia Privacy Act commissioned by the coalition government has been completed, and the final report has been handed over to the Attorney General, which will now review the revision and is expected to publish it along with the Act and the government’s response in the first half of 2023. Read here →

4) Strong Impact Tech

  • Microsoft started the phase-in of the ‘EU data boundary’, which allows cloud European customers to process and store data in the EU area. The ‘EU data boundary’ applies to Microsoft’s core cloud services. The first phase will include customer data, followed by registration and service data. Reported here →
  • Uber suffered a breach of sensitive corporate information of its third-party provider Teqtivity. The hacker then published archives on the dark web that would contain the source codes of the mobile device management platforms used by Uber, Uber Eats, and other third parties. The stolen personal data also include e-mail addresses and information belonging to more than 70,000 Uber employees. Read here →

Other key information from the past weeks

  • The European Commission initiated the formal process for adopting an adequacy decision on the EU-US Data Privacy Framework on Tuesday (13 December). But the third attempt to underpin transatlantic data transfers is bound to face more legal challenges.
  • Elon Musk is reportedly considering forcing Twitter users to accept personalized advertising, barring an opt-out for ads if they subscribe, according to a report by Platformer.
  • The director of the US Federal Trade Commission’s Bureau of Consumer Protection warned that the agency “is not afraid to take companies to court” over data practices.

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com