惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
CERT Recently Published Vulnerability Notes
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
宝玉的分享
宝玉的分享
Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
L
LangChain Blog
博客园_首页
有赞技术团队
有赞技术团队
The Register - Security
The Register - Security
GbyAI
GbyAI
Blog — PlanetScale
Blog — PlanetScale
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Security Archives - TechRepublic
Security Archives - TechRepublic
量子位
雷峰网
雷峰网
Security Latest
Security Latest
博客园 - 【当耐特】
V2EX - 技术
V2EX - 技术
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
IT之家
IT之家
爱范儿
爱范儿
S
Schneier on Security
N
News | PayPal Newsroom
H
Help Net Security
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
N
News and Events Feed by Topic
C
Cyber Attacks, Cyber Crime and Cyber Security
U
Unit 42
博客园 - 司徒正美
Forbes - Security
Forbes - Security
P
Proofpoint News Feed
W
WeLiveSecurity
Cisco Talos Blog
Cisco Talos Blog
小众软件
小众软件
The Cloudflare Blog
AWS News Blog
AWS News Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Palo Alto Networks Blog
Google DeepMind News
Google DeepMind News
H
Heimdal Security Blog
V
Vulnerabilities – Threatpost
Microsoft Azure Blog
Microsoft Azure Blog
T
Tailwind CSS Blog
G
GRAHAM CLULEY

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
Privacy Monthly: August 2023
Carlo Cilent · 2023-08-24 · via Blog of Simple Analytics
  1. European Commission finalizes US data transfer framework
  2. European Commission looking to break up Google’s businesses
  3. Meta to change privacy policy again after CJEU ruling
  4. EU moving forward with digital legislation
  5. 24 US States call for damage control after Dobbs v. Jackson
  6. French watchdog fines major adtech player € 40M
  7. Landmark CJEU ruling on GDPR damages
  8. OpenAI faces class action over web scraping
  9. Meta delays EU Threads launch
  10. US intelligence bought consumer data

The UK Government chose Simple AnalyticsJoin them

European Commission finalizes US data transfer framework

On July 10, the European Commission adopted an adequacy decision for the United States. This is the final step in implementing the long-anticipated Trans Atlantic Data Privacy Framework, a bilateral framework between the EU and the US that allows for easier data flows between the US and EU/EEA Countries.

The framework is the EU and US’s attempt to solve the legal uncertainty surrounding data transfers as a result of the Schrems I and II rulings of the EU Court of justice. Not everyone is happy about it: the European Parliament opposed the framework by an overwhelming majority in a non-binding vote, and noyb- an NGO already involved in the legal drama surrounding data transfers- already announced that it will challenge the decision before the EU Court of Justice.

Only time will tell if the new framework will survive the Court’s scrutiny or meet the same fate as the Safe Harbor and Privacy Shield frameworks.

For more information about the framework, check out our blog.

European Commission looking to break up Google’s businesses

The European Commission informed Google owner Alphabet Inc. of its preliminary view that Google violates antitrust law and may be ordered to break up its businesses.

The communication results from an investigation of Google’s role in the online advertising market in which the Commission found that Google holds a dominant position in at least two distinct markets- publisher ad servers and online ad buying tools. The Commission holds that Google abuses its dominant position by favoring its own services in ad exchanges carried over its AdX platform.

In the Commission’s view, divesting some of Google’s services is the only way to stop the abuse. The investigation is still ongoing and is worth following closely.

In the recent Bundeskartellamt ruling, the EU Court of Justice held that Facebook’s tracking tools process sensitive data, and that Meta cannot track users for behavioral advertising without their consent.

The Court’s remarks on behavioral advertising in particular could mean the death of Meta’s new privacy policy. Meta recently announced their intention to collect user consent for targeted advertising. The announced changed would mark the second update to the company's privacy policy within the year, after Meta already changed its legal bases in response to the Irish privacy watchdog's fines.

In the meantime, the Norwegian data protection authority temporarily banned targeted advertising on Facebook and Instagram because of the Court's ruling.

Bundeskartellamt is a very important decision, so we analyzed it in detail in two blogs (click here for part one).

EU moving forward with digital legislation

The European Parliament adopted a new version of the AI Act draft. The proposal now needs to be negotiated between the Parliament, the European Commission, and the European Council. The new draft currently includes stricter rules for generative AI and biometric surveillance in public spaces.

At the same time, the European Council and representatives of the Parliament reached an agreement over the Data Act draft. The proposal is now pending approval from the European Parliament and Commission. If finalized, the Data Act will enhance data portability rights across the EU and address contractual imbalances with regards to data sharing, in an attempt to move towards an internal data market.

24 US States call for damage control after Dobbs v. Jackson

24 US States, led by the Attorney Generals of California and New York, called for Congress to strengthen the HIPAA (Health Insurance Portability and Accountability Act), mere months after the US Health and Human Services urged the legislator to do the same.

The push for stronger protectionf for health data is a response to the Doobs v Jackson ruling of the US Court of Justice, which opened the gate to a wave of anti-abortion legislation in conservative States. This led to a large scale human rights and privacy crisis: women’s health data are often used to prosecute them and sit in the hands of companies who are often more than willing to sell them to the highest bidder.

French watchdog fines major adtech player € 40M

The French data protection authority (CNIL) fined online advertising company Criteo €40M for not being able to provide proof of consumer consent and for other issues including a lack of transparency.

The decision touches upon interesting legal issues. In the CNIL’s view, advertising intermediaries such as Criteo cannot take a hands-off approach to compliance and let their partners deal with consent entirely. Instead, they must require their partners to collect data lawfully and must be able to provide proof of user consent.

The CNIL is an influential authority in Europe. Should other authorities follow its lead, this approach could have a significant impact on the position of intermediaries on the online advertising market.

The EU Court of Justice clarified some important aspects of the damage system under the GDPR in a ruling involving the Austrian postal service.

The decision is fairly technical and revolves around the compensation system provided for by Article 82 of the Regulation. The Court stated that there is no threshold for damages under the GDPR. The Court also clarified that damage cannot be awarded for a mere violation of the GDPR: the claimant must have suffered some form of damage- whether material or non-material- as a result of the violation.

OpenAI faces class action over web scraping

A class action was filed against OpenAI in the San Francisco federal court. The claimants complain that the ChatGPT and DALL-E engines scraped enormous amounts of personal information from the Internet without informing Internet users or asking for permission.

Data scraping is a hot legal issue on both sides of the ocean. The scraping of the data of millions of unaware Internet users was one of the concerns that led to the one-month ban of ChatGPT from Italy. In the wake of the Italian investigation, other European watchdogs are currently looking into ChatGPT’s privacy issues, and the European Data Protection Board created a task force to coordinate their efforts.

A Meta spokesperson announced that the Threads social platform will not be available in the EU. News sources including the Irish Independent and Politico report that the decision might be due to the EU’s Digital Markets Act, which prohibits gatekeeper companies from combining data sets from different platforms.

Incidentally, Meta is already merging data from Facebook and Instagram users. It will be interesting to see whether Meta will take steps to address DMA compliance with regards to the merging of databases.

US intelligence bought consumer data

In news that will surprise no one, a declassified report from the Office of the Director of National Intelligence confirms that US intelligence agencies bought consumer data from data brokers at least until 2022.

It is an open secret that intelligence agencies across the world are increasingly relying on commercially available information. This is a diplomatic way of saying that they buy enormous amounts of personal data from companies and data brokers. Buying data on the market is easier than collecting it directly and sometimes allows agencies to circumvent limitations that would otherwise apply to their operations. This practice raises issues with regards to privacy and civil rights, as highlighted by the report itself.