惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
IT之家
IT之家
博客园 - 叶小钗
雷峰网
雷峰网
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Data Protection & Privacy News (issue #12...
Aert Hulsebos · 2023-12-14 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • The Datatilsynet, Denmark’s data protection authority, has issued a guide on managing access rights. This guide specifically covers the topic of rights management, a concept that involves controlling access to an organization’s IT systems and physical locations, as well as determining the specific information that individual users are allowed to access. Read the press release here → (in Danish)
  • The Dutch data protection authority, Autoriteit Persoonsgegevens, has released a Privacy guide advising companies on privacy policies and emphasizing transparency in data protection. The guide stresses the importance of demonstrating GDPR compliance and robust data management for building trust in online businesses. Access here → (in Dutch)

2) Notable Case Law

  • The EU Court of Justice (CJEU) ruled in terms of Article 22 of the General Data Protection Regulation (GDPR) against automated decision-making systems like Germany’s SCHUFA, which uses personal data for scoring creditworthiness. The Court declared such practices illegal if they significantly impact individuals’ lives, especially when these scores play a ‘decisive’ role in decisions by entities like banks. Read about the decision here →
  • The CJEU determined that administrative fines under the GDPR can only be imposed for wrongful infringements, either intentional or negligent. This ruling, responding to inquiries from Lithuanian and German courts, clarifies that data controllers are may also be liable for fines resultant of their processors’ actions. The press release can be found here →
  • The Belgian Data Protection Authority settled with four media websites, L’Avenir, RTBF, Mediafin, and IPM regarding their cookie usage, following noyb’s complaints. While fines were not imposed, the companies must modify their cookie banners to include a ‘refuse all’ button, avoid emphasizing the ‘accept all’ option, and simplify the consent revocation process. Except for Mediafin, all must also clarify the use of essential cookies and the effect of withdrawing consent, within one month to implement these changes. Read more here on our blog →
  • The EDPB published its urgent binding decision against Meta for GDPR violations in behavioral advertising. The EDPB identified ongoing breaches in Meta Ireland’s use of contract and legitimate interest for data processing and non-compliance with DPAs’ decisions. Consequently, the EDPB instructed the Irish DPA to enforce a ban on Meta Ireland’s data processing for behavioral advertising based on these legal grounds. Press release here →

3) New and Upcoming Legislation

  • The California Privacy Protection Agency has released proposed amendments to the current California Consumer Privacy Act. These updates aim to expand the scope and penalties of the act, and include modifications regarding dark patterns and responsibilities pertaining to the rights of data subjects. Access here →

4) Strong Impact Tech

  • Meta, Facebook’s parent company, is facing a €550 million lawsuit from AMI, an association representing 83 Spanish media outlets. The lawsuit accuses Meta of unfairly dominating the advertising market through the extensive and systematic exploitation of user data from Facebook, Instagram, and WhatsApp. They allege it is often collected without explicit consent, violating data protection laws and constituting unfair competition. Reported here →
  • The U.S. Federal Trade Commission has urged a federal appellate court to deny Meta’s plea for a temporary suspension of their legal dispute concerning user data monetization. The FTC argues that Meta’s request is an attempt to evade a potential FTC directive that might bar the company from monetizing the data of minors. Read more here →

Other key information from the past weeks

  • Italy’s data protection authority, Garante, is conducting an investigation into the data collection methods used for training algorithms. This investigation targets both public and private organizations, aiming to ensure they implement adequate security measures to protect against the webscraping of personal data. There is a 60-day public consultation underway to discuss potential security strategies to prevent data scraping. Read here → (in Italian)
  • The UK Information Commissioner’s Office has sent warning letters to the country’s top websites, urging them to enhance their third-party cookie practices within 30 days or face enforcement actions. “Companies must make changes now or face consequences,” stated ICO Executive Director of Regulatory Risk. More here →

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com