惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
WordPress大学
WordPress大学
小众软件
小众软件
云风的 BLOG
云风的 BLOG
IT之家
IT之家
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
博客园 - 【当耐特】
T
Tailwind CSS Blog
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
宝玉的分享
宝玉的分享
博客园 - Franky
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
D
Docker
博客园 - 聂微东
C
Check Point Blog
H
Help Net Security

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Global Data Protection & Privacy News (is...
Janeth Hassan · 2024-02-13 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • The Italian Garante has released a guidance document for email management and metadata processing in the workplace, targeting both public and private sector employers. This follows investigations revealing that certain email management programs automatically collect and store comprehensive metadata from employee email accounts, including details like sender, recipient, and email size. The findings also highlighted instances where employers did not stop this data collection or reduce storage duration. Read more here → (in Italian)
  • IAB Europe has released it’s updated “Guide to Quality” for 2024 which provides guidance on how to improve digital advertising campaigns, by focusing on viewability, brand safety, user experience and privacy. IAB Europe will be holding a webinar on 7 March to discuss the guide and hear from contributors. Access here →
  • The Dutch data protection authority, Autoriteit Persoonsgegevens (AP), plans to target misleading cookie banners in 2024, ensuring they clearly request tracking consent. AP’s guidelines include offering clear purpose information, avoiding pre-ticked boxes, using straightforward language, consolidating choices, making all options visible, minimizing extra steps, avoiding hidden links, clarifying consent withdrawal, and not equating consent with legitimate interest. See here for more → (in Dutch)
  • France’s CNIL has outlined its regulatory focus areas which include monitoring data collection during the Paris Olympics and Paralympics, online personal data collection from minors, the management of loyalty programs and electronic receipts, and ensuring data subjects’ right of access. The Authority’s summary can be found here → (in French)
  • The U.K. Information Commissioner’s Office published a blog wherein app developers were reminded of their obligations to protect users’ privacy whilst also maintaining transparency in how they use personal information, obtain valid consent and establish a lawful basis for processing personal data. Accountability towards users was also highlighted in the blog. Access here →
  • Brazil’s data protection authority, the Autoridade Nacional de Proteção de Dados, (ANPD) is seeking input from personal data holders and data processors until 4 March 2024, to draft a regulation concerning data subject access rights. Separately, the ANPD has launched guidance on the interpretation and practical application of the notion of legitimate interest. Press release → (in Portuguese)

2) Notable Case Law

  • Italy’s data protection authority, the Garante, has fined Nirvam Srl, the owner and operator of dating site nirvam.it for GDPR violations. A fine of €200,000 was issued due to failing to maintain an adequate data processing register, lacking a clear policy on data retention periods and missing a legal basis for processing activities. The company also failed to obtain explicit consent for the processing of sensitive personal data, such as one’s sexual orientation. Read more here →
  • The California Third District Court of Appeal has reversed a prior decision that paused the implementation of new CCPA regulations by the California Privacy Protection Agency (CPPA). Previously set for delay until March 29, 2024, from an initial start of July 1, 2023, the appellate court’s ruling now allows immediate enforcement of these extensive regulations.
  • Poland’s Urząd Ochrony Danych Osobowych (UODO) fined the e-commerce site Morele.net PLN3.8 million for GDPR breaches after a data breach impacted 2.2 million users due to insufficient cybersecurity. UODO found that Morele.net failed to encrypt certain data, lacked two-factor authentication, and did not perform a risk analysis for public network access, leading to unauthorized access and data compromise. Access here →

3) New and Upcoming Legislation

US law updates:

  • Nebraska: Legislative Bill 308 which concerns an Act to adopt the Genetic Information Privacy Act passed the final reading in the Nebraska State Legislature and was presented to the Governor of Nebraska for signature.
  • Virginia: House Bill 707 to amend Consumer Data Protection Act for children’s protections was passed by the Virginia House of Delegates.
  • West Virginia: House Bill 5338 which introduced the Consumer Data Protection Act was presented to the House of Representatives.

4) Strong Impact Tech

  • The U.K. Competition and Markets Authority has issued a report demanding that Google does “not design, develop or use the Privacy Sandbox proposals in ways that reinforce the existing market position of its advertising products and services, including Google Ad Manager.” Meanwhile, IAB Tech Lab has also published an assessment which analyzes the challenges that the advertising industry may be subjected to upon adopting Google’s Privacy Sandbox.
  • A 2023 ransomware activity analysis reported by the Record, revealed that companies paid more than USD1.1 billion to buy back data stolen during breaches. Hackers deployed “zero-day vulnerabilities” and sharpened “their operations and targeting high-profile institutions and critical infrastructure like hospitals, schools, and government agencies” throughout last year. Read the full story here →

Other key information from the past weeks

  • Meta is updating its platforms, including Facebook and Instagram, to empower users in the EU, EEA, and Switzerland with greater control over their data usage, in compliance with the EU’s Digital Markets Act (DMA). Read about it here →
  • IAB Europe, a key player in digital marketing, advertising, and media, has recently voiced significant concerns about the European Parliament’s draft report on the GDPR procedural regulation. Follow the news here →
  • Apple has just rolled out a series of significant updates for iOS, Safari, and the App Store, specifically tailored for the European Union (EU) region. These changes are a response to the new Digital Markets Act (DMA). Full story here →

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com