惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
Vercel News
Vercel News
U
Unit 42
L
LangChain Blog
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
F
Fortinet All Blogs
小众软件
小众软件
I
InfoQ
P
Proofpoint News Feed
D
DataBreaches.Net
Martin Fowler
Martin Fowler
H
Help Net Security
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Data Protection & Privacy News (issue #11...
Aert Hulsebos · 2023-06-22 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • The U.K. Information Commissioner’s Office has published both a review and post-transition impressions of the Children’s Code. Over 50 organizations have been assessed for conformance with the code, and there are currently 11 open investigations. 10 online services have also been audited. The ICO has also supported various other countries and states, including California, to show how they have implemented the code. The aim is also to develop similar approaches, extending the benefits of the code beyond the UK to help other countries and states set up their own laws to protect children. Read here →
  • The Spanish AEPD has launched a redesigned version of its Gestiona tool to support entities with processing activities, risk management and conducting impact assessments under the GDPR. Access here → (In Spanish)
  • The Brazilian ANPD has published a model for the simplified registration of operations for small and medium-sized businesses to track records of personal data processing activities. The “simplified model” requires information on among others categories of data subjects and data retention, the security measures applied vis-à-vis such data and information on how data is to be shared. Read here → (In Portuguese)
  • The United States Federal Communications Commission has announced the inception of its Privacy and Data Protection Task Force. This new task force is interested in focusing upon “approaches to data breaches and data security vulnerabilities while contributing to potential privacy rule-making, enforcement and public awareness efforts.Announcement here →

2) Notable Case Law

  • The Italian data protection authority, the Garante Privacy (Garante) imposed a fine of just over €7.6 million on TIM S.p.A., for several violations of the GDPR and of the Personal Data Protection Code, Containing Provisions to Adapt the National Legislation to the GDPR (the Code). The Garante had received several complaints from individuals alleging:
    • TIM’s inability to display its privacy policy to users making use of its website, in particular when purchasing mobile subscriptions online;
    • TIM’s outright omission or delay in responding to data subject rights requests submitted under the GDPR;
    • a data breach, and
    • telemarketing calls by TIM to users that have availed of the public opt-out register, and users that have denied their consent for promotional purposes.
  • The CNIL fined the company KG COM which operates a number of websites to offer its customers’ clairvoyance readings by chat or phone, a fine to the tune of €150,000 “because it failed to comply with its obligations under the GDPR and the French Data Protection Act. In particular, the company collected excessive data, as well as sensitive data without prior and explicit consent, and did not sufficiently ensure the security of the data.Access here →
  • Two United Kingdom energy companies, Maxen Power Supply and Crown Glazing, were found to have carried out illegal marketing phone calls to both individuals and companies that have specifically enrolled on the United Kingdom’s “do not call” register. The companies have been subsequently fined GBP 120,000 and GBP 130,000 respectively by the Information Commissioner’s Office. Read more here →

3) New and Upcoming Legislation

  • Members of the European Parliament have agreed to negotiate upon rules for “safe and transparent” AI regulation. The rules intend to protect people from the harmful effects of any untrustworthy AI and “would ban AI systems for social scoring, biometric categorisation and emotion recognition.Press release →
  • Texas: House Bill 18 which creates the Securing Children Online through Parental Empowerment (SCOPE) Act and relates to the protection of minors on digital services was signed by the Governor.
  • Connecticut: Senate Bill 3, for an act concerning online privacy, data, and safety protections became law after being signed by the Governor of Connecticut.
  • Montana: Senate Bill 351 for genetic information privacy was passed to the Governor for signing.

4) Strong Impact Tech

  • Google’s generative AI tool Bard will not be launched in the EU until the company addresses privacy concerns raised by Ireland’s Data Protection Commission. The commission, acting as Google’s primary European data supervisor, has expressed that the tech giant has not provided adequate information about how Bard protects privacy for Europeans, thus delaying its EU debut under the General Data Protection Regulation (GDPR). Read about this on our blog →
  • A cyberattack on UK payroll provider Zellis has affected major organizations like the BBC, British Airways, and Boots. The attackers exploited a vulnerability in the MOVEit file transfer software used by Zellis and stole sensitive employee information. The incident highlights the risk of vulnerabilities in widely used third-party software. Zellis has confirmed a few affected customers, including Aer Lingus and Jaguar Land Rover. Investigations are underway by cybersecurity authorities. Organizations need to take proactive measures to protect against such attacks. Reported here →

Other key information from the past weeks

  • The United States and the United Kingdom have announced the Atlantic Declaration for a Twenty-First Century U.S.-UK Economic Partnership.
  • According to Euractiv, French senators confronted European TikTok representatives about the company’s connections with the Chinese government and its handling of data protection.
  • The Netherlands Data Protection Authority (AP) has opened an investigation into OpenAI’s ChatGPT data processing practices and their compliance with the GDPR.

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com