Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Data Protection Reforms in UK

This year in May, the United Kingdom Government announced the intention to introduce a reform bill that will implement extensive changes to the existing domestic data protection framework. If implemented, the proposed changes are expected to contribute towards UK to deviate from the standards that apply in the EU under the General Data Protection Regulation […]

Read More… from Data Protection Reforms in UK

What are the Leading Causes for Individual GDPR Fines?

At least 65 private individuals have received fines for GDPR violations in the EU since 2018. The total number of GDPR fines since the law came into force in 2018 is 1,186, but only large fines against major corporations tend to make the news.  Still, private citizens can just as easily end up in court […]

Read More… from What are the Leading Causes for Individual GDPR Fines?

ICO issue fine of £4.4 to Interserve for security failings

On 24 October 2022, the ICO issued a penalty notice (MPN) to Interserve Group Limited (Interserve), imposing a fine of £4.4m for violations of the GDPR (the violations were pre-Brexit). The ICO found that Interserve had failed to put appropriate technical and organizational measures in place to secure personal data (in contravention of Articles 5(1)(f) […]

Read More… from ICO issue fine of £4.4 to Interserve for security failings

ICO consultation on draft employment practices guidance – information about workers’ health

The Information Commissioner’s Office (ICO) is producing an online resource with topic-specific guidance on employment practices and data protection. We are releasing our drafts of the different topic areas in stages and adding to the resource over time. A draft of the guidance on handling information about workers’ health is now out for public consultation. […]

Read More… from ICO consultation on draft employment practices guidance – information about workers’ health

Video surveillance (including guidance for organizations using CCTV)

The steady growth of the use of video surveillance systems across public and private sectors, has led to both fixed and mobile cameras becoming more accepted in society. As video surveillance technology becomes more mainstream and affordable, it is now more common to see technologies such as smart doorbells and wireless cameras. Traditional closed circuit […]

Read More… from Video surveillance (including guidance for organizations using CCTV)

Guidance on direct marketing using electronic mail

The Privacy and Electronic Communications Regulations 2003 (as amended) (PECR) cover the sending of electronic mail for direct marketing purposes. This guidance discusses electronic mail marketing in detail. Read it if you have detailed questions not answered in the Guide to PECR, or if you need a deeper understanding of how PECR applies to electronic […]

Read More… from Guidance on direct marketing using electronic mail

Luxembourg delivers first GDPR accreditation

The national commission for data protection has become the first data protection authority in Europe to accredit a GDPR certification body. On 12 October, Luxembourg’s national commission for data protection accredited the entity EY PFS Solutions via its certification mechanism, GDPR-CARPA (General Data Protection Regulation-Certified Assurance Report-Based Processing Activities). The mechanism is the first to be adopted […]

Read More… from Luxembourg delivers first GDPR accreditation

Who is responsible for complying with the rules on live marketing calls?

In general, the PECR rules apply to anyone that wishes to make unsolicited live calls for the purposes of direct marketing. It is the ‘caller’ or the ‘instigator’ of the call who has responsibility for complying with the rules. PECR do not define the term instigator. However, you are likely to be instigating if you […]

Read More… from Who is responsible for complying with the rules on live marketing calls?

President Biden Signs Executive Order to Implement the European Union-U.S. Data Privacy Framework

President Biden signed an Executive Order on Enhancing Safeguards for United States Signals Intelligence Activities (E.O.) directing the steps that the United States will take to implement the U.S. commitments under the European Union-U.S. Data Privacy Framework (EU-U.S. DPF) announced by President Biden and European Commission President von der Leyen in March of 2022.  The […]

Read More… from President Biden Signs Executive Order to Implement the European Union-U.S. Data Privacy Framework

ICO Plan for the upcoming period – ICO 25

Introduction On 19th July 2022 the Information Commissioner’s Office (ICO) held its annual Data Protection Practitioners’ Conference – the first with John Edwards in the role of Commissioner. ICO25 A key theme running through many of the sessions was the ICO’s draft strategic plan “ICO25” and, in particular, the four proposed strategic objectives to: (i) safeguard […]

Read More… from ICO Plan for the upcoming period – ICO 25