Reporting Personal Data Breaches: proving the “unlikely”

There has been an ongoing discussion regarding the reporting of breaches to National Authorities since Regulation (EU) 2016/679 (GDPR) went live just over a year ago. Pinsent Mason’s law firm, in their recent review of reporting of personal data breaches (PDBs) in the UK, noted that there had been a spike in the reporting of […]

Cookie Guidance – Data Protection Authorities publish update

ePrivacy e1564134761706

Data Protection Authorities including the ICO and the Irish Data Protection Commission have recently released updated cookie guidance and CNIL, the French Data Protection Authority, have released updated guidelines, repealing their 2013 guidelines which suggested that a valid form of consent to cookies included the action of a user continuing to navigate a website – […]

Preventing SMEs data breaches – the UK NCSC guidance

Data Breaches 1 e1564134828890

Since the GDPR took effect, a large number of personal data breaches have been reported across Europe, with major data breaches reported in the UK and Ireland. British Airways, Marriott International, Equifax , WhatsApp and Facebook are only a few examples of the investigatory action taken by the Irish and British Data Protection Authorities (DPAs). […]

Data Protection Authorities publish updated cookie guidance

ePrivacy e1564134761706

Data Protection Authorities including the ICO and the Irish Data Protection Commission have recently released updated cookie guidance and CNIL, the French Data Protection Authority, have released updated guidelines, repealing their 2013 guidelines which suggested that a valid form of consent to cookies included the action of a user continuing to navigate a website – […]

The right to rectification – clarifications from the Data Protection Commission

GDPR right to rectification

Ireland’s Data Protection Commission (DPC) in a blog post on its website examined complaints into the right to rectification within Article 16 of the General Data Protection Regulation (GDPR). Whilst the blog post is for guidance purposes only, it does offer some insight into the thought process within the DPC. The legal framework According to […]

New EU Regulation refreshed the legal regime for data processing by European institutions

Regulation for European institutions resized

The European Union recently enacted a new Regulation that refreshes the data protection regime applicable to European Union institutions and organs. Issued as a replacement of the legacy Regulation (EC) 45/2001, the new Regulation (EU) 2018/1725 (EU DPR) adds a new tile to the continental data protection mosaic. The new Regulation is essentially an adaptation of Regulation […]

Biometric Data in the workplace – French Authority to address the GDPR regime

Biometrics

Regulation (EU) 2016/679 (GDPR or Regulation) is a complex and lengthy piece of legislation, which impacted all functions of organisations in the public and private sector like a bull in a china shop. Data Protection compliance specialists have spent the past two years redrafting, privacy policies, records of processing, and personal data breach processes among […]