
Sign up to save your podcasts
Or


Send a text
Privacy Corner Newsletter: Jan 16, 2025
In this edition:
▶ European Commission must pay damages for Facebook Login feature violation
▶ Texas sues Allstate under new privacy law for illegal data collection
▶ CJEU rules gender data collection not lawful for personalization under ‘contract’ basis
Send a text
Privacy Corner Newsletter: January 2, 2025
In this edition:
▶ OpenAI faces penalties for GDPR breaches linked to ChatGPT, including transparency failures and inadequate age verification.
▶ California Privacy Protection Agency settles with two more data brokers
PayDae and The Data Group fined for failing to register under California’s Delete Act, with further enforcement anticipated.
▶ Google will permit device fingerprinting starting February 16, 2025, despite ICO objections.
Before we wrap up…
Privado.ai is thrilled to announce Bridge 2025: A Technical Privacy Summit, happening virtually from February 5-6, 2025.
👇 Discover actionable solutions that connect privacy laws to practical engineering strategies, including:
- Unlocking privacy ROI
- Navigating adtech compliance challenges
- Designing privacy-first engineering frameworks
Mark your calendars and join the privacy engineering revolution here:
https://www.privado.ai/bridge-privacy-summit
Send a text
Privacy Corner Newsletter: December 19, 2024
In this edition:
The Irish DPA fines Meta €251 million over a 2018 data breach, the Dutch DPA fines Netflix €4.75 million for transparency failings, and the French DPA cracks down on non-compliant cookie banners.
▶ Irish DPA fines Meta €251 million over 2018 data breach
The fine follows a breach affecting 29 million Facebook accounts. The DPC found violations of GDPR’s data protection by design, breach reporting obligations, and more.
▶ Dutch DPA fines Netflix €4.75 million for transparency failures
Netflix failed to disclose adequate privacy information, leading to a fine for GDPR violations regarding transparency, data retention, and international data transfers.
▶ French DPA issues cookie banner crackdown
Website operators have one month to comply with stricter cookie consent rules, addressing dark patterns and ensuring an equal choice between accepting and rejecting cookies.
Send a text
Privacy Corner Newsletter: Dec 5, 2024
In this edition:
The FTC proposes orders targeting sensitive data misuse, Australia bans kids from social media, and noyb gains new powers for collective GDPR actions.
▶ FTC targets sensitive location data misuse in proposed orders:
Gravy Analytics and Mobilewalla face sanctions for selling sensitive location data, including segments like “New Parents” and “LGBTQ+ Community.”
▶ Australia bans kids from social media and reforms privacy laws:
New laws require stricter age verification, ban accounts for under-16s, and introduce a tort for serious privacy invasions.
▶ Noyb gains rights to bring GDPR “class actions” across the EU:
Now recognized as a “qualified entity,” noyb can enforce collective claims and injunctions against GDPR violations.
Send a text
Privacy Corner Newsletter: November 21, 2024
▶ German Court Opens the Door to Mass Data Breach Lawsuits:
Germany’s Federal Court rules that "loss of control" over personal data qualifies for damages under GDPR Article 82—no proof of distress or financial loss required.
▶ Meta’s ‘Unskippable Ads’ Solution Gains EDPB Attention
Meta launches a free tier with ads using minimal data and unskippable formats in response to EU demands.
▶ Cyber Resilience Act Imposes New Rules on Digital Products
The EU’s Cyber Resilience Act sets strict cybersecurity and data protection requirements for most digital products, with significant penalties for non-compliance starting 2027.
#Privado #ThePrivacyCorner #GDPR #EDPB #CyberAct #EU
Send a text
Privacy Corner Newsletter: November 7, 2024
In this edition, we dive into the latest updates on GDPR fines, data broker enforcement, and the EU-US Data Privacy Framework review:
▶ Ireland fines LinkedIn €310 million, six years after a complaint—with full EDPB support:
The Irish DPC issues a €310 million fine against LinkedIn for GDPR violations, marking a significant shift in enforcement under new leadership.
▶ California prepares for a data broker enforcement sweep:
The California Privacy Protection Agency targets non-compliant data brokers, enforcing new registration and deletion requirements under the Delete Act.
▶ The EDPB reviews the first year of the EU-US Data Privacy Framework:
The EDPB’s first-year review of the EU-US DPF highlights both successes and areas for improvement in the data-sharing framework.
#privado #privacycodescanning #compliance #privacyengineering #gdpr #cpra #ccpa #mhmda #dataprivacy #compliance #softwarecodescanning
Send a text
Privacy Corner Newsletter: October 24, 2024
This week, we dive into the UK’s resurrected data reform bill, ePrivacy Directive guidelines, and a new complaint against Pinterest.
▶ Back from the Dead: Comparing the UK’s New and Old Data Reform Bills
The UK has introduced a new Data (Use and Access) Bill (DUAB), which incorporates several proposals from the previously scrapped Data Protection and Digital Information Bill (DPDIB). The DUAB revives and reshapes key provisions, such as legitimate interests and cookie consent exemptions, while dropping several controversial aspects from its predecessor.
How might these changes in UK legislation affect your organization's data compliance strategy?
▶ EDPB Finalizes ePrivacy Directive Guidelines: Fingerprinting, SDKs, and APIs Firmly in Scope
The European Data Protection Board (EDPB) has published its final guidelines clarifying how the ePrivacy Directive applies to modern tracking technologies. Developers and privacy professionals should note that the Directive covers not just cookies but newer methods like device fingerprinting and SDKs—tightening consent requirements across digital platforms.
Are your tracking technologies compliant with the latest ePrivacy Directive guidelines?
▶ Pinterest Hit by noyb Complaint: Cookies and the Right to Data Recipient Information
A complaint has been filed by privacy group noyb against Pinterest, alleging insufficient disclosure about the sharing of users' personal data. The case could set a new precedent on the amount of detail required in responses to data subject access requests, especially regarding which third parties receive personal data.
Could your data subject access request processes withstand a similar challenge?
Send a text
Privacy Corner Newsletter: October 10, 2024
▶ Court ruling on credit card data: The UK tribunal rules that credit card numbers alone may not always qualify as personal data, challenging the ICO’s interpretation. This decision could reshape how companies assess their data protection obligations after a breach. How will this impact your approach to classifying sensitive data?
▶ EDPB clarifies processor responsibilities: New guidance outlines the extent to which controllers are accountable for sub-processors. Critical insights for your GDPR compliance strategy.
▶ CJEU redefines legitimate interest: A commercial interest can now qualify as a legitimate interest under GDPR—but only under specific conditions. What this shift means for your data processing activities.
Sponsored by Privado.ai
Send a text
Privacy Corner Newsletter: September 26, 2024
This week’s Privacy Corner highlights key developments in EU data protection:
▶ French CNIL: New guidelines set to affect over 10,000 mobile app developers; enforcement sweep scheduled for Spring 2025.
▶ UK ICO: Issued a reprimand to SkyBet, marking their most significant cookie action to date; 99% of top websites now comply with cookie regulations.
▶ EU Advocate General: Emphasized the need for clear and concise explanations of automated decisions; data subjects entitled to meaningful information about the decision-making process.
Sponsored by Privado.ai
Send a text
Privacy Corner Newsletter: September 5, 2024
This newsletter covers key privacy developments, including:
▶ Uber's €290 Million GDPR Fine: The Dutch DPA fined Uber for failing to use appropriate safeguards when transferring personal data from its EU entity to the US, despite Uber's claim it wasn't necessary. This case highlights the confusion around international data transfers under GDPR.
▶ Swedish Pharmacies Fined for Using Meta Pixel (Even with Consent): These pharmacies demonstrate that getting user consent for tracking isn't enough. Organizations must also implement proper security measures and assess risks before using tracking tools.
▶ Google Loses Round in Chrome Tracking Case: A California court revived a lawsuit against Google for allegedly misleading users about data collection in Chrome's "Basic Browser Mode." The court ruled a "reasonable user" wouldn't expect such data collection without being signed in.
From the publisher's feed
Join Privado.ai each week as he navigates the ever-changing landscape of data breaches, surveillance, and individual rights, offering expert insights and actionable advice to help you take control…

4,347 Listeners

87,180 Listeners

111,779 Listeners

5,787 Listeners

22 Listeners

29 Listeners

10,186 Listeners

509 Listeners

5,559 Listeners

6 Listeners

10,753 Listeners

10 Listeners

610 Listeners

12 Listeners