An update from WP29 on the “right to be forgotten” in Europe

On June 18, 2015, the Article 29 Working Party (WP29) released a press statement to share the results of a survey launched to evaluate the EU practice regarding de-listing requests. A little more than one year ago the European Court of Justice (“ECJ) issued its famous”right-to-be-forgotten”decision in the Costeja case, C-131/12, holding that data subjects have […]

Tags: ,

U.S. has the strongest cybersecurity in the world, according to the Global Cybersecurity Index (GCI)

On May 28, 2015, ABI Research and the International Telecommunication Union issued a Global Cybersecurity Index (GCI) report according to which the U.S. has the strongest cybersecurity in the world. The CGI aims at providing a worldwide snapshot of where countries stand on cybersecurity. It drafts a country-level index and a global ranking on cybersecurity […]

Tags: , ,

Italian DPA issued guidelines on online profiling of personal data

On March 19, 2015, the Italian Data Protection Authority issued Doc 3881513 providing guidelines for web operators performing online profiling. The document applies to web operators established in Italy. The guidelines clarify the principles applicable to profiling activities aiming at singling out users. These profiling activities generally aim at offering targeted services, or advertisement, as […]

Tags: ,

EU Data Protection Regulation update: EU Council reaches agreement on main topics of Regulation

On June 15, 2015, Ministers in the Justice Council have sealed a General Approach on the Commission Data Protection Regulation proposal. According to the Commission’s memo, the general approach on the Data Protection Regulation includes agreement on the following main topics: One continent-one law – the Regulation will establish a single set of rules on data […]

Tags: ,

Italian Data Protection Authority issued guidelines on the use of cookies

On June 5, 2015, the Italian Data Protection Authority (“DPA”) issued Doc 4006878 clarifying specific issues concerning the implementation of the law on cookies (Individuazione delle modalità semplificate per l’informativa e l’acquisizione del consenso per l’uso dei cookie – Means to inform and obtain consent for the use of cookies, dated May 8, 2014 [3118884]). In […]

Tags: ,

ePrivacy Directive: assessment of transposition, effectiveness and compatibility with proposed Data Protection Regulation

On June 10, 2015, The European Commission published a study on the “ePrivacy Directive: assessment of transposition, effectiveness and compatibility with proposed Data Protection Regulation” (SMART 2013/0071). The study examines two main issues. Whether the ePrivacy Directive has achieved its intended effects and puts forward recommendations for future revision on the basis of the Directive transposition […]

Tags: ,

Italian Data Protection Authority’s guidelines for controllers of biometric data

On November 12, 2014, the Autorità Garante della Privacy (Italian Data Protection Authority) issued a decision together with guidelines on the processing of biometric data. The DPA clarified that “a biometric data is a personal data as it can always be considered to be “information relating to an identified or identifiable natural person” by having […]

Tags: ,

European Data Protection Supervisor (EDPS)’s Opinion 1/2015 on m-health

On May 21, 2015, the European Data Protection Supervisor (EDPS) published Opinion 1/2015 (Mobile Health – Reconciling Technological Innovation with Data Protection). The opinion acknowledges that Mobile Health (“mHealth”) is a rapidly growing sector stemming out of the convergence between healthcare and ICT. mHealth includes mobile applications designed to deliver health-related services through smart devices. Big […]

Tags: , ,

WP29 clarifies how multinational processors implement Binding Corporate Rules (BCR)

On May 22, 2015, the Article 29 Working Party (WP29) adopted a revised version of the Explanatory Document on the Processor Binding Corporate Rules (BCR). “Binding Corporate Rules” are binding internal rules intended to regulate the transfers of personal data that are originally processed by the organization as Controller within the same organization. The Document aims […]

Tags: ,

1 2 3 4 5 6 12