Conseil d’Etat “sanctioned” French Data Protection Authority For Not Anonymizing A Decision

The Conseil d’Etat (the French supreme administrative court) sanctioned the CNIL (Commission Nationale de l’Information et des Libertés) which is the Data Protection Agency for not anonymizing the personal data contained in a decision issued that the DPA issued, as recommended by the same CNIL in Délibération n° 01-057 du 29 novembre 2001 portant recommandation sur la diffusion de données […]

Bipartisan Bill to extend European citizens certain rights that Americans have under the Privacy Act of 1974

Last week a bipartisan bill (Judicial Redress Act of 2015) was introduced by Senators Chris Murphy (D-Conn.) and Orrin Hatch (R-Utah). The proposal echoes a  similar proposal in the House presented in March from Congressmen Jim Sensenbrenner (R-Wis.) and John Conyers (D-Mich.) (here), which received also the support of the major tech companies of the United […]

U.S. has the strongest cybersecurity in the world, according to the Global Cybersecurity Index (GCI)

On May 28, 2015, ABI Research and the International Telecommunication Union issued a Global Cybersecurity Index (GCI) report according to which the U.S. has the strongest cybersecurity in the world. The CGI aims at providing a worldwide snapshot of where countries stand on cybersecurity. It drafts a country-level index and a global ranking on cybersecurity […]

Italian DPA issued guidelines on online profiling of personal data

On March 19, 2015, the Italian Data Protection Authority issued Doc 3881513 providing guidelines for web operators performing online profiling. The document applies to web operators established in Italy. The guidelines clarify the principles applicable to profiling activities aiming at singling out users. These profiling activities generally aim at offering targeted services, or advertisement, as […]

EU Data Protection Regulation update: EU Council reaches agreement on main topics of Regulation

On June 15, 2015, Ministers in the Justice Council have sealed a General Approach on the Commission Data Protection Regulation proposal. According to the Commission’s memo, the general approach on the Data Protection Regulation includes agreement on the following main topics: One continent-one law – the Regulation will establish a single set of rules on data […]

Italian Data Protection Authority issued guidelines on the use of cookies

On June 5, 2015, the Italian Data Protection Authority (“DPA”) issued Doc 4006878 clarifying specific issues concerning the implementation of the law on cookies (Individuazione delle modalità semplificate per l’informativa e l’acquisizione del consenso per l’uso dei cookie – Means to inform and obtain consent for the use of cookies, dated May 8, 2014 [3118884]). In […]

Data breach notification obligation and increased fines for privacy violations in The Netherlands

On May 26, 2015, the Eerste Kamer (First Chamber), aka the Dutch Senate, passed into law a draft bill that had been approved by the Tweete Kamer (Second Chamber), aka House of Representatives, in March (text available in Dutch here). The Law introduces an obligation to notify the Dutch DPA ‘without delay’ in case of a data breach. After broadening the DPA’s […]

ePrivacy Directive: assessment of transposition, effectiveness and compatibility with proposed Data Protection Regulation

On June 10, 2015, The European Commission published a study on the “ePrivacy Directive: assessment of transposition, effectiveness and compatibility with proposed Data Protection Regulation” (SMART 2013/0071). The study examines two main issues. Whether the ePrivacy Directive has achieved its intended effects and puts forward recommendations for future revision on the basis of the Directive transposition […]