Data broker legislation enacted in Vermont

On May 22, 2018, Vermont passed a new data broker piece of legislation, Act No. 171 (H.764), which adopts a number of consumer protection provisions relating to data brokers, their data collection practices, and consumers’ right to opt out of them. It ensures that data brokers have adequate security standards, it aims at prohibiting the […]

ICO fines Emma’s Diary £140,000

On August 20, 2018, the Information Commissioner Officer, ICO – the British data protection authority – fined Lifecycle Marketing (Mother and Baby) Ltd, aka Emma’s Diary, £140,000 for failing to comply with the data protection ‘fairness’ principle. The principle imposes a transparency duty requiring data controllers to provide data subjects with information about the purposes […]

Brazil approves new General Data Protection Law

On August 14, 2018, the Brazilian president signed the Lei Geral de Proteção de Dados Pessoais (“LGPD”) into law. The LGPD is a comprehensive data privacy regulation, which has many similarities with the GDPR, such as for example its broad scope of application, which includes processing activities conducted wholly outside of Brazil, but affecting or […]

Italian DPA issues 2017 annual activity report – some interesting (and perhaps unexpected) information

On July 10, 2018, the Italian Data Protection Authority (DPA), the Garante per la Protezione dei Dati Personali, issued the annual report on its activity for 2017. The English version of the report is not yet available. However, we extracted some numbers for you from the Italian text. Overall, there is a decrease in the number of […]

Irish DPA prepared a list of processing operations that require DPIA open for public consultation

In June 2018 the Irish Data Protection Commission (DPC) published a draft list of processing operations for which it is mandatory to conduct a data protection impact assessment (DPIA). The list is intended to encompass both national and cross-border data processing under Article 35 of the General Data Protection Regulation (GDPR). With a view to […]

Another step toward an EU online market place without discrimination based on customers’ location: Regulation (EU) 2018/302

On March 22, 2018, the new EU rules against unjustified geo-blocking (Regulation (EU) 2018/302) entered into force and will be applicable starting December 3, 2018. The Regulation aims at abolish discrimination based on nationality and residence. Sellers will have to stop denying access to websites from one Member States to the other, preventing purchases of […]

Italian DPA forbids pop-up requiring one consent for data processing for various purposes

On May 22, 2018, the Garante per la Protezione dei Dati Personali, Italy’s Data Protection Authority (DPA), prohibited a company offering a comparison service for light, gas, mobile line, insurance, mortgages (and other services) on its website (Company) to process for marketing and sales purposes the data collected through a pop-up on its website. The […]

Italian police authority explains how it will verify companies’ privacy compliance

Informazionefiscale.it reported an interesting interview with Marco Menegazzo, commander of the Special Privacy Unit of the Italian Guardia di Finanza, who spoke during the Privacy Day Forum held on May 25, 2018, and which dealt with privacy, sanctions and checks under the GDPR. Which checks will be carried out by the Italian authority under the GDPR? […]