EU Data Protection Regulation update: EU Council reaches agreement on main topics of Regulation

On June 15, 2015, Ministers in the Justice Council have sealed a General Approach on the Commission Data Protection Regulation proposal. According to the Commission’s memo, the general approach on the Data Protection Regulation includes agreement on the following main topics: One continent-one law – the Regulation will establish a single set of rules on data […]

Italian Data Protection Authority issued guidelines on the use of cookies

On June 5, 2015, the Italian Data Protection Authority (“DPA”) issued Doc 4006878 clarifying specific issues concerning the implementation of the law on cookies (Individuazione delle modalità semplificate per l’informativa e l’acquisizione del consenso per l’uso dei cookie – Means to inform and obtain consent for the use of cookies, dated May 8, 2014 [3118884]). In […]

Data breach notification obligation and increased fines for privacy violations in The Netherlands

On May 26, 2015, the Eerste Kamer (First Chamber), aka the Dutch Senate, passed into law a draft bill that had been approved by the Tweete Kamer (Second Chamber), aka House of Representatives, in March (text available in Dutch here). The Law introduces an obligation to notify the Dutch DPA ‘without delay’ in case of a data breach. After broadening the DPA’s […]

ePrivacy Directive: assessment of transposition, effectiveness and compatibility with proposed Data Protection Regulation

On June 10, 2015, The European Commission published a study on the “ePrivacy Directive: assessment of transposition, effectiveness and compatibility with proposed Data Protection Regulation” (SMART 2013/0071). The study examines two main issues. Whether the ePrivacy Directive has achieved its intended effects and puts forward recommendations for future revision on the basis of the Directive transposition […]

Italian Data Protection Authority’s guidelines for controllers of biometric data

On November 12, 2014, the Autorità Garante della Privacy (Italian Data Protection Authority) issued a decision together with guidelines on the processing of biometric data. The DPA clarified that “a biometric data is a personal data as it can always be considered to be “information relating to an identified or identifiable natural person” by having […]

Cristina Vicarelli, Cookies: ten things to consider

Nowadays in Italy there is a big debate on “cookies”. Starting on June 3, 2015, data controllers shall implement the requirements issued by the Italian Data Protection Authority (Garante) with  Decision no. 229 of 8 May 2014 “Simplified Arrangements to Provide Information and Obtain Consent Regarding Cookies” (Published in the Official Journal no. 126 of […]

Email containing personal and health information is protected by privacy law and cannot be forwarded without consent, Italian Data Protection Authority holds

On April 23, 2015, the Italian Data Protection Authority (DPA) held that the privacy of the sender of an e-mail containing her personal and health information is violated when the email is forwarded without her consent. In this case, an employer of an IT company sent a promotional email to some franchisors of a real […]