French data protection authority CNIL Friday published the final version of its guide on impact assessment of data transfers. The guide aims to ensure that companies ensure the same level of protection as the General Data Protection Regulation (GDPR) in their data flows.
The European Court of Justice's General Court ruled Wednesday that the Irish Data Protection Commission (DPC) acted unlawfully when it refused to investigate a complaint from Noyb, the Austrian privacy organization. The ruling was issued in Data Protection Commission v. European Data Protection Board (joined cases T‑70/23, T‑84/23 and T‑111/23).
Personal data protection is important but shouldn't be an unnecessary obstacle to innovation and development, the Swedish Data Protection Authority said Tuesday in a newspaper op-ed unofficial translation. Accordingly, there are good reasons to consider criticism of the General Data Protection Regulation (GDPR), it added.
European collaboration with the U.S. on privacy issues is going to be tough, representatives from the European Commission and European Parliament said Tuesday at a Data Protection Day conference in Brussels.
Finding common ground on data protection "remains a challenging task, primarily because privacy is deeply shaped by cultural, legal, and economic contexts," Ginervra Cerrina Feroni, vice-president of Italian privacy watchdog Garante, said in an email. The General Data Protection Regulation (GDPR), for example, is rooted in a fundamental rights-based approach, while frameworks like the Global Cross Border Privacy Rules (CPBR) system emphasize voluntary compliance and flexibility, reflecting different traditions and priorities.
CNIL, the French regulator, will pay "particular attention" in coming months to whether software development kit (SDK) providers are complying with the GDPR, it announced Tuesday (according to an informal translation). SDK providers play a central role in the operation of mobile apps. Popular SDKs include audience measurement and advertising monetization, the CNIL document said. When the regulator published recommendations earlier on integrating SDKs and implementing controls to ensure GDPR compliance, it notified SDK suppliers that it would start checking compliance this spring.
There are grounds for "intense" collaboration among authorities responsible for enforcing EU digital laws such as the General Data Protection Regulation (GDPR) and AI Act (AIA), privacy lawyer Petruta Pirvan said during a Sypher webinar Wednesday in Bucharest, Romania. Especially in the context of AI systems that process personal data, logic is strong for regulators cooperating, said Pirvan, a member of the European Commission's GPAI code of practice working group.
In addition to an increase in privacy laws, 2025 is expected to bring an escalation of privacy and data protection claims under old laws, said International Association of Privacy Professionals (IAPP) members on a webinar Wednesday.
The European Data Protection Board (EDPB) Friday clarified the use of pseudonymized data for EU General Data Protection Regulation compliance. Comments on the guidelines are due Feb. 28.
Mobile apps often process personal data that users provide or is collected directly when the app accesses resources in smartphones and tablets, French data protection agency CNIL said Tuesday, according to an unofficial translation.