#materials #privacy #databreach

И завершаю сегодняшнюю кофеинную ддос атаку интереснейшим отчетом от IBM - Cost of Data Breach Report 2022

А вот и подборка новостей от Олега Блинова, на английском.

🔸 Baden-Württemberg: Public Procurement Chamber finds possibility of data access by third country contrary to GDPR.

The Public Procurement Chamber of Baden-Württemberg decided it is an infringement upon Chapter V if there is even a possibility that the US parent of a EU subsidiary providing cloud services may access data. Crazy and adding to operational risk of use of AWS, Azure and others.

🔸 Geolocation of rental vehicles: UBEEQO INTERNATIONAL fined 175,000 euros.

The CNIL carried out investigations on the company UBEEQO INTERNATIONAL, which rents vehicles for a short period. The company collected data relating to the geolocation of the rented vehicle every 500 meters. Breaches:

minimisation: CNIL decided that the purposes of the company (maintenance and performance of the service, location in case of theft, assistance to customers) do not justify collection of geolocation. Impact: just higher uncertainty when approving business activities.

retention: 3 years storage is too much. CNIL also took issue with the fact that the company stored data of people who had been inactive for more than eight years. Impact: storage period are consistently capped at below 3 years; regulators regularly state that inactive users should be booted.

transparency: not entirely clear what the CNIL did not like.

🔸 900,000 euro fine against credit institution for profiling for advertising purposes.

A bank analyzed data of active and former customers (total volume of purchases in app stores, the frequency of use of statement printers, and the total amount of transfers). Results of the analysis were compared with a credit agency and enriched from there. The aim was to identify customers with a greater propensity for digital media and to address them more effectively. The DPA was extremely clear that LI cannot be relied upon for profiling, as people do not have an expectation that data controllers will use data files on a large scale to identify their inclination toward certain product categories or communication channels.

Impact: very straight-forward ban on reliance on LI for creating ads profiles and optimization based on user actions and attributes.
15.6 MB
#materials #privacy

Data Protection Supervising Authorities.
Liability for infringements of data protection law

Источник: Денис Садовников
#materials #fines #privacy

С просторов Linkedin - калькулятор рассчета стартовой суммы штрафов за нарушения GDPR - DeFine, учитывающий, в тч EDPB методологию.

💬Источник: Екатерина Калугина
#materials #special #privacy

Стоит обратить внимание на решение CJEU, содержащее в себе в том числе трактовку определения спец категории ПД.

▫️Article 9(1) of the GDPR provides that, inter alia, processing of personal data ‘revealing’ racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of data ‘concerning’ health or data ‘concerning’ a natural person’s sex life or sexual orientation, are to be prohibited.

▫️The verb ‘reveal’ is consistent with the taking into account of processing not only of inherently sensitive data, but also of data revealing information of that nature indirectly, following an intellectual operation involving deduction or cross-referencing, the preposition ‘concerning’ seems, on the other hand, to signify the existence of a more direct and immediate link between the processing and the data concerned, viewed inherently.

▫️Those provisions cannot be interpreted as meaning that the processing of personal data that are liable indirectly to reveal sensitive information concerning a natural person is excluded from the strengthened protection regime prescribed by those provisions, if the effectiveness of that regime and the protection of the fundamental rights and freedoms of natural persons that it is intended to ensure are not to be compromised.
Article 9(1) of the GDPR must be interpreted as meaning that the publication of personal data that are liable to disclose indirectly the sexual orientation of a natural person constitutes processing of special categories of personal data, for the purpose of those provisions.

💬Источник: Денис Садовников
3.1 MB
#materials #privacy

Ответы на вопросы по статистическому методу расчета рисков доступа представителей ин власти к данным от Розенталя

💬Источник: Олег Блинов
#НеДляГалочки #podcast

🎙Реформа закона о персональных данных 2022 — как жить с новыми требованиями?

14 июля 2022 года был принят Федеральный закон № 266-ФЗ, которым внесены существенные изменения в Закон о персональных данных (№ 152-ФЗ). В этом выпуске обсуждаем самые горячие и сложные вопросы в связи с изменениями:

🔥 Экстерриториальное действие закона: как иностранные компании будут исполнять его требования [2:00]
🔥 Трансграничная передача: новые правила об уведомлении РКН и проверке контрагента [16:10]
🔥 Уведомления об утечках: будет ли работать новый порядок на практике [40:18]
🔥 ГосСОПКА: что это такое и надо ли всем туда подключаться [54:05]

Ведущие выпуска:
🤩 Приглашенная privacy-звезда — Алексей Мунтян, со-основатель RPPA, фаундер фирмы Privacy Advocates
Ирина Шурмина, SEAMLESS Legal (ex-CMS)
Кристина Боровикова, со-основатель RPPA, Kept
Ксения Андреева, Morgan Lewis
Елизавета Дмитриева, data privacy engineer в российском инхаусе

🧸Благодарим всех за поддержку и призываем писать нам отзывы, пожелания и предложения!

Apple | Yandex
Реформа 152-ФЗ "О персональных данных" за 33 секунды =)
Спасибо, @ShirmanV!

#materials #privacy

Статья Персональные данные. Ответы на вопросы работодателей и примеры формулировок для договора.

💬Авторы: Марина Юфа, Владислав Симоненко

Свежачок от Олега Блинова

🔸 Facebook avoids a service shutdown in Europe for now (

As was probably predictable, the Irish regulator received objections to their intention to shutdown FB for transfer of data to the US. It is likely that the internal discussions and dispute resolutions will take months and months.

🔸France: CNIL proposes €60M fine against Criteo for non-compliance with GDPR (

Very little is actually clear from the news. From my short review of the 2018 complaint of an activist group, it seems the applicant (and later CNIL) allege that AdTech data brokerage should rely on consent due to cross-tracking. Relevant for fb and TCF-based data sharing.

🔸 EU: NOYB lodges 226 complaints against websites’ cookie banner settings (

Another case of NOYB activism.

🔸 IP (Slovenia) - 0612-23/2019/19 ( (kudos @actuaris)

From the description of the case it may appear that the vendor fulfilled a completely technical role of providing integrations for data transmission. However, the DPA found that because clients had no power to ensure technical compliance with the GDPR, the cloud computing provider was acting as controller. Hence, the parties had to sign a JC agreement. No fine imposed.
#jobs #privacy

Data Privacy Jobs Report

💬Источник: Денис Садовников
