OpenAI, the company behind the successful ChatGPT, has been in the spotlight recently due to privacy concerns, particularly in the European Union. Italy’s data protection authority, known as the Garante, imposed a temporary ban on the platform on 31 March, following reports of a data breach that affected ChatGPT users‘ conversations and payment information. As […]
Internationaler Datenschutz
Internationaler_Datenschutz
New regime for data transfers from China to third countries
February 2023 was a busy month for China’s data protection regulator and supervisory authority – the Cyberspace Administration of China (CAC). This month marks the end of the six-month grace period for the Regulation of Security Assessment for Outbound Data Transfer (hereinafter referred to as the “Regulation”). With the Regulation now fully in force, companies […]
TikTok auf Diensthandys verbannt!
Aus Sicherheitsgründen unternehmen immer mehr Staaten und Institutionen Maßnahmen, um die Nutzung der chinesischen Kurzvideoplattform zu unterbinden. So dürfen Beschäftigte der EU-Kommission und des EU-Parlaments seit Mitte März die App weder auf ihrem Diensthandy installieren noch nutzen. Hintergrund Neben mangelndem Schutz junger Nutzer*innen wird TikTok längst eine unzureichende Datensicherheit vorgeworfen. Mehrere Staaten gehen davon aus, […]
EU – most relevant GDPR fines of the last years
More than four years after the General Data Protection Regulation 2016/679 (GDPR) came into force, companies and organizations that process personal data inside and outside the EU have come to realize the benefits that a privacy-friendly business management can entail. Moreover, in the last years it became evident that processing personal data in violation of […]
The New Look of Cross-Border Transfers in Switzerland
The Swiss Parliament passed the revised Federal Act on Data Protection (nFADP) in the fall of 2020. The Swiss Federal Council announced that the law will enter into force on September 1, 2023. As there will be no transition period, the requirements must be met from the first day the law becomes effective. While we […]
EU Commission published Draft Adequacy Decision for EU – US data transfer
On 13 December 2022, approximately only 1 month after the signing of President Biden’s Executive Order, the European Commission announced the Draft Adequacy Decision for EU – US Data Transfers. This time-record achievement officially launches the process towards the adoption of the Adequacy Decision for the proposed EU-US Data Privacy Framework, and may put a […]
Irish DPC: Facebook Data Scraping not in line with Art. 25 of the GDPR
In 2021, media reports raised serious questions about how Facebook was dealing with the collected personal data of around 530 million Facebook users. Between 2018 and 2019, these datasets, which also included the email addresses and mobile phone numbers of Facebook users, were exposed on the internet. Following the media reports of these serious data […]
Das neue Schweizer Datenschutzgesetz
Das erste Bundesgesetz über den Datenschutz in der Schweiz (DSG) vom 19.06.1992 trat 1993 in Kraft. Seit dem Inkrafttreten des DSG gab es vielfältigste technologische Entwicklungen, die in der bestehenden Form – logischerweise – nicht im Gesetz aus 1992 berücksichtigt werden konnten. In 2008 erfolgte bereits eine Teilrevision des Schweizer DSG mit dem Ziel, die […]
Google and the U.S.: A multi-state historic privacy settlement
Google, the giant U.S. tech company, will pay a total of $391.5 million to 40 U.S. states, which is the largest multi-state privacy settlement with state Attorneys General in the U.S. history. The main reason behind the fine is that the online search engine platform has engaged in deceptive and unfair actions in violation of […]
„Old“ Standard Contractual Clauses to be Invalid as of the End of December (27.12.2022)
The European Commission decided on new Standard Contractual Clauses (SCCs) in June 2021. After 27 December 2022, only these „new“ SCCs may be used without exception. What does that mean for companies and organizations? If personal data is transferred to processors (or their sub-processors) or to controllers in a country outside the EU or the […]
One Step Closer to a EU-U.S. Adequacy Decision
On October 7, 2022, U.S. President Biden signed the long-awaited Executive Order (EO) on ‘Enhancing Safeguards for United States Signals Intelligence Activities‘. Some would say it is merely a memorandum on how the US will continue to spy on individuals. Others would say it is an effort to control the intelligence system in place without […]
„Alte“ Standardvertragsklauseln ab Ende Dezember ungültig
Wenn Sie bzw. Ihr Unternehmen personenbezogene Daten in Drittstaaten übermitteln, dann ist bis zum 27.12.2022 eine Überprüfung dieser Drittland-Datenübermittlungen erforderlich. Rechtlicher Hintergrund Erfolgt bei der Zusammenarbeit mit Auftragsverarbeitern (bzw. dessen Unterauftragsverarbeitern) oder Verantwortlichen eine Übermittlung personenbezogener Daten in ein Land außerhalb der EU bzw. des EWR, für das kein Angemessenheitsbeschluss der EU-Kommission besteht, wird regelmäßig […]
Spanish Supreme Court: Data subjects can submit their complaint directly to a supervisory authority
According to a decision of the Spanish Supreme Court (Tribunal Supremo) of July 2022, filing a request to exercise the data subject rights with the data controller is not a prerequisite for filing a complaint to the relevant Supervisory Authority for an alleged breach of the GDPR. The decision was issued after a complaint of […]
Will the American Data Privacy and Protection Act Become Law Eventually?
While some U.S. states have data privacy laws, amongst them California, known to have the strictest privacy law, to date, the United States do not have a federal data protection act. In June this year, a first draft of the American Data Privacy and Protection Act (ADPPA) was proposed. The draft bill received bipartisan support and […]
UK GDPR Reform
In September 2021, the government launched its consultation here to draw proposals to make substantial changes in the UK Data Protection Laws which were less stringent than the EU GDPR but still covered all the important data protection rights. The UK government has expressed that the focus of this reform is to make a trusted […]